A defined lifecycle, not an improvised one.
Every engagement follows the same seven stages. Each stage has an objective, a set of activities, and outputs you can actually see.
- Discover
- Assess
- Plan
Seven stages, in order.
Stages one to three happen during onboarding. Stages five to seven repeat continuously for as long as we work together.
- STAGE 01
Discover
Understand the business, the people, and the environment before recommending anything.
Activities
- Business priorities and growth plans
- Users, roles, and working patterns
- Locations and connectivity
- Devices and operating systems
- Applications and dependencies
- Vendors and support arrangements
- Current pain points and recurring issues
- Security concerns and past incidents
Outputs
Environment overviewStakeholder mapInitial issue logScope of assessmentWhat we need from youA short series of structured conversations with leadership and the people who use the systems daily.
Risk this addressesRecommendations made without context, and hidden dependencies discovered mid-project.
- STAGE 02
Assess
Establish a factual baseline of the current state and where the meaningful gaps are.
Activities
- Device and software inventory
- Administrative and user access review
- Patch and update status
- Security control coverage
- Backup posture and restore evidence
- Microsoft 365 configuration review
- Network and wireless review
- Documentation completeness
- Vendor dependencies
- Operational and process gaps
Outputs
Inventory baselineRisk registerGap analysisFindings summaryWhat we need from youRead-only access where possible, plus confirmation of what is in scope and business-critical.
Risk this addressesUnknown assets, stale accounts, unpatched systems, and untested backups.
- STAGE 03
Plan
Turn findings into a sequenced plan the business can actually fund and absorb.
Activities
- Risk prioritization by impact and likelihood
- Immediate fixes and quick wins
- 30-day stabilization plan
- 90-day improvement roadmap
- Long-term lifecycle recommendations
- Budget considerations and phasing
- Change sequencing and dependencies
Outputs
Prioritized remediation plan30/90-day roadmapBudget outlineAgreed success criteriaWhat we need from youA working review of the plan so priorities reflect business reality, not just technical preference.
Risk this addressesEffort spent on low-impact work while critical exposure remains open.
- STAGE 04
Implement
Deliver the agreed changes predictably, with documentation and a way back.
Activities
- Deployment of agreed tooling and standards
- Configuration against a defined baseline
- Documentation written as work is completed
- Testing before and after change
- User communication ahead of impact
- Change control and approvals
- Rollback planning for significant changes
Outputs
Configured baselineAs-built documentationChange recordsTest evidenceWhat we need from youScheduling, approvals, and communicating change windows to affected teams.
Risk this addressesUnplanned disruption, undocumented configuration, and changes that cannot be reversed.
- STAGE 05
Protect
Keep the environment monitored, patched, and defensible as day-to-day operations resume.
Activities
- Monitoring and alerting
- Patch management cycles
- Endpoint security coverage
- Identity and access controls
- Backup operation and verification
- Logging and retention
- Access management and review
- Security awareness support
Outputs
Monitoring coveragePatch reportingBackup verification recordsAccess review notesWhat we need from youAgreeing maintenance windows, escalation paths, and who can authorize access changes.
Risk this addressesDrift, unpatched systems, silent backup failures, and stale privileged access.
- STAGE 06
Optimize
Reduce effort, cost, and inconsistency once the environment is stable.
Activities
- Automation of repetitive tasks
- Standardization across devices and users
- Cost and spend review
- License review and cleanup
- Performance troubleshooting
- Workflow improvement
- Vendor and tooling consolidation
Outputs
Automation runbooksStandard build definitionsLicense and cost findingsWhat we need from youConfirming which workflows matter most and where friction is felt.
Risk this addressesManual error, duplicated tooling, and licensing spend with no owner.
- STAGE 07
Review
Keep the roadmap aligned with how the business is actually changing.
Activities
- Service reporting
- Risk review and register updates
- Strategic planning discussions
- Service standard review
- Roadmap updates
- Business change intake
- Technology lifecycle planning
Outputs
Review summaryUpdated risk registerRefreshed roadmapWhat we need from youA recurring review session with the people accountable for budget and operations.
Risk this addressesA plan that quietly becomes obsolete as the organization grows or changes direction.
Onboarding duration depends on the size and condition of the environment. We would rather give you an accurate schedule after discovery than a generic promise before it.
Begin at stage one.
Discovery is a conversation, not a commitment. It gives you a clear picture of your environment either way.