Turning an Expensive Legacy Platform Into a Stable, Growing Product
Engagement type: Ongoing technical advisory retainer Client: A production software platform, anonymised at the client's request Result at a glance: Recurring costs cut, a serious data risk closed, ongoing strategic technical direction provided, and new features shipped — all within one advisory relationship
The Problem
The client had been paying an external development supplier to maintain their platform for years. The relationship had stopped making sense: costs kept rising, but even small, everyday changes were taking far longer — and costing far more — than they should have. The supplier's work had left the underlying software in poor shape, riddled with shortcuts and outdated components, to the point where every new request came back slower and pricier than the last.
This is a familiar position for growing businesses that depend on software they didn't build in-house and can't fully evaluate themselves: costs climb, delivery slows, and it's hard to tell whether you're being asked to pay for genuine complexity or for years of accumulated poor practice. That's the gap this engagement was brought in to close.
The Approach
Rather than a large, fixed-price rewrite, the client opted for an ongoing advisory retainer — a trusted technical partner with a standing amount of time each month, directed wherever it created the most value. In the early months that meant closing down risk and waste; later it shifted toward building new capability. The client got a say in priorities every step of the way, without having to commit to a big-bang project upfront.
What Changed
Risk was brought under control
An in-depth review uncovered a serious data exposure risk: under the right conditions, one customer could have accessed another customer's account and personal data. This is exactly the kind of issue that's easy to miss without deliberate, expert scrutiny — it took tracing how the software handled user identity across several inconsistent, overlapping systems that had built up over years of ad-hoc changes. It was fixed the same day it was confirmed, and the client was informed transparently as soon as it was resolved. The underlying structural weakness behind it was then addressed too, closing off the risk of similar issues recurring in future.
Separately, the platform had a hidden reliability problem on its AWS infrastructure: a spike in customer activity had previously been enough to take the whole service offline, requiring manual intervention to bring back. The root causes were fixed, safeguards were put in place that hadn't existed before, and automated early-warning alerts were added so the business would know about a developing problem long before customers did.
Costs came down
A review of the platform's recurring third-party costs — spanning its AWS infrastructure and its use of Twilio for customer messaging — found several avoidable sources of waste. The AWS environment had been over-provisioned for years: infrastructure was running that nobody currently at the business could explain the purpose of, and several services were being self-hosted and manually managed at real ongoing cost and effort, when a standard managed alternative would have been cheaper, more reliable, and far less to maintain. One clear example: several static websites and applications had been served from multiple load-balanced EC2 instances running around the clock, when the actual traffic didn't need anything close to that. Moving them onto a CloudFront distribution instead brought them comfortably within AWS's free tier — cutting their hosting cost to effectively zero, while improving load times for end users at the same time. On the Twilio side, a software bug was causing repeated, unnecessary charges, and a paid protection feature was being applied inefficiently where a cheaper configuration would do the same job just as safely. Fixing all of this identified roughly £975 a month in ongoing savings — on its own, enough to cover the cost of the advisory retainer itself, before counting the infrastructure waste removed on top.
Strategic technical direction
Beyond hands-on fixes, part of the retainer's value was acting as an independent, senior technical voice for decisions the client didn't have in-house expertise to evaluate alone — effectively CTO-level support without a full-time CTO hire.
One example: a third-party supplier had pitched an ambitious, expensive infrastructure overhaul. Independent review found that a simpler, far cheaper approach could deliver the same practical outcome, without the cost and risk of the larger commitment — steering the client away from a significant, avoidable spend at a time when budget discipline mattered.
Another: a vendor dependency the business was relying on was reviewed before further budget was committed to it, and was found to be a dead end — it could never deliver the control the client needed, for reasons baked into how the vendor's technology worked. Catching this early, before it was built on, avoided wasted spend and a much costlier discovery later. In its place, a realistic, workable alternative was identified and scoped.
In both cases, the value wasn't writing code — it was giving the client a second, independent opinion before a large decision was made, from someone with no incentive to sell them anything.
Building structure that outlasts any one supplier
A recurring theme behind the platform's problems was that nothing had ever been documented or standardised — there was no consistent way of tracking versions, releasing changes safely, or bringing anyone new onto the codebase without a lengthy, informal handover. That meant the client was effectively locked into whichever individual or supplier currently held the knowledge in their head, with little ability to shop around, bring in extra help, or switch suppliers without significant risk.
Part of the retainer's focus was fixing that dependency directly: introducing a proper, repeatable versioning and deployment pipeline, and writing up clear documentation and working processes for the codebase and its environments. Deployments themselves had previously been done by manually pushing files over FTP — with no record of what had changed, when, or by whom. This was replaced with a standard GitHub-based pipeline: changes are tracked, reviewed, and deployed through a repeatable process rather than a manual file transfer, removing a significant source of risk and guesswork from every release. None of this depended on any one person to keep running — it's designed to remain in place and useful well beyond this engagement.
The business intent behind this was deliberate: a codebase with clear structure, documentation, and a repeatable release process is one that any competent developer or supplier can safely contribute to. That gives the client real choice going forward — the option to bring in additional developers or suppliers for future work, rather than being tied to a single relationship, because the risk of "someone new breaks something nobody understands" has been engineered out.
This was a conscious rejection of how the previous supplier had operated. The goal was never to become the next gatekeeper — the opposite: to make the platform as open and easy for anyone competent to maintain as possible. The fact that the advisory relationship has continued well beyond the initial clean-up isn't because access has been gated to keep it that way; it's because the client has continued to find the work valuable enough to keep bringing more of their roadmap to the table.
New capability was delivered
Alongside the clean-up, the retainer also delivered forward progress: early versions of new mobile functionality, and groundwork for new features aimed at growing the product — moving the platform from a cost the business was managing down, to one it could invest in growing.
Outcomes
- A critical data-exposure risk closed the same day it was found, with the root cause addressed, not just the symptom
- A recurring reliability problem eliminated, with early-warning monitoring now in place
- ~£975/month in ongoing costs saved, plus removal of over-provisioned and unnecessarily self-hosted infrastructure
- Independent, CTO-level input that steered the client away from a costly vendor proposal and a dead-end vendor dependency before either drained further budget
- A repeatable versioning, deployment, and documentation process introduced, reducing dependency on any single supplier and opening the door to bringing in additional development help in future
- New product capability delivered without pausing to first "fix everything"
Why This Matters for Decision-Makers
If your business depends on software you inherited, outsourced, or simply haven't looked under the hood of in a while, the risk usually isn't visible until it's expensive — a security incident, an outage at the worst possible time, or a vendor quote for a fix that turns out to be unnecessary. The value of an independent, senior technical review is catching these before they cost you, and building a plan to move forward that fits your actual budget and risk appetite — not the roadmap a vendor would prefer to sell you.
This case study describes a real, ongoing engagement. Identifying details have been withheld at the client's request.
Facing something similar? Let's talk about it.

