Selected technical projects

Infrastructure built to solve a specific problem.

We show the actual scope of work without client names, addressing details or sensitive environment parameters. No marketing percentages that cannot be honestly verified.

CASE 01

Proxmox virtualisation with VM backup

Service consolidation on a managed virtual environment with a separate backup and recovery verification process.

Starting point

Services ran in a distributed environment, while updates, workload moves and disaster recovery required a consistent operating model.

Technology scope

Proxmox VEVM backupvirtualisationrecovery test

What we implemented

  • deployment of Proxmox VE and separation of services into virtual machines
  • workload migration in an agreed sequence and maintenance windows
  • backup schedule, retention policy and a controlled recovery test
  • environment documentation and basic incident procedures

Operational outcome

  • one management plane for resources and virtual machines
  • a repeatable backup process instead of ad-hoc copies
  • simpler planning for updates, migrations and service recovery
CASE 02

Layered security with XDR, Wazuh and UDM Pro

Endpoint telemetry combined with network-edge protection and an organised alert-handling process.

Starting point

Events from workstations, servers and the network were not analysed in one place, making incidents and priorities harder to assess.

Technology scope

XDRWazuhUbiquiti UDM ProIDS/IPSVLAN

What we implemented

  • Wazuh agents and rules for the agreed systems
  • XDR protection across endpoints included in the scope
  • Ubiquiti UDM Pro configuration: segmentation, firewall rules and IDS/IPS
  • alert severity, escalation and initial response scenarios

Operational outcome

  • a central view of security events across infrastructure layers
  • clearer traffic separation and fewer unnecessary connections
  • faster alert qualification and a documented response path
CASE 03

NAS as a secure shared-file platform

A central file repository with role-based access, version history and an independent data backup.

Starting point

Documents were stored locally and across inconsistent shares, with unclear access rules and backup ownership.

Technology scope

NASSMBgroup permissionssnapshotsbackup

What we implemented

  • directory structure, user groups and access-level design
  • network shares and least-privilege access
  • snapshots and a separate data-backup process
  • file migration, access testing and user handover

Operational outcome

  • one organised location for working with business documents
  • role-based access instead of shared accounts and accidental permissions
  • the ability to recover an earlier version or restore data from backup
CASE 04

Service containerisation and resource optimisation

Applications and dependencies separated into repeatable environments that are easier to update, move and recover.

Starting point

Several smaller services used separate heavy environments or shared dependencies, making changes risky and difficult to reproduce.

Technology scope

containersDockerComposevolumesautomation

What we implemented

  • inventory of services, ports, volumes and dependencies
  • migration of agreed applications into isolated containers
  • versioned configuration for networking and persistent data
  • update, data-backup and restart procedures

Operational outcome

  • repeatable service startup and simpler configuration recovery
  • better isolation of applications and their dependencies
  • lower resource overhead for services that do not need a separate virtual machine
CASE 05

Carbonio deployment for email and collaboration

A managed email environment with organised account administration, domain protection and a controlled data migration process.

Starting point

The goal was to replace the existing email environment with a solution that gives the business greater control over accounts, security and future service development.

Technology scope

CarbonioSPFDKIMDMARCTLSemail migration

What we implemented

  • server preparation and Carbonio installation aligned with the environment requirements
  • domain, account, alias and access-policy configuration
  • SPF, DKIM and DMARC setup together with TLS transport security
  • migration of agreed mailboxes, mail-flow testing and administrator documentation

Operational outcome

  • one managed email and collaboration environment for users
  • organised administration of accounts, domains and message security
  • a controlled transition with operational verification before migration completion

Projects are anonymised for security reasons. The exact scope and outcome always depend on the existing environment and the agreement with the client.

Facing a similar environment or problem?

We first assess the technical state and dependencies. Only then do we propose the scope, sequence of work and a safe migration approach.

Check your IT health