← Back to portfolio
Why this engagement needed a phased approach: Corporate separation means
losing the parent's shared IT infrastructure — network perimeter, Active Directory, and
access controls — simultaneously. The customer needed a design that could be stood up
incrementally without disrupting operations, while building toward a mature security posture
that no longer depended on the parent company's estate.
Architecture Diagram
Click diagram to expand
Key Design Principles
- Identity becomes the control plane — not the network
- Users and sites connect via secure tunnels or lightweight agent-based access
- Applications are exposed through ZTNA instead of broad network access
- Security services are delivered inline through a unified cloud platform
Transformation Phases
- Phase 1: ZTNA for remote access — replace VPN dependency immediately
- Phase 2: Branch integration through SD-WAN / IPsec connectivity
- Phase 3: CASB and DLP to extend data protection across SaaS and cloud
- Phase 4: Full visibility through Digital Experience Monitoring (DEX)
My Involvement
I led the presales architecture for this engagement — conducting technical discovery with
the customer's IT and security stakeholders, producing the existing and future state
high-level design, and presenting the phased roadmap to the CISO and IT director.
The architecture draws directly from Zscaler's SSE and ZTNA portfolio (ZIA, ZPA, ZDX),
extended with identity integration across Microsoft Entra ID and Okta, and aligned with
the branch connectivity constraints of a manufacturing environment with multiple sites.
- Discovery and current-state mapping across remote access, branch connectivity, and SaaS usage
- Future-state architecture design spanning SSE, ZTNA, CASB, DLP, and DEX
- POC scoping and success criteria definition with the customer's IT team
- Executive presentation of phased roadmap and business case
Customer Value
- Immediate access continuity during the separation window — no dependency on parent infrastructure
- Consistent access policy across remote users, branch offices, and datacentres from day one
- Each phase delivers standalone value — the customer is not locked into completing the full roadmap before seeing results
- Security posture that scales with the business as a newly independent entity