Skip to content

Home Expertise / Network security

NET / NET-04

Secure remote access and Zero Trust Network Access

Give each user or supplier access only to required resources after verifying identity and access conditions. The project reduces broad network access without presenting Zero Trust as a magic product.

WHEN IT HELPS

A focused response
to a defined need.

Remote working, supplier maintenance, internal applications exposed through overly permissive VPNs or a need to distinguish managed and unmanaged devices.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-04

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • User and application inventory
  • SSO/MFA
  • role-based policies
  • device posture where available
  • temporary access
  • logs
  • revocation
  • emergency access

Deliverables

  • Access architecture
  • resource catalogue
  • population-specific rules
  • joiner and leaver procedures
  • user pilot
  • denial tests
  • support documentation

Acceptance evidence

Approved access works and is logged; user removal takes effect; out-of-role resources remain inaccessible; lost-factor and outage scenarios are addressed.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Who accesses what remotely? Are devices managed? Which applications cannot support the proposed access mechanisms?

IMPORTANT BOUNDARIES

Protection depends on identity, devices and applications. A ZTNA service alone does not secure the entire network or every use case.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A consultancy gives every consultant full VPN access. Project: restrict access to assigned applications and require strong authentication. Target outcome: verifiable separation between engagements, with documented exceptions for legacy tools.

Scenario 02

A manufacturer hosts an external maintenance provider. Project: time-limited access to approved resources with logging. Target outcome: maintenance without permanent access to the wider environment; access is removed after acceptance.

Technology and reference context

Examples: ZTNA solutions, segmented VPNs and compatible identity services; select according to protocols, endpoints and operating constraints.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.