Zum Hauptinhalt springen

Network Segmentation

in the Data Center

A Case Study from the Financial Industry

Axel.Hinz-IT-Netzwerk

Project Details

Client

An International Major Bank

Categorie

Financial Industry

Project Date

2022

Initial Situation

Challenge

In an era where security and compliance have top priority, a leading company in the financial industry faced the challenge of optimizing its network segmentation within the data center.

The output of a preceding external audit did not deliver clear guidelines, neither from the auditors, nor from project management side. My project team, consisting of experienced external specialists, thus faced a demanding task. The challenge was to meet the security requirements of the audit on the one hand but to integrate existing and new internal processes and policies as well.

Background

Best Practice

Drawing on my extensive underlying experience, I leveraged best practices to create high-quality solutions. In my role as technical project manager, I held fundamental decision-making authority that allow me to coordinate team members and involve stakeholders – a key factor for high motivation and ultimate success.

Objective

The main objective was to isolate network segments by firewall deployments. Within an ambitious timeframe of nine months, we needed to cover technical aspects, but also the documentation of evidences, including segmentation design, migration path and future processes.

Task

Implementation During Live Operations

While the target design was outlined quickly, the path for the technical implementation still had to be developed. Non-technical requirements were complex as well, including the integration of new parent company specifications, the migration of services within daily business operations, coordination of additional, interfering audit tasks — among other things.

A key employee was close to retirement. Firewalls had to be procured (not knowing the future data throughput). The documentation for the services to be segmented was incomplete and outdated. Finally, almost all of the client’s services were affected. The implementation took place during live operations (brownfield); a redesign (greenfield) was not an option. The complete IT environment remained operational even in non-prod areas. Legacy IT systems not able to be segmented have been discussed intensively to find a solution. At the same time, there were overlaps with other IT migration tasks. Contradictory regulatory requirements demanded a solution. We worked on technical, organisational and personnel challenges while IT systems remained operational all the time.

Solution & Implementation

Migration Path

The project team developed scenarios, then a clear migration path by diligent planning. Initially, only non-productive systems were migrated into the new security zones, while production operations remained undisturbed. Later, also productive systems were secured based on a major network migration cutover. A detailed data analysis was needed to identify migration groups, eminently including communication relationships between services.

Establishing the new security zones was done by implementing the firewalls, as well as by the the migration of services — this way, the project team was able to ensure that all services were operational following the new segmentation guidelines. The migration of services was successfully completed once several hundred migrations were done.

Results

Succeeded

The project was a complete success: We realised the network segmentation in the given timeline without any service outage. All regulative requirements have been fulfilled including the needed documentation.

  • On schedule
  • No service outages
  • All requirements fulfilled

Conclusion and Recommendation

IT is created by people!

A positive atmosphere, transparent communication and involving all stakeholders led to a high degree of appreciation which causes not only a positive project outcome, but also long-lasting success and improvements.
Nächstes Projekt

Fallbeispiel Cloudanbindung

Die Umstellung von einem lokalen auf einen Cloud-basierten Proxy veranlasste einen Kunden aus der Finanzbranche, für die geplante Cloud-Anbindung seines Rechenzentrums ein neues Konzept zu erstellen …