// capability study

Onyx Advisory — Modernization Audit

A seven-domain technology and operations audit, carried through to a costed roadmap — the Regent Assessment, demonstrated end to end.

consultingconcept engagement · self-directed
// one maturity scale, seven domainsInfrastructurefragileApplicationsDatafragileSecurityIntegrationfragileOperationsGovernancephase 1 · unblockphase 2 · rebuildphase 3 · defer
// the brief

A firm with a functioning business and ageing infrastructure, unsure whether what it faces is a maintenance problem or a strategic one. The brief was to produce the answer a board can act on: what is genuinely at risk, what modernization would cost, what it would return, and what should be deliberately left alone.

// the approach
  1. 01

    Seven domains, one scale

    Infrastructure, applications, data, security, integration, operations, and governance are each assessed against the same maturity scale. The output is therefore comparable across domains rather than a collection of unrelated opinions.

  2. 02

    Risk before ambition

    The audit separates what is fragile from what is merely old. Systems that are unfashionable but stable are explicitly recommended for deferral. A modernization plan that touches everything is a plan that finishes nothing.

  3. 03

    Cost the roadmap, including the cost of waiting

    Every recommendation carries an estimate and a decay curve: what it costs to address now, and what the same problem costs at twelve and twenty-four months. Deferral is a legitimate decision, priced as one.

  4. 04

    Sequence by dependency, not by severity

    The most severe finding is rarely the right thing to fix first. Work is ordered by what unblocks what, so that each phase makes the phase after it cheaper.

  5. 05

    Written for the person signing

    Findings are stated in plain language with the technical evidence carried in an appendix. An assessment a board cannot read is an assessment a board cannot fund.

// domains assessed
Infrastructure
Hosting, network, resilience, and lifecycle exposure
Applications
Portfolio inventory, support status, and rationalisation candidates
Data
Ownership, quality, retention, and reporting reliability
Security
Control coverage, identity posture, and third-party exposure
Integration
Interfaces, manual bridges, and failure surface between systems
Operations
Run process, escalation, and dependency on individuals
Governance
Decision rights, change control, and technology spend visibility
// next

Vellum Studio — Brand Identity

Read itAll work