Mid-market manufacturing · India
Flat Azure estate to hub-and-spoke with segmentation, in 90 days, without an outage.
Customer had grown into Azure by spinning up VNets per project; everything peered to everything. We baselined the topology in 2 weeks, agreed the target hub-and-spoke with 4 spokes (prod, non-prod, shared services, DMZ), migrated workloads spoke by spoke during published change windows, and stood up the segmentation matrix as Terraform. The diagram is now reviewed quarterly with their head of IT.
- Flat estate → 4-spoke segmented topology in 12 weeks, zero customer-impacting outages
- Default-deny segmentation: 138 reviewed allows, all in version control
- Firewall log volume dropped 41% after rule consolidation
- Change-window adherence: 11 of 11 routine windows since cutover
- Audit finding resolved: 'inadequate network segmentation' closed at next review