Skip to content
Our process

A defined lifecycle, not an improvised one.

Every engagement follows the same seven stages. Each stage has an objective, a set of activities, and outputs you can actually see.

  • Discover
  • Assess
  • Plan
Lifecycle

Seven stages, in order.

Stages one to three happen during onboarding. Stages five to seven repeat continuously for as long as we work together.

  1. STAGE 01

    Discover

    Understand the business, the people, and the environment before recommending anything.

    Activities

    • Business priorities and growth plans
    • Users, roles, and working patterns
    • Locations and connectivity
    • Devices and operating systems
    • Applications and dependencies
    • Vendors and support arrangements
    • Current pain points and recurring issues
    • Security concerns and past incidents

    Outputs

    Environment overviewStakeholder mapInitial issue logScope of assessment
    What we need from you

    A short series of structured conversations with leadership and the people who use the systems daily.

    Risk this addresses

    Recommendations made without context, and hidden dependencies discovered mid-project.

  2. STAGE 02

    Assess

    Establish a factual baseline of the current state and where the meaningful gaps are.

    Activities

    • Device and software inventory
    • Administrative and user access review
    • Patch and update status
    • Security control coverage
    • Backup posture and restore evidence
    • Microsoft 365 configuration review
    • Network and wireless review
    • Documentation completeness
    • Vendor dependencies
    • Operational and process gaps

    Outputs

    Inventory baselineRisk registerGap analysisFindings summary
    What we need from you

    Read-only access where possible, plus confirmation of what is in scope and business-critical.

    Risk this addresses

    Unknown assets, stale accounts, unpatched systems, and untested backups.

  3. STAGE 03

    Plan

    Turn findings into a sequenced plan the business can actually fund and absorb.

    Activities

    • Risk prioritization by impact and likelihood
    • Immediate fixes and quick wins
    • 30-day stabilization plan
    • 90-day improvement roadmap
    • Long-term lifecycle recommendations
    • Budget considerations and phasing
    • Change sequencing and dependencies

    Outputs

    Prioritized remediation plan30/90-day roadmapBudget outlineAgreed success criteria
    What we need from you

    A working review of the plan so priorities reflect business reality, not just technical preference.

    Risk this addresses

    Effort spent on low-impact work while critical exposure remains open.

  4. STAGE 04

    Implement

    Deliver the agreed changes predictably, with documentation and a way back.

    Activities

    • Deployment of agreed tooling and standards
    • Configuration against a defined baseline
    • Documentation written as work is completed
    • Testing before and after change
    • User communication ahead of impact
    • Change control and approvals
    • Rollback planning for significant changes

    Outputs

    Configured baselineAs-built documentationChange recordsTest evidence
    What we need from you

    Scheduling, approvals, and communicating change windows to affected teams.

    Risk this addresses

    Unplanned disruption, undocumented configuration, and changes that cannot be reversed.

  5. STAGE 05

    Protect

    Keep the environment monitored, patched, and defensible as day-to-day operations resume.

    Activities

    • Monitoring and alerting
    • Patch management cycles
    • Endpoint security coverage
    • Identity and access controls
    • Backup operation and verification
    • Logging and retention
    • Access management and review
    • Security awareness support

    Outputs

    Monitoring coveragePatch reportingBackup verification recordsAccess review notes
    What we need from you

    Agreeing maintenance windows, escalation paths, and who can authorize access changes.

    Risk this addresses

    Drift, unpatched systems, silent backup failures, and stale privileged access.

  6. STAGE 06

    Optimize

    Reduce effort, cost, and inconsistency once the environment is stable.

    Activities

    • Automation of repetitive tasks
    • Standardization across devices and users
    • Cost and spend review
    • License review and cleanup
    • Performance troubleshooting
    • Workflow improvement
    • Vendor and tooling consolidation

    Outputs

    Automation runbooksStandard build definitionsLicense and cost findings
    What we need from you

    Confirming which workflows matter most and where friction is felt.

    Risk this addresses

    Manual error, duplicated tooling, and licensing spend with no owner.

  7. STAGE 07

    Review

    Keep the roadmap aligned with how the business is actually changing.

    Activities

    • Service reporting
    • Risk review and register updates
    • Strategic planning discussions
    • Service standard review
    • Roadmap updates
    • Business change intake
    • Technology lifecycle planning

    Outputs

    Review summaryUpdated risk registerRefreshed roadmap
    What we need from you

    A recurring review session with the people accountable for budget and operations.

    Risk this addresses

    A plan that quietly becomes obsolete as the organization grows or changes direction.

Timing

Onboarding duration depends on the size and condition of the environment. We would rather give you an accurate schedule after discovery than a generic promise before it.

Next step

Begin at stage one.

Discovery is a conversation, not a commitment. It gives you a clear picture of your environment either way.