Madrid and all of Spain+34 600 237 257Client portal
ISI Tech Consulting
Client portal

Some real projects, told with what can be told

Out of respect for our clients’ privacy, none of them is named here, and neither is anything that would identify them. Everything else is here: the sector, the size, how long it took, what was broken, what it was fixed with and what changed afterwards. They are the projects with enough documented detail to be told properly, and the list will keep growing.

Pharmaceutical company

60 employees · 4 weeks

Sixty people at work and no IT department behind them. There was no architecture either: machines and systems had been added as the need arose, every problem was solved on its own, and nobody had the full picture of what depended on what. When something broke, the first half hour went on working out whose job it was to look at it.

The department was built from scratch, which in practice means deciding who does what, where each thing lives and how you ask for help. The infrastructure was built on that base: Windows Server and SQL Server for what the company uses daily, virtualisation to stop multiplying physical machines, and containers for what was worth isolating. It was documented as it was built, not at the end, which is the difference between infrastructure somebody can inherit and infrastructure somebody has to decipher. Part of the work was digitising processes that until then did not live in any system.

What changed: The company went from improvising every incident to knowing who to ask and where to look. Four weeks later there was a department that genuinely existed and documented infrastructure that did not depend on anyone remembering how it had been put together.

Built with: Windows Server · SQL Server · Virtualisation · Containers

The service behind it: IT Consulting

Financial services firm

6 employees · 3 weeks

A six-person firm handling other people’s money, with no maintenance of any kind. The backups were listed as configured and did not work, which is the worse of the two possible situations: with no backups you know you are exposed; with backups that do not restore, you believe you are not. Nobody had ever checked them.

The IT structure was reorganised against an explicit standard: that it could be maintained for years, not that it would hold until the next breakdown. Devices moved to MDM and Apple Business Manager, so a new laptop configures itself instead of being set up by hand. Custom scripts were written in Python for the tasks somebody was repeating every week. And a Linux server was set up running the firm’s own language models, so they could be used without client data ever leaving the building.

What changed: The backups went from existing on paper to existing for real, verified by restoring them rather than by reading a ticked box. Three weeks, and what used to depend on nobody touching anything now depends on something somebody can maintain. That difference is exactly what separates a backup that genuinely exists from one that merely appears to.

Built with: Python · Linux · MDM · Apple Business Manager · Self-hosted language models

The service behind it: IT Support

Driving school

300 employees · 1 month

Three hundred people and no training at all. The most likely way in for an attacker is not a badly configured firewall: it is somebody clicking where they should not, and the more people there are, the more times a day that door opens. The company already knew, because its own internal audits kept saying so, but it had nothing to answer with.

Staff were trained in two things at once. The cybersecurity half was not a talk: it was phishing simulations built with Gophish and other attack simulation tools, using messages that looked like the ones people were actually going to receive, with the results laid out afterwards. The artificial intelligence half was teaching people to use language models — Copilot and Claude among them — knowing what can go in and what must never leave the company.

What changed: Their internal cybersecurity audits came back with better results. Training does not stop a fraudulent message from arriving; it changes how many of the ones that arrive get opened, and that is what the audit measures.

Built with: Gophish · Attack simulation · Copilot · Claude

The service behind it: Cybersecurity

Chemical industry

200 employees · Ongoing relationship

Two hundred people in chemical manufacturing, with no clear technology structure and development needs nobody inside could cover. Decisions about what to buy and what to build were taken one at a time, with no common standard behind them, and the data production generated every day stayed wherever it landed.

The work has three strands and still has them. Consulting, to decide what gets done, in what order, and what is not worth doing. Internal development written to fit, in Python and Go, with SQL Server behind it, containers to deploy it and web development for what people use from a browser — all on open source software, with Git and GitHub in the middle so the code does not depend on a single head. And the IT maintenance of what is already running, which is what stops what has been built from decaying.

What changed: Technology decisions stopped being taken one at a time, and production data that used to be lost started being collected. It is the only published case with no duration, and that is exactly the part that counts: the relationship is still open, with no end date.

Built with: Python · Go · SQL Server · Containers · Git · GitHub · Open source software

The service behind it: Software Development

Contact

Tell us about your situation

None of these projects started with a fixed quote over the phone. They all started by looking at what was there, which is the only honest way to say what something costs before anybody has seen it. If any of this sounds like your situation, say so and you will know soon enough whether it fits — and if it does not fit, you will hear that too, which is the faster answer of the two.

Tell us about your case+34 600 237 257info@isitechconsulting.com