The Practice

Four engagement models. Nine services inside them.

Four shapes a relationship with Hikvara can take. Most clients start with one service and add others as the relationship deepens. Every service below has been delivered, not proposed.

Model 1

Standing advisory

Fractional technology leadership

Who it's for
Organisations with a real technology estate and no one senior accountable for it.
What triggers it
A board asking questions the organisation can't answer. A budget cycle no one can defend. A vendor relationship that has quietly inverted.
First thirty days
An estate review — what you run, what it costs, who controls it, where the risk sits. A written assessment your board can read without translation.
What you own at the end
A governance cadence, a roadmap tied to budget, vendor accountability with contract terms that favour you, and a senior voice in decisions before they're made.

Vendor management and procurement governance

Contracts, SLAs, sourcing decisions and vendor accountability across a full infrastructure stack — structured so the organisation sets the terms rather than accepting them.

Directed enterprise-wide vendor management and procurement governance for a large institutional operation, including a ~BDT 3 crore Cisco infrastructure modernisation programme and a ~BDT 2.5 crore World Bank–financed national project.

Large-scale operations management

End-to-end IT operations: uptime, service continuity, and operational resilience across an institution-wide footprint, run to ITIL service management practice.

Ran operations for a 13,000-user enterprise with a twenty-person department led through three managers, directing roughly BDT 8 crore of annual technology investment with endorsement authority over BDT 2–3 crore more.

Model 2

Recovery and reconstruction

Who it's for
Anyone whose platform is down, degraded, or held together by a person who has left.
What triggers it
An outage. A failed change. A vendor withdrawal. The discovery that the running system exists only in production, with no source anyone controls.
First thirty days
Stabilise. Preserve — full artefact capture, read-only, catalogued, before anything is touched. Document what's actually there, which is rarely what the documentation says. Then decide: repair or rebuild.
What you own at the end
A working system, its source in your custody, a tagged baseline, independent backups, documented deployment, rollback and recovery procedures.

Platform recovery and continuity engineering

Emergency recovery and full-stack reconstruction of failed production systems, including reconstruction from compiled artefacts where no source code exists. Continuity practice aligned to ISO 22301 and ISO 27031.

Recovered a failed institutional production platform working alone over thirteen days, then reconstructed it front end and back end from compiled artefacts with no original source in existence anywhere — delivered with seventeen engineering documents and a versioned repository under the client's control.

Model 3

Transformation and architecture

Who it's for
Organisations modernising a platform, an ERP, or an estate — and unwilling to be the last party in the room to understand what they bought.
What triggers it
An ERP programme. A platform end-of-life. A requirements exercise where the vendors are writing the requirements. A new venture that needs its technology defined before procurement starts.
First thirty days
Requirements and constraints in writing — data classification, cross-border data handling, security by design, business impact analysis, continuity planning, recovery objectives. Then a vendor landscape you can actually compare.
What you own at the end
An architecture you can defend, procurement criteria written before you meet vendors, and a roadmap sequenced by risk rather than by sales cycle.

Enterprise architecture

Enterprise technology architecture across network, infrastructure and hybrid cloud — with data classification, cross-border data handling, security by design, business impact analysis, continuity planning and recovery objectives treated as part of the architecture rather than an appendix to it. Structured to ISO 38500 governance principles and ISO 42010 architecture description practice.

Applied as Infrastructure Lead on a PwC-led enterprise ERP and business transformation programme, directing architecture, security, resilience and connectivity readiness across internal teams, consultants and vendors.

Digital transformation and ERP modernisation

ERP and platform transformation: infrastructure readiness, integration, and the transition of a new platform into an environment that can actually support it after go-live.

Infrastructure Lead on a PwC-led enterprise ERP transformation across a 13,000-user institution, coordinating architecture, security and operational requirements across internal technology teams, institutional stakeholders, consultants and vendors.

Intelligent automation

Workflow and evaluation automation built under governance — defined agent roles, human approval gates, single-source outputs, and controlled reporting. Aligned to NIST AI Risk Management Framework practice.

Designed and built a multi-workflow automated evaluation system with a three-tier model pipeline for scoring, rubric design and structured reporting, generating dual-format outputs from a single source of truth to eliminate score drift across concurrent assessments.

Healthcare advisory

Fits: healthcare, diagnostics, and new-venture technology definition

Enterprise requirements definition and vendor-landscape advisory for clinical and diagnostic organisations — clinical and EMR platforms, imaging, RIS and PACS, enterprise ERP, digital experience, and locally hosted AI, with commercial and open-source routes compared rather than assumed.

Prepared the enterprise requirements and vendor landscape for a proposed AI-enabled diagnostic, outpatient and telemedicine venture — governed under NIST Cybersecurity Framework 2.0, with a tailored NIST SP 800-53 control baseline, zero-trust principles, PACS security guidance, and NIST AI RMF controls for locally hosted AI.

Model 4

Security, cloud and continuity

Who it's for
Organisations that need to know how exposed they are, and what it would cost to stop being exposed.
What triggers it
An audit finding. An incident, yours or a peer's. A cloud migration with no security design. A continuity plan that has never been tested.
First thirty days
Posture assessment against a recognised framework, network and access architecture review, backup and recovery verification — actual restore tests, not documented intentions.
What you own at the end
A remediation plan ranked by risk and cost, policy your auditors accept, and a continuity plan that has been exercised rather than filed.

IT governance and cybersecurity strategy

Governance frameworks, security posture, institutional policy and audit readiness — built to ISO 27001 principles and NIST Cybersecurity Framework practice, sized to the organisation rather than copied from an enterprise template.

Built and led governance and cybersecurity strategy for a 13,000-user institution: authored institutional IT and cybersecurity policy, served as primary liaison for auditors and technology partners, and appeared as a cybersecurity subject-matter expert on national television.

Cloud and virtualisation modernisation

Data centre and hybrid cloud modernisation — virtualisation, migration, cloud security architecture, backup and disaster recovery design across on-premises and cloud estates.

Modernised institutional data centre infrastructure through VMware ESXi and vCenter virtualisation with SAN/NAS, backup and DR ownership, moving legacy environments toward a hybrid on-premises and cloud model across Azure and AWS.

Sectors

Higher education · healthcare and diagnostics · engineering and industrial · regulated financial services · public and donor-funded programmes.

The environments differ. The failure modes don't.

Standards and frameworks

I work to established frameworks rather than invented ones. ITIL for service management. ISO 27001 principles for information security governance, ISO 38500 for IT governance, ISO 22301 and ISO 27031 for business continuity and ICT readiness. NIST Cybersecurity Framework 2.0 for security posture, and the NIST AI Risk Management Framework where AI enters the estate.

Following a framework is not the same as being bound by one. Small organisations get proportionate governance, not enterprise paperwork. What it means in practice is that decisions are documented as they're made — so when an auditor, a board, or your next technology lead asks why something was done, there is an answer on file rather than an opinion in someone's memory.

  • ITIL
  • ISO 27001
  • ISO 38500
  • ISO 22301
  • ISO 27031
  • ISO 42010
  • NIST CSF 2.0
  • NIST AI RMF

Questions I'm asked first

Because responsibility doesn't diffuse. The person who wins the engagement is the person who does the work, and every decision traces back to someone accountable for it — not a rotating cast of consultants at different seniority levels. Documentation-first delivery means the practice doesn't create a single point of failure either: everything is versioned, recorded, and transferable, so the client isn't dependent on me being available forever.

Availability

Bangladesh · Gulf · remote