Capital One's Data Centre Exit
A major US bank closed all eight of its data centres and moved fully to public cloud, treating governance automation as the enabling technology rather than a constraint.
The programme
Capital One announced in 2020 that it had closed the last of its eight data centres, becoming the first major US bank to run entirely on public cloud. The migration ran from around 2014.
That a heavily-regulated institution reached this position matters, because "we are regulated" is routinely offered as a reason cloud adoption cannot proceed.
What made it possible
Governance expressed as automated policy. The central insight: in a regulated environment, manual review does not scale to cloud's rate of change, so controls must be preventive and automated — policy that stops a non-compliant resource being created, rather than a report saying one was created last month. They open-sourced tooling in this space (Cloud Custodian), which is a useful signal about where the effort actually went.
A standardised landing zone. Account structure, network topology, identity, logging and guardrails defined once and applied to everything, so compliance is inherited by construction rather than assessed per application.
Application-by-application migration, with a disposition decided per application — retire, replatform, rebuild — rather than one strategy for the estate.
Substantial organisational change. They hired heavily into engineering and moved to product- aligned teams. This is the part that is hardest to copy and most determines success; the technology migration was the visible half of a capability change.
The lesson
Compliance is an argument for automation, not against change. Automated, preventive controls produce better evidence than manual processes: every action is logged, every configuration is declarative and reviewable, and drift is detectable. Many organisations end up more auditable after such a migration than before.
The necessary caveat
The 2019 breach — SSRF against a misconfigured WAF, reaching an over-permissive IAM role — happened at the same organisation, mid-programme. Both things are true, and holding them together is the honest reading: a well-governed cloud estate is achievable and does not make individual misconfigurations impossible. Guardrails reduce the rate and the blast radius of mistakes; they do not eliminate them, and a programme that claims otherwise is selling something.