- Thailand
- region
For companies using Amazon Web Services (AWS) through their Thai subsidiaries, the challenge lies not so much in the AWS environment itself, but in the inability of the Japanese headquarters to accurately grasp its operational status. Even when the local team reports that "everything is fine," in reality, monitoring settings, communication channels in case of failures, reasons for increases or decreases in AWS usage fees, IAM permissions, log acquisition, and backup settings may not have been verified. This is not due to malicious intent on the part of the local staff, but rather because they are also responsible for all aspects of the company's IT, prioritizing "keeping the system running" over the audits, recovery verification, and cost optimization required by headquarters.
The general availability of the AWS Asia Pacific (Thailand) region expands the options for using AWS within Thailand. However, simply deciding whether or not to use the Thailand region is not enough to prepare the operational structure. It is necessary to clarify how to handle existing environments running in the Singapore and Tokyo regions, how to design monitoring and backups, and how to divide roles between the local subsidiary and the Japanese headquarters.
This article explains common operational challenges faced by local subsidiaries in Thailand, the types of services that can be outsourced through AWS operations management services, and key points to consider when choosing a support company, for companies considering AWS operations outsourcing in Thailand.
For companies using AWS through their Thai subsidiaries, the challenge lies not so much in the AWS environment itself, but in the inability of the Japanese headquarters to accurately grasp its operational status. Even if the system is running locally, if headquarters cannot verify monitoring settings, communication channels in case of failures, reasons for increases or decreases in AWS usage fees, IAM permissions, log acquisition, and backup settings, the overseas subsidiary's use of AWS becomes a black box.
The local staff members don't have any malicious intent. However, when they are also responsible for all aspects of the company's IT, their top priority is "not to shut down the system right now." As a result, they don't have the time to handle the audits, recovery verification, cost optimization, and access control required by headquarters, and AWS operations depend on the individual staff member's experience and judgment.
Furthermore, the launch of the Thailand region will provide an opportunity to review the AWS environments at overseas locations in line with headquarters standards. This is not simply an addition of a region, but rather an opportunity to review the AWS environments at overseas locations, which have previously been operated individually, in accordance with headquarters standards.
In some Thai subsidiaries, there is no dedicated AWS specialist; instead, local IT staff handle network, PC management, business systems, and vendor support. When AWS monitoring and incident response are also handled under these circumstances, the response procedures and configuration intentions remain only in the minds of the individual staff member, making it difficult to create an operational system that can be replicated by the organization.
If it's not decided who will check an alert, what level of on-site initial response will be handled, and under what conditions will the Japanese headquarters or external vendors be contacted, then decision-making during a failure will be delayed. Even if backups are taken, if recovery procedures and verification methods are not shared, confusion will arise during the restore process.
In this situation, it's necessary to design an operational structure that incorporates external support, rather than leaving AWS operations solely to local staff.
If a Thai subsidiary uses its own AWS account, the Japanese headquarters may not be able to continuously monitor the AWS configuration and operational status. Even if the local subsidiary reports that "there are no problems," the headquarters cannot make a judgment without knowing which AWS account is running which system, which resources are incurring costs, and whether the IAM and network settings comply with headquarters standards.
The issues are cost and security. If AWS usage fees increase without an explanation, it becomes impossible to manage the budget or obtain approval for changes. If the status of log acquisition, backups, and permission settings is not visible, security audits and internal control checks also come to a halt.
The role of AWS operations outsourcing is not limited to simply performing on-site tasks. It also involves creating a system where headquarters can access AWS configuration, costs, security, and incident response history, and connecting overseas AWS operations to headquarters' governance.
The general availability of the Thailand region expands the options for building AWS environments within Thailand. However, location shouldn't be the sole deciding factor. If your existing systems are running in the Singapore or Tokyo regions, you should compare the services used, availability, network, data management, cost, and operational structure before making a decision.
It's not just the region selection that needs reviewing. We also need to clarify who will monitor the system, where backups will be taken, who will make decisions in the event of a failure, and how headquarters will verify AWS usage fees and security settings.
The opening of the Thailand region presents an opportunity to review and ensure that AWS environments at overseas locations are not left outside of headquarters' management. To balance operations tailored to the local subsidiary's business needs with a management system that can be monitored by headquarters in Japan, utilizing AWS operations outsourcing is a viable option.
AWS operations at a Thai subsidiary involve not only technical aspects but also operational structure, scope of responsibility, cost management, and reporting procedures to headquarters. Even if the AWS environment is operational, if monitoring items, response procedures, access control, and cost analysis are not clearly defined, neither the local subsidiary nor the Japanese headquarters can accurately grasp the situation.
The main challenges are the following four:
While these may appear to be individual issues, the root cause lies in the lack of clarity regarding "who is responsible and to what extent." As long as the roles of local personnel, external vendors, and the Japanese headquarters remain ambiguous, both normal operations and responses to incidents will become dependent on specific individuals.
In AWS operations, simply receiving an alert is not enough to complete the response. It is necessary to decide who will review the content, what level of initial response will be provided, and under what conditions the issue will be escalated to the operations outsourcing company or the head office in Japan.
If the scope of notification, troubleshooting, and recovery decisions remains unclear, responses to failures will come to a standstill. When local personnel are also responsible for all aspects of the company's IT, it is essential to have a system in place that does not rely on individual judgment for initial responses to failures.
AWS pricing varies depending on usage. Your monthly bill will differ based on your use of instances, storage, backups, data transfer, and managed services.
If only the local subsidiary is checking AWS usage fees, the Japanese headquarters will not be able to understand the reasons for the increase in costs. It is necessary to be able to check which resources are causing the increase in costs, whether there are any unnecessary resources remaining, and whether there is room for improvement in the configuration.
If you can organize the breakdown of usage fees, the reasons for increases or decreases, and areas for improvement on a monthly basis, it will be useful for budget management and explaining proposals.
IAM permissions, logging, backups, and network settings are fundamental to AWS operations. However, if operational rules differ from one local subsidiary to another, it becomes difficult to determine their consistency with the security standards of the Japanese headquarters.
Companies using AWS across multiple locations need to standardize rules for account management, access control, and log management. The more localized and optimized practices become, the greater the burden of later aligning them with company-wide standards.
Even if you outsource your AWS operations to a local vendor, you won't receive the support your headquarters expects if the scope of their services remains unclear. Whether the support includes only monitoring and notifications, initial troubleshooting, root cause investigation, and proposals for preventing recurrence will vary depending on the contract.
If you require reports for the Japanese headquarters, cost analysis, and improvement proposals, clarify the scope of support before signing the contract. You should also confirm that you will receive information that the headquarters can use to make informed decisions, not just technical support.
The problems with AWS operations at a Thai subsidiary aren't limited to a lack of individual tasks. By creating a situation where the Japanese headquarters can monitor the configuration, costs, security, and incident response status while the local operations run on a daily basis, it's possible to continuously manage AWS operations at overseas locations.
AWS operational outsourcing allows you to entrust monitoring, incident response, backup, cost management, security checks, and operational improvements to an external partner. However, the scope of services varies depending on the provider and contract details. When using AWS at a Thai subsidiary, you should clarify the roles of the local person in charge, the Japanese head office, and the operational outsourcing company.
The main tasks requested are as follows:
What needs to be confirmed is the scope of incident response. The role you can expect from the operations outsourcing company will vary depending on whether it only includes alert notifications, initial troubleshooting, or support for recovery work and root cause investigation. You should also decide in advance who to escalate the issue to: the Thai subsidiary, the Japanese head office, or the development vendor.
Cost management involves not only checking the billing amount, but also examining which AWS services are increasing costs, whether there are any unnecessary resources remaining, and whether there is room for improvement. If you can organize the breakdown of usage fees, reasons for increases or decreases, and improvement suggestions on a monthly basis, it can be used for budget management and approval explanations at the Japanese headquarters.
In terms of security, you may be able to request verification of IAM permissions, log acquisition, backups, and network settings. However, whether this includes only checking the current settings, implementing improvements, or providing audit reports will vary depending on the contract. The scope of support will be defined in accordance with the security standards of our Japanese headquarters.
AWS operations outsourcing is not a system where all operations are outsourced. By dividing the scope of tasks to be handled in-house and those to be outsourced—such as monitoring, incident response, backup, cost management, security checks, and operational improvements—you can design an operational system that balances on-site support with headquarters management.
The general availability of the Thailand region expands the options for building AWS environments within Thailand. This chapter will address more than just whether or not to migrate to the Thailand region. The increased regional options necessitate a reassessment of existing AWS environments against headquarters' management standards.
The AWS environment at a Thai subsidiary may be operating in a way that is optimized for individual needs due to the circumstances at the time of implementation. This could include situations where the environment built by the local vendor is still being used, the AWS account administrator is isolated to the local area, or the Japanese headquarters is not regularly checking the status of costs and permission settings. In this situation, simply changing the region will not solve the operational problems.
The following are items we would like to review in conjunction with the opening of the Thailand region:
If existing systems are running stably in the Singapore or Tokyo region, it doesn't necessarily mean migrating everything to the Thailand region. We compare the AWS services to be used, availability, network, data management, costs, and operational structure, and make a decision from both a local operations and headquarters management perspective.
With the opening of the Thailand region, we will review not only the region selection process but also the entire system, including monitoring, incident response, backup, cost management, and security checks, so that headquarters can also have a grasp of these processes. Ensuring that the AWS environments of overseas branches are not left outside of headquarters' management is a prerequisite for continuously managing the AWS operations of our Thai subsidiary.
In addition to fees and response times, we also check their local capabilities and their reporting and governance support for headquarters. Local vendors have strengths in handling practical matters on-site. On the other hand, it is necessary to check whether they can provide reports with a level of detail that can be used for approval processes, audits, and budget management at headquarters in Japan. When choosing a partner on the Japanese side, we also check whether they can handle daily communication with local subsidiaries and coordination in the local language.
If you only consider the choice between a local vendor and a Japanese partner, you'll have to deal with challenges in either local support or headquarters management. What you need to look at is whether they can handle communication with local personnel while also providing reporting and governance support that allows headquarters in Japan to make informed decisions. Before signing a contract, you should clarify the scope of support, including monitoring and notification, incident response, cost management, and security checks.
Practical communication with local personnel and reporting to the Japanese head office occur simultaneously. Local personnel will handle work requests, reports of failures, and consultations regarding configuration changes. The head office will require information that allows them to make decisions regarding AWS configuration, usage fees, security settings, and incident response history.
Local vendors have an advantage in providing local support. However, we need to check if they can provide reports with a level of detail that is suitable for approval, audits, and budget management at the Japanese headquarters. When choosing a Japanese partner, we also need to consider whether they can handle local language support and coordination with local subsidiaries.
We design the actions to take after receiving a monitoring alert. By deciding who will review the content, how far the issue will be isolated, and under what conditions recovery measures or escalation will be initiated, the initial response to a failure will be clear.
What needs to be confirmed is whether the service includes only monitoring notifications, initial troubleshooting, and also root cause investigation and proposals for preventing recurrence. Additionally, it's important to confirm whether consultation is available regarding reviewing monitoring items, adjusting alert thresholds, backup design, and improving resource configuration.
The Japanese headquarters needs to understand the reasons for increases or decreases in AWS usage fees. Simply looking at the billing amount isn't enough to determine which AWS services have increased costs, whether there are unnecessary resources remaining, or if there's room for improvement in the configuration.
When choosing an operations outsourcing company, check whether they can report on the breakdown of AWS usage fees, month-on-month comparisons, reasons for increases or decreases, and improvement suggestions. The selection criteria include whether they can organize the information at a level of detail that can be used by the Japanese head office for budget management and approval processes, not just for work reports for the local subsidiary.
IAM permissions, logging, backups, network settings, and external access settings all require continuous verification. If settings and operational rules differ among local subsidiaries, there will be insufficient information to verify consistency with the security standards of the Japanese headquarters.
The term "security response" alone doesn't clarify the scope of support. We need to clarify whether it includes checking the configuration status, performing improvement work, or providing audit reports, by breaking it down into areas such as IAM, logs, backups, network, and vulnerability response.
Serverworks provides support to companies using AWS in their Thai subsidiaries, covering everything from implementation, design, construction, operation, monitoring, and maintenance of AWS.
We can address common challenges in AWS operations at overseas locations, such as reliance on individual expertise in local operations, cost management, governance, and multilingual support. We offer access control using AWS Organizations and Guardrails, cost management utilizing Trusted Advisor and Budgets notifications, operational automation with Cloud Automator, and support in Japanese, English, and local languages.
While monitoring is provided 24/365, incident response is subject to the support hours of each country's branch, so the actual scope of support must be confirmed before signing a contract. If you wish to balance local support and management by the Japanese head office for AWS operations at your Thai subsidiary, please consult with us regarding the scope of operations, reporting system, cost management, and governance.
When choosing an AWS operations outsourcing service in Thailand, it's important to separately check whether the service can be handled locally and whether it can be managed by the Japanese headquarters. Relying solely on local support will result in insufficient information for headquarters' budget management, security checks, and decision-making during incidents. On the other hand, prioritizing headquarters management alone will lead to a disconnect between the daily consultations and practical work of the local staff.
Therefore, during the selection process, we comprehensively check aspects such as coordination with local personnel, scope of support in the event of a failure, reporting in Japanese, cost management, and governance support. AWS operations for a Thai subsidiary are not simply a matter of either leaving it to the local team or managing it from headquarters. Creating a system that allows headquarters to continuously receive information that enables decision-making without disrupting local operations is a key criterion when choosing an operations outsourcing company.
The opening of the Thailand region has expanded the options for AWS environments. Therefore, it's essential to review who is responsible for what scope, encompassing not only the region and configuration, but also subsequent monitoring, incident response, costs, and access control. Choosing a support system that balances local support with headquarters management will allow for continuous management of the AWS operations of your Thai subsidiary.