A network that is documented, segmented and diagnosable.
Design and rebuild of enterprise networks with segmentation that contains an incident, configuration held as code, and documentation that matches what is actually plugged in.
Networks that grew rather than were designed
Most enterprise networks were extended rather than designed. Each addition was reasonable; the accumulation is a flat network where a compromised laptop can reach a server, configuration lives only on the devices, and the diagram on the wall is several years out of date.
- The network is largely flat, so anything compromised can reach everything.
- Device configuration exists only on the devices themselves.
- The documentation does not match what is actually connected.
- Diagnosing a slow application means guessing whether the network is involved.
What we build
A segmented design that limits how far an incident can travel, with configuration managed centrally and documentation generated from the live network rather than maintained by hand.
- Segmentation by function and trust level, with rules between segments
- Configuration backup and version control across network devices
- Standard configuration templates so devices are consistent
- Documentation generated from discovery, so it stays current
- Resilient paths for the links that matter, sized to their importance
- Change process with rollback for network changes
How it runs
Discovery first, because the documented network and the real one usually differ.
- 01Discover what exists
Automated discovery of devices, links and traffic patterns, producing an accurate picture rather than an assumed one.
- 02Design the segments
Boundaries by function and trust, with the rules between them derived from observed traffic rather than guesswork.
- 03Version the configuration
Device configuration backed up and version controlled, so a change is reviewable and reversible.
- 04Migrate carefully
Segmentation introduced in stages with monitoring, because the flow nobody documented always exists.
- 05Keep documentation live
Generated from discovery on a schedule, so it reflects reality instead of the last time somebody updated it.
What changes once it is running
What segmentation and configuration management change.
Incidents stay contained
Segmentation limits how far a compromise can travel, which is the difference between an incident and a crisis.
Changes become reversible
Version-controlled configuration means a bad change is rolled back rather than reconstructed.
Documentation is trustworthy
Generated from the live network, so it is worth reading during an incident.
The network stops being the suspect
Visibility means it can be ruled in or out quickly instead of blamed by default.
How an engagement is shaped
Discovery, then staged change. Big-bang network cutovers rarely end well.
Discovery and design
Two to three weeks of discovery and traffic analysis, producing an accurate current-state picture and a segmentation design.
Implement in stages
Segmentation introduced progressively with monitoring at each step and rollback available.
Operate
Configuration management, documentation refresh and change support, optionally managed.
Common questions
The things buyers ask before they commit. If yours is not here, it is a good first question for the assessment.
- Do we need to replace our hardware?
- Often not. Much of this is design and configuration on equipment you already own. Replacement is recommended where capability or support status genuinely requires it, not as a default.
- Will segmentation break things?
- It can, which is why it is introduced in stages with monitoring rather than in one weekend. Discovery is what finds the undocumented flows before they become an outage.
- Which vendors do you work with?
- The major enterprise vendors and open networking platforms. The design principles transfer; the configuration syntax is the easy part.
If a laptop were compromised, where could it reach?
If the honest answer is most places, segmentation is the highest-return work on the network.
