Skip to content
Case Study

ČSOB CZ — DevOps Capabilities Assessment

The Grow2FIT team working with ČSOB on the DevOps assessment

How we conducted a detailed DevOps assessment for ČSOB — delivering actionable recommendations and clear roadmaps across GitOps, Service Mesh, and Observability to accelerate their digital transformation.

About the Project

For ČSOB CZ (Czechoslovak Commercial Bank), Grow2FIT conducted a structured DevOps Capabilities Discovery Phase to assess current practices and design transformation strategies across three key areas: GitOps and Versioning, Service Mesh, and Observability. The engagement delivered concrete recommendations with clear prioritisation, enabling ČSOB's teams to implement meaningful improvements while respecting banking-sector regulatory requirements.

Our Proven Assessment Methodology

Phase 1: Introductory workshop & current-state analysis

  • Infrastructure assessment — detailed evaluation of existing DevOps tools, including GitLab, GitHub Actions, ArgoCD, OpenShift, and the Broadcom monitoring stack.
  • DevOps process evaluation — in-depth analysis of development and deployment workflows, CI/CD configurations, release management, and operational procedures to identify optimisation opportunities.
  • Team engagement — direct collaboration with ČSOB's development and operations teams to understand real pain points and organisational constraints.
  • Baseline establishment — documentation of current capabilities across all focus areas.

Phase 2: Gap analysis & solution design

  • Industry benchmarking — comparison against banking-sector best practices and modern DevOps standards.
  • Technology evaluation — assessment of tools like OpenTelemetry, Prometheus, Elastic Stack, HashiCorp Vault, and Consul for their fit within ČSOB's environment.
  • TO-DO recommendations — detailed activity lists for each focus area, with specific recommendations ranked by importance and implementation complexity.
  • Roadmap prioritisation — prioritised implementation roadmaps identifying quick wins and strategic initiatives, with immediate next steps selected by impact.

Key Outcomes and Value Delivered

GitOps & versioning optimisation

The assessment provided specific recommendations for consolidating CI/CD workflows, implementing a Software Bill of Materials (SBOM) for container security, and establishing automated certificate lifecycle management. A clear path was designed from their current multi-tool environment (GitLab, UrbanCode, GitHub Actions, ArgoCD) to a standardised, secure deployment process.

Service Mesh enhancement

A modular implementation strategy broke down their complex service mesh into manageable components (API Gateway, Ingress/Egress Gateway, Service Discovery), with guidance for gradual integration starting with 5–10 applications. Recommendations addressed their existing Consul, Envoy, and Vault implementations while planning for OpenShift integration.

Comprehensive observability

A hybrid approach maintained their Broadcom investments while introducing modern capabilities through OpenTelemetry and Prometheus. This addressed vendor lock-in concerns while improving troubleshooting by better correlating metrics, logs, and traces.

ČSOB DevOps assessment output — prioritised roadmap across focus areas

Key Benefits Achieved

  • Enhanced security through container signing and SBOM implementation.
  • Improved operational efficiency via automated deployment processes.
  • Vendor flexibility through open-standards adoption.
  • Faster problem resolution with better observability correlation.

Why Our Approach Works

This engagement demonstrates a systematic methodology for DevOps transformation in highly regulated environments. It combines in-depth technical assessments with collaborative workshops to ensure recommendations are both technically sound and organisationally achievable.

ČSOB received not just an assessment report, but a practical transformation roadmap they could immediately begin executing with their existing teams and resources.

Key success factors

  • Banking-sector expertise — understanding of regulatory constraints and compliance requirements.
  • Collaborative approach — working directly with client teams rather than imposing external solutions.
  • Practical focus — delivering actionable recommendations with clear implementation paths.
  • Risk-aware planning — phased implementation minimising operational disruption.

Client Perspective

"The external study has provided us with a valuable independent perspective on our processes and brought in new insights that go beyond our existing in-house know-how. Thanks to the objective and pragmatic assessment of further development options, we now have a clearer understanding of potential innovations and risks that we might have overlooked internally. I especially appreciate the perspective and independence that the external team brought to the evaluation, enabling us to make more qualified decisions about our future direction."

Roman Mašek Roman Mašek
Director, IT Digital Services, ČSOB

How We Work

Independent, pragmatic assessments are how many of our banking engagements start — an objective view of where you are, what to fix first, and how to do it within your regulatory reality. Explore our services or read more of our case studies.

Want an independent view of your DevOps maturity?

No pitch, no obligation — just a focused conversation about where you are today and what makes sense as a next step.

Schedule a call with us