The challenge
The organization had a flat network where a single compromised credential or device could reach almost everything — the classic lateral-movement risk. Prior attempts at segmentation relied on sprawling, brittle IP-based ACLs that were impossible to maintain and routinely bypassed by “temporary” fallback VLANs.
Our approach
- Identity foundation — consolidated identity with MFA and conditional access as the basis for every decision.
- Full visibility — profiled every device and flow before enforcing anything.
- Policy decision + enforcement — deployed Cisco ISE as the Policy Decision Point, with switches, wireless controllers and firewalls as enforcement points.
- Identity microsegmentation — used TrustSec Scalable Group Tags so policy follows the user and device, replacing thousands of IP ACLs with one policy matrix.
The solution
Rather than buy a “Zero Trust product,” VeeMost built a cohesive control system. Identity decides who and what is allowed; the network enforces where they can go. Users, servers, OT, guests and vendors are now separated by identity-based policy, lateral movement is constrained, and access is continuously verified against the same identity source that governs cloud and email.