Identity and token security
Entra ID, Conditional Access, phishing-resistant MFA, token protection and PIM. Identity is the new perimeter.
How: Tier 0/1/2 admin model, just-in-time access via PIM, Conditional Access as code, token binding where clients support it, and a review of every app registration and consent.
Maps to: ISO 27001 A.5.15–A.5.18, A.8.2–A.8.5; NSM basic principles 2.6.
Certificate infrastructure (PKI)
Cloud-based SCEP or internal CA, automated issuance and rotation, TLS hygiene. No certificates expiring on a Friday.
How: Inventory of every certificate and key, two-tier CA hierarchy where needed, automated issuance to devices and services (SCEP/Intune), alerting and rotation before expiry, and a plan for shorter lifetimes.
Maps to: ISO 27001 A.8.24; NIS2 art. 21(2)(h).
Infrastructure as code
Bicep/Terraform, landing zones, policy-as-code, GitOps. Everything built can be rebuilt.
How: Azure landing zone per good-practice frameworks, Azure Policy as code, pipelines with approvals, drift detection, and a handover where the customer owns the repo.
Maps to: ISO 27001 A.8.9, A.8.32; ISO 9001 change control.
AI and automation
Agents in Azure AI Foundry on the same rig as Coldbyte's security module – in your environment, with control and oversight.
How: One central rig for every AI need that requires control: model choice per purpose, logging of every call, data classification before data reaches a model, cost caps, and Copilot governance for what happens outside the rig. Data foundation first – a model is no better than the access control it inherits.
Maps to: ISO 42001; AI Act art. 9, 13, 14.
Data sovereignty and closed environments
Data location in Norway/EU, your own keys, air-gapped environments where regulation requires it – and a tested exit plan.
How: Assessment of which data and services must sit where, customer-managed keys, closed environments without internet access where required (including licensing that works without the cloud), and a documented way out of every vendor.
Maps to: GDPR ch. V; the Norwegian power-sector preparedness regulation; NIS2 art. 21(2)(d).
Network and datacenter
Segmentation, zero trust, hybrid architecture and on-prem where it belongs. Not cloud for the cloud's sake.
How: Target network design with segments by risk, micro-segmentation where OT or sensitive systems demand it, hybrid connectivity to Azure, and a datacenter plan that says what stays – and why.
Maps to: ISO 27001 A.8.20–A.8.22; NSM basic principles 2.5.
Visibility and logging
Central logging and log analysis/correlation.
How: Log sources prioritised by what an attacker actually does, retention per requirement, detection rules that are tested, and Coldbyte translating deviations into something management can read. Arctic Wolf keeps watch.
Maps to: ISO 27001 A.8.15–A.8.16; NIS2 art. 21(2)(b), 23.
Modern workplace
M365, Intune, device baseline and tenant-to-tenant migration. Done many times, documented every time.
How: Device security baseline, Autopilot, app and data policies, and a migration path with a feasibility study before the move – so you know what breaks before it breaks.
Maps to: ISO 27001 A.8.1, A.8.7.
Everything above is delivered as code in your repo, documentation you can read, and a measure management can follow. That is how technical work becomes something a board can steer by.