Fitness for Growth

Are you ready for fast growth? If success, a large influx of cash or an acquisition propelled you to the next level, would your IT sustain the load: new employees, new locations, new needs?

Fixing or building up an IT infrastructure for a fast-growing company involves making hundreds of IT and best-practice choices that all must be correct. There is little room for trial and error and no room for software beta testing, even when you rely heavily on the cloud.

Start with what will not break. Microsoft 365 and Google Workspace scale to any size you are likely to reach. The suites are not the problem, and neither is the cloud they run on.

What does not scale is everything underneath them, and the pattern never varies. A thing that merely annoys you at ten people cannot be relied on at two hundred. The tool does not change. What changes is that nobody is watching it anymore.

You need technology that can scale to hundreds or thousands of users in multiple locations and yet be affordable at the beginning when you have only a few users in one place.

Take hardware. In 2012 Backblaze bought 4,829 of one consumer 3TB drive model, because a flood in Thailand had cut supply and it was what could be had. It looked fine: 2.7% failed the first year, 5.4% the second. In the third, 47.2%. By March 2015, 29.5% of that batch was dead, against 4.1% for another maker's drives bought the same year and run in the same racks.1 The first sign had been 27 drives in a single month: half a percent. You cannot see half a percent in ten machines. Unvetted hardware is cheap exactly once.

Take administration. You cannot run hundreds of users out of an admin portal by hand, and Microsoft documents its own ceiling: error lists "display 999 users at a time" and "you must scroll to the bottom of the list", and group-based licensing "doesn't currently support nested groups", so only "users in the first-level group are assigned licenses" and nothing warns you.2 The portal is right for a small firm. Past that the work has to be automated, which is why Microsoft ships the scripting.

Take policy. At ten people you know everyone. You notice the login that does not fit, and you remember to close the account of the person who left on Friday. That is not a policy. That is your attention, and it is the first thing growth takes away from you.

The VPN is the case that matters, and it fails twice. As arithmetic: every remote person's cloud traffic goes into your building and back out again, so the pipe you sized for ten is carrying two hundred. As policy, it never was one. At ten people you know who is on the tunnel. At two hundred you cannot, and a tunnel is built to make whoever is on it an insider.

NIST Special Publication 800-207, the reference definition of zero trust, names the tool in its eighth tenet: "a remote subject should not be required to use a link back to the enterprise network (i.e., virtual private network) to access services ... hosted by a public cloud provider (e.g., email)." Its founding assumption grants "no implicit trust ... based solely on ... network location".3 That is the engineering answer to a policy that was only ever your attention.

The alternative is built and documented. NIST's own cybersecurity centre worked with 24 vendors to stand up 19 sample zero trust implementations, each published as a model to replicate.4

You need an IT manager/CIO who can deploy new systems and software in hours or days rather than months, and one who can bring new life to the hardware and software you already own (a must in our AI-driven memory crunch).5 Azure Virtual Desktop answers the second: an older PC can still carry the screen. Its transport "doesn't use a TCP listener to receive incoming RDP connections", so the desktop reaches the service and nothing reaches the desktop.6 No inbound port means no firewall to open when the next office is in another country.

Throwing more money than necessary at an IT problem is more likely to waste time than to save any. Every item above was cheap when it was bought, and each was bought by somebody who was, at the time, entirely right.

Knowing which of them will not survive your next hundred people is not a product and it does not come in a box. It is judgment, built from having watched it happen to other firms first. That is what our Principal Stewards are for.

Concierge CIO Partners is a unified Guild of senior technologists providing dedicated, long-term fiduciary IT leadership to midmarket service firms. It offers a strategic alternative to fragile internal IT silos and to Managed Service Providers who advise you on what to buy and are paid on what you buy. With transparent unit pricing and an automated service catalog, the Guild eliminates administrative bloat and ensures every IT dollar spent and decision made directly drives your financial performance. It builds what a firm will still be able to rely on at two hundred people, which is rarely what that firm chose at ten.



1 Backblaze, CSI: Backblaze, Dissecting 3TB Drive Failure, 15 April 2015. Seagate ST3000DM001 vs HGST, both deployed 2012 in the same Storage Pod model, both measured at 31 March 2015. These are data centre duty cycles, not office ones. 2 Microsoft Learn, Assign or unassign licenses to a group in the Microsoft 365 admin center, updated 18 May 2026, under "Limitations of group-based licensing in the Microsoft 365 admin center". 3 NIST Special Publication 800-207, Zero Trust Architecture, August 2020, section 2.1 (tenet 8) and the abstract. 4 NIST SP 1800-35, Implementing a Zero Trust Architecture, National Cybersecurity Center of Excellence, final June 2025. 5 TrendForce memory pricing survey, 3 July 2026: "record-high contract prices" for DRAM and NAND, as suppliers reallocate capacity to AI servers, with retail notebook prices "expected to rise across the board". Quarterly rises are moderating (13-18% QoQ, down from 58-63%), but the level is a record. 6 Microsoft Learn, Understanding Azure Virtual Desktop network connectivity. Microsoft's own comparison is to on-premises Remote Desktop Services.