Case studies

Zero Trust Network Architecture & Business Case for leading global provider of professional assurance services.

key fact

Delivered a comprehensive Zero-Trust Network Strategy that mitigated security risks, avoided major hardware costs, and enabled digital transformation.

Our client is a trusted  provider of risk and compliance management services that help organisations optimise their operations and maintain regulatory compliance. Its global reach extends to more than a 100 countries, where it supports a diverse range of industries from energy and utilities to healthcare and aviation.

Offering services such as certification audits, compliance training, and process assessments, our client enables businesses to reduce risks and improve sustainability.

With a team of dedicated professionals, our client’s in-depth expertise across industries helps its partners achieve their strategic objectives and strengthen their market position.

Challenge

Following completion of a private equity purchase and becoming an independent business, the client underwent an IT separation project leaving them with a ‘red rated’ network that needed urgent attention.

The client has inherited a network with security and support challenges introducing risk and inhibiting the progress of digital transformation.

As a result of the protracted lock-downs associated with COVID followed by the private equity purchase, a large percentage of the network estate is now End Of Life meaning vendor support and security patching was not available.

Upgrading the hardware is an option but is expensive and does not support the clients IT strategy.

Options for the newly formed business need to be examined evaluating the business operation, security, and cost.

As we had supported the separation activity and had a strong understanding of the new business, both commercially and technically, we were uniquely placed to provide the required guidance.

Solution

Our approach was to start with the business strategy and how the IT strategy provides support. The key themes would be the support of the Digital Workplace Roadmap Initiative, cost management, security, and simplification.

From this we were able to identify 8-key themes that would allow effective evaluation of any proposed network architecture and articulate the risk associated with doing nothing.

Deeper investigation then followed, collaborating with key stakeholders within the client’s organisation and also key vendors.

We collated the options and performed evaluation against the key criteria.

We then provided our recommendation.

We provided additional detail regarding the recommendation including project activity describing a phased risk-averse approach, whilst getting the business benefits at pace.

Outcome

We produced a Network Strategy document for the client.

The document divided into 3-sections:

Current Global Network

  • Detail current network and quantify security and network risk
  • Global Network Options Analysis

Continue as-is.

    • Maintain and Upgrade current infrastructure.
    • Migrate to Zero-Trust Architecture.
    • Recommended Zero-Trust Architecture

What is Zero-Trust?

      • What are the benefits to the client?
      • Initial Evaluation of client for Zero-Trust.
      • Recommended Phased Approach.
  • The recommended architecture will provide the following benefits for the client: Security – Remediate the current high risk attributed to the EOL and Vulnerability of the corporate network hardware. All traffic will tunnel from user device across the corporate network ensuring no possible interception. The removal of trust and associated lateral movement. All users will be authenticated, all of the time. Cost avoidance – As the security risk is remediated, the urgency to upgrade the network hardware is reduced, and therefore the cost can be avoided. Simplification – The target network solution required will be far simpler focusing on the availability of an Internet service.Support for Digital Transformation – remote workers will be secured from source when connecting to hybrid cloud environments, agile connectivity to platforms in support of agile application deployment.Support for Office Strategy – The solution is fully supportive of a mobile workforce.

    Support for further Acquisitions – Integration effort is reduced allowing quick interim access to be provided with full security control and visibility, only requiring a path to the Internet, license procurement and a valid authentication source.

    Application Performance Monitoring – As access policy decisions for user requests requires application visibility, there is the additional capability to proactively monitor application performance and raise proactive alerts. This a key requirement when aspiring towards digital transformation.

    Remote User Connectivity Intelligence – An additional capability associated with the deployment of client software is the ability to pull remote intelligence with regard the users connectivity. This is increasingly useful when moving away from a managed corporate network.

If you would like to speak to one of our industry experts regarding this case study, email contact@masonadvisory.com. Find out more about our services.

Our services

View all