Skip to main content
INSIGNIA.
Engage
SPEC0001
PG. SUB · network-and-connectivity
DOC · INS-NET-001REV · 2026.Q2CLASS · PARTNERPRACTICE · Capability§ · 4.6
/ CAPABILITY · NETWORK AND CONNECTIVITY

Network and Connectivity

Enterprise network, telecom, and connectivity transformation. Architecture, SD-WAN, SASE, M&A separation, NOC operations. Engineered as an audit-grade capability, not a packaged service.

Manifesto

Network programs fail at the seams. The architecture review is fine. The SD-WAN POC is fine. The carrier statement of work is fine. What sinks the program is the joint between them: the contract clause that does not survive the routing change, the policy plane that does not survive the vendor merger, the NOC runbook that did not anticipate the 3 AM page from a branch that runs PCI. We run network practice where the seams meet.

Consulting-led, not vendor-led. We evaluate Cisco, VMware, Versa, Fortinet, Palo Alto, Cato, and Aruba against Gartner SASE convergence and MEF 70.1 service attributes, not against the deck the vendor sent last quarter. Telecom audit decodes the carrier’s tariff binder line by line. Zero Trust runs per NIST SP 800-207 with the policy decision point separated from enforcement. Operations runs per ITIL v4 with NOC tiering rehearsed quarterly.

The practice lead has spent two decades inside Fortune 500 managed-services accounts and 18 months embedded onsite at a 160-site infrastructure divestiture. Many Fortune 500 companies have engaged this seat for transitions, separations, and SLA governance, including Meta and GE. The roster section names the lead and the receipts.

Receipts · practice posture

$350M+
Portfolio under governance
99.9%
SLA across Fortune 500
−40%
Delivery cost, sustained
160
Sites separated in 18 mo.
The sub-practices
/ 01

Enterprise network transformation

Architecture, campus and branch modernization, data center networking, segmentation, multi-site resiliency, and standardization programs.

  • Campus + branch
  • DC fabric
  • HA / resiliency
  • Standardization
/ 02

WAN / SD-WAN / SASE transformation

WAN assessment, MPLS rationalization, SD-WAN strategy and governance, SASE convergence (ZTNA + SSE + DEM), internet-first connectivity, hybrid cloud networking.

  • MPLS audit
  • SD-WAN
  • SASE
  • ZTNA
/ 03

Telecom advisory and optimization

Spend analysis, carrier assessment, contract negotiation, circuit inventory, service rationalization, vendor performance management, cost reduction.

  • TEM
  • Tariff decode
  • Vendor mgmt
  • Rationalization
/ 04

Cloud and data center connectivity

AWS Direct Connect, Azure ExpressRoute, GCP Cloud Interconnect strategy. Multi-cloud network design, on-ramp assessment, hybrid architectures, DC exit planning.

  • AWS DX
  • Azure ER
  • GCP CI
  • DC exit
/ 05

Secure network architecture

Zero Trust strategy per NIST SP 800-207, network security architecture, secure remote access, identity-aware connectivity, segmentation and micro-segmentation, secure partner connectivity.

  • ZTNA
  • Micro-seg
  • Secure remote
  • Partner DMZ
/ 06

M&A and divestiture infrastructure

Infrastructure due diligence, Day-1 readiness, network separation programs, TSA exit planning, integration roadmaps, synergy identification, risk assessment.

  • DD
  • Day-1
  • TSA exit
  • Network separation
/ 07

Network operations excellence

NOC transformation, service delivery governance, ITSM integration, incident and problem management, monitoring and observability strategy, automation, KPI and SLA framework.

  • NOC
  • ITIL v4
  • ITSM
  • Observability
Depth · WAN, SD-WAN, SASE
REF§ 4.N.A

Vendor-neutral evaluation against the convergence taxonomy.

SD-WAN / SASE vendor matrix · 2026.Q2

The shortlist we actually evaluate against

Selection criteria mapped to Gartner SASE convergence, MEF 70.1/88 SD-WAN service attributes, and FedRAMP authorization tier where federal procurement is in scope. ZTNA convergence flagged as native, partner-integrated, or absent.

VendorZTNASSEApp-awareFedRAMPMEFControl plane
Cisco Catalyst SD-WAN
Viptela / Meraki
via partnermoderateMEF 70.1hybrid
VMware VeloCloud
Broadcom Symantec SSE
via partnervia partnermoderateMEF 70.1cloud
Versa Networks
Versa SASE
in-processMEF bothhybrid
Fortinet Secure SD-WAN
FortiSASE
moderateMEF 70.1hybrid
Palo Alto Prisma SD-WAN
Prisma SASE
highcloud
Cato Networks
Cato SASE Cloud
MEF 70.1cloud
HPE Aruba EdgeConnect
Silver Peak
via partnervia partnermoderateMEF 70.1hybrid
Frame · Gartner SASE convergence + MEF 70.1 / 88
Companion treatment

See Security · network and perimeter report for the interface-inventory treatment, NIST SP 800-41 firewall posture, and the OCSF event-class mapping the same SD-WAN telemetry feeds into.

Depth · Telecom advisory
REF§ 4.N.B

Read the invoice line by line, against the tariff binder.

Carrier invoice anatomy · representative sample

What an audited carrier statement looks like

USOC line items decoded against the carrier’s tariff binder. Regulatory recovery fees cross-checked against the current FCC and state PUC rules. Findings flag stranded service, superseded tariffs, and ported numbers still billing.

CodeLine itemCategoryMonthly
USOC: 1L5XX
DS3 dedicated access · 45 Mbps · 36-month term
Circuit$ 2,840.00
USOC: HXEA1
Cross-connect, intra-LATA, 1 GbE handoff
Circuit$ 340.00
USOC: VCYR9
MPLS VPN port, COS-marked, 100 Mbps CAR
Circuit$ 1,975.00
FCC §54.706
Federal Universal Service Fund contribution
Regulatory$ 178.41
TX PUC §26.420
Texas Universal Service Fund surcharge
Regulatory$ 62.10
47 CFR §64.5001
Federal regulatory recovery fee
Tariff superseded 2024-Q3; recoverable.
Regulatory$ 94.80
TX TAX §151.0103
State telecommunications tax
Tax$ 216.55
MUNI ROW
Municipal right-of-way fee · Allen, TX
Tax$ 38.20
Feature: E911
Enhanced 911 charge per DID, 47 lines billed
Only 31 DIDs in active rotation; 16 stranded.
Feature$ 56.40
Feature: STDIR
Standard directory listing · legacy
Service ported off 2023; line item never cancelled.
Feature$ 11.20
Statement total$ 5,811.66
Recoverable on first pass$ 162.40
Frame · USOC decode + FCC §54 + TX PUC §26
Depth · Cloud and DC connectivity
REF§ 4.N.C

Direct Connect, ExpressRoute, Cloud Interconnect. Fabric on-ramps where they earn the bypass.

Depth · Secure network architecture
REF§ 4.N.D

NIST SP 800-207 on the control plane. Microsegmentation east-west.

Standards in scope
  • NIST SP 800-207 · Zero Trust Architecture
  • NIST SP 800-125B · East-west microsegmentation
  • ISO/IEC 27033 · Network security, 7-part series
  • PCI DSS 4.0 §1, §11.4, §11.5
  • HIPAA §164.312(a), §164.312(e)
Segmentation policy matrix · representative pattern

East-west policy that survives an audit

Row = source zone, column = destination zone. PCI DSS 4.0 §1.4 boundary, NIST SP 800-207 trust algorithm enforcement, NIST SP 800-125B east-west microsegmentation. Every inspected flow lands a log line in OCSF event class 4001 (Network Activity).

Source ▸PCI CDEProductionOT / IoTPartner DMZMgmt VLANDevelopmentGuest WiFi
PCI CDE·
Production·
OT / IoT·
Partner DMZ·
Mgmt VLAN·
Development·
Guest WiFi·
AllowInspect (NGFW + IDS)Deny
Companion treatment

See Security · Layer Zero for the full Identity + Policy + Consent gate (NIST SP 800-63B identity, NIST SP 800-162 ABAC, ISO/IEC 29184 consent) that runs in front of the trust algorithm shown here.

Depth · M&A and divestiture infrastructure
REF§ 4.N.E

The TSA window is the contract. The program is run against the window.

Case · GE Plastics divestiture

Public 2007 transaction. 160-site infrastructure separation across the GE Plastics → SABIC Innovative Plastics + Momentive Performance Materials split. 18-month TSA window, $5.1M program budget, $425K under budget at TSA exit, zero major incidents through cutover. The practice lead was embedded onsite at Pittsfield for 2.5 years as project manager.

Depth · Network operations excellence
REF§ 4.N.F

ITIL v4 service operations. MTTA and MTTR you can put in the SOW.

NOC severity framework · MTTA / MTTR

What 99.9% adherence actually looks like on the floor

MTTA = mean time to acknowledge. MTTR = mean time to resolve. Tier responder mapped per severity. Escalation path documented in the runbook and rehearsed quarterly. ITIL v4 incident management practice with ISO/IEC 20000-1 governance overlay.

SeverityExample triggerMTTAMTTRResponderEscalation
S1
Critical
Site offline, WAN failover failed, payment processing down15 min4 hrL2 + L3 + Practice LeadPager → CIO + Account Director within 30 min
S2
Major
Branch link degraded, redundancy lost, app latency > 3x baseline30 min8 hrL1 → L2 → L3Pager → CIO within 2 hr if unresolved
S3
Minor
Single circuit congestion, non-redundant flap, monitoring alert2 hr1 BDL1 → L2Email → Service Delivery Manager next business day
S4
Service request
MACD (move/add/change/delete), feature request, FAQ1 BD3 BDL1Standard ticket queue
Frame · ITIL v4 incident · ISO/IEC 20000-1
ITSM integration matrix · 5 tools

How the network ops stack talks to your service desk

For each ITSM tool we integrate against, the transport surface and the ITIL v4 practice it serves. CMDB items synced bi-directionally; incident, problem, and change pushed via webhooks; knowledge articles via REST where the vendor supports it, batch CSV where they do not.

ToolCMDB syncIncidentProblemChangeKnowledge
ServiceNow ITSM
ServiceNow
RESTRESTRESTRESTREST
BMC Helix Remedy
BMC
RESTRESTRESTRESTCSV / Batch
Jira Service Management
Atlassian
RESTRESTRESTRESTREST
Cherwell · now Ivanti Neurons
Ivanti
RESTRESTRESTRESTCSV / Batch
Freshservice
Freshworks
RESTRESTRESTRESTREST
Frame · ITIL v4 service-management practices
Companion treatment

See Platform Implementations · ServiceNow for the underlying Flow Designer, scoped-app, IntegrationHub, and ATF patterns the NOC integrates against.

Standards · ten frameworks, mapped to deliverables
REF§ 4.N.G

Every artefact references a published standard.

Network standards crosswalk · 10 frameworks

Which standard governs which deliverable

Every architecture decision cross-references a published standard. The crosswalk below maps the standards the practice routinely cites to the artefacts they govern, so auditors and procurement read off the same sheet.

StandardScope usedApplied to
NIST CSF 2.0
Cybersecurity Framework
Govern · Identify · Protect · Detect · Respond · Recover
  • Architecture review
  • Risk register
  • NOC runbook
NIST SP 800-53 r5
Security and privacy controls
AC, AU, CM, CP, IA, SC, SI control families
  • Network segmentation
  • Logging baseline
  • Change control
NIST SP 800-207
Zero Trust Architecture
Trust algorithm, PEP, PDP, policy administrator
  • ZTNA rollout
  • Identity-aware connectivity
NIST SP 800-125B
Server virtualization security
East-west micro-segmentation patterns
  • Segmentation policy matrix
ISO/IEC 27033
Network security · 7-part series
Design, threat modelling, gateways, IP, wireless, virtual, VPN
  • Architecture baseline
  • Secure remote access
PCI DSS 4.0
Payment Card Industry Data Security Standard
§1 (network), §11.4 (IDS/IPS), §11.5 (file integrity)
  • CDE segmentation
  • Audit-ready logging
HIPAA §164.312
Security Rule technical safeguards
§312(a) access control, §312(e) transmission security
  • TLS 1.3 baseline
  • Healthcare segmentation
MEF 70.1
SD-WAN service attributes
Service definition, performance, security
  • SD-WAN evaluation matrix
  • Carrier SOW
ITIL v4
Service management framework
Incident, problem, change, service request, knowledge
  • NOC tiering
  • ITSM integration
ISO/IEC 20000-1
Service management system
Plan, do, check, act over the service lifecycle
  • Service governance
  • KPI / SLA framework
Sources · NIST CSWP · ISO/IEC catalog · PCI SSC · ONC · MEF · AXELOS

Engagement modes

  • 01
    Assessment

    Fixed-scope, time-boxed. Architecture review, telecom audit, SD-WAN readiness, M&A infrastructure due diligence. Findings memo plus prioritized roadmap.

  • 02
    Transformation program

    Multi-quarter execution. SD-WAN / SASE rollout, network separation, NOC stand-up. Steering cadence, milestone gates, named owners on every workstream.

  • 03
    Advisory retainer

    Senior practitioner on call. Architecture decisions, vendor negotiations, escalation cover, board-grade memos. Right when the in-house team owns delivery but needs the senior eye.

  • 04
    Managed service

    SLA-bound, ITIL v4 service operations. NOC, ITSM integration, monitoring, capacity, change. Multi-year, retainer-based, with quarterly governance review.

Certifications · on bench

  • PMP
  • ITIL v4
  • CCNP
  • CCNA
  • AWS Solutions Architect
  • Azure Data Fundamentals
  • PSM
  • Six Sigma GB
  • MCSE
  • CCSA (Check Point)
  • CCIE Lab (in progress)
Practice lead

Sanjeev Vishwakarma

Chief Network & Connectivity Officer

Eighteen years inside Fortune 500 managed-services engagements. AVP of IT Service Delivery, Resiliency and Compliance at Genpact, $350M portfolio across many Fortune 500 accounts including Meta, GE, and others, 99.9% SLA sustained, NPS lifted from 1 to 9. Twenty client transitions and six M&A integrations with zero major incidents. Embedded onsite as project manager for the 160-site GE Plastics divestiture, $5.1M program, $425K under budget. Currently leads the studio’s network, telecom, and connectivity practice from Frisco, TX.

Engagement · declassified sample

Engagement with , global hi-tech account, 47 sites across NA + EMEA + APAC. MPLS-to-SD-WAN migration with carrier rationalization. Recovered 22% of monthly telecom spend on first audit pass, sustained 99.95% WAN availability through cutover, completed segregation of PCI CDE from production within the SOW window. Managed service retainer continued through 2026.

Engage · file a brief

Network assessment, telecom audit, SD-WAN readiness, M&A separation, NOC stand-up. Tell us the shape and the timeline. SLA-bound 24-hour reply, no four-call qualifier.

REQ Open the file →
Frequently asked · network and connectivity

Seven questions buyers ask before the assessment.

Vendor specificity, standards citations, SLA framework, and how M&A separation actually runs. Substance instead of platitudes.

Which SD-WAN and SASE vendors do you actually work with?

Seven on the active shortlist: Cisco Catalyst SD-WAN (Viptela), VMware VeloCloud, Versa Networks, Fortinet Secure SD-WAN, Palo Alto Prisma SD-WAN, Cato Networks, HPE Aruba EdgeConnect (Silver Peak). Selection runs against Gartner SASE convergence (SD-WAN + SWG + CASB + ZTNA + FWaaS + DEM), MEF 70.1 / 88 service attributes, and FedRAMP authorization tier where federal procurement is in scope.

What does a telecom audit recover on the first pass?

Typical first-pass recovery lands between 18 and 30 percent of monthly recurring charges. Common findings: superseded FCC §54 regulatory recovery tariffs still billing, stranded E911 lines, ported numbers carrying directory fees, USOC codes mapped to retired service classes. We decode against the carrier's current tariff binder, not against last year's audit.

How does the M&A and divestiture practice work?

Six phases: Discovery, Blueprint, Datacenter onboarding, Network separation, BAU handoff, TSA exit. Gates at month 6 (cutover milestone) and TSA exit. Public reference: the GE Plastics divestiture to SABIC Innovative Plastics and Momentive Performance Materials, 160 sites, 18 months, $5.1M program, $425K under budget, zero major incidents. Sanjeev led that program embedded onsite.

What Zero Trust framework do you implement against?

NIST SP 800-207 as the spine. Subject → Policy Enforcement Point → Resource on the data plane. Policy Engine + Policy Administrator on the control plane, with trust inputs from CDM, threat intelligence, activity log, IdP, data access policy, PKI, and SIEM. NIST SP 800-125B for east-west microsegmentation patterns inside the data center. ZTNA replaces legacy VPN per-application, identity-aware, with session token revocation.

What is the NOC SLA framework?

Four severity tiers per ITIL v4 incident management. S1 critical: 15-min MTTA, 4-hr MTTR, L2+L3+Practice Lead on the bridge, pager to CIO within 30 min. S2 major: 30-min MTTA, 8-hr MTTR. S3 minor: 2-hr MTTA, 1 business day MTTR. S4 service request: 1 business day MTTA, 3 business days MTTR. Escalation paths documented in the runbook, rehearsed quarterly.

Which ITSM tools do you integrate against?

Five on the active integration list: ServiceNow ITSM, BMC Helix Remedy, Atlassian Jira Service Management, Ivanti Neurons (formerly Cherwell), Freshservice. CMDB items synced bi-directionally via REST. Incident, problem, and change pushed via webhooks. Knowledge articles via REST where the vendor supports it, batch CSV where it does not. ITIL v4 service-management practices as the framework.

What standards govern the deliverables?

Ten frameworks cited routinely. NIST CSF 2.0, NIST SP 800-53 r5, NIST SP 800-207, NIST SP 800-125B. ISO/IEC 27033 (network security, 7-part series), ISO/IEC 20000-1 (service management). PCI DSS 4.0, HIPAA §164.312. MEF 70.1 (SD-WAN service attributes). ITIL v4. Every architecture decision references at least one of these on the artefact itself.
Companion files

Where this practice meets the capability stack.

REGISTER · CAPABILITYIN.END · FILE CLOSED
File a brief