Skip to content

Enterprise

Your network cannot prove what is on it

Most enterprise networks still treat a physical port or a VLAN as sufficient evidence of trust. Everyone knows it is not. The reason it persists is that fixing it means enforcing — and enforcing is the part that can take the business down.

That is the actual problem we solve. The technology to identify and authorise every device has existed for two decades and most organisations already own a piece of it. What is missing is a way to switch it on that the network team can defend in a change advisory board meeting.

We do one hard thing: we take access control from a diagram to enforced policy in the switching fabric, in stages, with a rollback at every step.

When firms call us

The four situations that start this work

An audit came back with an access control finding

The finding is rarely "buy a NAC product". It is that you cannot demonstrate which devices are authorised to be on the network, or produce evidence of the decision.

You own a NAC product you never finished

Licences renewing on a deployment that has been logging quietly in monitor mode for years. The infrastructure is usually sound; the policy work is what stalled.

A merger just doubled your device estate

Two networks, two sets of assumptions about who belongs, and no shared basis for trusting a device from the other side.

Something got in through an unmanaged device

A contractor laptop, a piece of lab equipment, a camera. The endpoint agent could never have covered it, because it cannot be installed on it.

The real objection

Nobody is afraid of the technology

They are afraid of the day it starts saying no. Every one of these has an answer, and the answer is method rather than reassurance.

Will this take the business down?
Not if enforcement is staged. Nothing enforces before a monitor period has reported exactly what would have been denied, and every stage has a tested rollback.
What about devices that cannot do 802.1X?
Printers, badge readers, cameras, medical and industrial equipment. They are identified during discovery and given a different authorisation path — profiling and posture rather than a supplicant. This is normal, not an exception.
What does the help desk experience?
They get a runbook before anything changes: what users will see, which failures are expected, and what to do. A rollout that surprises the help desk is a rollout that gets reversed.

The full five-phase method

How it runs

Five phases, one outcome

  1. 1

    Discover

    What is actually on the network?

  2. 2

    Design

    What should be allowed, and who decides?

  3. 3

    Prove

    What would have happened if this were enforcing?

  4. 4

    Enforce

    Can we turn this on without an outage?

  5. 5

    Sustain

    Will this still be working in a year?

Find out what your network would deny today

Eight questions, scored instantly, nothing sent anywhere. It will not tell you what to buy — it will tell you what you can currently prove.

Take the readiness check