Cloud Computing for Banking Technology Teams Training Course
| Course code | SD-CC-009 |
|---|---|
| Duration | 5 days |
| Level | Foundation to Intermediate |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Bank technology teams are under pressure to modernise core-adjacent applications, data platforms, digital channels and resilience capabilities without weakening controls over customer data, payments, audit evidence or third-party risk. Cloud decisions in a bank cannot be treated as infrastructure choices alone: architecture, identity, data classification, outsourcing governance, operational resilience and cost accountability must work together. This course helps participants assess where cloud adoption is appropriate, identify control gaps early, and communicate defensible designs to security, risk, compliance and business stakeholders.
Participants examine banking cloud operating models across IaaS, PaaS, SaaS and managed services. They learn to apply shared-responsibility models, classify regulated workloads, design identity and access controls, select encryption and key-management patterns, and plan data residency and retention controls. The course also covers landing zones, network segmentation, DevSecOps guardrails, business continuity, disaster recovery, cloud monitoring, FinOps and supplier exit planning. Practical work uses AWS IAM, Azure Policy, Terraform and Kubernetes concepts to connect policy requirements with technical implementation.
The programme is delivered through instructor-led briefings, architecture reviews, guided tool exercises and a five-day banking cloud case study. Participants work in teams to design a controlled migration for a digital banking workload, documenting workload classification, target architecture, control ownership, resilience targets, cost controls and evidence requirements. Each participant leaves with a banking cloud adoption assessment pack and a 90-day application plan that can be adapted for their own platform, programme or governance forum.
It is suited to professionals moving from traditional infrastructure, security, risk or application delivery roles into cloud-enabled banking technology work, as well as managers who need a common decision framework across technical and control functions.
Course objectives
By the end of this course, participants will be able to:
- Assess banking workloads using a risk, data classification, criticality and cloud-suitability matrix
- Apply the shared-responsibility model to allocate security, operations and evidence obligations across cloud services
- Design a landing-zone control baseline covering identity, network segmentation, logging, encryption and tagging
- Configure least-privilege access patterns using AWS IAM roles, policies and multi-factor authentication concepts
- Translate banking control requirements into Azure Policy-style preventive, detective and audit guardrails
- Produce a cloud resilience design with RTO, RPO, backup, failover and service-recovery test requirements
- Build a FinOps tagging and chargeback model for banking applications, environments and cost owners
- Create a cloud adoption assessment pack including architecture decisions, control evidence and supplier exit actions
Benefits of attending
For you
- Gain a practical framework for judging whether a banking workload is ready for cloud migration or modernisation
- Build credibility in architecture and governance discussions by linking technical designs to risk and control evidence
- Learn to document cloud decisions in formats usable by security review boards, risk committees and delivery teams
- Develop hands-on familiarity with IAM, policy-as-code and container governance concepts used in regulated cloud environments
- Leave with a portfolio-ready banking cloud assessment pack that demonstrates applied cloud governance capability
For your organisation
- Improve cloud investment decisions through consistent workload classification, risk assessment and target-state criteria
- Reduce control gaps by defining ownership for identity, encryption, logging, resilience and audit evidence before migration
- Shorten security and risk-review cycles with clearer architecture documentation and reusable control baselines
- Strengthen operational resilience planning through explicit RTO, RPO, backup, failover and recovery-test requirements
- Increase cloud cost accountability through standard tagging, budget ownership, chargeback and optimisation practices
Target competencies
Who should attend
- Banking IT Managers — who approve cloud roadmaps and need to balance delivery speed with control obligations
- Cloud and Infrastructure Engineers — who design landing zones, connectivity and operational cloud services
- Information Security Professionals — who must translate security policies into enforceable cloud controls
- Application and Solution Architects — who assess which banking workloads can move, modernise or remain on-premises
- Technology Risk and Operational Resilience Analysts — who evaluate outsourcing, recovery and control evidence
- DevOps and Platform Engineers — who embed policy, identity, logging and cost controls into delivery pipelines
Requirements and prerequisites
Participants should understand basic enterprise IT concepts, including servers, virtual networks, applications, databases, user access and information security controls. Familiarity with a cloud provider console, Linux or Windows administration, networking, or software delivery is useful but not essential. Participants should also be able to discuss their organisation’s application landscape and the sensitivity of customer, payments or financial data. No previous AWS, Azure, Terraform, Kubernetes, coding or cloud certification is required. Complete beginners should expect a structured introduction before progressing to banking-specific architecture, governance and control exercises.
Training methodology
The instructor uses short technical briefings to establish concepts, then moves quickly into banking scenarios involving mobile banking services, customer data, payment interfaces and regulated third parties. Participants review architecture diagrams, classify workloads, identify control owners and test policy decisions through guided AWS IAM, Azure Policy, Terraform and Kubernetes exercises. Small groups complete daily design reviews and challenge each other’s assumptions as a risk, security or audit stakeholder would. The final session converts the case-study work into an individual 90-day cloud adoption application plan.
Course outline
Day 1: Banking cloud foundations and workload decisions
- Cloud service models for regulated banking workloads
- Shared-responsibility boundaries across IaaS, PaaS and SaaS
- Banking workload classification by data sensitivity and business criticality
- Cloud suitability assessment for core-adjacent and digital services
- Data residency, sovereignty and cross-border processing considerations
- Outsourcing governance and material third-party service assessment
- Cloud operating model roles across technology, risk, security and procurement
Workshop: Teams assess a mobile banking notification platform and produce a workload classification and cloud-suitability decision matrix.
Day 2: Secure cloud foundations and identity controls
- Landing-zone architecture for multi-account and multi-subscription environments
- Network segmentation using virtual networks, subnets and private endpoints
- AWS IAM users, roles, policies and least-privilege design
- Multi-factor authentication and privileged-access management patterns
- Encryption at rest, encryption in transit and customer-managed keys
- Centralised logging, audit trails and security event retention
- Azure Policy initiatives for resource governance and compliance reporting
Workshop: Participants design a controlled landing-zone baseline and create an identity-and-policy control map for a customer-data application.
Day 3: Cloud delivery, data and operational resilience
- Infrastructure as code with Terraform modules and state management
- DevSecOps control gates for code, infrastructure and deployment pipelines
- Kubernetes namespace, role-based access and workload isolation concepts
- Secure data migration patterns for customer and transaction datasets
- Backup architecture, immutable recovery copies and restoration evidence
- RTO and RPO definition for banking customer-facing services
- Failover design, disaster recovery testing and operational resilience scenarios
Workshop: Teams produce a Terraform-led deployment and recovery design for a digital account-opening service, including RTO, RPO and test evidence.
Day 4: Governance, cost and third-party assurance
- Cloud control mapping to banking security and operational-risk requirements
- Preventive, detective and corrective cloud control design
- Evidence collection for audit, assurance and regulatory review
- FinOps tagging standards for products, cost centres and environments
- Budget alerts, reserved capacity decisions and cloud cost anomaly analysis
- Supplier due diligence, service-level agreements and right-to-audit clauses
- Exit strategies, portability planning and concentration-risk mitigation
Workshop: Participants prepare a cloud supplier governance pack containing control evidence requirements, a tagging model and exit-plan actions.
Day 5: Banking cloud architecture review and adoption planning
- End-to-end target architecture for a regulated banking workload
- Architecture decision records for cloud design trade-offs
- Security, risk and compliance stakeholder review techniques
- Control ownership using responsibility assignment matrices
- Migration-wave prioritisation and dependency analysis
- Cloud service operational metrics and key risk indicators
- Ninety-day adoption roadmap and capability-building actions
Workshop: Each participant presents a banking cloud adoption assessment pack and completes a 90-day plan for applying the course methods in their organisation.
Tools & standards covered
AWS Identity and Access Management (IAM), Microsoft Azure Policy, HashiCorp Terraform, Kubernetes
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Cape Town · USD 4,200 -
05 – 09 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Mombasa · USD 3,200 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200 -
16 – 20 Nov 2026Book
Live Online · USD 1,500 -
23 – 27 Nov 2026Book
Live Online · USD 1,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
Pulumi Cloud Infrastructure Automation Training Course
Cloud teams often inherit manually created environments, inconsistent naming, undocumented access settings and deployment scripts that canno…
HashiCorp Vault Cloud Secrets Management Training Course
Cloud teams often inherit secrets scattered across CI/CD variables, Kubernetes manifests, cloud consoles, shared password stores, and applic…
Ansible Cloud Automation for Infrastructure Teams Training Course
Infrastructure teams are often asked to provision cloud environments quickly while maintaining consistent security controls, naming standard…
Cloud Security Controls for Cybersecurity Analysts Training Course
Cybersecurity analysts are increasingly expected to investigate alerts, validate cloud configurations, assess identity exposure and explain …