About

Hi, I'm Wesley Lomax.

This blog used to be about Sitecore and .NET. It's now about the problem I actually spend my days solving: making regulated Azure platforms both compliant and affordable, at the same time, without pretending those are two different projects.

I can support teams once they've outgrown whoever originally built the platform, or when nobody's confident their infrastructure would survive an audit or a serious incident — access control, logging and network architecture rebuilt to hold up under a QSA's questions and a security review's, usually the same weak points causing both.

I've been in IT since 2002 — starting as a developer, then over a decade as a freelance solution architect working with some of the world's leading brands, before specialising in cloud engineering and managed cloud services.

Most of what gets written about PCI DSS is compliance-shaped but not Azure-specific, and most of what gets written about Azure cost control ignores that half your "waste" is actually a control someone put there for a reason. I write from the seam between the two — landing zones, Application Gateway and Front Door configuration, IAM and service-principal hygiene, and the KQL queries that prove (or disprove) that any of it is actually working.

Connect with me on LinkedIn or find me on GitHub.

What I write about

Landing zones & platform architecture

Structuring an Azure estate — management groups, subscriptions, networking — so it holds up as it grows.

PCI DSS v4.0.1 on Azure

Where regulated estates actually fail an audit, and the concrete Azure config that satisfies each control.

Application Gateway, Front Door & WAF

Ingress and web-security decisions — AGIC vs. dedicated controllers, and the rules that quietly change behaviour.

IAM & service-principal hygiene

Access control and the stale, over-permissioned identities that are a finding waiting to happen.

Cloud cost & FinOps

Cutting waste without deleting the controls someone put there for a reason — compliance and cost as one story.

KQL & Log Analytics

The queries that prove — or disprove — that any of the above is actually working.

If you're a platform or engineering lead at a fintech, payments or regulated SaaS company trying to get your Azure estate through an audit without blowing the cloud budget doing it, this is written for you.

Work with me