All case studies
Secure Networking LANRepresentative engagement

Knowing What Is On the Network

A representative engagement, drawn from the environments ITBuilders works in across the Kingdom.

Delivered under the Fortinet Engage Partner Specialization — Secure Networking LAN.

The context

Asset inventory has become a compliance obligation rather than an operational nicety. Control frameworks applied across the Kingdom expect organisations to know what connects to their networks, to classify it, and to evidence that classification during review. Most organisations cannot. The inventory exists as a procurement record, which describes what was purchased rather than what is connected.

An education institution ran a campus network across several buildings with tens of thousands of connections a day and no reliable picture of what was on it. Any device reaching a wall port or joining the wireless network received an address and, across most of the campus, unrestricted internal access. Staff systems, student devices, lab equipment and building management shared the same layer 2 environment.

The problem became concrete when a compromised student laptop began scanning internal ranges and reached administrative systems holding personal data. The incident was contained, but the investigation established that containment had been luck rather than design.

The approach

ITBuilders began with visibility. Device profiling was deployed across the wired and wireless estate to classify what was actually connecting — managed staff endpoints, unmanaged personal devices, lab instrumentation, printers, cameras, building controllers. The inventory ran to several times the institution's estimate and included a category nobody had considered: a significant population of networked laboratory equipment, purchased departmentally, unmanaged, and in several cases unpatchable.

Access control followed the profiling rather than preceding it. Policy was built around device identity and posture, so that a managed staff endpoint, a student device, an unmanaged instrument and a guest each land in a defined segment with defined permissions. The lab equipment that cannot be patched is now isolated to the communication it genuinely requires, which is the only available control for that class of device.

Enforcement was introduced in monitoring mode first, across a full academic term, before anything was blocked. In an environment with this device diversity, enforcing policy built on incomplete profiling will deny access to something important during a teaching session. Running visibly and blocking nothing for a term produced the exception list that made enforcement viable.

Wireless was rebuilt alongside, with separate authentication paths for staff, students and guests, and consistent policy regardless of how a device connects — the same device gets the same permissions wired or wireless, which removes a workaround that had been widely used.

Segmentation now prevents the lateral path the original incident exploited. Administrative systems sit behind an enforced boundary rather than a shared broadcast domain.

ITBuilders holds the Fortinet Engage Partner Specialization in Secure Networking LAN. Access control is the discipline most often deployed badly, because a policy that blocks the wrong device at the wrong moment generates enough institutional resistance to end the programme. Assessed capability matters here specifically because the risk is operational rather than technical.

What changed

The institution can now identify every connected device, apply policy by device class, and isolate a compromised endpoint from a console in minutes. The onboarding burden on the help desk fell, because most of what it had been doing manually now happens by policy.

Continuity of operation

ITBuilders continues to operate the profiling and policy estate — classifying new device types as they appear, maintaining exception handling, and producing the asset evidence the institution's compliance function submits at review. A campus network acquires unrecognised devices continuously, and an inventory is only current while someone is maintaining it.

Your next step

Facing a similar challenge?

Talk to ITBuilders about the constraints, priorities and operating requirements of your environment.

Start a conversation