LMAX Group: Cloud Native Threat Modelling and Purple Teaming

About LMAX Group
LMAX Group is a global financial technology company and the leading independent operator of multiple institutional execution venues for FX and digital assets trading. With offices in 9 countries and a global client base, the Group builds and runs its own high performance, ultra-low latency exchange infrastructure, which includes matching engines in London, New York, Tokyo and Singapore.
Validating Detection Capabilities in High-Compliance Environments
In highly regulated financial markets, maintaining total visibility over cloud-based infrastructure is paramount. LMAX utilises multi-account AWS architecture to host digital asset products across numerous environments. The core of its workload deployment relies on Amazon Elastic Kubernetes Service (AWS EKS) application deployment managed via a GitOps framework.
To secure this footprint, LMAX deployed a comprehensive set of security controls, including Runtime security and an auditing admission controller within Kubernetes. These logs, along with AWS CloudTrail logs, are sent to a centralised SIEM system. Despite this comprehensive security stack, LMAX required objective validation of its defensive posture to ensure real-world resilience.
Challenges
LMAX engaged ControlPlane to review their detection coverage and to mature their internal security capabilities.
The primary challenges and objectives included:
- Detection Posture: Validate that the firm’s current detection tooling deployment would provide effective alerting against realistic threats targeting their cloud and Kubernetes environments.
- Threat Landscape Visibility: LMAX wanted to gain a deeper, contextualised understanding of the specific threat landscape affecting their digital products and cloud infrastructure.
- Capability Development: Desire to upskill the internal security team, enabling them to independently scope, implement, maintain, and re-evaluate security controls across their cloud native systems.
Solutions
ControlPlane delivered a comprehensive, phase-based engagement combined with targeted technical training to validate the firm’s environments and upskill the team’s capabilities.
Strategic Deliverables
- Threat Modelling Workshop: An initial knowledge-sharing phase and workshop to map out AWS and Kubernetes operations, establishing what threats the business considers critical and how they are currently mitigated.
- STRIDE Threat Model: ControlPlane developed a STRIDE threat model tailored to the specific business context, mapping out common, real-world attack scenarios.
- Purple Team Tests: Using the threat model as a baseline, ControlPlane designed a series of test scenarios to simulate active threats against demo LMAX systems. ControlPlane executed the reviewed and agreed-upon attack scenarios while simultaneously utilising access to LMAX detection systems to verify in real time whether the malicious activity triggered appropriate alerts.
- Targeted In-Person Training: ControlPlane delivered two specialised, in-person training courses to the LMAX security team: Threat Modelling Kubernetes and Kubernetes and Container Security.
Benefits Achieved
- Quantified Detection Gaps: LMAX obtained empirical evidence regarding the exact operational boundaries and gaps within their existing detection platform.
- Actionable Posture Insight: The threat modelling and simulation provided a clear roadmap for assessing the efficacy of security controls across clusters, CI/CD pipelines, and cloud environments.
- Immediate Capability Uplift: Direct collaboration during the purple team exercises, paired with expert-led training, directly addressed the objective to improve the team’s ability to maintain and re-evaluate their cloud native defences.
Business Outcomes
The engagement provided LMAX with critical visibility into its defensive operational readiness. The purple team successfully identified several high-severity issues, highlighting gaps in detection coverage. By identifying these exposures through simulated threats rather than a real-world breach, LMAX obtained the exact technical insights required to remediate its platforms, refine its SIEM alerting logic, and solidify its overall compliance posture.
Alfie Griver, Security Engineer at LMAX Group
“Operating with digital assets means we require absolute certainty across our cloud native infrastructure. We wanted to evaluate whether our existing configurations provided sufficient detection coverage and to upskill the team in managing these complex environments. Additionally, ControlPlane provided clear areas for improvement across our CI/CD pipelines and IAM infrastructure.
Communication was exceptional throughout, with dedicated Slack channels and regular sync meetings that kept both teams aligned and enabled real-time technical exchange. ControlPlane has not only helped us strengthen our platform but has upskilled our internal capabilities to scope, maintain and continuously evaluate our cloud security controls."
Similar case studies

Kubernetes Purple Teaming for a UK Banking-as-a-Service Provider

Straiker: AI Security CTF at RSA Conference

OpenAI: Red Teaming GPT-4o, Operator, o3-mini, and Deep Research
Similar articles

Sovereign Signing: A Self-Hosted Supply Chain with OpenBao, Cosign, and Flux CD

Internal ≠ Isolated (Or Secure): The Argo CD Repo-Server Flaw
