ZTNA Pilot (Single App / Group)

Security & Continuity PS Pilot
Code: SC-PIL-ZTNA
Not sure if ZTNA or SWG/DNS comes first? Start with the SASE Quickstart to trial one path and get a roadmap.

Summary. Validate Zero Trust Network Access for one application or a small user group. We configure policy‑based access via your identity provider and a cloud ZTNA gateway to replace or complement VPN for a specific use case, with minimal change risk and a fast rollback plan.

Who it's for. Organisations needing secure, granular access to internal apps without exposing networks or opening broad VPN tunnels.

What’s Included

ScopeDescription
Core Inclusions
  • Discovery workshop: target app, flows, users, security goals; confirm pilot cohort and success criteria.
  • Connect IdP (e.g., Entra ID/Okta) to ZTNA policy engine; enable MFA for pilot users.
  • Publish 1 internal web app or RDP/SSH resource via connector; define baseline policies (who, where, device posture).
Optional Add‑Ons
  • Device posture checks (OS version, disk encryption, EDR present).
  • SSO header/rewrite support for modern web apps; legacy protocol access via secure connector where feasible.
  • SIEM/syslog forwarding; comms pack (email/how‑to) for pilot users.

Timeline & Deliverables

Note: these are estimates and may vary depending on the tier

PhaseDeliverables
01 — DiscoverExtended Discovery (client‑signed), environment read‑in, inventory & stakeholders.
02 — Identify & Mitigate RDC/LInitial RDC/L register; mitigations, dependencies & constraints agreed.
03 — PlanLabel model, success criteria, test plan, change & rollback plan, schedule.
04 — ImplementVisibility → draft policy; ring‑0 controls; HA & logging verified.
05 — TestExecute UAT; fix exceptions; ring‑1/2 as per tier; evidence captured.
06 — Close‑outClose‑out report, scale‑out proposal, next steps.

Service Levels (Summary)

PlanCoverageResponse / RestoreGovernance
Bronze Business hours (Mon–Fri 08:30–17:30 NZT) P1: 2h / NBD • P2: 4h / 2BD Email support • Change log • Close‑out report
Silver Extended hours (Mon–Fri 08:00–20:00 NZT) P1: 1h / Same day • P2: 2h / NBD Weekly check‑in (Std/Plus) • Findings register • Acceptance criteria
Gold Business + after‑hours (24×7 P1 only) P1: 30m / ASAP • P2: 1h / Same day Executive summary • CAB‑ready rollback • Handover pack

Success criteria (from our perspective)

Prerequisites

Assumptions

Out of scope

Risks & mitigations (examples)

Next steps (after-pilot)

Start the pilot

Early Adopter Program (limited): 10% off the pilot package for customers who start by 31-Dec-25. Not combinable with other offers. May be applied as a credit on close‑out.

For pricing, terms and conditions see the Pricing Annex.

Happy with the outcome?

Related Resources