Projects & Templates

Case studies from real engagements, with client names and identifying details removed. The thinking is real, the org isn't nameable. Plus a couple of the actual templates, free to take and adapt.

Case studies

CASE STUDY · SECURITY ASSESSMENT

Repricing security for a regional trucking and warehousing company

A logistics company owned a full stack of Microsoft 365 and security licensing alongside several competing point solutions, paying twice for overlapping capability without a coherent picture of either. The engagement started as a straightforward security assessment and became a licensing consolidation story: a heat-mapped gap analysis against Microsoft and CIS baselines, a tooling review that surfaced real duplicate spend, and a phased adoption roadmap the client's leadership could actually act on. The lesson that generalized past this one client: most security assessments should start by asking what the org is already paying for and not using, before anyone sells a new tool.

CASE STUDY · PUBLIC SECTOR ROADMAP

A multi-year Microsoft foundation roadmap for a county government

A county government needed to move off a patchwork of legacy identity and collaboration tooling onto a coherent, regulation-aware Microsoft foundation: single sign-on, conditional access, self-service password reset, and a phased Exchange Online and collaboration rollout, sequenced over several budget cycles because public-sector procurement doesn't move at a vendor's pace. The interesting part was the sequencing. Staging identity and access controls ahead of collaboration tooling meant every subsequent phase inherited a stronger security baseline instead of bolting one on afterward.

CASE STUDY · GO-TO-MARKET STRATEGY

Building the business case for an AI practice at a regional IT solutions provider

A Midwest managed-services and solutions provider was leaning into a deeper Microsoft partnership at the same moment the industry pivoted from selling hardware to selling AI-enabled services. The strategy work connected those two threads: AI-enabled MSP platforms were trading at meaningfully higher revenue multiples than general MSPs, buyers were already ranking AI capability as the top factor in picking a managed-services provider, and the gap holding most organizations back from agentic AI was data, integration, and governance, which happens to be exactly the kind of work a solutions provider is built to sell. The resulting practice thesis reframed "adding an AI offering" from a bolt-on product line into the thing that repriced the whole company.

CASE STUDY · ENDPOINT & DEVICE MANAGEMENT

Modernizing device management for a mid-market client

A full mobile device and workstation management rebuild: configuration and compliance profiles across iOS, Android, and Windows for both corporate-owned and BYOD devices, a patch and update cadence with driver approvals and hotpatching, imaging via modern provisioning tooling, and a documented set of next-step recommendations against CIS benchmarks. The as-built documentation from this engagement became the template I now use to make sure "current state" is actually written down somewhere before the next person has to reverse-engineer it from the console.

Templates

The genuinely reusable parts, stripped of any client data, free to take.

FREE TEMPLATE

Zero Trust Identity, Device, and Privileged Access Framework

The same spectrum-based framework behind the Stryker Lessons Learned brief: four risk profiles, a quick-reference control matrix, and the full reasoning behind tiered admin accounts, Authentication Contexts, PAW, and risk-based access. Pick your organization's profile, replace the bracketed placeholders, delete what doesn't apply.

Download as Word (.docx) →  ·  Download as plain text →

FREE TEMPLATE

Microsoft 365 Security Assessment — Statement of Work

The complete SOW structure I use to scope a Microsoft 365 / Zero Trust security assessment engagement: a strategy workshop, five discovery sessions with full agendas (tenant configuration, endpoint management, identity and Conditional Access, the Defender stack, and data protection/Copilot readiness), a week-by-week deliverables schedule, roles and time commitments for both sides, assumptions, and a milestone-based pricing structure. Useful whether you're pricing this as a consultant or scoping it as an internal project.

Download as PDF →  ·  Download as plain text →

FREE TEMPLATE

Innovation Grant Program — Framework & Implementation Plan

A grant-funded proof-of-concept pipeline for organizations whose innovation committee has become "where ideas go to die." Any employee can request modest funding ($5–10K) to test an idea, but the request must arrive with a problem statement, success criteria, and an ROI estimate, and every completed POC gets presented to leadership with evidence, whether it succeeded or not. Includes the grant request form template, the findings report template, committee governance, KPIs, and a launch plan. Built for a real mid-market organization (details removed); three grants were approved and funded in its first year.

Download as PDF →