Zero trust for mid-market businesses: practical first steps
Full zero-trust implementation is a multi-year programme most mid-market businesses don't need yet. A handful of its principles, applied now, deliver most of the benefit.
Read perspectiveTechnical perspectives
Notes on the decisions beneath a working system. Written for the people responsible for building, changing and operating complex environments.
Full zero-trust implementation is a multi-year programme most mid-market businesses don't need yet. A handful of its principles, applied now, deliver most of the benefit.
Read perspectiveA stalled migration usually doesn't need a restart. It needs a diagnosis of which specific decision is blocked, and who actually has the authority to unblock it.
Read perspectiveA flat network means one compromised device is one step away from everything. Segmentation buys the time a security team needs to actually respond.
Read perspectiveThe real early return on IaC is speed and consistency, not the cost savings it gets sold on — and it needs an owner, not just a repository, to keep paying off.
Read perspectivePublic cloud wins on elasticity and managed services. It loses on egress cost, data-gravity constraints and latency-sensitive workloads — and pretending otherwise gets expensive.
Read perspectiveA completed backup job only proves data was written. Industry research puts real restore failure rates high enough that an untested backup should be treated as unverified, not safe.
Read perspectiveA server list tells you what exists. A dependency map tells you what breaks if you move it — and it's the document most stalled migrations were missing from the start.
Read perspectiveReserved capacity, right-sizing and auto-shutdown of non-production environments account for most realistic Azure savings — in that rough order of effort versus return.
Read perspectiveDependency mapping and a wave plan before implementation — the sequence that prevents a migration from becoming a more expensive datacentre.
Read perspectiveThe person who single-handedly keeps a business's technology running is a genuine asset and a structural risk at the same time — recognising both is the first step to managing it.
Read perspectiveThe co-managed arrangements that hold up over years share a few habits — regular communication, clear ownership, and treating the internal team as a client, not a client's IT department.
Read perspectiveA second set of experienced eyes before a change ships catches the class of mistake that's cheap to fix in review and expensive to unwind in production.
Read perspectiveBringing in outside help can read as a vote of no confidence if it's handled badly — the framing that avoids that is specific about what's being added, not replaced.
Read perspectiveThe decision usually isn't about cost per hour — it's about whether the need is ongoing and generalist, or specialist and intermittent.
Read perspectiveA $70k salary commonly becomes $95k–$115k in fully-loaded cost — for coverage that still has no redundancy, no after-hours capacity, and no deep specialist expertise in any one discipline.
Read perspectiveA defined escalation path specifies who gets contacted, how fast, and what happens next — response and resolution are not the same commitment, and treating them as one hides the real number.
Read perspectiveThe most common source of co-managed IT friction is an undefined boundary. Here's how to draw one that survives contact with a real incident.
Read perspectiveDelayed projects, unworked alerts and a growing backlog usually mean the team is stretched, not underperforming — and the fix is capacity, not a new hire or a full outsourcing decision.
Read perspectiveThe gap between vendor patch release and exploitation is measured in days. Most environments take months to close it — here's what closes it faster.
Read perspectiveUnlimited-ticket pricing usually means the limits moved somewhere else in the contract — after-hours rates, on-site charges, or a narrower definition of what's included.
Read perspectiveEmployee resistance to multi-factor authentication is almost always a rollout problem, not a security objection — and a staged approach fixes most of it.
Read perspectiveBackup protects your data. Disaster recovery protects your uptime. Most businesses have bought one and assumed it covers the other.
Read perspectiveThe difference between a new starter who's productive on day one and one who spends their first week waiting on access requests — and what that says about the environment.
Read perspectiveThe layer of protection that actually stops most incidents — device encryption, managed patching, endpoint detection and least-privilege access — before anything more advanced.
Read perspectiveThe questions that separate a genuine capability from a sales pitch — response versus resolution, scope boundaries, and what a reference call actually reveals.
Read perspectiveThe difference between an alert firing at 2am and someone actually being accountable for acting on it — and why the two get sold as the same thing.
Read perspectiveWhat to check 60–90 days before renewal — unused seats, duplicate SKUs and the licence tiers nobody re-evaluated since onboarding.
Read perspectiveWhy technical debt and deferred security work compound quietly, what it costs organisations that let it, and what a managed backlog actually looks like in practice.
Read perspectiveWhat actually happens inside a support tier structure when a problem is too complex for tier one — and what a defined escalation path should guarantee instead.
Read perspectiveThe gap between a help desk that closes tickets and a provider that can actually own infrastructure risk — and how to tell which one you have.
Read perspectiveTelemetry, identity, change records and environment access — the unfashionable prerequisites before AI can operate on your estate.
Read perspectiveWhere agents help IT operations, where scheduled automation and runbooks still win, and how to keep a human on the approval path.
Read perspectiveRetrieval-augmented generation against SharePoint, file shares and ticketing data — with access control, logging and failure modes made explicit.
Read perspectivePlatform engineering without the hype: golden paths, paved roads and what changes for people who currently run servers and tickets.
Read perspectiveA method for hybrid Azure network incidents: DNS, routing, NSGs, firewalls and ExpressRoute — in the order that actually finds the fault.
Read perspectiveA practical comparison of AVD and Citrix for Australian estates that already have identity, profiles and application delivery constraints.
Read perspectiveThe usual reasons Terraform, Ansible and pipeline programmes stall — and how to scope automation so it survives contact with operations.
Read perspectiveWhat belongs in an Azure landing zone that an operations team can run — and what to leave out of the first release.
Read perspectiveA decision sequence for moving VMware workloads to Azure — and the cases where staying put, or using Azure Local, is the better engineering answer.
Read perspectiveHow to compare VMware on-premises, Azure Local, and public Azure when licence, skills, latency and data residency actually matter.
Read perspectiveStart a conversation
Tell us how your environment is managed today and what isn’t getting done. We’ll work out the right starting point together.
Talk to an experienced engineer