Australian superannuation fund CareSuper has completed one of the financial sector's most strategic cloud migrations, transitioning from VMware on AWS to a fully managed Microsoft Azure environment with Macquarie Cloud Services. This 18-month transformation represents a blueprint for APRA-regulated entities navigating cloud adoption while maintaining strict compliance with data sovereignty requirements.
The Catalyst for Change
Facing mounting pressure to modernize its 30-year-old IT infrastructure, CareSuper needed a solution that could:
- Reduce operational complexity from managing multiple cloud environments
- Improve security posture for sensitive member data (A$18 billion in assets under management)
- Achieve cost predictability after experiencing AWS bill volatility
- Meet APRA CPS 234 and CPS 230 compliance mandates
"Our previous VMware-on-AWS setup served us well initially, but we needed a partner who understood both the technical and regulatory dimensions of superannuation," explained CareSuper CIO Mark O'Reilly in an exclusive interview.
Why Azure Won Over AWS
Macquarie Cloud Services' evaluation identified three key advantages for Azure:
- Native Compliance Controls: Azure's Australian regions offered pre-certified configurations for APRA, IRAP, and ISO 27001 compliance
- Hybrid Consistency: Seamless integration with CareSuper's remaining on-premises systems via Azure Arc
- Cost Structure: 23% lower TCO over 3 years compared to maintaining VMware Cloud on AWS
The Migration Architecture
Macquarie implemented a phased approach:
| Phase | Duration | Workloads Migrated | Key Milestones |
|---|---|---|---|
| 1 | 4 months | Non-member-facing systems | Established Azure landing zone with private connectivity |
| 2 | 6 months | Core administration platform | Implemented Azure Policy for compliance guardrails |
| 3 | 8 months | Member portal & claims processing | Finalized DR failover testing |
The architecture leveraged:
- Azure Virtual Machines for legacy applications
- Azure Kubernetes Service for new cloud-native services
- Azure SQL Managed Instance for database workloads
- Azure Sentinel for unified security monitoring
Security & Compliance Breakthroughs
Macquarie's solution addressed critical financial services requirements:
- Data Sovereignty: All data remains within Azure's Sydney regions with geo-redundancy to Melbourne
- Access Controls: Just-in-time privileged access via Azure PIM
- Audit Trail: Immutable logging integrated with CareSuper's existing SIEM
- Encryption: Customer-managed keys through Azure Key Vault
"APRA now expects super funds to demonstrate cloud controls at the same rigor as on-premises systems," noted Macquarie's financial services cloud architect. "We built compliance into every layer."
Performance & Cost Outcomes
Post-migration metrics showed significant improvements:
- 37% faster member portal response times
- 28% reduction in monthly infrastructure costs
- 99.99% availability during peak processing periods
- 4-hour RTO for critical systems (down from 12 hours)
The shift to Azure's reserved instances and hybrid benefit licensing contributed to most savings.
Lessons for Financial Services Firms
CareSuper's experience offers key insights:
- Regulatory Alignment Matters More Than Cloud First - Their Azure choice prioritized compliance over being "cloud-native"
- Managed Services Reduce Hidden Costs - Macquarie's 24/7 operations team prevented staffing spikes
- Exit Strategies Require Planning - Contract terms ensured data portability to avoid lock-in
As O'Reilly reflected: "This wasn't just about technology—it was about creating an operating model that could evolve with regulatory changes."
The Road Ahead
With the core migration complete, CareSuper is now exploring:
- AI-powered member services using Azure OpenAI
- Real-time analytics with Azure Synapse
- Edge computing for remote advisor capabilities
Macquarie has since packaged this engagement model as their "Financial Services Cloud Framework," already adopted by three other APRA-regulated entities.
For Windows-centric financial organizations, this case demonstrates how Azure's enterprise capabilities can meet even the strictest compliance demands when paired with the right managed services partner.