Modernising a critical wealth platform to reduce risk and improve stability
At a glance
A large Australian financial services organisation needed to reduce security and operational risk across a critical wealth management platform while a broader transformation program was underway. Cevo partnered with its engineering team, combining specialist expertise with an AI-accelerated delivery approach to modernise the platform, improve stability and manage the transition into production without disrupting adviser services. The modernisation reduced production errors, addressed known security vulnerabilities and created a more supportable platform for the organisation’s ongoing transformation.
Capabilities
Industry
Financial Services
Business challenge
The organisation’s wealth management platform had supported financial advisers for more than a decade, providing portfolio management, trading, reporting and administration capabilities.
Several parts of the platform were running on ageing or unsupported technology, including the application server, Java runtime, frameworks and third-party dependencies. Some also carried known security vulnerabilities.
This created an ongoing risk for a platform that advisers continued to rely on every day. The organisation had prioritised remediation, with executive approval required to continue operating the platform in its existing state.
At the same time, it was progressing a broader, multi-year program to move adviser workflows to a modern portal. Until that transition was complete, the existing platform still needed to remain secure, stable and available.
Production monitoring also showed significant levels of application errors, with approximately 167,000 recorded each day across 59 exception classes. Much of this volume came from a recurring authentication issue, creating noise that made genuine faults harder for engineering teams to identify.
The platform also had a known issue in its session-management process that had previously contributed to production outages.
The organisation needed to modernise a complex, business-critical platform without disrupting adviser services. This required specialist modernisation and production engineering expertise, combined with close collaboration with its internal team throughout the migration.
Solution
The organisation engaged Cevo to deliver the migration alongside its internal engineering team. Cevo supported the program from initial analysis pre production in establishing a baseline through to engineering, production deployment, hypercare and post-hypercare remediation, helping the team understand the risks, modernise ageing components and manage the transition safely.
Understanding the risks before migration
Cevo worked with the internal engineering team to build a clear picture of the application, its dependencies and its performance in production.
Using an AI-accelerated delivery approach, the team combined engineering expertise with Claude Code to identify dependencies on legacy frameworks, review more than 100 third-party dependency changes and map the main areas of code affected by the migration. This helped engineers assess a large and complex codebase more efficiently and focus attention on the areas carrying the greatest risk.
The team also established a production baseline of approximately 167,000 errors per day across 59 exception classes. This gave engineers a clear benchmark for measuring platform stability after migration and helped separate recurring noise from issues that required action.
Before deployment, Cevo and the internal team tested the migrated environment and stabilised hundreds of existing automated tests on the modern Java runtime. This gave the team greater confidence that they could modernise the underlying technology while maintaining the platform’s existing business functions.
Modernising the platform foundations
The internal engineering team upgraded or replaced ageing components while maintaining the existing experience for advisers, with Cevo helping confirm that the changes were ready for production release.
The team moved the platform from a legacy enterprise Java application server to a modern servlet container, upgraded Java and Spring to supported versions, and removed several end-of-life frameworks and dependencies.
This included Apache Struts, the legacy dependency injection layer and other components associated with known vulnerabilities. The team also addressed identified security issues across networking, connection pooling, cryptographic libraries and other dependencies.
AI-assisted code analysis helped Cevo trace how these legacy components interacted with the wider application, giving the team greater confidence to make targeted changes without unnecessarily changing business logic.
These changes reduced reliance on unsupported technology, addressed known security risks and reduced the complexity involved in supporting the platform while the wider transformation continued.
Addressing a known cause of outages
Cevo also addressed a long-standing issue in the platform’s session-management process.
Every new user session depended on an identifier generated by the database. Under certain conditions, this process could lock the database and prevent new sessions from being created across the platform. The issue had previously contributed to production outages.
Cevo used engineering analysis supported by Claude Code to trace how the platform created and used session identifiers. The team confirmed that the database process did not support business logic, auditing or coordination with other systems.
Cevo then designed a new approach that generated unique session identifiers within the application rather than relying on the database. The team tested the design across millions of identifiers under concurrent use before deployment.
The new approach removed the known database locking issue from session creation, reduced database activity and simplified a process that advisers relied on to access the platform.
Managing the move into production
Cevo managed the production migration using rolling deployment, moving the platform progressively to the modernised environment while keeping adviser services available.
Cevo then worked alongside the internal engineering team through a two-week hypercare period, using AI-accelerated monitoring and engineering analysis to track platform health and respond quickly as issues emerged.
The team continuously compared production results with the pre-migration baseline, grouped recurring errors and investigated unexpected behaviour. Using AI-accelerated analysis, Cevo produced more than two dozen structured reports during hypercare, giving engineers faster visibility of platform health and the issues requiring action.
This approach also helped the team distinguish temporary deployment-related errors from genuine application problems and accelerate root-cause analysis. When an application pod exceeded its memory limit, for example, the team identified the cause, adjusted the configuration and recorded no further out-of-memory kills for the remainder of hypercare.
Cevo either resolved issues directly or gave the internal engineering team a clear explanation of the cause and recommended next steps. The majority of post-deployment issues were resolved within the first week of hypercare.
Outcomes
The migration improved the security and stability of a critical wealth management platform while maintaining services for financial advisers. Key outcomes include:
- Greater platform stability: Production errors fell by more than 99% from the pre-migration baseline during the second week of hypercare, reducing operational noise and making genuine issues easier for engineering teams to identify.
- Reduced security exposure: Removing or upgrading ageing technologies addressed known vulnerabilities and reduced the risk of continuing to operate the platform during the broader transformation program.
- Clearer production monitoring: The recurring authentication error was no longer observed during hypercare, giving engineering teams a clearer view of genuine application issues.
- Lower risk of session-related outages: Redesigning session management removed the database locking issue that had previously contributed to production outages and adviser disruption.
- Service availability maintained: Rolling deployment allowed the organisation to complete the production migration without reported service interruption to advisers.
- Faster issue resolution: AI-accelerated monitoring compressed analysis that would typically have taken weeks of manual log review into hours, helping Cevo and the internal team identify issues sooner and resolve the majority of post-deployment issues within the first week of hypercare.
- Reduced legacy complexity: Removing unsupported technology and simplifying key parts of the application made the platform easier for engineering teams to support while the broader transformation continued.
Enjoyed this customer story?
Share it with your network!
You may also like



