Post-Implementation IT Satisfaction Survey – NexaTech Staff
Dear Team,
As part of our commitment to improving our IT infrastructure and security, we value your feedback. Please take a few minutes to complete this short survey. Your input will help us identify what is working well and where further improvements may be needed.
Project Summary: NexaTech Cybersecurity Infrastructure Overhaul
Initial Network Security Issues:
NexaTech IT Solutions originally operated on a legacy setup inherited from its home-office environment. The infrastructure included a SOHO router, a standalone VPN server, shared administrative access to a NAS device, and unmanaged endpoints. The network lacked segmentation, had no audit trails, and exposed the organisation to multiple vulnerabilities such as insider threats, malware, and data loss. User accounts operated with full administrative privileges, remote access was unsecure and complex, and there was no formal endpoint protection or backup solution in place.
Proposed and Implemented Solutions:
To address these weaknesses and support NexaTech’s growing team and hybrid working model, a modern, cloud-centric solution was developed and implemented. Key upgrades include:
- Deployment of Microsoft Entra ID (Azure AD) with Windows Server AD for centralised identity and access control.
- Removal of local admin rights through Group Policy Objects (GPO) and enforcement of role-based access control (RBAC).
- Replacement of the VPN and local file sharing with Microsoft 365, SharePoint, and OneDrive for seamless collaboration.
- Upgrade to Ubiquiti EdgeRouter and UniFi APs to enable VLAN segmentation and WPA3-secured wireless networks.
- Replacement of the legacy NAS with a Synology DS923+ device featuring encrypted user-specific access and cloud backup integration via Acronis.
- Implementation of ESET Endpoint Security and Cisco Umbrella for malware detection and DNS filtering.
- Device management and compliance oversight through Microsoft Intune.
Security Risks and Mitigations:
- Insider threats: Mitigated by removing local admin rights and enforcing RBAC.
- Malware/ransomware: Addressed through ESET endpoint protection, DNS filtering, and encrypted backups with versioning.
- Data exfiltration and loss: Prevented using cloud backups, DLP policies, and audit logging on storage systems.
- Phishing and unauthorised access: Reduced via multi-factor authentication (MFA) and staff training.
Performance Evaluation:
The project was completed within the allocated timeframe and met all client requirements. Solutions were researched using credible vendor sources and justified based on technical suitability, security compliance, and cost-efficiency. Communication with the client was maintained through technical and non-technical documentation. Visual design of network diagrams and consistent formatting across documents reflected professionalism.
One area for improvement would be enhancing my time management during the early stages of task research, as initial delays reduced review time. In a future project, I would plan tighter research windows to allow for more time on evaluation and feedback integration.
Next Steps:
A satisfaction survey has been created and distributed to staff to evaluate the success of the implementation across usability, security, and access. While results have not yet been returned, the survey is designed to collect both quantitative and qualitative feedback. This will inform any future refinements to the IT infrastructure or training programme.
Conclusion:
The solutions implemented provide NexaTech with a secure, scalable, and cloud-integrated IT environment that meets modern cybersecurity standards. The infrastructure supports hybrid working, enhances data protection, and enables efficient IT management across all endpoints. With these upgrades, NexaTech is now well-positioned for continued growth with reduced security risk.
Comments
Post a Comment