Kanadevia Inova s.r.o · Group Lead Cloud & Connectivity · 2026
Insourcing a 480-server estate from a managed service provider in a six-month window
- 480servers migrated in 3 waves
- 14business-critical applications
- 15–22 mopayback on annual cost reduction
Context
As Group Lead for Cloud & Connectivity within Kanadevia Inova's SSC-GID Digital Core Services, I was accountable for core cloud and infrastructure services that had been operated end-to-end by an external managed service provider. The group needed to bring these services in-house, and the contractual timeline left a compressed six-month execution window to do it.
Challenge
Take over a 480-server estate supporting 14 business-critical applications without disrupting the business, land it in an Azure environment that satisfies Swiss data-protection requirements, and make the investment case stand on its own.
Approach
- End-to-end insourcing programme. I spearheaded the extraction from the MSP as a single accountable programme — services, infrastructure and operating responsibility — rather than as a series of disconnected handovers.
- Three-wave migration strategy. The 480-server estate was sequenced into three waves so that the 14 critical applications moved with controlled dependencies and clear rollback points inside the six-month window.
- Sovereign guardrails for the Azure landing zone. HYOK encryption and customer-owned HSM controls keep key material under the group's jurisdiction; edge autonomy preserves local operation; and PIM/JIT access with zero standing privileges removes persistent administrative rights.
- Cost case built into the plan. The migration strategy was designed around annual cost reduction with an explicit 15–22 month payback period, so finance could track the return against the plan.
Outcomes
- Core cloud and infrastructure services insourced from the MSP within the compressed 6-month window.
- 480 servers and 14 business-critical applications migrated under a 3-wave strategy.
- Annual cost reduction with a 15–22 month payback.
- Swiss data-protection requirements met through HYOK, customer-owned HSM, edge autonomy and zero standing privileges.