CloudBuzz Operates Secure Research Rooms on AWS for KSM

The Challenge
KSM, the research arm of one of Israel's largest HMOs, runs data-driven medical research on highly sensitive genetic and clinical data. Each research partner needs its own hardened, internet-isolated environment, provisioned and decommissioned continuously as studies begin and end. KSM needed to run these environments securely at scale, govern sensitive data in a central data lake, and enable GenAI safely, without building an in-house cloud operations team.
The Solution
CloudBuzz operates KSM's multi-account AWS environment as a managed service across four continuous phases: Plan – landing-zone and organizational design plus a repeatable Research Room blueprint. Build – a Terraform Research Room factory, central-egress networking, a governed data lake, and a dedicated security stack. Operate – day-to-day provisioning, incidents, patching, backup, and security operations. Optimize – FinOps, right-sizing, Well-Architected reviews, and progressive self-service handover to KSM. GenAI (Amazon Bedrock and Amazon Q) is made available safely inside the isolated rooms.
The Results
KSM runs isolated research environments at scale with a security posture uplifted across the organization: MFA enforced org-wide, workloads isolated from the internet, and a dedicated security-tools account. New research rooms are provisioned on demand and completed studies cleanly decommissioned, under a governed weekly and monthly cadence, with FinOps-driven cost control and safe GenAI enablement inside the restricted environments.



