NET / NET-05
Secure internet access and SASE/SWG architecture
Control users’ web and cloud access in the office and remotely through consistent policies. SASE combines networking and security capabilities; the actual purchased scope must be defined.

WHEN IT HELPS
A focused response
to a defined need.
Distributed business whose users bypass headquarters protection, growing branch networks or a need for web filtering and visibility into cloud-service use.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Users, sites and applications
- secure web gateway
- category and risk rules
- identity integration
- remote traffic
- exceptions
- TLS inspection when authorised
- logging
Deliverables
- Target architecture
- browsing policies
- multisite pilot
- privacy assessment
- performance tests
- exception guide
- monitoring and exit procedures
Acceptance evidence
User profiles receive intended policies; critical workflows operate; exception handling works; availability and latency are measured in the customer’s context.
DELIVERY
How the work is structured.
Approach
Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.
Prerequisites & responsibilities
Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.
Scope factors
Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.
Questions to clarify
Which web activities need protection or permission? Where do users work? Which applications are sensitive to proxies or inspection?
IMPORTANT BOUNDARIES
SWG, ZTNA, CASB and DLP capabilities are not automatically all included. Decryption must respect privacy constraints and necessary exclusions.
Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
A company has several branches with inconsistent security. Project: phase in a shared secure web gateway. Target outcome: consistent rules for remote and onsite employees, with support able to approve justified exceptions.
Scenario 02
An engineering firm wants control over unapproved cloud services. Project: observe use and distinguish prohibited from approved services. Target outcome: fewer uncontrolled accesses without indiscriminately blocking collaboration tools.
Technology and reference context
Examples: SASE/SWG platforms compatible with customer identities and endpoints; verify modules, processing countries and licenses.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
