SystimaNX
Back to case studies
Financial ServicesNetworking & CloudSecurity & Compliance

Hybrid Network Overhaul

Modernizing enterprise connectivity with Zero Trust patterns, replacing a brittle, perimeter-only hub-and-spoke design with an identity-aware architecture built for hybrid work and cloud-first traffic.

Better performance and enforced least privilege
Client
Confidential — financial services
Industry
Financial Services
Timeline
6 months
Technologies
6+ tools

The Challenge

!The client's core network still ran on a decade-old hub-and-spoke design that routed all branch and remote traffic back through two centralized data centers, even when the destination was a SaaS application sitting a few network hops away. This backhauling added latency to everyday tools like CRM and trading-support platforms and made every regional outage a global one.
!Security was enforced almost entirely at the network perimeter, with a small set of large firewall rules granting broad subnet-to-subnet access once a device was inside the corporate network. This model assumed a trusted internal network that no longer existed once remote work, contractor access, and cloud workloads became the norm.
!Branch offices reported inconsistent, unpredictable performance when reaching SaaS platforms and cloud APIs, with latency spikes during peak trading and reporting windows that IT could not reliably reproduce or diagnose. Support tickets frequently closed as 'intermittent, cause unknown' because the existing tooling could not correlate path, application, and time.
!There was little to no visibility into identity-based access decisions or east-west traffic between servers and services inside the data center. Security analysts could see that a connection existed but not which user or service account initiated it, which made investigating anomalous internal traffic slow and largely manual.
!Firewall policies had accumulated for years across multiple teams and acquisitions, resulting in thousands of overlapping and occasionally contradictory rules. Nobody had full confidence that removing an old rule would not break something, so the rule base kept growing instead of being cleaned up.
!Compliance and audit cycles consumed weeks of manual evidence-gathering, since access logs, firewall configurations, and change records lived in disconnected systems with no common reporting layer. Auditors regularly asked for artifacts that took days to assemble by hand from configuration exports and email threads.
!Segmentation between sensitive workloads — including systems in scope for financial regulations — and general corporate traffic was minimal, relying mostly on VLAN separation rather than enforced policy. A compromised workstation could, in principle, reach far more of the environment than any real business process required.
!The IT and security teams were also under pressure to support new hybrid and remote-first operating models without expanding headcount, meaning any redesign had to be operable by the existing team rather than requiring a large, specialized platform staff.

Our Solution

SystimaNX began with a full traffic and dependency assessment across branch sites, data centers, and cloud environments to map which applications actually needed direct, low-latency paths versus which could tolerate centralized inspection. This baseline became the foundation for every routing and policy decision that followed.
We redesigned wide-area connectivity around Cisco SD-WAN, introducing policy-based routing so that SaaS and cloud-bound traffic could break out locally at the branch instead of backhauling through central data centers. Application-aware path selection let latency-sensitive traffic take the most direct available route while less critical traffic used cost-optimized links.
We implemented a Zero Trust access model built on Azure AD, replacing broad network-level trust with continuous, identity-based verification for every session. Access decisions now factor in user identity, device posture, and context rather than simply whether a connection originated inside the corporate network.
Next-generation firewalls from Palo Alto Networks were deployed in high-availability pairs at all critical sites, consolidating and rationalizing years of accumulated rule sprawl into a smaller, clearly documented policy set. Redundant pairing at each site removed the single points of failure that had previously turned local outages into extended incidents.
We established explicit micro-segmentation for regulated and sensitive workloads, isolating them from general corporate traffic with enforced policy rather than VLAN convention alone. This gave the security team a defensible, demonstrable boundary around the systems that mattered most for compliance.
Infrastructure changes were codified using Terraform, so firewall rules, routing policies, and segmentation boundaries could be version-controlled, peer-reviewed, and deployed consistently across sites instead of configured by hand one device at a time. This also gave the team a reliable rollback path whenever a change needed to be reverted.
Ansible playbooks automated recurring configuration and compliance tasks across the firewall and SD-WAN fleet, reducing the manual effort needed to keep dozens of sites in a consistent state. Routine patching and policy pushes that once took days of coordinated change windows became repeatable, scheduled jobs.
Splunk was deployed as the central logging and analytics layer, correlating identity, network, and firewall events into unified dashboards for both the security and network operations teams. This gave both teams a shared source of truth for investigating incidents and generating audit evidence on demand.

Measurable Impact

User experience
30-40% latency reduction

Local SaaS breakout via SD-WAN cut round-trip latency to cloud and SaaS platforms by an estimated 30-40% for branch users during peak trading and reporting windows.

Security posture
Zero Trust aligned

Identity-centric access decisions through Azure AD replaced broad implicit trust granted to anything inside the perimeter.

Operations
70% fewer manual firewall changes

Terraform and Ansible standardized policy and configuration across sites, cutting manual, error-prone firewall changes by roughly 70%.

Compliance
From weeks to under 3 days

Splunk dashboards and evidence packs mapped controls to common frameworks, cutting audit preparation from several weeks to under 3 days per cycle.

Rule base
60% fewer firewall rules

Years of overlapping firewall rules were consolidated by roughly 60% into a smaller, clearly owned policy set on the new HA firewall pairs.

Incident scope
Blast radius cut to a single segment

Segmentation of regulated workloads confined the practical impact of any single compromised endpoint or account to one micro-segment instead of the broader network.

Visibility
100% of east-west traffic correlated

East-west traffic and identity-based access decisions became fully traceable in Splunk for the first time across data center and cloud paths.

We needed performance and security without another science project. The architecture was pragmatic and something we could operate, and it finally gave us clear answers when auditors or leadership asked who could reach what and why. That combination of speed, control, and evidence is what we couldn't get from our previous setup.

S
Security leader
CISO, financial services (NDA)

Technology stack

Palo Alto NetworksCisco SD-WANAzure ADTerraformSplunkAnsible
Book a consultation
Hybrid Network Overhaul | Case Study | SystimaNX