Practice 01 / Infrastructure

Infrastructure you can draw on one page.

Most environments were never designed; they accumulated. A server here, a SaaS subscription there, a cloud tenant somebody opened for one project in 2019. We map what you actually run, find where it will fail you first, and put the upgrades in an order your budget can absorb.

What the review covers

Six layers, assessed as one system.

A finding in one layer is almost always a symptom in another. Reviewing them together is the only way to tell a capacity problem from a design problem.

Cloud and tenancy

Azure, Microsoft 365 and AWS: what is provisioned, what is being billed for, what is running with nobody’s name against it, and which commitments renew before you could act on them.

Network and segmentation

How traffic actually moves between sites, VLANs and VPN tunnels, and which flat stretch of it would let one compromised laptop reach the file server, the backups and the finance workstation.

Compute and storage

Age, support status, capacity headroom and the single points of failure your team has quietly learned to work around rather than report.

Backup and recovery

Not whether backups run. Whether a restore has actually been performed, how long it took, what came back incomplete, and whether the copy would survive the event you are insuring against.

Identity and access

Who can sign in, from where, with which second factor, which accounts belong to people who left, and how many of them hold rights nobody would grant them today.

Endpoint lifecycle

Patch state, hardware age, imaging and the replacement cadence, so device refresh stops arriving as a capital surprise every few years.

What you get

Three deliverables, all of them usable without us.

The report is written for the people who will live with it: your team, your auditor, your insurer, or whoever you hire next. Nothing in it depends on a tool only we can run.

01

A current-state map

One diagram per layer, drawn so a new engineer or an underwriter can follow it without a guided tour, plus the inventory behind each diagram.

02

A ranked remediation list

Every finding with the evidence attached, the effort required to fix it, and an honest statement of what it costs you to leave it alone, because some things genuinely should be left alone.

03

A sequenced, priced plan

Twelve to twenty-four months of work ordered by dependency and risk rather than by vendor convenience, with each phase priced before you commit to any of it.

Who you are working with

The migrations on this page have already been run at 16,000 endpoints.

VanDien.io is led by Christopher Moskowitz, who most recently ran engineering for Jefferies, a full service capital markets, investment bank, leading a 55-person organization that supported more than 16,000 endpoints on a budget of $15M to $20M, and was CTO at two premier New York alternative investment organizations before that. SCCM to Intune, Entra ID and conditional access, server provisioning automated across on-premise, AWS and Azure: these were delivered in production, at a scale your environment is unlikely to reach.

About Christopher Moskowitz →

Common questions

How long does an infrastructure assessment take?

Typically two to four weeks from kickoff to the written report, depending on how many sites and systems are in scope. Most of that is our work, not yours; we ask for roughly two hours of your team’s time in interviews plus read-only access to the systems under review.

Do you need administrative access to our systems?

Read-only is enough for the assessment itself, and we prefer it. Where a finding needs proving rather than inferring, we will ask for a supervised session rather than standing credentials.

Will you tell us to move everything to the cloud?

No. Some workloads are cheaper, safer and simpler where they already are, and we will say so. The output includes the three-year cost comparison behind each recommendation so you can check the reasoning rather than trust it.

Can you carry out the work you recommend?

Yes, as a separate fixed-fee phase, and only if you want us to. The assessment is written so that your own team or another provider could execute it without us, because a plan you can only use by hiring the author is not a plan.

We have no internal IT. Is this still relevant?

It is usually more relevant. Environments without a dedicated owner accumulate the most undocumented dependencies, and the first deliverable, a current-state map, is the thing that has been missing.

Bring us the environment nobody has fully documented.

info@vandien.io · (551) 236-3191 · Ridgewood, NJ, serving the New York metro

Start the conversation