IT project and programme management
Run infrastructure and security projects to a defined outcome: scope held, dependencies surfaced early, risks tracked, and a cutover with a rehearsed way back.
What we review
- Objective and success criteria: What this project must achieve, and how everyone will know it did.
- Current state: What is already built, what is assumed, and what has quietly changed since planning.
- Dependency map: Technical, vendor, licensing and staffing dependencies, including the ones nobody has raised.
- Sequencing: What must happen in what order, and which steps cannot be parallelised.
- Risk register: What could derail this, how likely, what it would cost, and what reduces it.
- Cutover plan: The change itself, who approves it, how success is validated, and the rollback path.
- Stakeholder map: Who decides, who is affected, who must be informed, and when.
- Reporting: What status is reported, to whom, how often, and in what form.
Deliverables
- Project plan: Sequenced work with owners, dependencies and realistic dates.
- Risk and issue register: Live, ranked, with owners and mitigation, not a document written once.
- Cutover runbook: Step by step, with validation checks and a tested rollback path.
- Status reporting: Regular, honest reporting including bad news early rather than late.
- Decision log: What was decided, by whom, when, and on what basis.
- Handover pack: Documentation your team or another provider can operate from after the project closes.
Engagement boundaries
- Project management is coordination and accountability; it does not replace the technical specialists doing the work.
- HAI Consulting does not hold budget authority or sign contracts on your behalf.
- Delivery dates depend on your team's availability and vendor performance, neither of which we control.
- This work does not guarantee a project succeeds. It makes risks visible early and decisions explicit.
- Vendor-delivered work remains the vendor's responsibility under your contract with them.
- Scope changes are surfaced and costed as decisions for you to make, not absorbed silently.
- PMP certification informs the approach; it is not a guarantee of any particular outcome.
- Staff performance management within your organization remains yours.
- Where a plan cannot meet a fixed date, that is reported early rather than discovered at cutover.
Questions before the work starts
Do you do the technical work as well?
Sometimes, where it falls inside our consulting services. Often the technical work belongs to your team or a vendor, and this engagement provides the sequencing, risk tracking and accountability around it. Both arrangements are scoped explicitly at the start.
Our project has already stalled. Can it be recovered?
Usually, but the first step is an honest read of why it stalled. That is often a dependency nobody owned, a scope that quietly grew, or a date that was never achievable. Recovery planning starts from the real position, not the original plan.
How is status reported?
Regularly, in writing, including problems as soon as they are known. Status reporting that only contains good news is not reporting. If a date is at risk, you hear it while there is still time to act.
What happens to scope changes?
They are documented as decisions with their cost in time and money, and you decide. Scope that expands without anyone deciding is the most common reason projects overrun.
Who owns the project after you leave?
Your team. The handover pack, decision log and documentation exist so the project does not depend on us remaining involved.
The platforms this work covers
Project work spans the platforms a migration or build actually touches, rather than a single vendor stack.
- Microsoft 365 and Entra ID
- Microsoft Azure
- Amazon Web Services
- Cisco
- Palo Alto Networks
- Check Point
- Fortinet FortiGate
- F5
- Cloudflare
- On-premises and colocation data centre
Audits available
- Migration readiness review: dependencies, licensing, cutover sequence and rollback before committing to a date.
- Vendor delivery review: whether what is being delivered matches what was contracted and designed.
- Cutover plan review: validation checks, approval path and a rollback that has actually been rehearsed.
Other ways we can help
Engagements are often scoped together; these are the closest neighbours to this one.
Need a second set of eyes on a security or infrastructure decision?
Describe the environment, the risk and the outcome you need.