We know exactly what we're doing.
Not a client portfolio, but a competency map. Each area represents a technical domain that GEMP owns, manages and masters — with validated architectures, defined processes and measurable KPIs.
On-Premise Infrastructure
Design, installation and maintenance of physical infrastructure. Server racks, storage arrays, UPS, structured cabling: we manage the entire hardware lifecycle with tracked interventions and guaranteed SLAs.
Virtualisation
VMware vSphere / Hyper-V environments with vMotion, HA and DRS. Server consolidation up to 20:1 ratios, with snapshot management, templates and affinity policies.
Storage & SAN
iSCSI, Fibre Channel and NFS architectures on dedicated storage. RAID configuration, LUN masking, automatic tiering and real-time IOPS / latency monitoring.
Structured Cabling
Cat6A/Cat7 installation, single-mode and multi-mode optical fibre. Link certification with Fluke DSX, as-built documentation and rack labelling.
Hardware Lifecycle
Centralised inventory, End-of-Life planning, warranty and spare-parts pool management. On-site interventions with response times <4h for P1 criticalities.
Every infrastructure is documented with an up-to-date CMDB and configuration baseline. Change management follows the ITIL Change Management process with CAB for high-impact changes. Post-intervention testing includes stress tests, PSU redundancy verification and storage path validation.
Networking & Connectivity
From layer 2 to layer 7. We design, configure and maintain complex enterprise networks: segmented LANs, redundant WANs, SD-WAN and secure remote access with centralised policy management.
LAN / VLAN Design
Segmentation by functional zones (production, offices, IoT, guest). RSTP spanning-tree, port-security, 802.1X NAC and QoS for VoIP and video conferencing traffic.
WAN & SD-WAN
Dual-link WAN with automatic failover <30s. SD-WAN with traffic shaping, application-aware routing and end-to-end path quality monitoring.
Wireless Enterprise
Wi-Fi 6 deployment with centralised controller, RF heat-mapping, seamless roaming and SSID separation per user profile. Signal certification with Ekahau.
Remote Access & VPN
SSL/IPSec site-to-site and client VPN, Zero Trust Network Access, integrated MFA. Split tunnelling, device posture policies and centralised access logging on SIEM.
Cloud & Hybrid Environments
We don't sell cloud: we manage it. Microsoft Azure, AWS and hybrid on-premise/cloud architectures with cost governance, security and performance optimisation workload by workload.
Migration & Lift-and-Shift
Workload discovery and assessment via Azure Migrate and AWS MGN: automated inventory, dependency mapping, on-premise vs cloud TCO comparison. Structured wave planning with prioritisation by application criticality, agreed cutover windows and tested rollback plan. RTO defined per workload before go-live.
Identity & Access (IAM)
Azure AD / Entra ID with Conditional Access, PIM, MFA and federated SSO. On-premise AD synchronisation via Azure AD Connect and privileged identity governance.
FinOps & Cost Control
We implement granular tagging policies for BU/project cost allocation, dynamic budget alerts, automatic rightsizing based on utilisation metrics, and Reserved Instance / Savings Plan planning to reduce on-demand costs by up to 60%. Monthly report with waste analysis, cost anomaly detection and ROI-prioritised optimisation recommendations.
IaC & Automation
Infrastructure as Code with Terraform and ARM/Bicep. CI/CD pipelines for infrastructure deployment, drift detection and centralised state management on Terraform Cloud.
Cloud migrations follow the AWS 6R / Azure CAF framework, classifying each application into one of six migration paths before any activity begins:
Rehost (Lift & Shift) — the VM is moved as-is to the cloud via disk replication. Minimal refactoring, maximum speed, for stable workloads where agility is prioritised.
Replatform (Lift & Optimize) — the core architecture is kept but specific components are replaced: e.g. on-premise SQL Server to Azure SQL Managed Instance. Minor effort with significant operational benefits.
Refactor (Re-architect) — the application is redesigned to leverage cloud natively: microservices, containers on AKS/EKS, serverless. Highest investment, maximum return in scalability and resilience.
Repurchase / Retire / Retain — adopt an equivalent SaaS, decommission apps with no value, or keep constrained workloads on-premise, documented and re-evaluated at each review.
Post-migration includes 30 days of hypercare with dedicated 24/7 support, intensive performance baseline monitoring, active rollback plan and SLA validation defined during the assessment phase.
IT Security
Perimeter and zero-trust protection. From system hardening to incident management, with end-to-end visibility via SIEM and structured response to security events.
Perimeter & NGFW
Next-gen firewalls with IPS/IDS, deep packet inspection, URL filtering and sandboxing. Zero-trust segmentation and TLS inspection for encrypted traffic.
EDR / XDR
Endpoint detection & response with CrowdStrike, Defender and SentinelOne. Proactive threat hunting, automatic isolation of compromised hosts and behavioural analysis.
SIEM & SOC
Microsoft Sentinel with event correlation, automated SOAR playbooks and compliance dashboards. Log retention and centralised forensic analysis.
Incident Response
Structured incident response per NIST SP 800-61: preparation, detection, containment, eradication and recovery. Vulnerability management with Qualys VMDR.
Help Desk & Service Desk
Multi-level L1/L2/L3 application support. Single point of contact for all business users, with ITIL ticketing, structured knowledge base and monthly tracked KPIs.
L1 — Front Line
Single point of contact, ticket logging and categorisation, resolution on documented SOPs. High First Contact Resolution target with up-to-date knowledge base.
L2 — Specialist
In-depth technical analysis and error reproduction. Triage to specialised teams, creation of new SOPs and management of application escalations.
L3 — Application Mgmt
Application specialists for complex resolutions, problem management and root cause analysis. Vendor ticket opening and bug management with software suppliers.
KPI & Reporting
Monthly reporting with SLA compliance, First Call Resolution, average resolution times, CSAT and ticket trend analysis by application area.
Endpoint & Device Management
Centralised management of PCs, laptops, mobile devices and thin clients. Automated provisioning, patch management and compliance policies on enterprise fleets of any size.
Modern Device Provisioning
Windows Autopilot and Zero-Touch Deployment: the device is ready to use from first boot, without manual intervention. Intune profiles per user role with automatic configuration of VPN, Wi-Fi and enterprise apps.
Patch Management
Structured monthly patch cycle: Patch Tuesday + out-of-band for critical CVEs. Testing on pilot ring before broad rollout, compliance reporting and documented exceptions per system.
Mobile Device Management
MDM/MAM on iOS and Android with Intune: separation of corporate/personal data, conditional access for device compliance and selective remote wipe for loss or decommission.
Software Distribution
Application deployment via MECM/Intune with detection rules, dependencies and retry logic. Licences tracked per asset, automatic software inventory and alerts for unauthorised installations.
Backup & Disaster Recovery
Data protection and business continuity. 3-2-1 strategies, immutable anti-ransomware backups and tested disaster recovery plans with contractual RPO and RTO.
Immutable Backup
Immutable and air-gapped repositories against ransomware. Veeam with hardened linux repository, S3 object lock and periodically verified offline copies.
Disaster Recovery
Continuous replication with Zerto and Azure Site Recovery. Orchestrated failover to secondary site or cloud, with automated runbooks and documented semi-annual DR tests.
RPO / RTO SLA
Definition of RPO and RTO for each critical workload, contractualised and verified. System tiering for recovery priority in case of disaster.
Ransomware Recovery
Rapid post-attack recovery procedures with malware scanning on backups, isolated clean recovery and data integrity validation before production restore.
Monitoring & Operations
Total visibility before the problem becomes an incident. Proactive monitoring stack on infrastructure, network, applications and cloud with multi-level alerting and real-time dashboards.
Infrastructure Monitoring
CPU, RAM, disk, temperature and power metrics collection on all hosts. Dynamic thresholds based on historical baseline, anomaly detection and event correlation between related systems.
Application Performance (APM)
Response time, error rate and throughput monitoring for each critical application. Distributed tracing, slow query analysis on databases and alerts on performance degradation before user impact.
Log Management
Log centralisation from OS, applications, firewall and cloud on ELK stack or Azure Monitor Logs. Structured parsing, compliance-driven retention policy and full-text search for incident analysis.
Alerting & Escalation
Escalation tree configured by severity, time and on-call. Multi-channel notifications (SMS, email, Teams, PagerDuty), alert storm suppression and alert correlation for noise reduction.
ERP & Application Management
Business management software is the operational heart of the company. We manage the entire application lifecycle: onboarding, upgrades, performance tuning, system integration and specialist user support.
ERP Environment Management
Management of dev, test and production environments with controlled release procedures. Application change management, rollback plans and functional regression testing before every go-live.
DB Performance Tuning
Query plan analysis, index optimisation, statistics and tempdb on SQL Server / Oracle. Identification of killer queries, wait management and implementation of automatic maintenance plans.
System Integration
ETL pipelines with SSIS / Power Automate / REST API for integration between ERP, CRM, e-commerce and third-party systems. Data mapping, error handling and centralised flow logs.
Specialist Support
L2/L3 on complex application issues: application server log analysis, data replication, session management and advanced configuration debugging in coordination with the software vendor.
Every application release follows a pre-go-live checklist with 20+ verification points: pre-update DB backup, functional smoke tests, active integration verification and coverage in the first 24h post-deploy. Critical incidents are managed with a dedicated bridge call between the technical team, vendor and company contact.
Put us to the test.
Got a technical domain keeping you up at night? Let's talk. We respond within one business day.
Contact us