Measurable outcomes from sovereign cloud, resilience and security engagements. Select a card to read the full study.
MSP Insourcing · Sovereign Azure
Insourcing a 480-server estate from an MSP in six months
End-to-end extraction of core cloud and infrastructure services at Kanadevia Inova: a 3-wave migration of 480 servers and 14 business-critical applications into a sovereign Azure landing zone with HYOK, customer-owned HSM and zero standing privileges.
Read case study
- Critical applications
- 14
- Payback
- 15–22 mo
Sovereign AI · DORA & NIS2
Sovereign Agentic AI & RAG pipelines
Proprietary frameworks for routing Agentic AI and RAG workloads through localised, HYOK-encrypted pipelines for Tier-1 FSI clients.
- PII to public hyperscalers
- Zero
- Mandates
- DORA · NIS2
Read case study
Cloud Extraction · OpEx
Cloud extractions & multi-million-euro OpEx strategy
Fractional Principal-level leadership for Tier-1 FSI clients: technical blueprints, sovereign guardrails and cloud extractions that expanded Azure API capacity.
- Azure API capacity
- +64%
- OpEx strategies
- Multi-M €
Read case study
Compliance · Resilience
Compliance-aligned multi-cloud with ≤24h DR
AWS and Azure environments at Zurich Insurance aligned to NIST, ISO 27002, CIS and COBIT, with cloud-native disaster recovery proven in quarterly drills.
- Compliance gaps
- -40%
- RTO / RPO
- ≤24h
Read case study
Security Operations · Private Cloud
Private cloud hardening & breach response
VMware private cloud at AT&T Global Network Services: OS and virtualisation hardening, IDS/IPS rollout, forensics-led incident response and 2h RTO/RPO disaster recovery.
- Critical exposure
- -85%
- MTTR
- -60%
Read case study
Kanadevia Inova s.r.o · Group Lead Cloud & Connectivity · 2026
Insourcing a 480-server estate from a managed service provider in a six-month window
- 480servers migrated in 3 waves
- 14business-critical applications
- 15–22 mopayback on annual cost reduction
Context
As Group Lead for Cloud & Connectivity within Kanadevia Inova's SSC-GID Digital Core Services, I was accountable for core cloud and infrastructure services that had been operated end-to-end by an external managed service provider. The group needed to bring these services in-house, and the contractual timeline left a compressed six-month execution window to do it.
Challenge
Take over a 480-server estate supporting 14 business-critical applications without disrupting the business, land it in an Azure environment that satisfies Swiss data-protection requirements, and make the investment case stand on its own.
Approach
- End-to-end insourcing programme. I spearheaded the extraction from the MSP as a single accountable programme — services, infrastructure and operating responsibility — rather than as a series of disconnected handovers.
- Three-wave migration strategy. The 480-server estate was sequenced into three waves so that the 14 critical applications moved with controlled dependencies and clear rollback points inside the six-month window.
- Sovereign guardrails for the Azure landing zone. HYOK encryption and customer-owned HSM controls keep key material under the group's jurisdiction; edge autonomy preserves local operation; and PIM/JIT access with zero standing privileges removes persistent administrative rights.
- Cost case built into the plan. The migration strategy was designed around annual cost reduction with an explicit 15–22 month payback period, so finance could track the return against the plan.
Outcomes
- Core cloud and infrastructure services insourced from the MSP within the compressed 6-month window.
- 480 servers and 14 business-critical applications migrated under a 3-wave strategy.
- Annual cost reduction with a 15–22 month payback.
- Swiss data-protection requirements met through HYOK, customer-owned HSM, edge autonomy and zero standing privileges.
AzureMSP insourcingHYOKCustomer-owned HSMPIM / JITZero standing privilegesSwiss data protection
Ne Plus Ultra Global Solutions · Founder & Principal Cloud Architect · 2024 –
Sovereign Agentic AI and RAG pipelines with zero PII leakage to public hyperscalers
- ZeroPII leakage to public hyperscalers
- HYOKencrypted, localised pipelines
- DORA · NIS2regulatory mandates
Context
Tier-1 financial-services clients want the productivity of Agentic AI and retrieval-augmented generation, but DORA and NIS2 leave no room for personal data to flow uncontrolled into public hyperscaler AI services. Enterprise Architects at these institutions need a pattern they can defend to regulators, not a pilot that has to be unwound later.
Challenge
Make AI workloads usable inside strict regulatory mandates: route Agentic AI and RAG traffic in a way that guarantees no PII reaches public hyperscalers, while keeping the architecture simple enough to adopt.
Approach
- Proprietary routing frameworks. I engineered frameworks that route Agentic AI and RAG workloads through localised pipelines, so sensitive data is processed within controlled boundaries rather than at the model provider's edge.
- HYOK-encrypted pipelines. Hold-Your-Own-Key encryption keeps the client in control of key material end to end, making jurisdictional control a property of the pipeline rather than a contractual assurance.
- Blueprints and guardrails for FSI. As fractional Principal, I authored the technical blueprints and defined the sovereign cloud guardrails that C-suite executives and Enterprise Architects adopt as their standard.
Outcomes
- Zero PII leakage to public hyperscalers for Agentic AI and RAG workloads.
- AI adoption that holds under DORA and NIS2 mandates.
- Reusable blueprints and guardrails for Tier-1 FSI clients.
Agentic AIRAGHYOKDORANIS2Tier-1 FSI
Zurich Insurance · IT Business & Solution Architect · 2022 – 2025
Compliance-aligned AWS and Azure with sub-24-hour disaster recovery
- -40%enterprise compliance gaps
- ≤24hRTO / RPO, zero data loss
- -50%data-leakage risk
Context
In Business Technology Services at Zurich Insurance, I designed and directed the migration of complex legacy and on-premise systems into cloud architectures that had to satisfy both security and regulatory scrutiny across AWS and Azure.
Challenge
Move legacy systems into the cloud securely, close the gap between the environments and the control frameworks the enterprise is measured against, and prove recoverability rather than assume it.
Approach
- Framework-aligned environments. AWS and Azure environments were architected against NIST, ISO 27002, CIS and COBIT, so controls were part of the design baseline.
- Cloud-native disaster recovery. DR strategies built on native cloud capabilities, targeting sub-24-hour RTO and RPO, and exercised in quarterly drills rather than left on paper.
- Threat modelling of data flows. Azure Data Factory, Lambda and Glue pipelines were threat-modelled and secured to reduce the risk of data leakage through integration paths.
Outcomes
- Enterprise compliance gaps reduced by 40%.
- Sub-24-hour RTO/RPO delivered, with zero data loss in quarterly drills.
- Data-leakage risk across ADF, Lambda and Glue flows cut by 50%.
AWSAzureNISTISO 27002CISCOBITDisaster recoveryThreat modelling
AT&T Global Network Services · Senior Systems Engineer · 2012 – 2015
Hardening a VMware private cloud and cutting breach-response time by 60%
- -85%critical exposure
- -60%MTTR in breach response
- 2hRTO / RPO, validated in HA tests
Context
As Senior Systems Engineer at AT&T Global Network Services in Bratislava, I managed a VMware private cloud for a global network operator, where security operations and availability were measured continuously.
Challenge
Reduce the platform's exposure, respond to incidents faster and with better evidence, and make recovery objectives demonstrable — while raising the operating discipline of the wider team.
Approach
- Hardening. Enforced OS and virtualisation hardening across the private cloud to shrink the attack surface.
- Detection and vulnerability management. Rolled out IDS/IPS and ran recurring vulnerability scans to find and remove critical exposure.
- Breach response. Led incident response, forensics and log correlation so that root causes were identified quickly and reliably.
- Resilience. Developed DR strategies meeting 2-hour RTO/RPO and validated them in high-availability tests.
- Operating discipline. Mentored junior engineers on secure operations and introduced SOPs and training to control configuration drift.
Outcomes
- Attack surface reduced by 40% through hardening.
- Critical exposure reduced by 85% via IDS/IPS and vulnerability scanning.
- Mean time to recovery cut by 60%; configuration drift cut by 50%.
- 2h RTO/RPO DR strategies validated in high-availability tests.
VMwarePrivate cloudHardeningIDS / IPSForensicsDisaster recoveryMentoring
Executive-level perspectives on sovereign cloud, compliance, cloud economics and scalable architecture. Select a card to read the full article.
Compliance · Sovereignty
De-risking European Enterprise Cloud: Navigating DORA, Swiss nDSG, and Sovereign Data Logic
Why HYOK encryption, zero standing privileges and continuous auditing form the backbone of a Zero Trust landing zone that regulators can sign off on.
4 min read · DORA · nDSG · NIS2
Read article
FinOps · MSP Insourcing
The 49% OpEx Blueprint: Achieving Extreme Cloud Cost Optimization via MSP Insourcing & FinOps
A three-phase FinOps strategy — tagging and visibility, high-velocity MSP insourcing, unit economics — for enterprises whose cloud spend has outgrown their MSP model.
4 min read · FinOps · Cloud economics
Read article
Architecture · Scale
High-Throughput Telemetry: Scaling IoT Data Ingestion Capacity by 64%
Queue-based ingestion, hot/cold storage tiering and protocol optimisation: the structural changes that let telemetry platforms absorb unpredictable surges without runaway cost.
3 min read · IoT · Event streaming
Read article
Article · By Sashree Seepersad · Principal Enterprise Architect & Founder, Ne Plus Ultra Global Solutions
De-risking European Enterprise Cloud: Navigating DORA, Swiss nDSG, and Sovereign Data Logic
European enterprise cloud strategy has fundamentally shifted. Beyond performance and raw scalability, compliance with stringent regulatory frameworks — specifically the Digital Operational Resilience Act (DORA), Swiss nDSG, and NIS2 — has become an existential operational priority.
The Compliance Reality
Traditional multi-tenant public cloud deployments often struggle with data residency enforcement and strict regulatory audit readiness. DORA demands continuous risk assessment, strict ICT third-party risk management, and guaranteed operational continuity during major disruptions. Simultaneously, Swiss nDSG requires explicit control over personal data processing locations and encryption keys.
Building Sovereign Data & Cloud Logic
To resolve the tension between hyper-scale agility and strict compliance, enterprise architects must implement a Zero Trust Landing Zone framework built on three core pillars:
- HYOK (Hold Your Own Key) Encryption. Standard provider-managed or customer-managed keys (CMK) still allow sovereign jurisdiction access through legal mechanisms like the US CLOUD Act. HYOK guarantees that cryptographic control remains exclusively within sovereign-boundary HSMs.
- Zero Standing Privileges (ZSP) via PIM/JIT. Eliminating permanent administrator access in favour of Privileged Identity Management (PIM) and Just-In-Time (JIT) access reduces identity attack surfaces by up to 70% while leaving a complete, auditable trace for regulators.
- Immutability & Continuous Auditing. IaC automation (such as NIST-aligned Terraform templates) must enforce continuous configuration monitoring to detect and instantly revert drift, closing compliance audit gaps by up to 40%.
Sovereignty in the cloud is not about avoiding hyperscalers — it is about implementing governance architectures that ensure complete data authority regardless of underlying physical hardware.
DORASwiss nDSGNIS2HYOKZero TrustPIM / JITTerraform
Article · By Sashree Seepersad · Principal Enterprise Architect
The 49% OpEx Blueprint: Achieving Extreme Cloud Cost Optimization via MSP Insourcing & FinOps
As cloud investments mature, enterprise organizations frequently reach a tipping point where Managed Service Provider (MSP) markup, unoptimized resource provisioning, and fragmented tagging lead to unsustainable cloud spend growth.
The Pitfalls of Legacy MSP Models
Many enterprise MSP models rely on fixed resource markups or opaque management fees, creating a structural disincentive to rightsize cloud environments. When combined with uncoordinated cloud migrations, organizations often find themselves paying premium cloud rates for legacy operational patterns.
The 3-Phase FinOps Strategy
- Phase 1Tagging & Visibility
- Phase 2MSP Insourcing
- Phase 3Unit Economics
- Granular Tagging Taxonomy & Visibility Engineering. Before cutting costs, you must allocate them accurately. Implementing automated tagging policies across AWS and Azure links every running resource to specific business units, applications, and environments.
- High-Velocity MSP Insourcing. Transitioning cloud infrastructure management in-house or extracting estates from third-party MSPs enables direct hyperscaler billing discounts, reserved instances, and savings plans. In a recent enterprise engagement, extracting a CHF 1.7M cloud estate yielded a 49% OpEx reduction within 6 months.
- Unit Economics & Continuous Rightsizing. Shift focus from overall spend to unit cost efficiency (e.g., cost per API transaction or active user). Automated shut-down schedules, storage tier lifecycle policies, and rightsizing workloads ensure continuous financial optimization.
FinOpsMSP insourcingTaggingReserved instancesUnit economicsRightsizing
Article · By Sashree Seepersad · Principal Enterprise Architect
High-Throughput Telemetry: Scaling IoT Data Ingestion Capacity by 64%
Industrial IoT platforms and modern enterprise architectures generate massive, unpredictable surges of telemetry data. Scaling ingestion systems without incurring exponential cloud costs or bottlenecking processing pipelines requires modern decoupling techniques and optimized API architectures.
The Scalability Challenge
When processing high-frequency data streams, synchronous processing pipelines suffer from high latency, thread exhaustion, and excessive compute costs during peak loads.
Key Architectural Drivers
- Asynchronous Queue-Based Ingestion. Decoupling API ingress from data persistence using message brokers (e.g., Apache Kafka, Event Hubs) allows edge gateways to acknowledge requests instantly while downstream workers consume data at predictable rates.
- Cold/Hot Storage Tiering. Routing incoming telemetry through stream processors allows time-critical analytics to hit in-memory stores, while raw historical logs flow directly into low-cost object storage for long-term retention.
- Protocol & Connection Optimization. Transitioning legacy payloads to binary formats (e.g., Protocol Buffers) and maintaining persistent network channels drastically reduces CPU overhead during serialization and network transport.
Implementing these structural enhancements can expand data ingestion capacity by over 64% within weeks, providing the scalability needed for enterprise-grade IoT ecosystem demands.
IoTKafkaEvent HubsStream processingProtocol BuffersStorage tiering