Networks that stay up.
Security that holds.
I design, build, monitor and defend the network and infrastructure your business runs on. One engineer, end to end, from network design and monitoring through segmentation, disaster recovery and the deep dive troubleshooting nobody else managed to close.
No account manager, no handover between tiers, no repeating your topology to a stranger.
Most work is remote and scheduled around your change window. I attend in person when the problem is physical.
I do not resell hardware, so the recommendation is simply the one that fits your estate.
Packet captures, counters and restore timings. You get the proof, not a plausible story.
Ten services, one operating standard
Delivered as fixed scope projects, recurring support, or block hours. Every engagement ends with documentation, monitoring coverage and evidence you can hand to an auditor.
Network Design & Deployment
Routed, switched and segmented networks built to survive growth.
Greenfield builds and brownfield rebuilds: campus LAN, data centre fabric, WAN and SD-WAN edge, delivered with documentation you can actually operate from.
NMS Deployment
A monitoring system your engineers trust at 3am.
Design and rollout of a full network management system: discovery, polling, flow, syslog, traps, dashboards and alert routing, tuned so that every page means something.
24/7 Network Monitoring
Continuous eyes on the estate, with a person behind the alerts.
Managed monitoring of your network, servers and connectivity with defined response targets, incident handling, and monthly capacity and availability reporting.
Network Security & Segmentation
Firewalls, zones and policy that reflect how the business actually works.
Perimeter and internal security: next generation firewall design, zero trust segmentation, remote access, IPS tuning and policy lifecycle management.
Security Operations & Hardening
Detection, response and the unglamorous hygiene that prevents both.
Log collection and correlation, vulnerability management, patch orchestration, endpoint hardening, and incident response retainers.
Infrastructure & Virtualization
Compute, storage and platform services that stay boring.
Server and hypervisor builds, storage design, identity services, hybrid cloud connectivity and platform lifecycle management.
Backup & Disaster Recovery
Recovery you have actually tested, with numbers to prove it.
Backup architecture, immutable and offsite copies, documented recovery objectives, and scheduled restore testing with evidence.
Network Troubleshooting
For the problem nobody has been able to close.
Deep dive diagnostics on intermittent, performance and application layer network faults: packet capture, flow analysis and structured root cause.
Wireless Engineering & Surveys
Coverage designed with a spectrum analyser, not with optimism.
Predictive and on site wireless surveys, high density design, roaming optimisation and RF troubleshooting for campus, warehouse and industrial sites.
Managed IT & Co Managed Support
A full operations function, or extra capacity for the team you have.
Service desk, endpoint management, vendor coordination, documentation and technical account management under a defined SLA.
The difference is in how the work is done
I measure before I recommend
No recommendation leaves my desk without telemetry behind it. Two weeks of real baseline data beats any assessment questionnaire.
Every change is reversible
Staged cutovers with a written rollback gate at each step. If a step cannot be undone, it gets its own window and its own approval.
Documentation is part of delivery
As built diagrams, runbooks and configuration baselines are updated inside the change window, not three months later.
Alert noise is a design defect
Thresholds are tuned against real baselines before handover. If an alert does not require action, it gets retuned or removed.
You always deal with me
The person who designs your network is the person who fixes it at 3am. Nothing gets lost in a handover.
Evidence, never assertions
Restore tests with timings. Availability measured against target. Root cause with the capture that proves it.
A five stage model that survives contact with reality
The same stages run on every engagement, scaled to the work, so documentation, monitoring coverage and evidence are never the thing that gets dropped when a deadline tightens.
Read the full approach- 01
Discover
Estate discovery, traffic baseline and a risk register you keep whether or not you engage me further.
- 02
Design
A documented design with explicit failure domains, written so your team can operate it without me.
- 03
Deliver
Staged change with rollback gates, rehearsed before it touches production.
- 04
Operate
Monitoring with runbook backed alerts and an agreed response target.
- 05
Improve
A regular review against evidence, ending in a decision list rather than a slide deck.
Environments where downtime has a number attached
Healthcare
Clinical systems under strict change control, medical device segmentation and audit evidence.
Logistics and warehousing
Wireless scanning that cannot drop, round the clock shift patterns, multi site distribution networks.
Financial services
Regulated environments, immutable backups and restore evidence as a contract term.
Manufacturing
Plant floor isolation, OT and IT convergence, and conduit models aligned to IEC 62443.
Retail
Branch networks at scale, edge standardisation and LTE failover that actually fails over.
Education
Dense campus wireless, large user counts and budgets that have to be defended line by line.
Tell me what is failing, and what it is costing you
Send me the problem, even a vague one. I read every enquiry myself and reply with a straight answer, including when I am not the right fit.