33 locations. Two operating models. How one security architecture unified them.
A multinational alcoholic beverage company operating across North America and Europe was boxed in by the capacity and functionality of its site-level hardware. With network and security managed as separate functions, every new requirement added processing load, introduced another set of site-specific rules and created more manual work for the team.We designed and deployed a managed SASE architecture that moved security inspection to the cloud and brought network and security operations together. Centrally defined policies can now be enforced consistently across all locations.
Inspection was limited by the capabilities of each branch firewall. As traffic volumes and security requirements grew, every site effectively became a separate capacity-planning and upgrade decision.
One-off rules, exceptions and local configurations had accumulated over time. Each location had become slightly different, making changes slower, troubleshooting more difficult and security enforcement less consistent across the environment.
Network and security were managed as separate functions, with separate budgets, responsibilities, platforms, vendors and management interfaces.
Retail and hospitality locations had been designed and configured differently, making it difficult to apply PCI-DSS segmentation consistently across the network. Each variation created additional rework and audit complexity. The organization also lacked a standardized segmentation model that could be applied and validated across the full network.
The branch firewall had become the primary enforcement point for security and compliance. Replacing the hardware would have introduced newer devices, but it would not have removed the organization’s dependence on site-level management.
The company’s network spanned 33 locations across the US, Canada and Europe, including manufacturing, distribution, corporate, retail and hospitality environments, supported by an IT team of approximately 10 people. The challenge went beyond the scale of the network. Site types, local requirements and operational needs differed, while many security controls remained tied to branch infrastructure.
Several firewalls were already due for replacement, but a like-for-like refresh would have addressed the age of the hardware without resolving the wider operating problem. The organization needed a model that could standardize control across different locations, rather than another cycle of site-by-site infrastructure decisions.
The heaviest security inspection workloads moved from branch firewalls into Prisma Access, including TLS decryption and scanning, threat prevention, URL filtering and malware sandboxing.
Threat signatures, content updates and inspection policies are now managed centrally, while inspection capacity is provided in the cloud rather than sized at each site. This reduces per-site maintenance and supports more consistent enforcement.
Prisma SD-WAN provides SASE connectivity and zone-based firewalling at each site, moving local routing and segmentation functions onto the appliance.
Each location uses the same zone-based architecture to separate key traffic types, including staff access, guest Wi-Fi, internet access and cardholder-data environments.
WAN, LAN and security controls are now managed through Strata Cloud Manager, bringing network and security operations into one platform. The deployment replaced multiple vendors, consoles and handoff points with a shared operating view across the environment.
Policy and segmentation templates are configured and enforced uniformly across every retail location, making compliance repeatable and easier to demonstrate.
Because policy is tied to zones rather than specific circuits or IP addresses, segmentation persists through failover, circuit and broader network changes.
A Prisma SD-WAN ION appliance is deployed at each new location to provide branch connectivity, routing, and local segmentation. Once connected, it retrieves its approved configuration from Strata Cloud Manager.
This allows future sites to follow the same deployment model, reducing manual configuration and avoiding the need to redesign the network and security setup for every location.
Before any technology was selected, we brought network and security stakeholders together to agree on what needed to remain on-premises, what could move to the cloud and how policy should be applied consistently across all locations.
We designed a managed SASE model using Palo Alto Networks Prisma Access and Prisma SD-WAN. The architecture reduced the infrastructure each site needed to host, moved heavy inspection workloads into the cloud and replaced site-by-site firewall management with a more consistent way to run network and security operations across all locations.
Sites were migrated in waves over approximately 12 months, allowing the organization to move to the new model without disrupting store or plant operations.
Security maintenance
Updates, signatures, threat feeds, and patches managed against local infrastructure.
Cloud security layer keeps inspection and threat controls current.
Capacity management
Branch hardware sized around TLS inspection and security demand.
Heavy inspection shifts into the cloud, reducing local capacity pressure.
Policy and segmentation
Site-specific rules and exceptions accumulate over time.
Standard templates apply policy consistently across locations.
Operations and support
Internal teams coordinate monitoring, troubleshooting, carriers, and vendors.
Globalgig managed service owns monitoring, escalation, coordination, and day-to-day support.
Globalgig helped network, security and budget owners translate separate priorities into a single, shared set of requirements.
The shared framework prevented the solution from being shaped solely by the constraints, tools or budget cycle of one team. The final design had to work technically, operationally and commercially without shifting complexity from one part of the organization to another.
We reframed the project before any solution was built. Instead of starting with hardware sizing or product selection, we focused the design on the patterns creating day-to-day friction: local exceptions, unclear ownership, inconsistent support paths and too many decisions pushed down to each location.
The design had a clear target: reduce local variation, clarify ownership and make the environment easier to operate after deployment.
The organization gained 24/7 operational support, clearer escalation paths and day-to-day service ownership without having to build the function in-house.
The managed service reduces the burden of troubleshooting, escalation and vendor coordination, giving the internal IT team a simpler environment to manage.
Alongside the technical design, we created a Business Incident Policy that specifies how issues are monitored, prioritized, escalated and resolved on an ongoing basis. This policy gives the organization a clear playbook for day-to-day network and security operations.
Globalgig continues to support roadmap decisions, tool evaluations and future changes, helping the organization avoid short-term fixes that would reintroduce fragmentation.
globalgig.com
We design, implement, and operate unified network and security architectures for organizations whose environments are growing faster than their teams. If stronger security keeps adding more hardware, consoles, and site-by-site maintenance to your environment, let’s talk about delivering more advanced, consistent protection without increasing local complexity.