
Case study
Global Infrastructure Modernisation
Modernised a global, multi-region estate at scale - ~1,000 VMs, flat-to-segmented networks, and a migration to Azure and Microsoft 365 - on a live 24/7 business.
- VMware / vSphere
- Azure (Blob, AVS)
- Microsoft 365
- SD-WAN
- Aruba ClearPass
- Palo Alto / FortiGate
- Veeam
Problem
Enterprise estates accrete. Flat networks, sprawling VM counts, aging firewalls, and on-prem-only services become a security and operations drag. The work: modernise a global, multi-region business that runs 24/7 - without breaking it.
Constraints
- Keep the lights on - change a live, multi-region estate without downtime.
- Security and compliance - segmentation, patching, and auditability throughout.
- Cost-aware - modernise to cloud where it pays, justified through CapEx/OpEx cases.
Design
Across global roles I ran and improved a ~1,000-VM VMware estate, managed centrally for the IT team and operated across regions including the UK. I re-segmented flat sites into isolated VLAN ranges with ACLs, layering in SD-WAN and Aruba ClearPass with 802.1x onboarding for a tiered, authenticated network. Palo Alto / FortiGate firewalls were upgraded and redesigned around the new segmentation - RCA, staging through FortiManager, and a flat-to-segmented redesign.
On the platform side: workloads and identity moved to Azure (Blob storage, AVS - lifting existing vSphere environments) and Microsoft 365, with a hybrid AD sync I architected to bridge on-prem and cloud identity. The estate work also covered an ERP hardware refresh with a new DR / mainframe solution, file shares to Azure Blob over Kerberos auth, Veeam backups, and a region-wide PBX-to-VoIP migration (RingCentral).
Security & reliability decisions
- Flat → segmented - isolation by design, not by exception.
- Authenticated access (ClearPass, 802.1x) - the network knows who's on it.
- Patched, current firewalls - closing the easy doors first.
- DR built in - recovery designed, not assumed.
Outcome
A more secure, segmented, cloud-leaning estate that's cheaper to run and easier to operate - delivered against live-business constraints across multiple regions.
Future improvements
The throughline from this work to the edge platforms: take the same segmentation and identity rigour and express it as code, so a thousand-VM estate and a single edge node are governed the same way.

