Most networks grow organically until they're too complex to change safely. We design networks simple enough to understand, operate and defend, from flat-network segmentation to a full OT architecture.
Devices get added, VLANs multiply, documentation lags, until the network is too tangled to touch with confidence. Design work is the right move when you know change is needed, but the target architecture isn't there yet.
Everything on one or two VLANs. A compromised device can reach the whole network. You need zones, but the architecture doesn't exist yet.
The project is approved and budgeted, but nobody has designed the target. Firewall rules without an architecture is just complexity without structure.
The two are merging without a plan. OT wants isolation, IT wants integration. You need an architecture that gives both sides what they need.
NIS2, the IKT-Minimalstandard, ISO 27001: they demand documented segmentation. You need an architecture you can defend in an audit.
We design zone models, addressing and segmentation concepts, and a realistic path to get there. Every design starts from real network data, not interviews and assumptions alone.
A zone model with clear boundaries for IT, OT, DMZ and management: the structure the whole network hangs from.
An IP addressing plan, VLAN assignments, VRF structure and naming conventions, consistent and ready to grow.
Firewall rule sets, inter-zone policies and traffic-flow definitions: the rules that make the zones real.
A phased rollout from the current state to the target, with rollback points. No big-bang required.
From understanding the current state to handing over a design your team can implement and maintain.
Explorer and assessment data show the real network: topology, traffic flows, dependencies.
We create the zone model, the VLAN/VRF layout, the IP plan and the inter-zone policies.
We walk the design through with your team: challenge assumptions, refine constraints, align on priorities.
We support the rollout: config generation with OT Connect, IP planning with IPAM, device protection with Diode.
Documentation, runbooks and knowledge transfer, so your team can maintain and evolve the design.
In practice: a design is developed together with the people who will run it.
A full network architecture redesign for a Swiss utility: from a flat OT network to zone-based segmentation, with OT Connect.
Network security architecture for nuclear-power-plant infrastructure: the highest compliance requirements.
Campus network segmentation for a high-performance computing and research environment.
Typically 1–3 months from kickoff to handover, depending on scope such as network size and whether an assessment was already done.
Yes. We offer implementation support, from config generation with OT Connect to hands-on deployment. Some teams prefer to implement themselves with our design as the blueprint. Both work.
We review what exists, identify the gaps, and extend or refine it. No need to start from scratch. Many projects begin with a concept that needs to be validated and completed.
The assessment creates the baseline: current state, risks, priorities. Design turns that baseline into a target architecture. They are complementary, but can be done independently.
Network architectures delivered for real critical-infrastructure operators.
Fig. — sciCORENetwork design and build for the University of Basel's scientific computing centre.
Read →
Fig. — EniwaA regional energy utility's network, rebuilt around clear zones with a realistic migration path.
Read →
Fig. — resilienceFinding the broadcast-storm loop in an OT network you didn't design.
Read →Whether you're starting from a flat network or refining an existing segmentation concept, we help you get to a design your team can actually run.
Discuss your architecture