Skip to content
BritonOne Technology
CybersecurityGovernment & Public

Zero-trust rollout for a government agency

Rolled zero-trust access to 25,000 civil servants without a productivity dip.

25k
OktaZscalerEntra IDTerraform
Zero-trust rollout for a government agency
IndustryGovernment & Public
DisciplineIAM & Zero Trust
CountryUnited Kingdom
Headline result25k
The story

Problem, approach, and the outcome

About the client

The client is a UK government agency of around 25,000 civil servants running on a flat internal network. As a public body handling sensitive systems, it is a high-value target and accountable for protecting them.

The flat network meant one compromised device could reach almost anything, but re-architecting access at that scale risked disrupting essential public services.

The challenge

A flat internal network meant one compromised device could reach almost anything on sensitive systems: exactly the lateral movement modern attacks depend on. The architecture itself was the vulnerability.

Re-architecting access for 25,000 civil servants risked disrupting essential public services if handled clumsily. The scale and the stakes left little room for a misstep.

The agency needed to raise the security floor without a productivity hit or a big-bang cutover that could fail loudly. Security had to improve without services suffering.

Our approach

We introduced device- and identity-aware access in phases, starting with the most sensitive systems where the risk reduction was greatest. Sequencing by risk means the biggest security gains land first.

Each phase was aligned to NCSC guidance and rolled out to a cohort first, so issues surfaced small and were fixed before the next wave. A phased, cohort-based rollout is what kept disruption contained.

Access decisions moved from network location to verified identity and device posture, and we instrumented productivity and support metrics throughout to catch friction early rather than after complaints. The floor rose without the services faltering.

Results
  • Zero-trust access for 25,000 staff
  • No measurable productivity dip
  • Sensitive systems protected first
  • Phased rollout aligned to NCSC guidance
Next step

Get a senior architect on the call, first time, every time.

No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.