Skip to content

Home Expertise / Network security

NET / NET-05

Secure internet access and SASE/SWG architecture

Control users’ web and cloud access in the office and remotely through consistent policies. SASE combines networking and security capabilities; the actual purchased scope must be defined.

WHEN IT HELPS

A focused response
to a defined need.

Distributed business whose users bypass headquarters protection, growing branch networks or a need for web filtering and visibility into cloud-service use.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-05

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Users, sites and applications
  • secure web gateway
  • category and risk rules
  • identity integration
  • remote traffic
  • exceptions
  • TLS inspection when authorised
  • logging

Deliverables

  • Target architecture
  • browsing policies
  • multisite pilot
  • privacy assessment
  • performance tests
  • exception guide
  • monitoring and exit procedures

Acceptance evidence

User profiles receive intended policies; critical workflows operate; exception handling works; availability and latency are measured in the customer’s context.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Which web activities need protection or permission? Where do users work? Which applications are sensitive to proxies or inspection?

IMPORTANT BOUNDARIES

SWG, ZTNA, CASB and DLP capabilities are not automatically all included. Decryption must respect privacy constraints and necessary exclusions.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company has several branches with inconsistent security. Project: phase in a shared secure web gateway. Target outcome: consistent rules for remote and onsite employees, with support able to approve justified exceptions.

Scenario 02

An engineering firm wants control over unapproved cloud services. Project: observe use and distinguish prohibited from approved services. Target outcome: fewer uncontrolled accesses without indiscriminately blocking collaboration tools.

Technology and reference context

Examples: SASE/SWG platforms compatible with customer identities and endpoints; verify modules, processing countries and licenses.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.