Hybrid Multi-Cloud • Automotive • AWS
Modernization of SAP on AWS: Efficiency, control and scale for a leading automotive company
A renowned automotive company accelerated its digital transformation by migrating and modernizing its SAP S/4HANA environment on AWS, ensuring operational efficiency, scalability and cost savings.
The starting point: An ambitious challenge for Toyota Argentina
Toyota Argentina, a renowned Japanese automaker, embarked on an ambitious “Cloud First” strategy. The initial challenge was crucial: assessing its security posture within AWS environments and migrating its core SAP system from on-premise to AWS, including a version upgrade.
But beyond this first step, the ultimate goal was even greater: to operate this new infrastructure optimally, achieving efficiency, process standardization, and maximizing the full potential of AWS capabilities.
To accomplish this, Toyota required a strategic partner for consulting, support, and full AWS operations management, with a focus on security, cost optimization, and business continuity.


The first major step: SAP migration and modernization (a crucial milestone)
Toyota needed to move its SAP S4/HANA version 1709, Web Dispatcher, SAP PI & PO, and Solman from an on-premise (Hitachi) environment to AWS, while also performing a version upgrade and modernizing the entire infrastructure for improved efficiency, scalability, and security.
The solution involved designing a multi-account AWS architecture following best practices, separating Development, QA, and Production environments to ensure a secure and organized foundation. HANA database migration was executed via backup restoration from the on-premise environment.
Once in the cloud, security was significantly enhanced with AWS Secrets Manager for credential management and EBS encryption with AWS KMS for data at rest. Storage performance was optimized with EBS GP3, while data transfer costs between instances were drastically reduced by replacing EFS with an S3-based solution. Monitoring and proactive alerts were implemented with Amazon CloudWatch.
Early cost optimization was achieved by automating the startup and shutdown of non-production instances using AWS Systems Manager, Lambda, and EventBridge. Finally, a multi-region Disaster Recovery strategy was established (Pilot Light for Production with AWS Backup and HANA Replication, and Backup/Restore for Dev/QA) to ensure business continuity.
Immediate results of the migration
Toyota achieved an optimized SAP infrastructure with increased processing capacity. Results included:
- 40% reduction in server response times.
- 35% improvement in database read/write speeds.
- 50% decrease in overall IT infrastructure costs compared to on-premise.
- 30% reduction in operating costs through automation and managed services.
Additionally, 85% of users reported better system performance, with high satisfaction regarding stability and availability.
Toyota’s continuous cloud operations
Once in the cloud, Toyota’s real journey began: continuously operating, governing, and optimizing its cloud infrastructure.
Cloud operations required strategic decisions directly impacting efficiency, security, and profitability—not just infrastructure, but governance, cost optimization, and safe evolution as operations scaled.
Toyota’s needs evolved toward centralized security visibility, implementation of preventive and detective controls, identity and access management under a “Cloud First” model, and regulatory compliance.
This required robust operations in Cloud Governance, Financial Management, Monitoring & Observability, Compliance & Auditing, and Operational Management.
Nubiral supported Toyota in designing and implementing a comprehensive cloud operations strategy, establishing a secure, scalable foundation aligned with business goals.

Cloud Governance: A robust multi-account architecture with AWS Control Tower, including dedicated Log and Audit accounts, ensuring governance from the start. Service Control Policies (SCPs) and mandatory Guardrails were enforced to strengthen security posture and compliance.

Security and Access Management: Security monitoring centralized with AWS Security Hub, continuous threat detection with GuardDuty, and compliance monitoring via AWS Config. User management simplified and secured with AWS Identity Center (SSO) federated with Azure AD, enabling centralized, MFA-protected access.

Financial Management (FinOps): Automated EC2 scheduling in non-production environments drove cost savings. Continuous monitoring and resource adjustments ensured maximum efficiency and ROI, with a FinOps-driven approach.

Resilience and Continuity: The multi-region Disaster Recovery strategy was maintained and managed to ensure business continuity under any scenario.

Compliance and Auditing: Continuous monitoring and traceability with automated tasks for daily resource governance. The security team ensured protection, monitoring, and incident response.

Operational Management: Centralized operations management was established for AWS infrastructure and workloads, leveraging automation and best practices.
Tangible results of continuous operation
Thanks to proactive, well-managed operations, Toyota achieved:
- Unified visibility of security findings, simplifying incident identification and response.
- Strong prevention and detection of threats through continuous monitoring and proactive security policies.
- Automated governance, standardizing account provisioning and ensuring consistent application of security and compliance policies.
- Simplified, centralized access management with Azure AD-driven MFA authentication.
Ongoing collaboration with Nubiral allowed Toyota to optimize costs, improve agility, ensure business continuity, and significantly strengthen digital resilience, maximizing the benefits of AWS.
The road ahead: Advancing operational maturity
To further enhance security and efficiency, next steps include enabling Amazon Inspector, network firewalls (AWS Network Firewall, Route 53 Resolver DNS Firewall with AWS Firewall Manager), and Amazon Macie for sensitive data discovery. Visibility improvements will extend GuardDuty to Lambda and RDS, activate Amazon Detective, and integrate all logs into Toyota’s SIEM.
Additionally, IAM optimization is planned through delegated administration, strict least-privilege policies, and IAM Roles Anywhere. These initiatives ensure Toyota remains at the forefront of cloud adoption and security maturity.
Conclusion
Nubiral has been a key strategic partner for Toyota Argentina, not only facilitating the successful migration and modernization of its critical SAP environment to AWS but, more importantly, consolidating and significantly improving its cloud security and governance posture.
Through a robust Landing Zone with AWS Control Tower, key security tools like Security Hub and GuardDuty, and operational automation, Nubiral has enabled Toyota to optimize costs, improve agility, ensure business continuity, and strengthen its digital resilience.
Looking forward, the vision is to continue advancing security maturity and automation, keeping Toyota at the forefront of cloud adoption.
