About ACloud.Solutions
ACloud.Solutions builds Azure tooling and provides IT consulting. Both come from the same place: years spent as the entire IT and security function of a small SaaS company, where there was nobody else to escalate to and no budget for a platform team.
That background shapes the work more than any methodology would. When one person holds identity, endpoints, cloud, compliance and the helpdesk queue, you develop strong opinions about which of those actually matter first, and a low tolerance for advice that assumes a team.
Where the tools came from
The AzClean tools came out of real estate cleanup work. The numbers had to be defensible enough to put in front of a finance team, which turned out to be a higher bar than it sounds.
The first version of the cost script priced every disk at zero, which finance found unpersuasive. The second version priced disks by consumed gigabytes, which was wrong in a more interesting way: Azure bills managed disks by provisioned tier, so the estimate came out roughly four times too low. Presenting a number that is 3.7x light is worse than presenting no number, because either nobody acts or somebody acts and then stops trusting your figures.
Getting that right is most of what the tools are. The rest is refusing to write to anything.
Read-only by default
Every tool in the family is read-only, exits non-zero when it cannot reach Azure, and ships its licence terms in the download.
The read-only part is about blast radius and about trust. A script that only looks can run on day one of an engagement, before anyone has decided how much access to grant, and it cannot make a bad afternoon worse.
The exit code part is about honesty. A tool that cannot authenticate and reports "no findings" has produced a clean bill of health from an empty search. That is the failure mode most likely to cause real harm, because it looks like the outcome you wanted.
The book
ISO 27001 for the One-Person Team is 130 pages on taking a roughly 40-person SaaS company through ISO/IEC 27001:2022 single-handed, written from doing exactly that rather than from reading the standard.
It exists because the available material was written either for consultancies selling implementation or for organisations with a compliance department. Neither is much help when the person doing the risk assessment is also the person fixing the printer.
How we work
Three things worth knowing before getting in touch.
Assessments are read-only, so there is no need to decide how much to trust us before finding out whether there is anything worth doing.
Cost figures are for prioritising work, not for billing. Reservations, savings plans and negotiated discounts all move the real number, and we say that up front rather than being caught out by it in a finance meeting.
Anything we build gets handed over in a state you can maintain. If you cannot run it after we leave, it was built wrong. That means no automation tied to a named person's account and no runbook that stops at the interesting part.
The two posts that explain the approach
- Read-only Azure scripts: why these tools never write
- When to hire an IT consultant, and what to make them leave behind, which is deliberately more about when not to
Getting in touch
Email info@acloud.solutions. Roughly what the estate looks like and what is bothering you is enough to start with.
If you would rather read first, the notes cover the checks and arguments behind most of this, and the consulting page has more detail on how an engagement actually runs.