InsightNetwork and SecurityOperating Model

The network conversation and the security conversation merged. Most organisations are still having both.

Every internet link is now a security decision. Every firewall rule is a network design choice. Every identity policy shapes connectivity. The two stopped being separate the day branches started reaching the cloud directly. The operating model often has not caught up.

This insight covers where network and security still operate as separate conversations, what that separation costs in practice, and how to review the current state before choosing SD-WAN, SASE or provider consolidation.

Network / security / one operating model
CONVERGED MODELACCESSPOLICY One Operating Modelone, not twoIdentity-Led AccessOne Policy EverywhereTwo Separate Teamsduplicated effortFLOWFLOWFLOWFLOW LEGACY SPLIT
ModelOne operating model, not two
IdentityIdentity drives access
PolicyOne policy, applied everywhere
IntegrationEngineering-led
Why the merger already happened

Three questions that explain why the merger already happened.

The conversations were always linked. The technology now makes the link unavoidable. Three questions explain what merged, what the old silo costs, and what an integrated model looks like.

01

What does it mean that network and security have merged?

The technology stopped treating them as separate. SD-WAN devices include encrypted overlays and built-in firewalling by default. Identity drives access decisions, not just authentication. Branch traffic reaches cloud directly with security applied at the edge nearest the user. Every WAN choice now shapes the attack surface, and every firewall rule shapes connectivity.

ThemeConvergence
02

What does the old siloed model cost in practice?

Multiple consoles producing inconsistent policies between sites and tools. Change requests crossing separate ticket queues. Alerts bouncing between teams while one assumes a network fault and the other assumes a firewall drop. Compliance audits surfacing undocumented exceptions. Identity and remote access existing as ad-hoc combinations of VPN, MFA and cloud SSO that do not work together.

ThemeSilo cost
03

What does an integrated operating model look like?

One policy engine pushing consistent rules to every site. Identity as the access decision rather than just an authentication step. Telemetry from network, firewall, endpoint and cloud feeding one view. One accountable response model for incidents that cross connectivity, identity and security controls. Not exotic — what modern platforms can deliver if operated as one system.

ThemeIntegrated model
How the silos became one

Networks used to be plumbing. Security used to be gates. Both definitions are now wrong.

The old separation
  • Network team built the pipes
  • Security team controlled who got through them
  • Tooling own consoles, own people, own vendors
  • Change separate change-control processes
What the technology does now
  • SD-WAN ships encrypted tunnels and firewalling by default
  • Identity is the access decision, so the directory is a perimeter
  • Branch traffic reaches cloud applications directly
  • Attack surface every branch internet link
SASE platform
SD-WAN device
Identity-driven access
One operating model

Whatever gets bought, it is being bought into one operating model whether the organisation intended it or not. The question is whether the operating model is also intentional, or just a consequence.

What the silo costs

Where two separate conversations show up as one expensive problem.

The cost of running network and security as two functions does not appear as a line item. It appears in friction. None of these are dramatic individually. Together they describe a stack that is harder to operate, harder to defend, and harder to change than it should be.

Cost 01 · Multiple management consoles
The frictionDifferent teams or tools manage routers, firewalls, identity and endpoint protection, with no single source of truth for who has access to what or which policy applies where.
The costInconsistencies surface only when someone goes looking for them.
Cost 02 · Change control across queues
The frictionAdding a new branch involves the network ticket queue and the security ticket queue, often with different SLAs and different reviewers.
The costBranch builds slow down, policy updates lag, and procurement assumes both queues will move at the same speed and is repeatedly wrong.
Cost 03 · Alerts that bounce between teams
The frictionThe NOC reads it as a network fault. The SOC reads it as a firewall drop. Each escalates to the other.
The costTime-to-resolution is determined by whoever owns the incident first, not by what the incident actually is.
Cost 04 · Backhauling that outlived its purpose
The frictionBranch traffic still routes through head office because nobody has rebuilt the architecture, even though the cloud applications it accesses are everywhere else.
The costPerformance suffers and helpdesk volume rises. The fix needs both teams to act together, which is why it has not happened yet.
Cost 05 · Identity and access in fragments
The frictionVPN concentrators sit alongside cloud SSO, MFA and conditional access, none of which were designed to work together.
The costUsers get inconsistent experiences. Auditors find the gaps before the security team does.
Cost 06 · Compliance findings that surprise nobody
The frictionInconsistent firewall rules across sites. Undocumented exceptions. Policy that exists on paper but not in the live configuration.
The costThe findings are routinely the same. The silo is the structural reason they keep appearing.
The new operating model

What the integrated model looks like in practice, not in theory.

An integrated network and security operating model is not a particular vendor stack and not a particular organisational structure. It is a set of working assumptions that change how the team operates day to day. The technology choices follow from those assumptions, not the other way around.

Policy and access
01

One policy engine

Consistent rules pushed to every site rather than each branch firewall managed locally. The site cannot be an outlier because the policy is the same by design.

02

Identity is the access decision

Not the front door, the architecture. Every session evaluates user, device, location and posture, not just credentials. Identity systems become primary infrastructure.

03

The edge is governed like head office

The branch, the home office, the construction site, the remote mine: same controls, same monitoring, same policy — whether the connection is fibre, 5G or Starlink.

Visibility and response
04

Telemetry feeds one view

Network devices, firewalls, endpoints, cloud applications and identity events feed a single observability layer that makes incidents legible across the stack rather than across the org chart.

05

One accountable response model

When an alert crosses connectivity and security, one team owns it. Escalation is internal. The customer experience is one phone call, not two providers debating whose problem it is.

06

Procurement, not just deployment

SD-WAN, firewalls, identity, endpoint protection and managed services treated as one decision shaping one operating model, not five separate decisions stitched together later.

The integrated review

The current-state map that decides what changes first.

An integrated network and security review is not a vendor pitch and not a tooling recommendation. It is a current-state map that surfaces where the silos still cost money and visibility, and a prioritised list of what closing the gaps actually involves. The output should support both leadership decisions and technical remediation.

The diagnostic is the foundation. Platform decisions, consolidation projects, ZTNA rollouts, MDR engagements: all are downstream of knowing what the stack actually looks like and where the silo is genuinely hurting.

Review
Topology versus reality
How each site and user actually reaches applications; where backhauling persists.
Firewall and segmentation policy
Where policies are consistent, where they diverge, and why.
Remote access and identity
How VPN, ZTNA, MFA, conditional access and cloud SSO actually fit together.
Endpoint and device trust
Whether device posture feeds access decisions or merely coexists.
Cloud application protection
Conditional access, Defender configurations and data access controls.
Visibility and logging
Whether network, firewall, endpoint and identity events feed one view.
Operating model and ownership
Who owns policy, and who owns response when incidents cross domains.
The Inlight IT view

The technology has converged. The operating model needs to catch up.

Network and security now operate through the same control points: identity, edge devices, firewall policy, endpoint posture, cloud access and telemetry. Treating those controls as separate conversations creates gaps that only appear when something needs to change quickly or an incident needs one accountable owner. Some organisations can make a split-provider model work, but only when ownership, escalation, policy authority and incident handover are explicit. The practical question is not "how many providers do we have?" It is "can this operating model work under pressure?" Inlight IT runs integrated network and security reviews and operates the resulting architecture as part of cyber-first managed services for Australian businesses.

The starting point is not SASE, SD-WAN or provider consolidation. The starting point is understanding how network and security operate together today.

01

Map the current state first

02

Standardise policy where inconsistency creates risk

03

Integrate identity and network access

04

Consolidate where the operating model benefits

Network Review

Make network and security visible as one system.

Review network, firewall, identity and access controls as one operating environment. Scoped to your environment — Inlight IT remains the accountable service owner throughout.

Discuss Network Review