CASE STUDY · NETWORK & SECURITY ARCHITECTURE

Healthcare system modernizes network & security architecture

A research and medical organization whose aging campus network could not secure IoT, BYOD, or guest access — rebuilt as a 100 Gbps Software-Defined Access fabric with central identity policy and segmentation across four campuses.

Background

A combined research and medical organization runs a main campus network alongside research facilities and satellite campuses. The infrastructure predated current cybersecurity standards, and clinical, research, and IoT devices all shared it with no policy separating them.

Challenges

  • Aging infrastructure — the network no longer met current cybersecurity standards.
  • No flexibility or mobility — staff could not move between the campus network, research facilities, and satellite campuses.
  • IoT, BYOD, and guest access were under-secured — unmanaged devices landed on the same network as everything else.
  • Declining trust in IT — recurring network access difficulties eroded staff confidence.
  • No visibility — from users through to IoT devices, which made reacting to network issues slow and manual.

Solution

  • 100 Gbps campus-wide fabric with Cisco Software-Defined Access and automated segmentation.
  • Central policy management with Cisco ISE, with group policy enforced through Cisco Catalyst Center and ISE together.
  • Cisco Secure Firewall for perimeter and inter-zone enforcement.
  • A single management console in Catalyst Center, replacing per-domain tooling.
  • Standardized infrastructure and security controls to best practice, so the estate stays consistent as it grows.

Outcomes

  • Macro and micro segmentation in production — policy now follows identity, not cabling.
  • Wi-Fi access improved across four large campus facilities, with consistent and reliable access to digital resources.
  • Proactive monitoring replaced reactive troubleshooting, restoring confidence in the network.
  • IoT and unmanaged devices integrated and segmented rather than tolerated.
  • Workplace zero trust — the environment is future-proofed and the existing infrastructure was optimized rather than replaced wholesale.
100 Gbps
Campus-wide fabric with automated segmentation
4
Large campus facilities on consistent, reliable access
2
Segmentation models in production — macro and micro

Get the same outcome.

ModernISE Platform and Expert, and Cisco Security Expert as a Service — Cisco Security experts operating as an extension of your team.

Integrated · Agile · Zero Trust · AI