
Company Overview
An FDA-approved pharmaceutical manufacturer specializing in sterile injectable production, operating across corporate offices, R&D labs, cleanrooms, and warehouse facilities.
Challenge
The project involved building a complete greenfield network for a new facility - in a mixed IT and operational technology (OT) environment.
Key challenges quickly became clear:
- High risk of lateral movement between IT, lab, and manufacturing systems
- Strict segmentation requirements driven by regulatory compliance
- Need to securely support IoT devices and industrial equipment with overlapping networks
- Secure remote access for users and vendors without exposing critical systems
- Designing for future expansion without re-architecting the network
This wasn’t just a connectivity problem - it was a security architecture challenge.
Solution
We designed and implemented a Zero Trust–aligned network architecture, focusing on segmentation, visibility, and strict access control.
The approach was simple in principle: assume nothing is trusted - and enforce it at every layer.
Key elements included:
- Cisco Catalyst switching infrastructure to provide high-performance connectivity and structured segmentation (VLANs)
- Cisco Secure Firewall (FTD) deployed for deep traffic inspection, IPS, and policy enforcement between zones
- Clear separation of network zones:
- Implementation of a deny-by-default model, allowing only explicitly defined traffic between segments
- Secure remote access solution for internal users and third-party vendors
- Centralized logging and monitoring to improve visibility and auditability
Every communication path was intentional. Nothing was left open “just in case.”
Results
The result was a secure, scalable foundation built for a regulated environment:
- Strong segmentation significantly reduced the risk of lateral movement across critical systems
- Full visibility into traffic flows across IT, OT, and IoT environments
- Secure remote access without exposing sensitive network segments
- Scalable architecture ready to support new production lines and future facilities
- A security-first design aligned with modern Zero Trust principles
