Skip to content

Approach

Monitor mode is a stage, not a destination.

A large share of network access control deployments never reach enforcement. They get installed, they log everything, they authorise everything, and years later the organisation is still paying for licences that block nothing. It happens because the step from watching to enforcing is the step that can take the business down — so it gets deferred, and then it gets forgotten. Every phase below exists to make that step survivable.

  1. Phase 1: Discover

    What is actually on the network?

    You cannot enforce a policy against an inventory you do not have. This phase profiles every connected device — including the ones nobody remembers deploying: badge readers, cameras, printers, building controls, lab equipment, the machine in the corner running an operating system that went out of support a decade ago.

    Why this phase exists — The single most common cause of a failed enforcement day is a device class nobody knew was there.

    You receive

    • Device inventory by type, location, and authentication capability
    • Identification of devices that cannot do 802.1X and will need another path
    • Current-state assessment of any existing NAC or ISE deployment
  2. Phase 2: Design

    What should be allowed, and who decides?

    Policy design before any configuration. Roles, entitlements, and the trust decision for each device class — plus the certificate strategy, because device trust that rests on a MAC address is not trust at all.

    Why this phase exists — Policy written during a rollout becomes policy written under pressure. It is where permanent exceptions get created.

    You receive

    • Access policy model covering wired, wireless, and remote access
    • PKI and certificate lifecycle design
    • High-availability architecture and failure behaviour
    • Integration design for the tooling already in place
  3. Phase 3: Prove

    What would have happened if this were enforcing?

    Monitor mode, used properly and for a bounded period. The policy runs against live traffic and reports what it would have denied — so every gap surfaces while the cost of being wrong is still zero.

    Why this phase exists — This is the phase organisations skip, and skipping it is why enforcement days go badly. It is also the phase they get stuck in permanently — so it is time-boxed with an exit condition, not left open.

    You receive

    • Would-have-denied reporting by device class and location
    • Exception list with a decision and an owner for each
    • Remediation plan for devices that would fail
  4. Phase 4: Enforce

    Can we turn this on without an outage?

    Enforcement by stages — a site, a floor, a device class at a time — with a tested rollback at each stage and the help desk briefed before anything changes. Nothing goes wide until a bounded group has run enforced through a normal business day.

    Why this phase exists — Enforcing everywhere at once converts a small problem into a company-wide one. Staging keeps the blast radius the size of one stage.

    You receive

    • Phased enforcement schedule with defined success criteria per stage
    • Tested rollback procedure for every stage
    • Help desk runbook covering what users will see and what to do about it
  5. Phase 5: Sustain

    Will this still be working in a year?

    Access control decays. Certificates expire, exception lists grow, new device types arrive, and the person who understood the policy changes jobs. The handover is a deliverable, not a conversation.

    Why this phase exists — A design that only the consultant understands is a liability the day the consultant leaves.

    You receive

    • Standard operating procedures and operational runbooks
    • Certificate rotation and lifecycle calendar
    • Exception review process with a defined cadence
    • Evidence pack aligned to the applicable framework

Straight answers

What people ask before they commit

What happens when it locks out the CEO?
Nothing enforces before the Prove phase has reported what it would have denied, and enforcement rolls out in stages with a tested rollback. Executive and critical-path devices are identified in Discover and onboarded before any policy tightens.
How long does this take?
It depends on device diversity far more than on headcount or site count — a ten-thousand-device network of standard laptops is simpler than a two-thousand-device network with medical or industrial equipment on it. Scoping happens in Discover, and the enforcement schedule is set from real inventory rather than estimated up front.
We already own a NAC product we never finished. Is that wasted?
Usually not. Most stalled deployments have sound infrastructure and unfinished policy work, which is a much smaller problem than it looks. The current-state assessment in Discover establishes what is reusable before anything is proposed.
What do we get that outlasts the engagement?
Documentation is a deliverable at every phase — policy model, SOPs, runbooks, and the evidence pack an assessor asks for. The test of a finished engagement is whether your team can operate it without us.

Stuck in monitor mode?

It is the most common place for this work to stall, and the most straightforward to fix. Eight questions will tell you how far along you actually are.

Take the readiness check