ČSOB CZ — DevOps Capabilities Assessment
How we conducted a detailed DevOps assessment for ČSOB — delivering actionable recommendations and clear roadmaps across GitOps, Service Mesh, and Observability to accelerate their digital transformation.
About the Project
For ČSOB CZ (Czechoslovak Commercial Bank), Grow2FIT conducted a structured DevOps Capabilities Discovery Phase to assess current practices and design transformation strategies across three key areas: GitOps and Versioning, Service Mesh, and Observability. The engagement delivered concrete recommendations with clear prioritisation, enabling ČSOB's teams to implement meaningful improvements while respecting banking-sector regulatory requirements.
Our Proven Assessment Methodology
Phase 1: Introductory workshop & current-state analysis
- Infrastructure assessment — detailed evaluation of existing DevOps tools, including GitLab, GitHub Actions, ArgoCD, OpenShift, and the Broadcom monitoring stack.
- DevOps process evaluation — in-depth analysis of development and deployment workflows, CI/CD configurations, release management, and operational procedures to identify optimisation opportunities.
- Team engagement — direct collaboration with ČSOB's development and operations teams to understand real pain points and organisational constraints.
- Baseline establishment — documentation of current capabilities across all focus areas.
Phase 2: Gap analysis & solution design
- Industry benchmarking — comparison against banking-sector best practices and modern DevOps standards.
- Technology evaluation — assessment of tools like OpenTelemetry, Prometheus, Elastic Stack, HashiCorp Vault, and Consul for their fit within ČSOB's environment.
- TO-DO recommendations — detailed activity lists for each focus area, with specific recommendations ranked by importance and implementation complexity.
- Roadmap prioritisation — prioritised implementation roadmaps identifying quick wins and strategic initiatives, with immediate next steps selected by impact.
Key Outcomes and Value Delivered
GitOps & versioning optimisation
The assessment provided specific recommendations for consolidating CI/CD workflows, implementing a Software Bill of Materials (SBOM) for container security, and establishing automated certificate lifecycle management. A clear path was designed from their current multi-tool environment (GitLab, UrbanCode, GitHub Actions, ArgoCD) to a standardised, secure deployment process.
Service Mesh enhancement
A modular implementation strategy broke down their complex service mesh into manageable components (API Gateway, Ingress/Egress Gateway, Service Discovery), with guidance for gradual integration starting with 5–10 applications. Recommendations addressed their existing Consul, Envoy, and Vault implementations while planning for OpenShift integration.
Comprehensive observability
A hybrid approach maintained their Broadcom investments while introducing modern capabilities through OpenTelemetry and Prometheus. This addressed vendor lock-in concerns while improving troubleshooting by better correlating metrics, logs, and traces.
Key Benefits Achieved
- Enhanced security through container signing and SBOM implementation.
- Improved operational efficiency via automated deployment processes.
- Vendor flexibility through open-standards adoption.
- Faster problem resolution with better observability correlation.
Why Our Approach Works
This engagement demonstrates a systematic methodology for DevOps transformation in highly regulated environments. It combines in-depth technical assessments with collaborative workshops to ensure recommendations are both technically sound and organisationally achievable.
ČSOB received not just an assessment report, but a practical transformation roadmap they could immediately begin executing with their existing teams and resources.
Key success factors
- Banking-sector expertise — understanding of regulatory constraints and compliance requirements.
- Collaborative approach — working directly with client teams rather than imposing external solutions.
- Practical focus — delivering actionable recommendations with clear implementation paths.
- Risk-aware planning — phased implementation minimising operational disruption.
Client Perspective
"The external study has provided us with a valuable independent perspective on our processes and brought in new insights that go beyond our existing in-house know-how. Thanks to the objective and pragmatic assessment of further development options, we now have a clearer understanding of potential innovations and risks that we might have overlooked internally. I especially appreciate the perspective and independence that the external team brought to the evaluation, enabling us to make more qualified decisions about our future direction."
![]()
How We Work
Independent, pragmatic assessments are how many of our banking engagements start — an objective view of where you are, what to fix first, and how to do it within your regulatory reality. Explore our services or read more of our case studies.