Skip to content
Director-Tech
A quiet boardroom with process maps on the wall and mill buildings at dusk

Practice

Own the technology. Lead the people who run it. Leave both able to continue without you.

The platforms change. The obligation does not.

Clarity of the multi-cloud estate

The job is an operating picture that leadership and the operators can share: what is running, who owns it, cost, risk. The team should not depend on the last architecture slide, or on the person who still remembers it. Most organizations are not “in the cloud.” They are running across several of them. Azure may be the primary gravity well, AWS services that grew up elsewhere, Oracle Cloud for the ERP or databases, occasionally a sovereign tenant with its own portal. Those are the planes. The practical problem is not their presence. It is the absence of a coherent picture: unclear boundaries, unowned resources, and diagrams that no longer match what is actually deployed.

The work is to make that picture legible to the people who have to live with it. Resource Graph and equivalent tooling across clouds reveal what is running, not what the last slide claimed. Subscriptions, landing zones, networking, and policy are treated as a single operating picture. The goal is boring reliability and a map that survives the person who drew it.

  • Operating picture
  • Named ownership
  • Sovereign tenants
  • A map that survives the author

Identity as the control plane

The control plane is how the team stops depending on one person’s memory of leftover registrations and credentials. SSO is easy until it is not. The failures that matter live in the edge cases: application registrations that outlived their projects, service principals with lingering credentials, tokens embedded in runbooks, and directories that do not share a plane.

The practice treats identity as the primary control plane of the estate. Every significant application is mapped to a clear identity path. Conditional Access is applied where it actually reduces risk. Credential lineage is tracked rather than assumed. Global Administrator is a break-glass privilege, not a working account. When a SaaS platform cannot enforce recipient-domain restrictions, the response is operational—not another policy document. Successors are walked through the map until they can handle the odd registration without external help.

  • Control plane
  • Credential lineage
  • Break-glass only
  • A successor who can handle the odd case

Continuous control of the public perimeter

Perimeter work is a recurring discipline the operators can explain, not a scan that only a specialist can read. A public IP is not, by itself, a finding. The useful questions are layered: Is the resource even running? What controls sit in front of it? Does the certificate name match the DNS people actually use? Did a CNAME grow around the intended path?

What is reachable is enumerated across clouds. A clear disposition vocabulary (approved exception, remediation, decommission, false positive) keeps the backlog from becoming a list of opinions. Certificates, domain portfolios, and default-deny settings on collaboration and analytics platforms are brought under the same continuous review. The result is an explainable attack surface rather than two competing truths—one from the security tools and one from the people who actually run the systems.

  • Recurring review
  • Disposition vocabulary
  • Certificates and domains
  • An explainable surface

Keeping industrial and corporate networks intentionally separate

The work is to keep industrial and corporate planes separate and understandable to both the network team and the plant engineers. Manufacturing and industrial estates are not office networks with more dust. OT networks, plant automation, and SCADA-adjacent systems require strict segmentation. A well-intentioned peering or routing change can quietly collapse the boundary both groups depend on.

On the campus and WAN side this is still frequently Cisco—firewalls, edge routing, VPN termination—sitting next to Azure VNets and whichever cloud the ERP chose. That is what is actually there, not a certificate. The director’s responsibility is named change authority: what may route, what must not, and who is allowed to change it. Keep those planes from becoming one fabric by accident.

  • Intentional planes
  • IT/OT boundary
  • Named change authority
  • Understandable segmentation

Ownership that ends in transfer

The successor inherits how the work is run: the picture, the meeting, the named owners. Not only the diagrams. The through-line of the practice is not a particular technology. It is a contract: take ownership of the technology and of the people who have to live with it, then leave both able to continue. A long engagement that leaves the organization dependent is a failure of the original ownership.

The method is consistent across scales. Living artifacts, clear ownership with actual names, sandboxes on the surfaces that hurt, and a defined period of advisory support after exit. In earlier years this meant training clients until they no longer needed outside help to keep Novell and SCO Unix environments operational. The test remains the same: can they run the next cycle with the previous owner out of the room?

  • Living artifacts
  • Named ownership
  • Transfer test
  • Advisory after exit

AI that has a defined job

Most AI initiatives die in a deck. The standard applied here is the opposite. A capability ships only when it performs a job a person already does, on systems the organization already owns, with a clear owner, data boundary, and fail-closed behavior. The person decides what earns a place. The model does not.

The current working example is a receptionist on a published number (and in the browser) that reads the calendar, books or moves time, and takes messages during defined business hours. That same discipline is applied when evaluating where models belong inside a larger estate: identity boundaries on the tools, data that is appropriate for context, and a refusal to stand up copilots that no one will open on a Tuesday. Predictive or operational use cases in manufacturing are considered only when they meet the same bar—clear job, clear owner, clear failure mode—not as science projects.

  • Defined job
  • Clear owner
  • Data boundary
  • Fail-closed

How I think about the work

Five tests. Not a manifesto.

  • Ownership is only real if it ends in transfer.

    A long engagement that leaves the organization dependent on the person who just left is a failure of the original responsibility. The test is whether a successor can complete the next cycle without a call — including how the work is run, not only the diagrams.

  • Maps beat tribal knowledge.

    Living artifacts, clear ownership with actual names, and boundaries that can be explained are more valuable than heroics or undocumented expertise. The estate must remain legible to the people who operate it after the current owner is gone.

  • Boundaries exist to protect the business.

    Identity, network, cloud, and OT planes are not architectural preferences. They are controls. When they blur, risk accumulates quietly. Keeping them intentional and explainable is part of the work.

  • The hire is the person, not the platform.

    Matching a certification or a particular exposure is not the test. The test is whether this individual can own the enterprise technology and lead the team that runs it, then leave both operable. Platforms are the terrain of the work. They are not the proof of the hire.

  • New capability must earn its place.

    AI or any other technology ships only when it performs a job a person already does, on systems the organization already owns, with a defined owner, data boundary, and fail-closed behavior. The person decides what earns a place. The model does not. Science projects stay in the lab.

Where the work lives

The surfaces the work actually sits on.

Not a vendor matrix. The planes that have to stay intentional — identity, network, cloud, industrial — and the transfer that makes ownership real.

The multi-cloud picture

Subscriptions, landing zones, networking, and policy treated as one operating picture the operators can share — including a sovereign tenant when the business actually has one.

Identity as control

The corporate identity provider as the only reliable door. Credential lineage tracked rather than assumed. Break-glass kept as break-glass. A map the team can walk without the last owner in the room.

The public path

What is reachable, what sits in front of it, whether the certificate matches the name people use, and whether a CNAME grew around the intended path. Operators should be able to explain it.

Industrial and corporate planes

OT, plant automation, and the WAN kept intentionally separate. Segmentation that plant engineers and the network team can both explain.

SaaS that can share too freely

Collaboration and analytics platforms under default-deny. When a vendor cannot restrict by recipient domain, the response is operational.

Transfer, not dependency

Living maps, named owners, the meeting rhythm, and a successor who can complete the next cycle without a call. The close of the engagement is part of the work.

Engagements

Three ways in. Transfer is part of each of them.

Conversation

Speak with the line in the browser, or dial. It books the calendar or takes a message.

Written Picture

A time-boxed look at what is actually running. Two to four weeks. The deliverable is an ownership map, a sequence, and what not to do. Then a decision: retained director, or stop.

Retained director

A longer-term seat as the owner of the technology: priorities, spend, vendors, and the team’s operating rhythm. Not a project tied to one platform. When the successor can run the next cycle, the seat ends.

Written Picture

Written Picture

A time-boxed look at what is actually running. Leadership and the people who operate the estate get the same map.

Two to four weeks. An ownership map, a sequence, and what not to do. Then a decision: retained director, or stop.

No ticket queue. No staff-aug. No SOC.

A Written Picture is a defined engagement, not an open consulting meter. A retained director seat is a longer-term obligation with a transfer test, not a managed-services add-on.

Retained director

What the seat owns.

A checklist a board packet can hold. When the successor can run the next cycle, the seat ends. Advisory after exit is available. A ticket queue is never the product.

  • Cloud operating picture
  • Identity control plane
  • Public perimeter
  • IT/OT change authority
  • Vendor and spend decisions
  • Successor development

Industrial and manufacturing estates sit on a dedicated page. Plant automation and the corporate estate are not the same network. Manufacturing.

Talk through a fit