Utilities/ Case Study · Essential-services operator

One security fabric, edge to cloud

An office move became the trigger for a coordinated infrastructure investment — high-availability next-generation firewalls, Wi-Fi 7, resilient managed Ethernet, and on-premise server workloads migrated into M-Tech's private cloud — extending one security fabric end to end across the customer site, M-Tech's core network and the cloud-hosted systems behind it.

Introduction

This client runs technology that has to behave like utility infrastructure itself: dependable, secure and there when it's needed. A move to a new office was the trigger for the investment — the kind of moment that makes it sensible to do things properly rather than simply lift and shift. The brief that grew out of it spanned secure networking, resilient connectivity, cloud-hosted server workloads and the long-term operational resilience of the platform underneath.

For an organisation whose business is dependable infrastructure, the IT estate had to match. The reality is that established environments tend to grow up across separate disciplines: secure networking from one direction, switching and Wi-Fi from another, server workloads in whatever space was available when they first went in, backup and remote access tacked on as needs evolved. Each layer works on its own terms. The trouble is what they don't do together — and in a security-led world, that gap is where things go wrong.

The brief, in short: bring those layers into one resilient, security-led architecture — and start moving the things that no longer belong on-premise off the on-premise box. The result is a single protected security fabric stretching from the office edge, through M-Tech's own protected core, and into a private cloud where the operator's server workloads now sit — one platform, one accountable partner, and a meaningfully stronger position when something needs to flex or fail.

This client operates essential services and asked not to be named, or to have their location identified. We're glad to respect that — discretion is part of the job in this sector — so the scenario is told exactly as it happened, without identifying the organisation.

What this kind of estate has to do

  • Goal:

    Security has to be a fabric, not a fence — for an organisation whose own infrastructure is critical, the IT estate has to defend against threats that move across edge, core and cloud as one

  • Goal:

    Connectivity is part of the security model — resilient firewalls don't matter if the carrier path underneath is a single point of failure

  • Goal:

    Server workloads need a proper operational home — domain controllers, file servers and line-of-business systems deserve a managed platform engineered for them, rather than whatever space was available when they first went in

  • Goal:

    Backup has to assume the worst — daily, immutable, off-site and Microsoft 365 protection treated as part of the platform, not an afterthought

  • Context:

    Remote access is now identity, not network location — "on the network" is no longer a meaningful security signal; ZTNA changes the question

  • Context:

    The IT has to match the dependability the business itself delivers — for an organisation that is itself part of the country's everyday infrastructure, IT outages and gaps don't sit in a separate world from operations

What we delivered

High-availability security edge at the office

A high-availability firewall pair with premium vendor support and unified threat protection, plus centralised cloud management, analysis and log retention. The office edge isn't a standalone firewall — it's the customer-facing entry point of the wider security fabric.

Modernised LAN — 2.5G PoE and 10G fibre

Managed switching with 2.5Gb PoE access, 48-port aggregation, fibre patching and 10G optical transceivers — a LAN that can carry the next generation of endpoints, cameras, APs and PoE-hungry devices without compromise.

Wi-Fi 7 access layer

Wi-Fi 7 access points across the office, surveyed and remediated as part of the deployment — a wireless platform aligned to the same management plane as the rest of the network.

Resilient managed Ethernet to the office

A 1Gbps carrier-grade resilient Ethernet circuit — an access option engineered to remove single-path weaknesses at the carrier layer, so the connectivity underneath the security edge is as strong as the kit running on top of it.

SD-WAN and WAN resilience

SD-WAN configuration with failover and disaster recovery testing as part of the build — controlled use of available WAN paths, monitored and prioritised rather than just plugged in.

Server workloads migrated into M-Tech Cloud

Around thirteen server workloads — domain controllers (rebuilt to Windows Server 2022 rather than upgraded in place), file servers and the line-of-business application servers — migrated into M-Tech's hyperconverged private cloud, using a disaster-recovery methodology to keep the cutovers safe and reversible.

Layered backup and recoverability

Daily backups of the cloud-hosted workloads, plus Microsoft 365 backup. Behind that, immutable, off-site backup of the critical workloads kept separate from production — so recovery survives even a worst-case on-site event.

Managed LAN service wrapping the lot

Quarterly on-site spectrum analysis, scheduled monthly switch and firmware upgrades, unlimited 1st/2nd/3rd line LAN support, proactive monitoring and access to M-Tech's managed-service networking portal — security as a continuing posture, not a one-off install.

One security fabric, edge to cloud

The architectural strength of the design is what happens once the operator's traffic leaves the building.

That investment in the security fabric doesn't stop at the office edge. M-Tech's own core network sits behind the same protection — and the workloads that have just moved off the on-premise servers now run in M-Tech's private cloud, behind it too. The result is one consistent security architecture spanning the customer site, M-Tech's core, and the cloud-hosted systems behind it.

That alignment matters. Security policy, access control, WAN resilience and cloud access can be designed as part of one architecture rather than stitched together from unrelated platforms. It also strengthens the ZTNA story coming next: rather than treating remote access as a separate VPN-style service bolted on the side, ZTNA can be delivered as part of a single secure-access model from the user, through the device, into the application — protected at every hop by the same fabric.

The Hybrid AD to Entra migration review sits naturally alongside that direction, lining up identity modernisation with the network and cloud modernisation already in flight.

When the carrier becomes the bottleneck

Modernisation programmes don't survive contact with reality unless someone owns the parts that don't follow the plan.

The most challenging piece of the programme was the permanent resilient Ethernet delivery itself. Carrier-grade resilient Ethernet involves dependencies that sit well outside the customer's control — carrier surveys, engineering appointments, excess construction works, traffic management, internal cabling, final service handover. In this case those dependencies were particularly difficult, and the carrier delivery slipped.

Rather than letting the slip become a project problem, M-Tech pulled together alternative connectivity to bridge the gap. The wider infrastructure migration carried on. The security edge went in, the LAN and Wi-Fi got modernised, the server workloads moved into the cloud — and the permanent Ethernet service was completed underneath, in parallel, without ever blocking the rest of the programme.

That's the difference between a supplier who waits for a dependency to resolve itself and a partner who owns the outcome. For the operator it meant the project landed on time and in scope, with the carrier pieces resolving cleanly behind the scenes.

Platform at a glance

Client
an operator of essential services — anonymised at their request
Site
a single head-office site
Network edge
high-availability next-generation firewall pair with premium vendor support, unified threat protection, and centralised cloud management, analysis and log retention
LAN
managed switching with 2.5Gb PoE access, 48-port aggregation, fibre patching and 10G optical transceivers
Wi-Fi
Wi-Fi 7 across the office, surveyed and remediated
WAN
1Gbps carrier-grade resilient Ethernet, plus SD-WAN with failover and DR testing
Cloud
around thirteen server workloads migrated into M-Tech's hyperconverged private cloud — domain controllers (rebuilt to Server 2022), file servers and line-of-business application servers
Backup
daily backups of the cloud workloads; immutable off-site backup of critical workloads kept separate from production; Microsoft 365 backup
Security fabric
protection extending across the customer edge, M-Tech's core network and the cloud-hosted workloads behind it — one consistent architecture
Identity
Hybrid AD to Entra migration review alongside ZTNA enablement
Managed service
ongoing LAN managed service — quarterly on-site spectrum analysis, monthly firmware/switch maintenance, unlimited multi-line LAN support, proactive monitoring
Distinctive
end-to-end security fabric from customer site to private cloud, with M-Tech also providing the carrier delivery, the cloud platform and the alternative connectivity that kept the programme on track

In numbers

01 / 04
Security fabric — extended from the office edge through M-Tech's core into the private cloud
0
  • 02 / 04
    Off-site backup of critical workloads, kept separate from production
    Immutable
  • 03 / 04
    Backups on the cloud workloads, plus Microsoft 365 protection
    Daily
  • 04 / 04
    Project days lost to the carrier slip — alternative connectivity bridged the gap
    0

What changed

Outcome

A single set of rules, end to end

Policy, visibility and enforcement no longer differ between the office, the network between sites and the cloud platform behind it. The operator's IT team manages one architecture rather than reconciling three.

Outcome

Workloads in safer hands

The systems the operator depends on — domain controllers, file servers, line-of-business applications — now run on a professionally managed cloud platform with layered, immutable backup behind them. Recovery is part of the design, not part of the crisis.

Outcome

Failure becomes recoverable, not catastrophic

Critical workloads now have immutable, off-site copies kept separate from production, and the cloud workloads are backed up daily, with Microsoft 365 protected too. The carrier path uses a resilient access option. Each layer assumes the one above it might fail — and the platform keeps working anyway.

Outcome

One supplier, one set of decisions

Carrier delivery, security architecture, LAN and Wi-Fi, cloud hosting, backup and managed support all flow through the same partner. When something needs a decision it's one conversation, not three suppliers comparing contracts.

A platform owned end to end

The operator didn't need a supplier for individual pieces of technology. The brief was to bring connectivity, firewalling, switching, Wi-Fi, cloud hosting, backup, identity and access control into one coherent programme — and to land it without the carrier dependencies, the migration risk or the security choices undermining each other.

That meant joining a long list of usually-separate disciplines: carrier-grade Ethernet delivery, security architecture, LAN and Wi-Fi modernisation, SD-WAN, private cloud hosting, layered backup, identity modernisation review, ZTNA enablement and the managed support that holds it all together once it goes live.

It also meant taking ownership of the parts that didn't go to plan. When the permanent Ethernet delivery slipped, M-Tech provided the alternative connectivity that kept the wider migration moving. That's what an end-to-end programme owner actually looks like — not just designing the architecture, but making sure the difficult bits behind the scenes don't become the customer's problem.

/ Start a conversation

Tell us what you're trying to do.

Whatever the shape of your team or your stack — multi-site, lean on IT, or somewhere in the middle — we'll listen first, ask the right questions, and tell you honestly how we'd approach it.