Home/Solutions
SolutionsStart from the problem, not the product list.
Almost every conversation begins with one of six situations. Find yours below and see what the first ninety days would look like.
“Our data centre lease ends in 14 months.”
A hard deadline, an undocumented estate, and a team already at capacity. The board has usually announced it before anyone checked the dependency map exists.
What goes wrong without help. Discovery gets compressed to fit the deadline, waves are sequenced alphabetically instead of by dependency, and the first production cutover finds three undocumented integrations at 2am.
- Automated discovery and dependency mapping in weeks 1–3
- Wave plan sequenced by blast radius, with rollback triggers agreed in advance
- Landing zone and pilot migration live inside eight weeks
- Decommission tracked per wave, so the savings actually land
First 90 days
- Weeks 1–3
Assess
Inventory, dependency map, TCO model, 7R disposition per workload.
- Weeks 4–8
Mobilise
Landing zone, connectivity, identity, security baseline, pilot workload to production.
- Weeks 9–13
First waves
Non-production waves migrated and rehearsed; decommission process proven end to end.
First 90 days
- Week 1–2
Forensics
What changed, when, and who owns it. First quick wins identified with no architecture change required.
- Week 3–6
Attribution
Tag policy enforced, account structure aligned, showback dashboards live to engineering leads.
- Week 7–13
Structural
Rightsizing executed, commitments resized to the new baseline, anomaly detection routed to owning teams.
“They found $190k of annual waste in the first fortnight and then refused to bill us a percentage of it.”
“The AWS bill doubled and nobody knows why.”
Growth was real, but so was the waste. Finance wants an answer this month, and engineering has other priorities.
What goes wrong without help. Someone buys three-year commitments to make the number smaller, locking in a pre-rightsizing baseline. Or a percentage-of-savings provider is engaged, and the easy 15% appears while the structural work never does.
- Cost forensics: what changed, when, and who owns it — inside two weeks
- Quick wins first, with no architecture changes required
- Tag policy and showback so it does not recur next quarter
- Commitment strategy sized to the post-rightsizing baseline
“We're on-call for our own product and it's breaking us.”
A small engineering team carrying 24×7 infrastructure duty they never signed up for. Usually two people are carrying most of it, and at least one is interviewing elsewhere.
What goes wrong without help. An MSP takes the pager without understanding the system, so every alert escalates straight back to your team — now with an extra handoff and a delay in front of it.
- Alert hygiene first — every existing alert is fixed, deleted or given a runbook before we accept the pager
- Runbooks written with your team, owned jointly, tested in non-production
- We take first-line paging around week three, after a shadow week
- Your engineers stay as escalation, not as the front line
“Our biggest prospect sent a 200-question security review.”
Enterprise or government procurement has arrived, and the controls need to be real rather than aspirational. There is usually a deal date attached.
What goes wrong without help. The questionnaire gets answered optimistically to keep the deal moving, and the gap surfaces later in an audit or, worse, an incident — with the answers on file.
- Gap assessment against ISO 27001, SOC 2 or the Essential Eight
- Guardrails deployed, not just documented — preventive before detective
- Evidence pack and current architecture diagrams ready for assessors
- Continuous control monitoring, so it stays true at next year's audit
The response pack we maintain
Customers on Managed and Enterprise plans get a standing pack that answers most of what enterprise procurement asks:
- Control mapping against your framework
- Current architecture and data flow diagrams
- Sub-processor register and hosting locations
- Incident response plan and notification path
- Insurance certificates and personnel screening policy
- Backup, retention and recovery test results
Turnaround on a new questionnaire is usually one to two business days rather than three weeks of internal chasing.
The most common finding
Backups that complete successfully and cannot be restored — because nobody has tried, or because the restore depends on a credential, network path or licence that only exists in the environment being recovered.
“We have a DR plan, but we've never tested it.”
A recovery document written three years ago by someone who has since left, referencing a network topology that no longer exists.
What goes wrong without help. The RTO in the document was never agreed with the business, so it is simultaneously too expensive to deliver and too slow to be acceptable — and nobody discovers which until the day it matters.
- RTO and RPO agreed per workload with the business, not assumed by IT
- Backup and cross-region strategy rebuilt to match the agreed targets
- A live failover exercise with a written, timed result
- Scheduled re-tests as part of the managed service
“We migrated, and the savings never showed up.”
A lift-and-shift landed on time. Then the bill arrived with cloud pricing applied to on-premises sizing, and the business case quietly stopped being mentioned.
What goes wrong without help. Modernisation gets proposed as a multi-year rewrite, which is unfundable, so nothing happens and the estate stays expensive and fragile at the same time.
- Rightsizing against real post-migration usage before anything is rewritten
- Modernisation backlog ranked by payback period, not by architectural purity
- Managed database and container moves that pay for themselves inside a year
- The workloads that should simply be retired, named explicitly
Ranked by payback, not by purity
Decomposing a monolith can be the right call for delivery speed or team autonomy. It is almost never the right call if the stated goal is cost, and we will say so.
Regulatory context we already carry
Financial services
APRA CPS 230 and CPS 234, material service provider obligations.
Read moreHealthcare
Health data handling, privacy by design, long-retention storage.
Read moreGovernment & GovTech
IRAP readiness, residency, procurement documentation.
Read moreSaaS & technology
Multi-tenancy, per-tenant cost, enterprise security reviews.
Read moreTell us the situation you're actually in
We will tell you honestly whether it is a two-week fix or a twelve-month programme — and if we are not the right partner, who might be.