← Back to portfolio
Why this engagement needed a phased approach: Corporate separation means losing the parent's shared IT infrastructure — network perimeter, Active Directory, and access controls — simultaneously. The customer needed a design that could be stood up incrementally without disrupting operations, while building toward a mature security posture that no longer depended on the parent company's estate.

Architecture Diagram

Zero Trust architecture diagram Click diagram to expand

Key Design Principles

  • Identity becomes the control plane — not the network
  • Users and sites connect via secure tunnels or lightweight agent-based access
  • Applications are exposed through ZTNA instead of broad network access
  • Security services are delivered inline through a unified cloud platform

Transformation Phases

  • Phase 1: ZTNA for remote access — replace VPN dependency immediately
  • Phase 2: Branch integration through SD-WAN / IPsec connectivity
  • Phase 3: CASB and DLP to extend data protection across SaaS and cloud
  • Phase 4: Full visibility through Digital Experience Monitoring (DEX)

My Involvement

I led the presales architecture for this engagement — conducting technical discovery with the customer's IT and security stakeholders, producing the existing and future state high-level design, and presenting the phased roadmap to the CISO and IT director.

The architecture draws directly from Zscaler's SSE and ZTNA portfolio (ZIA, ZPA, ZDX), extended with identity integration across Microsoft Entra ID and Okta, and aligned with the branch connectivity constraints of a manufacturing environment with multiple sites.

Customer Value