See us at Cisco GSX · August 24 – 27 · Las Vegas. Book a meeting at the show →
Cisco PartnerSenior engineers in North America & Europe · 24/7 escalation
SupportContact Sales
Home/Use Cases/Software-Defined Enterprise

A competitive proof of concept, won on architecture — then delivered.

A global organization with a large, distributed IT estate invited multiple vendors to prove a credible path to a software-defined, policy-driven network. The Cisco architecture our engineers designed won the evaluation, and the same engineers led the implementation.

1
policy model across branch, campus, data center & cloud
Delivered engagement
0
business disruption — upgrades sequenced into off-peak windows
Delivered engagement
4
Cisco platforms unified into a single architecture
Delivered engagement
PROVENANCE

The project described in this use case was delivered by engineers who are now part of the Ngenium team, completed for past customers in prior roles. It reflects the hands-on Cisco expertise those engineers bring to Ngenium. The customer is described by profile only and is not identified.

The challenge

Three priorities that had to be proven before anyone committed.

During discovery, our engineers worked with the customer’s network and security teams to translate broad modernization goals into concrete, measurable priorities. Each had to be demonstrated in the proof of concept.

01 — DEVICE MANAGEMENT

Onboarding was manual and inconsistent.

Adding switches, access points and edge devices was largely hand-built and varied site to site. Every manual configuration introduced the risk of misconfiguration and a security gap. The customer needed template-driven provisioning that made adding a device a repeatable, policy-compliant action rather than a project.

02 — WIRELESS VISIBILITY

Troubleshooting was reactive and the evidence was thin.

Distributed teams depended on wireless, but the organization had no real-time insight into how those networks performed from site to site. They wanted monitoring and analytics that surfaced wireless health, client experience and emerging issues before users felt them.

03 — SWITCH UPGRADES

An aging switching layer, and no tolerance for downtime.

The hardware needed modernizing but the business could not absorb unplanned outages. That required a structured, scheduled upgrade approach — sequenced into off-peak windows with validation at each step.

THE COMMON THREAD

Although the three priorities looked operational on the surface, they shared one root cause: policy and configuration were tied to individual devices and individual sites. Without a unifying fabric, every improvement had to be re-implemented everywhere by hand. The evaluation therefore favoured a solution that could express identity, segmentation and policy once and apply it consistently across the entire estate — including the cloud.

The solution

One policy model, four Cisco platforms, a single fabric.

Rather than four point products, the customer saw one architecture in which intent defined in a single place is enforced everywhere automatically.

CONNECT
Cisco Catalyst SD-WAN
Software-defined connectivity linking every branch and remote site to the data center and cloud over any transport, with centralized policy, secure overlays and application-aware routing.
AUTOMATE
Cisco SD-Access
An intent-based campus fabric that automates device onboarding and segmentation, turning manual provisioning of switches and access points into consistent, template-driven policy.
SECURE
Cisco ISE
Identity Services Engine provides the identity and access-control foundation — authenticating users and devices and driving group-based segmentation policy across the fabric.
SCALE
Cisco ACI
Application Centric Infrastructure extends the same policy discipline into the data center, so workloads and applications inherit consistent segmentation and governance.
The engagement

From proof of concept to production, in four phases.

Winning the evaluation was the beginning, not the end. The rollout was structured to protect operations while moving the customer onto the new operating model.

PHASE 01
Discovery & Design
Mapped sites, traffic and policy requirements; defined the target architecture and success criteria with the customer’s teams.
PHASE 02
Proof of Concept
Stood up a working fabric and validated device onboarding, segmentation and wireless assurance against the evaluation criteria.
PHASE 03
Phased Rollout
Sequenced switch upgrades and site cutovers into off-peak windows, validating each step before proceeding to the next.
PHASE 04
Operate & Optimize
Transferred knowledge, tuned policy and established ongoing assurance so the customer’s own team owns the platform with confidence.

How each priority was delivered

The architecture was praised for its robustness and comprehensiveness — one consistent way to manage policy and devices across every location and the cloud, delivered without disrupting day-to-day operations.
Outcome of the customer evaluation
The outcome

Consistent policy, lower risk, and a team that owns it.

Enhanced security & control

Identity-driven segmentation through ISE gave the customer consistent, enforceable policy and device management across all locations, including cloud infrastructure.

Improved visibility

Fabric-wide assurance turned reactive troubleshooting into proactive operations, with real-time insight into wireless and network performance.

Operational efficiency

Automated, template-driven onboarding streamlined operations and reduced the risk of misconfiguration, freeing engineers for higher-value work.

A team left owning the design

Knowledge transfer was part of the engagement, not an afterthought. The customer’s own engineers operate the platform — which is the only outcome we consider finished.

Questions

About this use case.

Who was the customer?

We do not name customers without explicit written permission. This engagement was a global, multi-site organization with a large distributed IT estate spanning branch, campus, data center and public cloud.

Are these results from a delivered project?

Yes. The proof of concept was won competitively and the same engineers were engaged to deliver the implementation. The work was completed by engineers who are now part of the Ngenium team, for past customers in prior roles.

Which Cisco technologies were used?

Cisco Catalyst SD-WAN for connectivity, Cisco SD-Access for the campus fabric and automated onboarding, Cisco Identity Services Engine (ISE) for identity and segmentation policy, and Cisco Application Centric Infrastructure (ACI) in the data center.

Facing a similar modernization?

We provide solutions. We deliver success. Start with a 30-minute scoping call with a senior engineer.

Schedule a Scoping Call