The technical craft

Advice without technical depth is just opinion

This is what we build, secure and run – and how. Everything we build leaves behind code, documentation and a measure management can steer by later.

IT leader or architect?

Talk to Artem about the concrete stuff – architecture, security, code. No salespeople in the room.

Let Artem look for skeletons

Identity and token security

Entra ID, Conditional Access, phishing-resistant MFA, token protection and PIM. Identity is the new perimeter.

How: Tier 0/1/2 admin model, just-in-time access via PIM, Conditional Access as code, token binding where clients support it, and a review of every app registration and consent.

Maps to: ISO 27001 A.5.15–A.5.18, A.8.2–A.8.5; NSM basic principles 2.6.

Certificate infrastructure (PKI)

Cloud-based SCEP or internal CA, automated issuance and rotation, TLS hygiene. No certificates expiring on a Friday.

How: Inventory of every certificate and key, two-tier CA hierarchy where needed, automated issuance to devices and services (SCEP/Intune), alerting and rotation before expiry, and a plan for shorter lifetimes.

Maps to: ISO 27001 A.8.24; NIS2 art. 21(2)(h).

Infrastructure as code

Bicep/Terraform, landing zones, policy-as-code, GitOps. Everything built can be rebuilt.

How: Azure landing zone per good-practice frameworks, Azure Policy as code, pipelines with approvals, drift detection, and a handover where the customer owns the repo.

Maps to: ISO 27001 A.8.9, A.8.32; ISO 9001 change control.

AI and automation

Agents in Azure AI Foundry on the same rig as Coldbyte's security module – in your environment, with control and oversight.

How: One central rig for every AI need that requires control: model choice per purpose, logging of every call, data classification before data reaches a model, cost caps, and Copilot governance for what happens outside the rig. Data foundation first – a model is no better than the access control it inherits.

Maps to: ISO 42001; AI Act art. 9, 13, 14.

Data sovereignty and closed environments

Data location in Norway/EU, your own keys, air-gapped environments where regulation requires it – and a tested exit plan.

How: Assessment of which data and services must sit where, customer-managed keys, closed environments without internet access where required (including licensing that works without the cloud), and a documented way out of every vendor.

Maps to: GDPR ch. V; the Norwegian power-sector preparedness regulation; NIS2 art. 21(2)(d).

Network and datacenter

Segmentation, zero trust, hybrid architecture and on-prem where it belongs. Not cloud for the cloud's sake.

How: Target network design with segments by risk, micro-segmentation where OT or sensitive systems demand it, hybrid connectivity to Azure, and a datacenter plan that says what stays – and why.

Maps to: ISO 27001 A.8.20–A.8.22; NSM basic principles 2.5.

Visibility and logging

Central logging and log analysis/correlation.

How: Log sources prioritised by what an attacker actually does, retention per requirement, detection rules that are tested, and Coldbyte translating deviations into something management can read. Arctic Wolf keeps watch.

Maps to: ISO 27001 A.8.15–A.8.16; NIS2 art. 21(2)(b), 23.

Modern workplace

M365, Intune, device baseline and tenant-to-tenant migration. Done many times, documented every time.

How: Device security baseline, Autopilot, app and data policies, and a migration path with a feasibility study before the move – so you know what breaks before it breaks.

Maps to: ISO 27001 A.8.1, A.8.7.

Everything above is delivered as code in your repo, documentation you can read, and a measure management can follow. That is how technical work becomes something a board can steer by.

For management and boards

Have a coffee with Pål.

Thirty minutes, no slides. You tell us what keeps you up at night; we tell you honestly whether we can help – and who to call if we can't.

For IT leaders and architects

Or let Artem look for skeletons.

An hour on screen with whoever runs your environment. No installation, no access – just the questions that tend to surface what's waiting. You get a list; we get an honest conversation about it. If you want to go deeper afterwards, we do it with read access – by agreement.