
Cloud Network Architecture Review and Optimization
Review and optimize cloud networks for security, resilience, and cost-efficiency
What You Can Do
Systematically analyze your cloud network architecture across security, resilience, cost, and compliance dimensions. You receive a comprehensive assessment report with prioritized optimization recommendations, security hardening steps, and implementation guidance tailored to your infrastructure. The skill evaluates network design patterns, resource utilization, and compliance gaps to help you build cost-effective, secure, and highly available cloud networks.
Features
Evaluate network segmentation, firewall rules, VPN configurations, and access controls. Identify vulnerabilities and provide specific hardening recommendations including encryption protocols, DDoS mitigation strategies, and zero-trust architecture guidance.
Review availability zones, load balancing, and disaster recovery configurations. Assess single points of failure, redundancy levels, and failover mechanisms to ensure your network can withstand component failures.
Analyze bandwidth usage, NAT gateway costs, data transfer charges, and reserved capacity. Identify cost reduction opportunities through reserved instances, traffic routing optimization, and redundant resource elimination.
Map your network design against industry standards (HIPAA, PCI-DSS, SOC 2, GDPR, ISO 27001). Highlight compliance gaps and provide remediation steps for regulatory requirements specific to your industry.
Evaluate cross-region deployments, inter-region connectivity, and data residency requirements. Assess latency, failover timing, and compliance implications of your geographical architecture.
Interpret ASCII, JSON, or text descriptions of your network topology. Provide redline diagrams with suggested improvements and explain design trade-offs between competing optimization goals.
Analyze network flows, bandwidth allocation, and routing efficiency. Recommend changes to reduce latency, improve throughput, and optimize egress costs based on your traffic characteristics.
Example Output
Network Architecture Review Summary
Current State:
- Single-region deployment in us-east-1 with 3-AZ redundancy
- NAT gateway per AZ (monthly cost: ~$45)
- No cross-region failover
- Security groups allow unrestricted ingress on port 443
Security Findings:
- Missing VPC Flow Logs for compliance audit trail
- Database security group allows access from all application servers (not restrictive enough)
- SSL/TLS minimum version set to 1.0 (should be 1.2+)
Cost Reduction Opportunities:
- Consolidate to 1 NAT gateway with smart routing (save ~$30/month)
- Implement VPC endpoints for S3/DynamoDB (save ~$15/month on data transfer)
- Move infrequent backups to S3 intelligent-tiering (save ~$20/month)
Recommended Actions:
- Priority 1 (30 days): Update TLS version, enable VPC Flow Logs, add cross-AZ health checks
- Priority 2 (60 days): Implement VPC endpoints, consolidate NAT gateways
- Priority 3 (90 days): Plan multi-region failover in us-west-2
What's Included
- Comprehensive Architecture Assessment: Detailed evaluation of your current network design across security, resilience, cost, and compliance dimensions with visual findings summary.
- Prioritized Recommendations: Ranked list of optimization opportunities with estimated effort, timeline, and business impact (cost savings, security improvement, resilience gain).
- Security Hardening Checklist: Step-by-step guide to address security findings including firewall rule updates, encryption configuration, access control refinements, and monitoring setup.
- Cost Analysis Framework: Breakdown of network costs by component (NAT gateways, data transfer, VPN, DNS) with optimization strategies specific to your cloud provider.
- Implementation Roadmap: Phased execution plan with time estimates, dependencies, rollback procedures, and validation steps for each optimization initiative.
- Compliance Mapping Document: Table mapping your network controls to relevant compliance standards with gap analysis and remediation guidance.
Who It's For
- Cloud Architects
- Network Engineers
- DevOps and SRE Teams
- Security and Compliance Engineers
- Cloud Operations Managers
Best For
- Network redesigns and migrations
- Cost reduction and FinOps initiatives
- Security audits and hardening
- Compliance preparation and validation
- Disaster recovery and failover planning







