Building robust, efficient, and secure technology infrastructure. Leading the IT function — operations, security posture, and strategic decisions that support growth and optimise for cost.
I'm Bartosz Borowski, an IT Lead based in Leeds, UK with a passion for building robust, efficient, and secure technology infrastructure.
At Duchy Homes Ltd, I lead the IT function — from day-to-day operations and infrastructure management to strategic technology decisions that support business growth and optimise for cost. My recent work has been delivered using AI-assisted research, design, and implementation, including internal application development, infrastructure planning, and security programme design — enabling rapid, high-quality delivery without external dependency.
I enjoy solving complex problems, automating wherever possible, and building systems that just work. I follow the work of SpaceX, Anthropic, Tesla and FigureAI — organisations pushing the boundary of what's possible. Outside of IT, I'm interested in nutrition, fitness, mountain climbing, and US financial markets.
Leading all IT operations across a Leeds office and 7 remote development sites (~50 staff, ~250 endpoints). Responsible for network architecture, security posture, Microsoft 365 administration, vendor management, and digital transformation. Delivered multiple cost-saving initiatives reducing IT expenditure by 20%+, including a Sophos-to-Defender migration saving ~£6k/year, AI-assisted internal tooling replacing Adobe Acrobat Pro licences (~£1750/year), and migration of remote site network connectivity from managed solutions (£300–400/month/location) to an in-house Starlink fleet (sub-£100/month/site). Leading the company's Cyber Essentials compliance programme.
Managed client DNS, Windows Server (2016–2022) environments, and Linux (CentOS) LAMP stacks. Designed and deployed open-source management platforms including SnipeIT, Zabbix, and Zammad. Upgraded large-scale networking using Brocade, Ruckus, and pfSense. Provided remote support to 100+ users across West Yorkshire. Led the Royal Armouries network infrastructure refresh — a 10G, 3-building, 7-switch stack designed to serve ~3,000 concurrent clients at the annual UKREiiF conference.
First point of contact for internal IT support in a highly regulated legal environment. Managed a hybrid Azure/on-premises Active Directory, maintained Citrix VMs, and configured Ubiquiti switches and access points. Built and configured 10-Zig Zero Clients and supported YubiKey MFA rollout. Tested internally developed Citrix Beta releases ahead of business-wide deployment.
Provided 1st and 2nd line support across UK offices including Leeds, Manchester, Thetford, Cleckheaton, and Liverpool. Deployed Ubiquiti infrastructure, managed Microsoft Exchange Online, and built SharePoint portals. Deployed and managed company devices via Microsoft Autopilot and Intune. Overhauled Grandstream VoIP systems and supported Sage server maintenance.
Completed an Infrastructure Technician Apprenticeship while delivering IT support and infrastructure improvements. Guided the company through Cyber Essentials certification, introduced an IT lifecycle strategy, participated in the migration from on-premises systems to Office 365 and SharePoint, and transitioned the company to VoIP. Established the IT asset inventory and overhauled the new starter/leaver process.
Company-wide replacement of end-of-life Cisco Meraki APs with Ubiquiti UniFi U7 Pro Max (WiFi 7) across the main office and two remote sales centres. Projected savings of ~£5,000 over five years.
Full MDM solution for all corporate Apple devices (iPhones, iPads, Macs), integrating ABM with Intune to achieve Cyber Essentials compliance and replace an entirely unmanaged device estate.
Replaced the company's ageing DrayTek router with a UniFi Enterprise Fortress Gateway. One-time hardware investment, fully managed in-house vs expensive managed enterprise alternatives. Delivered IDS/IPS, encrypted DNS, and VLAN segmentation.
Replaced Sophos Intercept X and Sophos Email with Microsoft Defender, leveraging existing M365 Business Premium licences. Projected savings of ~£15,500 over three years, eliminating ~£6,000 in annual recurring costs, without compromising security.
Used AI-assisted development to build an internal PDF tooling suite from scratch with no prior development background, replacing high-volume Adobe Acrobat Pro workflows, while improving efficiency. (~£1,750/year saved).
Led the design and delivery of a 10G network infrastructure refresh across three buildings at the Royal Armouries Museum, designed to serve ~3,000 concurrent clients during the annual UKREiiF conference.
Led a comprehensive 17-initiative security and infrastructure modernisation programme. Delivered Apple ABM/Intune MDM, Windows 11 upgrades, network hardening, endpoint migration, and Zero Trust enforcement. £6k investment generated £10k+ savings and improved Microsoft Secure Scores from ~55% to ~80%. (88% as of June 2026)
Designed and implemented SAML/OAuth SSO for 6 enterprise SaaS platforms (Procore, Zutec, HubSpot, AutoDesk, EVA Check-In, SolarWinds). Centralised authentication via Entra ID, improved user experience, and enhanced governance through dynamic group assignment.
Multi-component initiative including Exchange Online mailbox archiving, modernised compliance notifications with self-remediation, NUC privilege model redesign using identity-based elevation, and Android BYOD compliance policies—all aligned with Zero Trust principles.
Self-built SFF home server running since 2021 on Ubuntu LTS (current release) for long-term security support. Hardware selected specifically for 4K Dolby Vision / HDR transcoding via Intel QuickSync. Accessible remotely through a Cloudflare Tunnel — no open ports.
Self-hosted Home Assistant with Claude API integration for energy analysis and recommendations. Connects SolisCloud, Intelligent Octopus Go, Saving Sessions, Free Energy Sessions, AxleVPP, MyEnergi Zappi, Tesla Fleet, Solar Forecast, Google, Zigbee2MQTT, and Thread/Google Home.
Self-managed UniFi network built around a UDR7 router with a static public IP, managed via UniFi Site Manager. Security enforced through Zero Trust firewall rules in combination with Cloudflare Tunnels.
Evolved from DuckDNS with open ports → own domain on Cloudflare → Cloudflare Tunnels with zero open ports. All home lab services run exclusively through Cloudflare's edge with Zero Trust access policies enforced.