One loop, four steps
Most failures happen neither in the decision nor in operations, but in the handover between them. So we work in one loop where the same house gives the advice, does the build and follows through.
Before guardrails and decisions, we describe the desired future state with you: where should the business be in three or five years, and what must then be true of technology, security and cost? Then we work backwards to SMART goals – specific, measurable, achievable, relevant and time-bound – owned by the steering group and used to measure every step of the loop.
Risk appetite, roles and what "good enough" means, on one page the board can adopt. Without it, every technical decision reopens the debate.
Priorities, budget and 5–8 KPIs. We use a fixed method with the same templates and measurable milestones in every engagement – so the steering group recognises the format from meeting to meeting. If you have your own framework, we work in it.
Built to good practice – current, automated, maintainable and documented. No loose ends. The customer owns the code and the documentation from day one.
Visibility and prioritisation, active cost management and 24/7 security monitoring and incident response keep the guardrails true, and a quarterly report in the board's language closes the loop – and opens the next.
Then we start at step 3. A technical delivery with code, documentation and one measure is often what gives the board a reason to set guardrails next time.
Who actually turns up
One person at IUXTA is accountable on every engagement, and your contract is with IUXTA alone. Around that person we assemble the team from our own staff and an ecosystem of people we have worked with for years.
| Role on a typical project | Who | Example |
|---|---|---|
| Programme owner and board contact | IUXTA | NIS2 programme: owns the plan, reports to the board quarterly |
| Lead engineer / architect | IUXTA | Azure landing zone in IaC, M365 hardening, identity and device baseline |
| Specialists (network, data, AI) | IUXTA, supported by the ecosystem | Network and datacenter design, AI/automation, data platform |
| Legal and regulatory | Partner law firm with technology and privacy practice | NIS2/DORA scope, contracts, GDPR assessments, board briefings |
| Project and change management | Ecosystem | Runs the day-to-day, owns adoption and training |
| Business architecture | IUXTA, supported by the ecosystem | Process maps, operating model, KPI design |
| Detection and response 24/7 | Arctic Wolf | SOC, incident response, security culture |
| Continuous visibility | Coldbyte | Daily operational and compliance signals for management |
We price deliveries, not hours, wherever we can. Where we can't, we say so – and give an estimate you can hold us to.
Have a coffee with Pål.
Thirty minutes, no slides. You tell us what keeps you up at night; we tell you honestly whether we can help – and who to call if we can't.
Or let Artem look for skeletons.
An hour on screen with whoever runs your environment. No installation, no access – just the questions that tend to surface what's waiting. You get a list; we get an honest conversation about it. If you want to go deeper afterwards, we do it with read access – by agreement.