Network Security Architecture & Segmentation
Defensive network engineering — segmentation strategy, firewall rule-base reviews, SASE / ZTNA design, OT-IT boundary architecture and microsegmentation roadmaps that survive procurement and the change-advisory-board. Distinct from our network-pentesting service: this is design and review, not exploitation.
- Quote SLA48 hours
- Typical engagement5–15 working days
- RetestFree within 30 days
- Reporting formatCERT-In + ISO + SOC 2 ready
- Team100% in-house · OSCP / OSWE / OSEP
What is network security architecture?
Network security architecture designs how your networks are segmented, monitored, and defended — spanning firewalls, SASE/ZTNA, and OT zoning — so a breach in one area can't spread. Macksofy designs and reviews architectures to IEC 62443 and Zero Trust principles for enterprises and industrial operators across India.
A Network Security engagement, in plain language.
Indian enterprise networks accrete. Two acquisitions later, the firewall rule base has 12,000 rules, half of them ANY-ANY-ANY, with comments like 'temporary - 2018'. A typical Macksofy engagement starts with a rule-base cleanup that drops 35–50% of dead rules without breaking a single application, then layers segmentation by trust zone — corporate, OT, DMZ, PCI, tier-0 — with documented exceptions. We close with a microsegmentation roadmap (NSX / Illumio / Cisco ACI / native cloud) that gives the SOC a fighting chance during the next ransomware blast.
- Eliminate flat-network lateral movement during incidents
- Pass RBI / SEBI / ISO / PCI segmentation evidence asks
- Cut firewall change-failure rate; recover engineering velocity
- Reduce attack surface visible to compromised endpoints
- Future-proof against board-level ransomware scenario asks
Phased delivery — every step documented.
Interactive walkthrough of how we run a Network Security engagement — tap a phase to expand its activities.
- Phase 01
1 · Topology + asset discovery
- Passive discovery (NetFlow, sFlow, span ports) — no agents required
- Active discovery where allowed (Nmap, Forescout, native cloud)
- Trust-zone classification — tier-0 / OT / PCI / DMZ / corporate
- Crown-jewel mapping with business + data-flow owners
01Station 0101Phase 011 · Topology + asset discovery
- Passive discovery (NetFlow, sFlow, span ports) — no agents required
- Active discovery where allowed (Nmap, Forescout, native cloud)
- Trust-zone classification — tier-0 / OT / PCI / DMZ / corporate
- Crown-jewel mapping with business + data-flow owners
- Phase 02
2 · Firewall + rule-base review
- Multi-vendor rule analysis (Palo Alto, Check Point, Fortinet, Cisco, Juniper)
- Dead rule + shadowed rule + overly-permissive rule identification
- Object cleanup + zone-based rebase plan
- Risk-ranked rule-by-rule remediation with rollback windows
02Station 0202Phase 022 · Firewall + rule-base review
- Multi-vendor rule analysis (Palo Alto, Check Point, Fortinet, Cisco, Juniper)
- Dead rule + shadowed rule + overly-permissive rule identification
- Object cleanup + zone-based rebase plan
- Risk-ranked rule-by-rule remediation with rollback windows
- Phase 03
3 · Segmentation strategy
- Target-state segmentation map per trust zone
- OT / ICS demarcation per IEC 62443-3-2 zones & conduits
- PCI cardholder-data-environment boundary memo
- Vendor-network and BYOD isolation design
03Station 0303Phase 033 · Segmentation strategy
- Target-state segmentation map per trust zone
- OT / ICS demarcation per IEC 62443-3-2 zones & conduits
- PCI cardholder-data-environment boundary memo
- Vendor-network and BYOD isolation design
- Phase 04
4 · SASE / ZTNA / microsegmentation
- SASE vendor short-list (Zscaler, Netskope, Cisco, Palo Alto Prisma)
- ZTNA design for remote + branch + third-party
- Microsegmentation tool short-list (Illumio, Akamai Guardicore, NSX, native cloud)
- Phased rollout plan that survives a 12-month CAB calendar
04Station 0404Phase 044 · SASE / ZTNA / microsegmentation
- SASE vendor short-list (Zscaler, Netskope, Cisco, Palo Alto Prisma)
- ZTNA design for remote + branch + third-party
- Microsegmentation tool short-list (Illumio, Akamai Guardicore, NSX, native cloud)
- Phased rollout plan that survives a 12-month CAB calendar
- Phase 05
5 · Evidence + handover
- Regulator-mapped segmentation evidence pack (RBI / SEBI / ISO / PCI)
- Network architecture diagram suite — current vs target
- Change-management playbook + rollback-tested templates
- Optional 90-day quarterly drift audit (retainer)
05Station 0505Phase 055 · Evidence + handover
- Regulator-mapped segmentation evidence pack (RBI / SEBI / ISO / PCI)
- Network architecture diagram suite — current vs target
- Change-management playbook + rollback-tested templates
- Optional 90-day quarterly drift audit (retainer)
Industry-standard + custom.
We use the same tooling top BFSI red teams operate — combined with Macksofy in-house extensions and proprietary scripts where commercial tools fall short.
Sectors we operate in
What you get
- Network topology + trust-zone map (current state)
- Firewall rule-base cleanup plan with risk-ranked actions
- Target-state segmentation architecture + diagrams
- SASE / ZTNA / microsegmentation vendor short-list memo
- 12-month phased rollout plan with CAB-aware change windows
- Regulator-mapped segmentation evidence pack
Anonymized engagement snapshots.
Scope · 12,000-rule firewall cleanup + zone rebase
Finding: 47% rules dead or shadowed; tier-0 reachable from BYOD VLAN
Rule count to 6,400 with zero outage; RBI inspection clean
Scope · IT-OT segmentation per IEC 62443
Finding: Engineering workstation in same VLAN as plant historian
Zone & conduit redesign; USFDA pre-approval inspection ready
Scope · PCI-DSS 1.x CDE scoping + microsegmentation pilot
Finding: CDE not properly isolated; sandbox env reachable from CDE
CDE blast radius reduced 80%; QSA pass on first attempt
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Build
- Tooling (Wazuh / ELK / Splunk) implementation
- Baseline detection rules
- Runbook authoring
Operate
- Everything in Build
- 24×7 monitoring across business hours
- Monthly threat-hunt + posture reviews
Resilience
- Everything in Operate
- L3 threat hunters + IR retainer
- Annual table-top + DR drill
Note · Indicative pricing in INR. Setup + 12-month operate is the most-asked combination. Custom blends available.
Rated 4.9 ★ from 612 client reviews.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Things people ask before signing.
Often paired with this engagement.
Where Macksofy delivers Network Security.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- 20,000+ professionals trained
- India + UAE engagements
