Cybersecurity is about small, targeted moves: 20% of the right actions prevent 80% of the risk. Find your 20%: assess your exposure →

01. Network

Network architectures built not to fall over

LAN, MAN, WAN, SD-Access and high-density Wi-Fi, in environments where downtime is measured in lost production.

Key points

  • Most corporate networks were never designed: they accumulated.
  • Mapping real traffic precedes any design: the official diagram rarely describes what exists.
  • A multi-site migration runs in reversible waves, never as a single cutover.
  • Monitoring is deployed before the migration, not after: it is what lets you detect a regression.

Why taking over an existing network is harder than building one

Because a live network carries twenty years of decisions nobody remembers. Each addition answered a real need, none was documented, and the whole thing works: until you have to touch it. Taking it over means first understanding it, and that is never a short phase.

A switch added for an office move, a VLAN created for a pilot that became permanent, a carrier link renewed by default at every term: the resulting structure is nobody's intention.

It has two consequences. Nobody in the organization knows which flows cross the core any more, which makes every change risky. And an attacker who gains a foothold moves through it unimpeded, because no compartmentalization was ever designed.

That is why our engagements start with measurement rather than with an architecture proposal. A target architecture drawn without knowing the existing estate is a stylistic exercise.

How do you migrate a multi-site network without downtime?

In reversible waves, site by site, against a single target architecture defined in advance. Each cutover has a scheduled window outside service hours, a written success criterion, and a rollback that has been exercised. Centralized monitoring is deployed before the first wave, not after.

  • Target architecture first. One model applied everywhere, rather than a per-site adaptation. Exceptions are paid for over ten years in operating cost.
  • Monitoring before cutover. Without a prior baseline, it is impossible to say whether a site is better or worse after migration, and therefore impossible to decide what comes next.
  • A pilot on a representative site. Neither the simplest nor the most critical. The first reveals nothing, the second forgives nothing.
  • A rollback that has been tried. A fallback plan never executed is a hypothesis. We exercise it on the pilot site, during the window, before continuing.

What makes industrial Wi-Fi different?

The physical environment and the tolerance for interruption. In a warehouse or a plant, metal structures, moving racking and vehicles create dead zones that appear on no floor plan. And a micro-interruption that would go unnoticed in an office stops a production line here.

Design therefore happens on site, not on paper. A coverage study produced from software gives a plausible and wrong result: it ignores what pallets, movable partitions and forklifts do to radio waves.

The second difference is roaming. A terminal mounted on a forklift changes access point constantly; the quality of those transitions matters more than signal strength, and it determines whether the line stops.

Finally, the device estate imposes its own constraints. Older industrial equipment does not support recent protocols, and the design has to accommodate them rather than ignore them.

Should you move to SD-Access?

Not automatically. SD-Access brings segmentation driven by policy rather than by device configuration, which changes operations fundamentally, for the better when the estate is homogeneous and the teams trained, for the worse otherwise.

The real gain is operational: applying an access policy without reconfiguring each device, and having it follow the user rather than the network port. Across a multi-site estate, that removes an entire class of configuration error.

The real cost is the learning curve. Day-to-day operations change in nature, and a team that was not supported through the change falls back on old practice: having paid for the technology.

We therefore check three things before recommending that direction: the homogeneity of the estate, the maturity of identity management, and the teams' genuine availability for the transition.

Frequently asked questions

Often, yes. Architecture and link provider are two separate decisions, even though they are frequently presented together. It is possible to revisit design, redundancy and routing policy while keeping existing links, then handle the contractual question separately, which avoids making a technical project depend on a commercial negotiation.

It is measured on site, under real operating conditions, which means spending representative periods of activity there: an empty plant tells you nothing about a plant in production. We do not set a duration in advance: it depends on the floor area, the number of levels and the variability of the environment.

Yes, with one methodological caveat: an inventory of connected assets comes before everything else, because these environments almost always contain equipment the IT department does not know about. Intervention windows are constrained by production, and the reversibility of each step matters more than elsewhere.

You return to the previous state within the planned window, and analyse in calm conditions. That is precisely the purpose of running in waves: a failure at one site stays a failure at one site. The rollback plan is not a document of principle: it is exercised on the pilot site before the following waves begin.

As you choose: full handover to internal teams with documentation and training, monitoring provided by us, or a mixed model with on-call cover on critical components only. This is the point to settle early, because it shapes the design: an architecture meant to be operated in-house is not drawn quite the same way as one that is not.

Sources

Is your infrastructure ready for the next threat?

An initial assessment, free and without commitment, to evaluate your security posture.

Home Expertise RISS 360 PME Assess