Skip to main content
GenioCT

Insights

Azure architecture, security, platform engineering, AI, and cloud economics.

Explore by stream
APIM v2 Migration Playbook: Moving from Classic to Standard v2 or Premium v2
| 11 min read | Platform Engineering

APIM v2 Migration Playbook: Moving from Classic to Standard v2 or Premium v2

A field playbook for migrating Azure API Management from classic Developer, Standard, or Premium to the v2 tiers: what carries over, what breaks, how to preserve subscription keys, the order to run the cutover in, and when staying on classic is the right call.

Read more →
Azure Container Apps Express in 2026 and Where Its Preview Gap Still Sends You Back
| 11 min read

Azure Container Apps Express in 2026 and Where Its Preview Gap Still Sends You Back

Azure Container Apps Express hit public preview at Build 2026 with subsecond cold starts and no environment to provision. The preview feature gap is large, and so is the region constraint. Here is what Express actually changes inside the ACA family, and where it still sends you back to a standard environment.

Azure Architecture
Read more →
Cloud Sovereignty in 2026 and Why It Is a Workload Classification Problem
| 9 min read

Cloud Sovereignty in 2026 and Why It Is a Workload Classification Problem

Cloud sovereignty in 2026 means SEAL levels and 48 EU procurement criteria beyond region selection. The architect's job is workload classification across five distinct concerns.

Azure Architecture
Read more →
AKS in 2026 and When It Still Wins
| 11 min read

AKS in 2026 and When It Still Wins

AKS has matured beyond recognition since its 2018 GA. Automatic upgrades, Workload Identity, Cilium, managed observability, and the new AKS Automatic tier have changed the operational picture. Here is when AKS is still the right call and when simpler platforms do the job better.

Azure Architecture
Read more →
The DNS Problems That Break Your Private Link Connectivity
| 8 min read

The DNS Problems That Break Your Private Link Connectivity

Private Link is easy to deploy. Getting DNS right across hub-spoke, hybrid, and multi-subscription environments is where it breaks. Seven failure modes.

Azure Architecture
Read more →
NIS2 Belgium After 18 April: From Basic Readiness to Continuous Azure Evidence
| 10 min read

NIS2 Belgium After 18 April: From Basic Readiness to Continuous Azure Evidence

The 18 April 2026 NIS2 checkpoint has passed for Belgian essential entities. The next challenge for Azure-heavy organisations is continuous evidence rather than another readiness questionnaire.

Security & Compliance
Read more →
Your Service Principals Are a Bigger Blast Radius Than Your VMs
| 8 min read

Your Service Principals Are a Bigger Blast Radius Than Your VMs

In most Azure tenants, real exposure is a forgotten service principal with Owner scope, an expired secret, no human owner. Four risk patterns mapped to NIS2.

Field lesson Security & Compliance
Read more →
Azure Front Door in 2026 and the Standard vs Premium Decision
| 8 min read

Azure Front Door in 2026 and the Standard vs Premium Decision

Front Door Standard vs Premium, Private Link to origin, the App Gateway overlap question, and what changed since Microsoft stopped new classic profiles. The enterprise decision guide.

Azure Architecture
Read more →
How to Prepare for an NIS2 Audit on Azure in 12 Weeks
| 12 min read

How to Prepare for an NIS2 Audit on Azure in 12 Weeks

The 12-week NIS2 readiness plan we run with Azure clients. Article 21 mapping, gap closure, evidence assembly, and pre-audit dry run, week by week, with the Azure controls and pitfalls at each stage.

Security & Compliance
Read more →

Start with a Governator-powered Azure Health Check

Not sure where to begin? A quick architecture review gives you a clear picture. No obligation.

  • Risk scorecard across identity, network, governance, and security
  • Top 10 issues ranked by impact and effort
  • 30-60-90 day roadmap with quick wins