CASE STUDIES

Three engagements, one consultant, security through to AI.

A Premier League club, a London hotel group and a modular buildings manufacturer. Different sectors, the same pattern: get the identity, network and governance right, then put the AI on top. Names are withheld by default; references are available on request.

Sport & venues

A Premier League club: security architecture, SIEM, network access control and storage modernisation across a stadium and a training ground.

Infrastructure & Security LeadStanding engagement, direct contract

The situation

Two sites run as one production estate: hybrid Active Directory and Entra ID, VMware vSphere clusters, ageing NetApp storage, a Fortinet perimeter, HPE/Aruba switching, and broadcast partners on dedicated VLANs every match day. Cyber Essentials Plus and the Premier League Security Baseline to maintain, with a small in-house team and near-zero tolerance for disruption during live events.

What we did

  • Microsoft Sentinel SIEM with FortiGate, FortiClient EMS, domain controller, Entra sign-in and M365 audit sources, plus a Linux collector for telemetry.
  • Storage migration from NetApp to Synology with snapshots and cross-site replication: the training ground complete, the stadium in flight.
  • FortiNAC network access control, VLAN segmentation, SNMPv3 and a FreeRADIUS-to-NPS migration for switch and Wi-Fi authentication.
  • Intune across Windows, macOS, iOS and Android, including FortiClient on macOS, endpoint remediations and a Windows 10 device refresh.
  • Cyber Essentials Plus answers and evidence, an IT disaster-recovery plan, and a VMware-versus-Hyper-V renewal assessment.
  • AI on top: AI usage policy, a SharePoint AI hub and training, Claude Desktop deployed through Intune, an M365 AI email assistant, and the architecture for an AI alert-triage agent across Fortinet, VMware, Veeam and Sentinel.

Outcome

Compliance maintained through every assessment cycle. Match days delivered without IT disruption. One person accountable from firewall policy to AI policy, so the security posture and the AI programme were designed together rather than negotiated afterwards.

Microsoft SentinelFortiGate HAFortiNACFortiClient EMSVMware vSphereSynologyHPE/ArubaIntuneEntra IDCyber Essentials PlusClaude
Hospitality

A London hotel group: its own administration, devices and provisioning inside a shared Microsoft 365 tenant, then a cross-tenant migration for a second property group.

Lead Technical ArchitectDelivered through a hospitality managed service provider

The situation

A European hotel group ran one Microsoft 365 tenant for every property. The London hotel needed to manage its own users and devices, with its own support desk, without leaving the group tenant or gaining rights over anyone else. A second engagement needed two tenants untangled: business mail and devices in one, family and personal email in another, with domains moving between them.

What we did

  • Administrative segregation: a dynamic Entra Administrative Unit for London users, scoped User, Groups and Helpdesk admin roles, an Exchange Online RBAC management scope, and Intune RBAC with a London scope tag.
  • Automated provisioning: a SharePoint intake list driving a Power Automate flow that creates the user, resolves the manager and assigns licences by group, with failures logged back to the list.
  • Device baselines: Windows Autopilot, security baselines, BitLocker, LAPS, Defender, firewall, update rings and compliance, all scoped to London devices.
  • Cross-tenant migration: MigrationWiz mailbox and OneDrive projects, DNS, MX, SPF, DKIM and DMARC cutovers, file shares into SharePoint, and Intune enrolment for Windows, macOS, iOS and Android, with hypercare after go-live.

Outcome

The London team manages its own users and devices in minutes rather than raising tickets with the group, and cannot touch anything outside its scope. The group tenant stayed intact. Every phase shipped with a handover document, a cutover runbook and a user migration guide the service desk could run without us.

Entra Administrative UnitsExchange Online RBACIntune scope tagsPower AutomateWindows AutopilotMigrationWizConditional AccessSharePoint
Manufacturing & construction

A modular buildings manufacturer: a board-approved AI policy, a live tools register and a SharePoint AI hub, with a Copilot pilot behind it.

AI governance & adoptionAround 160 staff, six public-sector frameworks, Cyber Essentials Plus

The situation

The board wanted AI adopted, not banned, but staff in several departments were already using consumer ChatGPT with company data. Public-sector frameworks require bid transparency, the Data (Use and Access) Act had changed the rules on automated decisions, and the internal IT lead was candid about limited AI experience. The policy had to survive tender questionnaires and the insurer, and the SHEQ team owned document control.

What we did

  • A criteria-led AI acceptable-use policy that names no tools: approval criteria in the policy, tools in a separate register reviewed monthly, so the board signs once and the register changes without re-approval.
  • The pack around it: an Approved AI Tools register, a staff one-pager, a ten-question knowledge test and a board session, with bid transparency, agentic-AI rules, a recruitment-AI procurement gate and insurer disclosure built in.
  • An “AI at” SharePoint hub built as an SPFx web part reading the register live, with a tool-request intake and training library the AI lead edits in the browser with no rebuild.
  • A Copilot pilot for the document-heavy teams, with Copilot Chat as the free like-for-like replacement for consumer tools.

Outcome

Policy approved by the board first time and reviewed by the data protection adviser without changes, recordable for pre-qualification questionnaires. Consumer-tier AI replaced rather than fought. A deployment runbook the in-house lead could follow, so the hub went into the production tenant without us holding the keys.

AI acceptable-use policyData (Use and Access) ActSharePoint SPFxPnP PowerShellMicrosoft 365 CopilotPower AutomateCyber Essentials Plus

On names. Client organisations are described, not named, unless they have agreed in writing to be. Detail is limited to what the client would be comfortable seeing in a tender response. References are available on request for serious enquiries.

Sound like your organisation?

Book a free discovery call. Thirty minutes on where you are, what is exposed and what a first engagement would look like — no pitch, no obligation.