From the field

Case Studies

Illustrative, anonymized scenarios based on recurring risk patterns the audit uncovers. These aren't specific clients — they're patterns I encounter repeatedly in practice.

Legacy system Bus factor

Delphi monolith with no documentation

Situation: A manufacturing company runs a critical ERP written in Delphi from the late 90s. The last in-house expert is retiring.

Findings: no current documentation, business logic hard-coded directly in the UI layer, a single source repository with no version history older than five years.

Recommendation: stabilization plus hybrid modernization (Delphi core + new modules in .NET), knowledge transfer into written architectural documentation before the expert leaves.

Outcome: eliminated the risk of total loss of operability within 6 months; the estimated cost of a full rewrite (well into seven figures) reduced to a managed, phased modernization.

About legacy systems & Delphi →
Vendor lock-in

Vendor lock-in with a low-code platform

Situation: A company built a core workflow on one vendor's proprietary low-code platform.

Findings: exporting data or logic off the platform is practically impossible, the licensing model scales exponentially with user count, and the contract contained no exit strategy.

Recommendation: a negotiating position backed by numbers, an exit plan prepared in parallel, a review of contract terms at the next renewal.

Outcome: negotiated a double-digit percentage reduction in licensing costs and a contractually secured exit clause.

People risk Bus factor 1

Bus factor 1 in a critical process

Situation: A financial institution's monthly close depends on one analyst and their personal spreadsheet macros.

Findings: no backup of the know-how, no documentation of the calculation, an error risk that nobody else could detect.

Recommendation: formalize the process, rewrite the critical logic into an auditable tool, introduce a second-person review.

Outcome: eliminated a single point of failure in a process that regulatory reporting depends on.

Data Integration

Undocumented database shared across departments

Situation: A mid-size distribution company runs a central database written to by six different internal and external systems, with no clearly defined contracts.

Findings: inconsistent data across systems, no clear source of truth, risk of data corruption on any schema change.

Recommendation: define contracts between systems, introduce input validation, gradually federate the sources.

Outcome: eliminated recurring incidents with mismatched reports between departments, previously resolved manually every month.

About system integration →
Shadow IT

Shadow IT and critical processes outside core systems

Situation: A sales team built its own solution in spreadsheets outside IT's oversight because "the main system couldn't handle it."

Findings: no backups, no access control, critical business data sitting outside the company's security policy.

Recommendation: formalize the process via a light integration into the core system, and identify why the shadow IT emerged in the first place (usually a symptom, not the root cause).

Outcome: closed the security gap and secured continuity when the key salesperson eventually left.

Recognize a similar pattern in your organization?

The introductory consultation is free of charge and takes place online — we'll discuss whether an audit makes sense for you before I propose anything.

Book an introductory consultation →

Jakub Lebeda · Company ID (IČO) 19074671 · +420 607 720 317