Enterprise network transformation
Architecture, campus and branch modernization, data center networking, segmentation, multi-site resiliency, and standardization programs.
- Campus + branch
- DC fabric
- HA / resiliency
- Standardization
Enterprise network, telecom, and connectivity transformation. Architecture, SD-WAN, SASE, M&A separation, NOC operations. Engineered as an audit-grade capability, not a packaged service.
Network programs fail at the seams. The architecture review is fine. The SD-WAN POC is fine. The carrier statement of work is fine. What sinks the program is the joint between them: the contract clause that does not survive the routing change, the policy plane that does not survive the vendor merger, the NOC runbook that did not anticipate the 3 AM page from a branch that runs PCI. We run network practice where the seams meet.
Consulting-led, not vendor-led. We evaluate Cisco, VMware, Versa, Fortinet, Palo Alto, Cato, and Aruba against Gartner SASE convergence and MEF 70.1 service attributes, not against the deck the vendor sent last quarter. Telecom audit decodes the carrier’s tariff binder line by line. Zero Trust runs per NIST SP 800-207 with the policy decision point separated from enforcement. Operations runs per ITIL v4 with NOC tiering rehearsed quarterly.
The practice lead has spent two decades inside Fortune 500 managed-services accounts and 18 months embedded onsite at a 160-site infrastructure divestiture. Many Fortune 500 companies have engaged this seat for transitions, separations, and SLA governance, including Meta and GE. The roster section names the lead and the receipts.
Architecture, campus and branch modernization, data center networking, segmentation, multi-site resiliency, and standardization programs.
WAN assessment, MPLS rationalization, SD-WAN strategy and governance, SASE convergence (ZTNA + SSE + DEM), internet-first connectivity, hybrid cloud networking.
Spend analysis, carrier assessment, contract negotiation, circuit inventory, service rationalization, vendor performance management, cost reduction.
AWS Direct Connect, Azure ExpressRoute, GCP Cloud Interconnect strategy. Multi-cloud network design, on-ramp assessment, hybrid architectures, DC exit planning.
Zero Trust strategy per NIST SP 800-207, network security architecture, secure remote access, identity-aware connectivity, segmentation and micro-segmentation, secure partner connectivity.
Infrastructure due diligence, Day-1 readiness, network separation programs, TSA exit planning, integration roadmaps, synergy identification, risk assessment.
NOC transformation, service delivery governance, ITSM integration, incident and problem management, monitoring and observability strategy, automation, KPI and SLA framework.
Selection criteria mapped to Gartner SASE convergence, MEF 70.1/88 SD-WAN service attributes, and FedRAMP authorization tier where federal procurement is in scope. ZTNA convergence flagged as native, partner-integrated, or absent.
| Vendor | ZTNA | SSE | App-aware | FedRAMP | MEF | Control plane |
|---|---|---|---|---|---|---|
Cisco Catalyst SD-WAN Viptela / Meraki | via partner | moderate | MEF 70.1 | hybrid | ||
VMware VeloCloud Broadcom Symantec SSE | via partner | via partner | moderate | MEF 70.1 | cloud | |
Versa Networks Versa SASE | in-process | MEF both | hybrid | |||
Fortinet Secure SD-WAN FortiSASE | moderate | MEF 70.1 | hybrid | |||
Palo Alto Prisma SD-WAN Prisma SASE | high | — | cloud | |||
Cato Networks Cato SASE Cloud | — | MEF 70.1 | cloud | |||
HPE Aruba EdgeConnect Silver Peak | via partner | via partner | moderate | MEF 70.1 | hybrid |
USOC line items decoded against the carrier’s tariff binder. Regulatory recovery fees cross-checked against the current FCC and state PUC rules. Findings flag stranded service, superseded tariffs, and ported numbers still billing.
| Code | Line item | Category | Monthly |
|---|---|---|---|
| USOC: 1L5XX | DS3 dedicated access · 45 Mbps · 36-month term | Circuit | $ 2,840.00 |
| USOC: HXEA1 | Cross-connect, intra-LATA, 1 GbE handoff | Circuit | $ 340.00 |
| USOC: VCYR9 | MPLS VPN port, COS-marked, 100 Mbps CAR | Circuit | $ 1,975.00 |
| FCC §54.706 | Federal Universal Service Fund contribution | $ 178.41 | |
| TX PUC §26.420 | Texas Universal Service Fund surcharge | $ 62.10 | |
| 47 CFR §64.5001 | Federal regulatory recovery fee | $ 94.80 | |
| TX TAX §151.0103 | State telecommunications tax | Tax | $ 216.55 |
| MUNI ROW | Municipal right-of-way fee · Allen, TX | Tax | $ 38.20 |
| Feature: E911 | Enhanced 911 charge per DID, 47 lines billed | Feature | $ 56.40 |
| Feature: STDIR | Standard directory listing · legacy | Feature | $ 11.20 |
| Statement total | $ 5,811.66 | ||
| Recoverable on first pass | $ 162.40 | ||
Row = source zone, column = destination zone. PCI DSS 4.0 §1.4 boundary, NIST SP 800-207 trust algorithm enforcement, NIST SP 800-125B east-west microsegmentation. Every inspected flow lands a log line in OCSF event class 4001 (Network Activity).
| Source ▸ | PCI CDE | Production | OT / IoT | Partner DMZ | Mgmt VLAN | Development | Guest WiFi |
|---|---|---|---|---|---|---|---|
| PCI CDE | · | — | — | — | — | ||
| Production | · | — | — | ||||
| OT / IoT | — | · | — | — | — | ||
| Partner DMZ | — | — | · | — | — | ||
| Mgmt VLAN | · | — | |||||
| Development | — | — | — | — | · | — | |
| Guest WiFi | — | — | — | — | — | — | · |
MTTA = mean time to acknowledge. MTTR = mean time to resolve. Tier responder mapped per severity. Escalation path documented in the runbook and rehearsed quarterly. ITIL v4 incident management practice with ISO/IEC 20000-1 governance overlay.
| Severity | Example trigger | MTTA | MTTR | Responder | Escalation |
|---|---|---|---|---|---|
Critical | Site offline, WAN failover failed, payment processing down | 15 min | 4 hr | L2 + L3 + Practice Lead | Pager → CIO + Account Director within 30 min |
Major | Branch link degraded, redundancy lost, app latency > 3x baseline | 30 min | 8 hr | L1 → L2 → L3 | Pager → CIO within 2 hr if unresolved |
Minor | Single circuit congestion, non-redundant flap, monitoring alert | 2 hr | 1 BD | L1 → L2 | Email → Service Delivery Manager next business day |
Service request | MACD (move/add/change/delete), feature request, FAQ | 1 BD | 3 BD | L1 | Standard ticket queue |
For each ITSM tool we integrate against, the transport surface and the ITIL v4 practice it serves. CMDB items synced bi-directionally; incident, problem, and change pushed via webhooks; knowledge articles via REST where the vendor supports it, batch CSV where they do not.
| Tool | CMDB sync | Incident | Problem | Change | Knowledge |
|---|---|---|---|---|---|
ServiceNow ITSM ServiceNow | REST | REST | REST | REST | REST |
BMC Helix Remedy BMC | REST | REST | REST | REST | CSV / Batch |
Jira Service Management Atlassian | REST | REST | REST | REST | REST |
Cherwell · now Ivanti Neurons Ivanti | REST | REST | REST | REST | CSV / Batch |
Freshservice Freshworks | REST | REST | REST | REST | REST |
Every architecture decision cross-references a published standard. The crosswalk below maps the standards the practice routinely cites to the artefacts they govern, so auditors and procurement read off the same sheet.
| Standard | Scope used | Applied to |
|---|---|---|
Cybersecurity Framework | Govern · Identify · Protect · Detect · Respond · Recover |
|
Security and privacy controls | AC, AU, CM, CP, IA, SC, SI control families |
|
Zero Trust Architecture | Trust algorithm, PEP, PDP, policy administrator |
|
Server virtualization security | East-west micro-segmentation patterns |
|
Network security · 7-part series | Design, threat modelling, gateways, IP, wireless, virtual, VPN |
|
Payment Card Industry Data Security Standard | §1 (network), §11.4 (IDS/IPS), §11.5 (file integrity) |
|
Security Rule technical safeguards | §312(a) access control, §312(e) transmission security |
|
SD-WAN service attributes | Service definition, performance, security |
|
Service management framework | Incident, problem, change, service request, knowledge |
|
Service management system | Plan, do, check, act over the service lifecycle |
|
Eighteen years inside Fortune 500 managed-services engagements. AVP of IT Service Delivery, Resiliency and Compliance at Genpact, $350M portfolio across many Fortune 500 accounts including Meta, GE, and others, 99.9% SLA sustained, NPS lifted from 1 to 9. Twenty client transitions and six M&A integrations with zero major incidents. Embedded onsite as project manager for the 160-site GE Plastics divestiture, $5.1M program, $425K under budget. Currently leads the studio’s network, telecom, and connectivity practice from Frisco, TX.
Engagement with , global hi-tech account, 47 sites across NA + EMEA + APAC. MPLS-to-SD-WAN migration with carrier rationalization. Recovered 22% of monthly telecom spend on first audit pass, sustained 99.95% WAN availability through cutover, completed segregation of PCI CDE from production within the SOW window. Managed service retainer continued through 2026.
Network assessment, telecom audit, SD-WAN readiness, M&A separation, NOC stand-up. Tell us the shape and the timeline. SLA-bound 24-hour reply, no four-call qualifier.
REQ Open the file →Vendor specificity, standards citations, SLA framework, and how M&A separation actually runs. Substance instead of platitudes.
The architectural spine the Zero Trust depth block above sits on. Identity, Policy, and Consent gate every interior layer; SD-WAN telemetry feeds the OCSF event ledger.
The platform-engineering surface the NOC and ITSM integration matrix lands on. Flow Designer, scoped apps, IntegrationHub, ATF for survival across platform upgrades.