About
Hi, I'm Wesley Lomax.
This blog used to be about Sitecore and .NET. It's now about the problem I actually spend my days solving: making regulated Azure platforms both compliant and affordable, at the same time, without pretending those are two different projects.
I can support teams once they've outgrown whoever originally built the platform, or when nobody's confident their infrastructure would survive an audit or a serious incident — access control, logging and network architecture rebuilt to hold up under a QSA's questions and a security review's, usually the same weak points causing both.
I've been in IT since 2002 — starting as a developer, then over a decade as a freelance solution architect working with some of the world's leading brands, before specialising in cloud engineering and managed cloud services.
Most of what gets written about PCI DSS is compliance-shaped but not Azure-specific, and most of what gets written about Azure cost control ignores that half your "waste" is actually a control someone put there for a reason. I write from the seam between the two — landing zones, Application Gateway and Front Door configuration, IAM and service-principal hygiene, and the KQL queries that prove (or disprove) that any of it is actually working.
What I write about
Landing zones & platform architecture
Structuring an Azure estate — management groups, subscriptions, networking — so it holds up as it grows.
PCI DSS v4.0.1 on Azure
Where regulated estates actually fail an audit, and the concrete Azure config that satisfies each control.
Application Gateway, Front Door & WAF
Ingress and web-security decisions — AGIC vs. dedicated controllers, and the rules that quietly change behaviour.
IAM & service-principal hygiene
Access control and the stale, over-permissioned identities that are a finding waiting to happen.
Cloud cost & FinOps
Cutting waste without deleting the controls someone put there for a reason — compliance and cost as one story.
KQL & Log Analytics
The queries that prove — or disprove — that any of the above is actually working.
If you're a platform or engineering lead at a fintech, payments or regulated SaaS company trying to get your Azure estate through an audit without blowing the cloud budget doing it, this is written for you.
Work with me