Infrastructure & Cloud

The foundation everything else runs on.

Domain 1 of 8. Back to the assessment

Infrastructure is the domain where problems stay invisible until the worst possible moment. Servers run past end-of-life without incident for years; backups report success every night for a decade. The question is never whether the estate looks fine today. It is what happens on the day something fails, and whether the answer matches what your leadership team assumes.

Why it matters

A company that cannot say how long it would be down, or how much data it would lose, is carrying an unpriced risk on behalf of every customer commitment it has made.

The benchmark

What good looks like at your size

We score against this benchmark, meaning what a well-run company of 50 to 500 employees should reasonably have in place, rather than against theoretical perfection.

Nothing critical is unsupported

Every system the business depends on runs on hardware and software with a support path and a known end-of-life date. Exceptions exist deliberately, with a documented reason and a plan.

Recovery targets are business decisions

Leadership has stated how long each core system can be down and how much data loss is tolerable. The technical setup is built to those numbers rather than the other way round.

Restores are tested, not assumed

Someone recovers a real system from backup on a schedule and writes down how long it took. Green checkmarks on a dashboard are evidence that a job ran, not that data can be recovered.

Cloud placement is a deliberate choice

Each workload sits where it does for a stated reason, with the cost of that choice understood. Staying on-premises is a perfectly good answer when someone has actually done the math.

Capacity is planned ahead of the business

Headcount growth, new sites, and acquisitions reach infrastructure planning before they reach infrastructure. Someone is looking 18 to 24 months out against the business plan.

The pattern

What we typically find

Patterns common enough to name. None of them indicate a bad team. They are what happens when a company grows faster than the decisions that shaped its technology.

A single point of failure nobody escalated

One server, switch, or internet link whose failure stops the business. It is usually known to exactly one person, who has mentioned it, and it has never been framed to leadership as a business risk with a number attached.

Backups that have never been restored

Backup jobs report success for years. The first genuine restore attempt happens during the incident, which is when missing application dependencies, encryption keys, or retention gaps are discovered.

Cloud spend that grew by accretion

Servers were lifted and shifted as-is and now run 24/7 at on-premises sizing for workloads used eight hours a day. The bill grows quietly; nobody owns reducing it.

One application holding the estate hostage

An end-of-life operating system stays alive because a single line-of-business application will not run on anything newer, and the vendor conversation has been deferred for years.

A recovery-time gap between IT and leadership

IT estimates a day. Leadership assumes an hour. Neither number has been tested, and the gap only surfaces when it matters.

The method

How we assess it

Where a document does not exist, that is itself a finding, and we say so plainly rather than treating the gap as an obstacle.

What we examine
  • Servers, network, and endpoint estate: age, support status, and single points of failure
  • Cloud posture: what has moved, what should, and what it costs either way
  • Backup and disaster recovery: tested recovery, not just green checkmarks
  • Capacity against your growth plan for the next 24 months
What we ask you for
  • Inventory of servers, network devices, and endpoints with age and support status
  • Backup configuration and the results of the most recent restore test
  • Cloud billing detail for the trailing twelve months
  • Network topology, internet and WAN links, and site connectivity
  • The disaster recovery or business continuity plan, if one exists
  • Working sessions with whoever actually operates the environment, whether internal staff or your provider
The output

Questions the readout answers

If our biggest system failed tomorrow, how long would we actually be down?

Are we running infrastructure a company our size should have outgrown, or outsourced?

The deliverable

What this domain contributes to your report

  • A scored view of the estate with every single point of failure named and priced
  • Realistic recovery time and data-loss estimates set against what the business actually needs
  • An infrastructure cost baseline, including where cloud spend is mispriced for the workload
  • The sequence of what to fix first, with budget ranges and owners
The scale

How this domain is scored

Every domain is scored 0–10 on the same scale, so the scorecard shows you where to look first rather than a single undifferentiated grade.

0–3
Material risk today

Something here can hurt the business now. These findings lead the roadmap.

4–6
Workable, but behind

Functioning, but behind where a company of your size and stage should be.

7–8
Solid

In good shape. Worth maintaining rather than investing further right now.

9–10
Ahead of peers

A genuine strength, and often something to build on elsewhere.