Infrastructure, Security & Operations

Systems, security, and what it costs to run them.

The Work

We run the whole of a company's technology operation, or any part of it, as the people accountable for it rather than as advisors describing it to someone else. The decisions are business decisions that happen to be technical, so we make them with the people who have to live inside them, and then we build what we agreed. The two we get called about most are the bill and the recovery — one put back against the contract, the other proven before anyone needs it.

Governance, Policy and Ownership

Decision rights and ownership.

Who approves a purchase. Who grants access, and who takes it away. Who answers when a rule gets skipped. We build that with the people who have to live inside it, hand whoever owns an outcome the authority to move it, and separate the duties that shouldn't sit with one person — nobody writes their own check and cashes it.

Policy and the controls under it.

Written policy is the standard an auditor holds you to, which makes a rule nobody follows evidence against you rather than protection. So we write policy your people can operate, and controls that get tested ahead of the audit — nothing in the findings should be news to you.

Compliance, and the evidence behind it.

Whichever standard your customer put in the contract. We determine what meeting it takes, close what's missing, and train the people it lands on — then help you choose an auditor who tests the practice, so what you hand that customer is worth what they think it is.

Security

Posture over product.

Siding and a vapor barrier aren't the same defense, and nobody building a house confuses them. Siding (posture) stands against the elements. The barrier (software) lets moisture out. Neither can do the other's job. Software is the easier of the two to buy, so it's usually the one that's furthest along. We give posture the attention it's owed — so the tools you already own are working behind something that holds.

An assessment, not a penetration test.

A test answers one question at one moment: is there a way in. An assessment asks whether your posture holds, whether your tools support it, and whether you do what your documents say. We run the assessment, bring in the firm that runs the test, and lead what follows — and unlike the test, the assessment is yours alone: no customer or vendor ever has to see it.

Access, and what leaves with it.

A salesperson who can export the whole customer list and the price book. Someone in finance who can pull the ledger into a spreadsheet and take it home. Neither needed that to do the job. We look inside the applications as well as at the perimeter and set the controls that stop data leaving, so what a person can take out is a permission someone granted — and can take back the day the role changes.

Zero trust is a plan, not a product.

It arrives in pieces, and it rarely runs everywhere. The plan is which resources matter, who may reach them, and what must be true when they ask — the products carry out whatever it says. We write that first, so everything you buy afterward has a job to do.

Systems and Networks

Where it runs.

Cloud and on-premises solve different problems. Which one your business belongs on depends on what growth or acquisitions do to your load, what your finances can carry, and where you're heading. We've moved organizations in every direction, hybrid included — so the recommendation you get is the one the facts support.

How much time you can afford.

A spare tire and an insurance policy both answer a flat, on completely different timelines. Replication is the spare: it gets the business moving in minutes. Backups are the insurance: they give you something to recover from after the worst day. Orders, production and customer service can't wait for the policy. Finance usually can. We work out which parts of your business are which, then build each to the clock it runs on.

After the acquisition.

Buying a company is one transaction. Making it one business is different work, and the part people underestimate is what runs between the two rather than what sits inside either one. Until that's right, you have two companies filing one set of accounts. We settle what has to work across them, then build it — so the numbers in the model have something to run on.

The Workplace

Day one and the last day.

A new person should be working by the time they sit down, and someone who leaves should be gone from everything before they reach the parking lot. Both come from the same place — your HR system deciding who exists, and everything else following it. A change of title moves access the same way. We build that chain, so a start date, a new title and an end date do the work instead of somebody remembering.

Estates grow one laptop at a time.

Each was the right machine that week. A few years on you have several generations of hardware, more than one way of setting them up, and more than one answer about which are patched. We set one standard and bring the estate onto it — so a machine can be replaced in a morning, and every one of them stays current.

What they open every morning.

Email, documents, chat, the phone system — Microsoft 365 or its equivalents — bought once, rolled out, and rarely looked at again. Meanwhile people quietly buy their own tools to fill the gaps, and you end up paying twice for the same thing. We settle what the business runs on, so the tools your people use are the ones you chose.

The desk.

How fast someone answers matters. So does who owns it until it's finished. But the part nobody funds is what happens to the answer — every problem solved once should stop the same question arriving again, put in front of the person about to ask and the person about to solve it. We build all three, so the desk gets faster as it goes, instead of bigger.

Cost, Suppliers and Lifecycle

The bill and the contract are two different documents.

They're written at different times by different people, and they drift. What you're charged quietly stops matching what was agreed. We put them side by side, recover what the gap is worth, and fix the language so it can't open again.

What to own, and what to rent.

It starts with cost over the life of the equipment, set against what the business will do in that time and where you're starting from: what you already have, what the finances will carry, where headcount is going. A company heading for a sale should look hard at every alternative before it buys new. We weigh all of it, put the options in front of you, and recommend what serves the business between now and whatever comes next.

How we handle vendors.

We bring you several options. Some of them we know, and some of them we don't — the shortlist is built for what fits your business, not from who we happen to have a relationship with. We tell you which one we'd take and why, in facts you can check. You decide, you contract with them, and you pay them directly. Where we do know a vendor, that history works in your favor: they see more of our clients over time, so they negotiate harder for you. We take nothing from them for it.

Your entire IT infrastructure — how decisions get made, how the place is secured, what the systems run on, what your people open every morning, and what all of it costs. Take any part of it, or all of it. You end up with a foundation built for the business you run today and for whatever it turns into — larger, sold, or something nobody has planned for yet. Start there →

A note for finance-minded sponsors:

on qualifying projects, a portion of the engagement effort may be capitalizable rather than expensed. Worth confirming with your finance team.

Three other ways in

Design · build · both

Not sure we're a fit? Not sure where to start?

Both are good reasons to call.

Start a conversation →

Tell us what you're dealing with

Pick any that apply, or none at all.

This form needs JavaScript to send. Reach out to us on LinkedIn instead — nothing you type here will reach us until it is enabled.

Direct to our inbox. No newsletters, no list — just a reply.