secureskies
Expertise/01 · Programme & Project Leadership

Leadership where
programmes tip.

Programmes and projects rarely fail everywhere. They fail at a few points: the architecture decision nobody takes; the cutover nobody wants to own; the stream that holds up all the others. That is where we start. We work inside your team, take over the leadership or the critical stream, and stay until every signed success criterion has been accepted and the programme has been handed over to your operations.

01 · Starting point

The status is green.
The project is red.

Almost every programme we are called into looks the same in the SteerCo: the report shows progress, the dates are “on track”, the budget is “within limits”. Six weeks before go-live it all tips at once. Not because anyone lied — but because nobody ever established what success is supposed to look like.

Reported vs. actual progressTypical curve · schematic
100 % · Go-liveDifference · 6 weeks before go-liveKick-offPlanned end
Status reportAccepted results, usable in productionFirefighting phase
RAG status in the SteerCoEight meetings · what was reported
Schedule
Budget
Scope
Resources
Risks
Success criteria
Meeting 1Meeting 8

The last row is empty because it does not exist in most reports. That is exactly where our model starts.

Symptom 01

“We are at 80 per cent.”

For four months now. Progress is counted in completed tasks, not in results somebody has accepted and can use.
Symptom 02

The architecture decision sits with the SteerCo.

For three meetings now. Nobody feels responsible, everyone waits for the other, and meanwhile the team is building on an assumption.
Symptom 03

The service provider delivers to contract.

Just not what the project needs. The statement of work dates from a time when the goal was different.
Symptom 04

The business units have “no capacity”.

For testing, acceptance, data cleansing. The project depends on people who were never in the project plan.
Symptom 05

The cutover date is fixed — the way back is not.

There is a go-live plan, but no abort criterion, no rollback rehearsal and nobody who takes the decision at three in the morning.
Symptom 06

Every stakeholder means something different by “success”.

The board is thinking about the date, the CIO about stability, the business unit about function, operations about handover. None of these definitions is written down anywhere.
02 · Method

We live in
success criteria.

Five stages, one principle: before we steer, we establish with everyone involved how the success of this programme will be recognised — measurable, accepted, with a date. Stage two is the core. Everything after it is steering against those criteria instead of against a plan that was still right at kick-off.

Stage 05 → stage 02 · criteria are renegotiated on every change of goal, not quietly adjusted↺
Stage 01

Analysis

Two to three weeks inside the project, not above it: conversations with the team, the business units, the service providers, the sponsor. We check status reports against actual work products and find the points where the programme is really stuck.

Situation report · pressure points
Stage 02

Success criteria

With the sponsor, the CIO, the business unit and operations: what must be true at the end for this programme to have been a success? One metric, one person to sign it off and one date per criterion. What does not make this list does not get built.

Success criteria map · signed
Stage 03

Realignment

Test the plan, the scope, the contracts and the roles against the criteria. What does not contribute is cut or deferred. Open decisions get a decision-maker and a date — not an agenda item.

Cleaned-up plan · decision register
Stage 04

Steering at the pressure points

We take over the leadership or the critical stream and are present where things tip: architecture decision, provider escalation, test acceptance, cutover. The SteerCo sees criteria status, not percentage of tasks done.

Criteria status at every meeting
Stage 05

Handover

A criterion is met when the person signing it off has confirmed it — not when the team is finished. Once all of them are met, the programme goes to your operations, documented. We stay until it runs without us.

Acceptance record per criterion
03 · Tool

What “done”
means.

The success criteria map is the one document that stays with the SteerCo through the whole programme. On the left, what project mandates usually say. On the right, what we turn that into before we steer.

Success criteria mapExtract · identity consolidation example
As it reads in the project mandate
Criterion
Metric
Signed off by · date
Goal
“Consolidation of the Active Directory landscape”
All production applications authenticate against the target domain
Applications with a legacy trust = 0
Head of operations · [DATE]
Security
“Raising the level of security”
No domain admin works without a privileged access workstation
Share of tier 0 accounts bound to a PAW = 100 %
CISO · [DATE]
Operations
“Handover to line operations”
Operations team resolves tier 0 incidents for 4 weeks with no project involvement
Escalations to the project during hypercare = 0
Head of operations · [DATE]
Business unit
“No impact on users”
Login time and ticket volume back to pre-cutover level
Tickets in weeks 1–2 ≤ baseline + 10 %
Division head · [DATE]
Way back
—
Rollback rehearsed for every wave, abort criterion in writing
Rollback rehearsal passed before every wave
Programme leadership · every wave

The map is signed at the realignment kick-off by the sponsor, the CIO and those who sign off the criteria. Changes to the goal are allowed — but only as a change to this map, visible to everyone.

04 · Intervention

Five points where
programmes tip over.

We are not equally present everywhere in the programme. We are where experience says the outcome is decided — and at those points we take over ourselves instead of advising.

Initiation
Design
Build
Test & cutover
Hypercare
Success criteria

Signed before anything is built. Renegotiated as soon as the goal changes — not quietly adjusted.

Architecture decision

One person, one date, one rationale. We prepare it and we get the decision taken — even against the wish to defer it.

Provider management

Check the statement of work against the criteria, run the escalation, negotiate change orders. The provider delivers what the programme needs.

Cutover

Go/no-go with a written abort criterion, a rehearsed rollback, named decision-makers for the night. We are in the room.

Handover

Criteria accepted by operations, not by the project. Knowledge transfer with evidence. Only then do we leave.

05 · References

Two programmes,
one pattern.

Both steered against signed success criteria. Anonymised; reference conversations after pre-qualification.

01

Incident remediation after a serious cyber attack.

E-commerce group · 2020–2021

Six streams — AD, server, client, network & applications, Exchange, remediation. New ESAE tiering architecture, PAWs with smart cards for all domain admins, 300 DMZ servers hardened, krbtgt reset against golden and silver tickets.

€4mBudget
30+FTE · 15 months
1,000+Servers
600Mailboxes migrated
ESAEPAWTier 0
02

AWS insourcing: managed service built and handed over.

Container shipping line · top 5 worldwide · 2022–2025

Insourcing strategy, governance framework, CI/CD with GitLab and integration with Microsoft Entra ID, 73 workloads across three tiers, a team of 23 FTE, 25+ knowledge transfer workshops, hypercare with simulated incidents. Budget held.

€1.5mBudget
73Workloads
23FTE
600+ hKnowledge transfer
AWSGitLabITSM

Which programme needs
real project leadership?