Cloud, Security & Managed IT
Cloud architecture, deployment, and day-to-day operation on AWS, Azure, or GCP, with the security work in the same engagement: hardening, compliance readiness, monitoring, incident response, and managed IT.
What we do
Architecture & deployment
Environments, networking, databases, and scaling designed around your actual load pattern, defined in Terraform or the provider's own IaC.
Migration
Moving from on-premise or between providers, in stages, with a rollback path at each one.
CI/CD and releases
Automated pipelines with blue-green or rolling deploys, so releases happen mid-week without a maintenance window.
Observability
Metrics, logs, traces, dashboards, and alert thresholds that fire before customers notice, routed to someone expecting them.
Cost optimisation & scaling
Right-sizing, autoscaling, reserved and spot capacity, storage lifecycle rules, and a per-service breakdown of where the bill goes.
Backup & disaster recovery
Backup schedules, retention, cross-region copies, and a documented recovery procedure with a tested restore time.
Threat modelling & hardening
IAM least privilege, network segmentation, secrets management, encryption in transit and at rest, and closing what the review turns up.
Compliance readiness
SOC 2, ISO 27001, GDPR, and HIPAA groundwork: controls, policies, evidence collection, and preparation for the audit itself.
Continuous monitoring
Intrusion detection, vulnerability scanning, dependency and container image scanning, patching, and brute-force blocking.
Incident response
A written runbook, an on-call arrangement, containment and remediation when something happens, and a post-incident report you can send to a customer.
Managed IT
Identity and device management, email and workspace administration, access provisioning and revocation, and everyday support.
Security questionnaires
Filling in the enterprise reviews and vendor assessments your prospects send, and fixing whatever they expose.
How an engagement starts
1. Audit
A read of the current infrastructure, IAM, network layout, deployment process, monitoring, backups, and the bill, written up with findings ranked by risk and cost.
2. Quick wins
The unowned admin accounts, missing backups, and idle resources are dealt with in the first weeks, before any larger project starts.
3. Plan
A phased plan for the rest, with effort, cost, and the order of work agreed before anything starts.
4. Implementation
Changes made in code and reviewed, applied to staging first, with a rollback path for each one.
5. Ongoing operation
Monitoring, patching, releases, cost review, and on-call, under a defined scope and response time.
What you keep
Your accounts
Cloud accounts, domains, and third-party services stay in your organisation's name with your billing attached.
Infrastructure as code
The environment is defined in version-controlled code in your repository, not assembled by hand in a console.
Runbooks
Written procedures for deploys, restores, incidents, and on-call, so a new hire can follow them.
No lock-in
Standard tooling and documented setup, so your own DevOps hire can take it over when you make one.
Who this is for
Products reaching real scale. Teams where deployments have become nerve-wracking or depend on one person. Companies whose cloud bill is outpacing revenue. Startups facing their first enterprise security questionnaire.
Frequently asked
Which cloud providers do you work with?
AWS, Azure, and GCP. The choice follows your existing stack, your team's experience, and your budget rather than a house preference.
Do you only do this for software you built?
No. Most of this work is inherited infrastructure. It starts with an audit, so you know what you have before anything changes.
Can we take just the cloud half, or just the security half?
Yes. Most engagements start with whichever is urgent — a cost problem, or a security questionnaire due Friday.
We're small. Do we really need the security work?
The traffic hitting your login page is automated and doesn't check your headcount. More often, though, it's a customer's procurement team asking for a security review before they'll sign.
Can you get us SOC 2 ready?
Yes: gap assessment, controls, policies, evidence collection, and readiness for the audit. We scope it so it doesn't consume a quarter of your engineering time.
What happens if we get breached at 2am?
Someone who knows your systems responds. Contain it, find the entry point, remediate, then a written post-incident report you can forward to customers.
What does an on-call arrangement cover?
Scope and response times are agreed up front — which systems, which hours, and what counts as an incident — so nobody is guessing at 2am.
Will we be locked into you?
No. Everything is in code and documented, in your accounts. A DevOps hire next year inherits a system with a manual.