Zero-trust rollout for a government agency
Rolled zero-trust access to 25,000 civil servants without a productivity dip.
25k
Problem, approach, and the outcome
The client is a UK government agency of around 25,000 civil servants running on a flat internal network. As a public body handling sensitive systems, it is a high-value target and accountable for protecting them.
The flat network meant one compromised device could reach almost anything, but re-architecting access at that scale risked disrupting essential public services.
A flat internal network meant one compromised device could reach almost anything on sensitive systems: exactly the lateral movement modern attacks depend on. The architecture itself was the vulnerability.
Re-architecting access for 25,000 civil servants risked disrupting essential public services if handled clumsily. The scale and the stakes left little room for a misstep.
The agency needed to raise the security floor without a productivity hit or a big-bang cutover that could fail loudly. Security had to improve without services suffering.
We introduced device- and identity-aware access in phases, starting with the most sensitive systems where the risk reduction was greatest. Sequencing by risk means the biggest security gains land first.
Each phase was aligned to NCSC guidance and rolled out to a cohort first, so issues surfaced small and were fixed before the next wave. A phased, cohort-based rollout is what kept disruption contained.
Access decisions moved from network location to verified identity and device posture, and we instrumented productivity and support metrics throughout to catch friction early rather than after complaints. The floor rose without the services faltering.
- Zero-trust access for 25,000 staff
- No measurable productivity dip
- Sensitive systems protected first
- Phased rollout aligned to NCSC guidance
More Cybersecurity case studies

Privileged access overhaul for a manufacturer
Cut standing privileged access 90% across a manufacturer's IT and OT estate.
Read the full case study
Customer identity rebuild for a wealth platform
Passwordless identity cut account-takeover 22% and sign-in friction at a wealth platform.
Read the full case study
Red-team engagement against a fintech app
Found and helped close three account-takeover paths before a fintech's launch.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
