Field experience

Technical decisions that hold up in production.

Organisations remain anonymous. The technology, scale and reasoning can still be explained without compromising confidentiality.

01

Technical delivery

Approximately 500 users

Anonymous Belgian organisation

From a legacy VPN cluster to a SASE architecture

Context
Remote access relied on a Cisco ASA cluster and a VPN model that no longer aligned as well with hybrid work and cloud services.
Intervention
Migration to Cisco Secure Access, progressive replacement of VPN access with ZTNA and introduction of SSE services including SWG and CASB.
Outcome
A Zero Trust access foundation better aligned with hybrid work, delivered through a managed transition from the existing environment.
Cisco Secure AccessZTNASWGCASBCisco ASA
02

Technical delivery

SME environment

Anonymous Belgian company

Consolidating an SME infrastructure through virtualisation

Context
Windows services spread across physical servers had become harder to maintain, protect and extend.
Intervention
Design and deployment of a virtualised platform combining servers, shared iSCSI storage and dedicated networking, followed by the integration of Windows services, backups and operating documentation.
Outcome
A consolidated environment that is easier to administer and recover, with a coherent foundation for additional workloads.
VMwareWindows ServeriSCSIShared storageBackup
03

Technical delivery

More than 10,000 mailboxes

Anonymous public-sector organisation

Migrating more than 10,000 mailboxes to Microsoft 365

Context
The move from an internally hosted mail platform to Microsoft 365 affected accounts and data as well as publishing, filtering, network flows and security policy.
Intervention
Preparation of infrastructure and security dependencies, adaptation of load balancers, firewalls and email gateways, support for migration waves and resolution of coexistence incidents.
Outcome
A large-scale transition to Microsoft 365 with coordinated ownership of messaging and all of its technical dependencies.
Microsoft 365ZimbraF5Check PointCisco ESA
04

Technical delivery

Enterprise data centre

Anonymous Belgian organisation

Migrating a data centre to Cisco ACI

Context
A legacy data centre network needed to move to software-defined networking without interrupting internal and published services.
Intervention
Migration scenario design, preparation of network and security dependencies, then progressive transition of firewalls, load balancers, VPN services and applications to Cisco ACI.
Outcome
A structured transition to SDN with rollback paths and explicit coordination across infrastructure, security and application teams.
Cisco ACISDNCheck PointF5VPN
05

Technical delivery

Hybrid environment

Anonymous Belgian organisation

Migrating data centre services to Azure

Context
Services hosted in the data centre needed to move to Azure while preserving required flows to users and systems remaining on premises.
Intervention
Flow analysis, preparation of hybrid connectivity, adaptation of security policy and support for application transitions.
Outcome
A cloud path that includes networking and security from the outset rather than addressing them after the server move.
Microsoft AzureCloud networkingVPNFirewalls
06

Technical delivery

Sites in Belgium and Luxembourg

Anonymous international organisation

Multi-country WAN modernisation

Context
Sites depended on a mixture of MPLS and DMVPN that had become difficult to operate and extend.
Intervention
Preparation and migration to Cisco Meraki SD-WAN, covering dependency mapping, routing policy, transition scenarios and operational documentation.
Outcome
More consistent site connectivity and simpler day-to-day operations without losing visibility into existing dependencies.
Cisco MerakiSD-WANMPLSDMVPNBGP
07

Technical delivery

Internet-facing services

Anonymous Belgian organisation

Redesigning the security posture of a DMZ

Context
The DMZ architecture had accumulated flows and rules over time, making risk and dependencies difficult to understand.
Intervention
Flow mapping, architecture review, clarification of trust zones and preparation of changes across Check Point VSX and Cisco infrastructure.
Outcome
A clearer architecture, better-justified rules and an operable basis for gradually reducing legacy access.
Check Point VSXCiscoDMZSegmentation
08

Technical delivery

UAT and production environments

Orthrus IT infrastructure

Self-hosted platform for internal services and web applications

Context
Internal services, automations and web applications needed clear separation between testing and production without adding a separate SaaS platform for every component.
Intervention
Deployment of a Kubernetes platform with declarative releases, persistent storage, backups, centralised monitoring and secure service publication.
Outcome
A reproducible platform for deploying, testing, monitoring and documenting services while retaining control over data and infrastructure costs.
KubernetesUAT & productionObservabilityBackupsAutomation
09

Intervention pattern

Teams of 5 to 50 people

Recurring intervention pattern

A secure SME network without unnecessary complexity

Context
Guest Wi-Fi shares a network with endpoints and the NAS, staff use inconsistent remote access methods and no current diagram is available when a device fails.
Intervention
On-site inventory, VLAN separation, an appropriate firewall such as OPNsense, secure remote access, configuration backups and recovery documentation.
Outcome
A clearer, more maintainable environment sized to the organisation’s actual risk and budget.
OPNsenseVLANWireGuardBackupMonitoring
01

Confidentiality is part of the service

No names, logos, sensitive data or unverified figures. We explain the problem, approach and operational value.

02

Does this sound familiar?

Share the context. We will tell you what can be assessed quickly and what requires a structured discovery phase.

Share your context