info@lookup.com.au 1300 553 559 Remote Assist
    Lookup Logo

    Standardising Technology Across an Existing Franchise Network

    Abstract editorial illustration of scattered franchise location nodes converging onto a single unified technology standard at a central glowing hub.

    A new location can be built to a standard. An existing one has to be moved to it, while trading, often by people who did not choose the current setup and have no reason to want it changed.

    The technology at each site was usually chosen sensibly at the time. The problem is not that individual decisions were wrong. It is that nobody owns the joins between them, and the network has drifted into a patchwork that head office cannot see, cannot support efficiently and cannot secure consistently.

    Bringing an existing network onto one standard is not a technology refresh. It is an operational change that has to happen site by site, without closing a single location for a day.

    The short answer

    You bring an existing network onto one standard by defining the blueprint first, then moving sites to it one at a time — proving the process at the first site before replicating it — so the standard is tested in practice before it is rolled out, and every site that moves validates the process for the next. The LOOKUP Business Modernisation Framework™ provides the sequence: understand the current state, secure the most exposed sites, define the standard, then move each site onto it without disrupting trade.

    How networks drift apart

    Drift is not caused by carelessness. It is the natural result of growth without a single owner of the technology standard. Each of these causes is reasonable in isolation. Together they produce a network that nobody designed.

    Locations opened at different times

    Each site was set up with whatever devices, licences and suppliers were current at the time. A network of ten locations may span three or four generations of hardware, software and security practice, none of them wrong when chosen but none of them aligned.

    Local decisions made sensibly in isolation

    A manager at one site found a problem and solved it locally. The solution worked, so it stayed. Across the network, dozens of those sensible local decisions add up to a patchwork that nobody designed and nobody can see in full.

    Acquisitions arriving with their own systems

    When a group acquires an existing business, it inherits a technology environment that was built by someone else for different reasons. That environment runs until someone has the time and authority to change it, which is often never.

    No single owner of the whole

    Nobody at head office holds responsibility for the technology standard across every site. Each location reports through operations, not IT, so technology drift is invisible until something breaks or a question cannot be answered.

    What drift costs head office

    The cost of an unstandardised network is not measured in any single incident. It is measured in the daily friction of running a business where every site is a separate problem to understand before it can be helped.

    Security is only as strong as the least managed site

    A single site with outdated security settings, no multi-factor authentication or unmanaged devices gives an attacker a way into the broader network. Head office cannot guarantee a standard it cannot see.

    Support is slower because every site is different

    When a staff member calls for help, the first question is not what the problem is but what system they are on. Every site is a new investigation, and simple issues take longer than they should.

    Reporting has to be assembled by hand

    Because each site uses different tools and configurations, head office cannot pull a single report across the network. Someone compiles it manually, which means it is always out of date and always incomplete.

    Licences are paid for and unused

    Different sites hold different numbers of licences for different products. Some are over-licensed, some are under-licensed, and nobody has a consolidated view of what the network actually pays for.

    Basic questions about the network cannot be answered

    How many devices do we have across all sites? How many have current security patches? Who has access to what? Without a standard, these questions require a site-by-site audit rather than a query.

    The Framework

    How this maps to the LOOKUP Business Modernisation Framework™

    Standardising an existing network follows the same eight-stage sequence as every other LOOKUP engagement — understand the current state before changing it, secure before standardising, and prove the process at one site before replicating it across the network.

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    01
    Discover

    Understand the current environment

    02
    Secure

    Protect identities, devices and information

    03
    Modernise

    Remove legacy technology constraints

    04
    Standardise

    Create consistent systems and processes

    05
    Optimise

    Improve workflows and productivity

    06
    Prepare

    Establish governance and AI readiness

    07
    Implement

    Introduce technology deliberately

    08
    Improve

    Measure, review and continuously improve

    Discover

    Map every site's current devices, licences, security settings and suppliers so head office can see the full picture before changing anything.

    Secure

    Apply multi-factor authentication, conditional access and endpoint protection as the first common baseline, starting with the most exposed sites.

    Modernise

    Bring every site onto the same Microsoft 365 tenant configuration, replacing ad-hoc email and file-sharing arrangements with governed, centralised services.

    Standardise

    Define the technology blueprint every existing site will be moved to and every new site will start from, covering devices, security, identity and support.

    Optimise

    Consolidate licences, retire unused tools and align support so the network runs on fewer, better-understood systems rather than a patchwork.

    Prepare

    Assess each site's data, permissions and governance so the network is ready for AI and automation introduced at a consistent standard.

    Implement

    Move sites onto the standard one at a time, proving the process at the first site before replicating it, so trade continues throughout.

    Improve

    Review the standard regularly as the network grows, so new acquisitions and new locations arrive at a current, maintained baseline rather than an outdated one.

    What the standard actually covers

    A technology standard is not a single decision. It is a defined position on each element that every site, including the next one acquired, has to match. The specifics vary by network, but the categories below are the ones that matter.

    Hardware, software and network standards

    A defined hardware specification for each site format, a standard set of approved software, and a network configuration covering firewalls, Wi-Fi and switching. A new site or a refreshed site orders from the same list, so the network is not assembled from whatever was available on the day.

    Identity management

    Every staff member across every site authenticates through a single identity provider, with accounts created and removed centrally. A person who leaves one location is removed from the network, not just from a local machine.

    Conditional access

    Access to business systems is governed by policy, not by whoever happens to know the password. Conditional access rules determine what can be reached from which devices, locations and risk levels, applied identically at every site.

    Device enrolment and management

    Every device is enrolled into central management before it reaches a site. Configuration, security settings and software are pushed to the device, not left to whoever sets it up. A device that is lost or retired can be wiped remotely.

    Security policies

    A single set of security baselines — multi-factor authentication, endpoint protection, patching, backup and email filtering — applied to every site so that head office can state with confidence what the security posture is, rather than discovering site by site what it is not.

    Business continuity

    Backup and recovery are configured to the same standard at every site, tested on the same schedule. If a site experiences a hardware failure, a security incident or a data loss event, the recovery path is already known and does not depend on a local manager remembering what they did last time.

    Centralised reporting

    Because every site runs the same systems and the same configurations, head office can pull a single report across the network — device count, security status, licence usage, support activity — without asking each manager to compile it by hand.

    Operational governance with named owners

    The standard is owned, maintained and reviewed. Someone at head office is accountable for keeping it current, for approving exceptions, and for ensuring that the next site acquired or opened arrives at the standard rather than being dragged up to it later.

    Mandate versus adoption

    In a wholly owned network, head office can mandate a standard and sites comply. In a franchise network, where locations are independently owned, a standard has to be adoptable rather than merely instructed. The distinction matters because the technology that runs a site is the operator's livelihood, and an instruction that makes their day harder will be worked around.

    A standard is adoptable when it is easier, cheaper or safer than what the site does now, and when the benefit is visible to the operator, not only to head office. If the standard means a site manager gets faster support, fewer outages and simpler onboarding, they will hold to it. If it means more overhead with no visible return, they will not.

    This is why the standard has to be designed from the operator's perspective as well as head office's. A franchise technology approach that works for a wholly owned chain may fail in a franchised one, because the operator's reasons for adopting it are different. The standard has to be worth adopting on its own merits at each site, not only because the network agreement says so.

    That does not mean lowering the security baseline. It means making the secure path the easy path — so that the standard way of doing things is also the simplest way, and working around it takes more effort than following it.

    Doing it without stopping trade

    A network standardisation programme is done site by site, never as a single cutover. The standard is proven at one location before it is replicated, so that the process is tested in practice — not just on paper — and any issues are found where they are cheapest to fix.

    The first site is the reference. It proves the deployment steps, the time required, the impact on staff and the support model. Once it is running cleanly, each subsequent site follows the same sequence, with the lessons from the first already built in.

    Sequencing is arranged around trading patterns. A site that is busiest on weekends is moved midweek. A site that never closes is moved in stages across low-traffic periods. The principle is simple: no site closes for a day to accommodate a technology change.

    This is also the model used when a new location is opened on the standard from day one. The opening new locations on a repeatable blueprint and the standardisation programme share the same target state — the difference is that one starts from empty and the other starts from an existing environment that has to be moved across while trading.

    Where to start

    Identity and security come first, because everything later depends on them and because they are the areas where one weak site exposes the whole network. A single location without multi-factor authentication or with unmanaged devices is a way in — not just to that site, but to the systems it connects to.

    The Essential Eight, published by the Australian Signals Directorate as a baseline set of mitigation strategies, can serve as a common security standard across locations. It gives head office a defined position to hold every site to, and it gives each site a clear set of controls to implement rather than a vague instruction to "be secure."

    From there, the sequence follows the framework: understand the current state of every site, secure the most exposed, define the standard, then move each site onto it. The first site proves the process. The rest follow the same path.

    How LOOKUP helps

    Defining the standard

    LOOKUP works with head office to define the technology blueprint — hardware, identity, security baseline, Microsoft 365 configuration and support model — so every site has a single, documented standard to move to rather than a set of aspirations.

    Microsoft 365 environment design

    LOOKUP designs the Microsoft 365 tenant configuration — tenants, licences, security policies and user accounts — so every site authenticates, collaborates and stores information through the same governed environment.

    Identity and device management

    LOOKUP configures centralised identity, conditional access and device enrolment so that accounts are created and removed centrally, and every device is managed from the moment it is provisioned to the moment it is retired.

    Establishing the security baseline

    LOOKUP applies the security baseline — multi-factor authentication, endpoint protection, conditional access and email filtering — across every site, with ongoing monitoring to ensure a site that drifts is detected and corrected. When an incident does occur, the containing a security incident across the network limits the blast radius across the network.

    Staged migration site by site

    LOOKUP moves each site onto the standard one at a time, proving the process at the first location before replicating it. Managed IT services provide the ongoing support model so the standard holds after migration, not just on the day of cutover. LOOKUP coordinates with point of sale and line-of-business platforms rather than replacing them.

    Frequently asked questions

    A single technology standard means every site uses the same identity platform, security baseline, device configuration, Microsoft 365 tenant and support path. It does not mean every site is identical in every respect — store size and layout differ — but the core technology layer is consistent, governed and visible to head office.

    No. Standardising means defining what the target looks like and moving each site toward it, keeping what already fits and replacing what does not. Hardware that meets the standard stays; hardware that creates risk or cannot be managed centrally is replaced when it reaches its natural end of life.

    Where sites are independently owned, the standard has to be adoptable rather than merely mandated. That means head office designs it so coming onto the standard is easier, safer or cheaper than staying off it, and the benefit to the operator is visible — not only the benefit to head office.

    Refusal usually signals the standard looks like cost or disruption from the operator's side. The response is to make the case in operational terms — what the operator gains — and to ensure the migration path is genuinely low-friction. Where a network agreement exists, the standard may also be a contractual expectation, but adoption works better when it is understood as a benefit.

    Security can be enforced where the identity, devices and Microsoft 365 tenant are managed centrally, even on an independently owned site. Conditional access, multi-factor authentication and endpoint protection are applied through the platform, not through physical control of the premises. The constraint is contractual and political, not technical.

    Identity and security come first, because every later stage depends on them and because one weak site exposes the whole network. Until accounts, access and device security are consistent, nothing else can be reliably standardised or reported on across the network.

    The change is done site by site, sequenced around trading patterns, and proven at one location before it is replicated. Work is scheduled for low-traffic periods, devices are pre-configured before they arrive, and the cutover at each site is planned so the business opens the next day on the new standard.

    It depends on the number of sites, how different they are, whether they are company-owned or independently owned, and how much needs to change at each location. A small network with similar sites moves faster than a large one with acquired locations carrying legacy systems. The process is sequenced, not simultaneous.

    Acquired locations are assessed against the standard and brought onto it as part of the integration process. The assessment identifies what can stay, what must change immediately for security reasons, and what can be migrated over a longer period. The standard means the integration is repeatable rather than a fresh project each time.

    No. The standard defines the minimum capability and the management requirements — such as a managed firewall, business-grade connectivity and enrolled devices — not a single brand or model. Sites of different sizes may use different hardware that meets the same standard and is managed through the same platform.

    Drift is prevented by centralised management — devices enrolled and monitored, policies enforced through the platform rather than relying on local compliance, and ongoing support that holds the standard. A site that drifts is detected through monitoring, not discovered when something breaks.

    The standard needs a named owner with authority across sites — typically a network operations lead or a virtual CIO — not a committee. Without a single owner, decisions default to whoever is loudest, and the standard erodes through exceptions that are never revisited.

    The cost depends on how far the site is from the standard, what hardware or licences it already holds that can be retained, and whether the migration is phased or done in a single cutover. Where the standard is adoptable, the ongoing cost is often lower than what the site was paying for ad-hoc support and unused licences.

    A common standard means head office can see devices, security status, licences and support activity across every site through a single pane rather than asking each site. Reporting becomes a query rather than a manual compilation, and it is current rather than out of date.

    Start with discovery — an assessment of what is actually running at each site, who has access, and what the security posture is. You cannot define a standard without knowing the current state, and most networks are surprised by what the assessment finds.

    Sources & Further Reading

    The following authoritative sources support the security and AI governance context discussed on this page:

    Essential Eight

    Australian Signals Directorate's Australian Cyber Security Centre. A baseline set of mitigation strategies that can serve as the common security standard across every location in a network.

    View Source

    Guidance for AI Adoption

    National AI Centre, Department of Industry, Science and Resources. Six essential practices for governing and adopting AI responsibly, which depend on the consistent systems a standard creates.

    View Source

    Evidence Standard

    LOOKUP references recognised industry, government, professional and technology sources when discussing research, regulation and industry trends. Research findings are paraphrased and linked to their original sources wherever practical. LOOKUP's professional observations and recommendations are presented separately from third-party research.

    Ready to bring your network onto one standard?

    If every site runs differently and head office cannot answer a simple question about the whole network, a strategy session is the place to start. Book a conversation with LOOKUP to map the current state and define the path to one standard.

    Peter Kantarelis

    Founder, LOOKUP — Business Technology Strategist

    Peter Kantarelis is the Founder of LOOKUP and a business technology strategist helping Australian organisations modernise technology, strengthen cyber security and prepare for practical AI adoption. He regularly works with business owners and leadership teams to improve productivity, reduce operational risk and implement technology that delivers measurable business outcomes. The LOOKUP Business Modernisation Framework™ reflects more than 25 years of helping Australian businesses make better technology decisions.

    Avatar
    Hi there! Have a question? Chat with us here.