Featured Projects

A selection of infrastructure projects we've delivered. Client names are withheld under confidentiality agreements — we're happy to discuss relevant references in a direct conversation.

Manufacturing · Engineering Design

VDI for a 40-seat engineering design team

A mechanical design company in Ho Chi Minh City was refreshing aging CAD workstations every few years, and design files were scattered across individual machines — a data-loss and IP-protection risk their management was no longer willing to accept.

We deployed VMware Horizon virtual desktop infrastructure on Dell PowerEdge servers with Dell EMC Unity All-Flash storage. Engineers now work on virtual workstations from thin clients or their own laptops, and project data never leaves the data center.

  • Provisioning a new workstation went from 1–2 days to under 30 minutes.
  • Design data centralized — no more project files on individual machines.
  • Secure remote work for engineers without VPN file-copy workarounds.
VMware Horizon Dell PowerEdge Dell EMC Unity All-Flash
Logistics · Business Continuity

Disaster recovery for a logistics operator

A logistics company running warehouse and fleet systems around the clock relied on nightly backups to a single NAS in the same server room — meaning a fire, flood, or ransomware event could take the business offline for days, and recovery had never actually been tested.

We designed a DR setup orchestrated with VMware Site Recovery Manager (SRM), with storage-based replication to a secondary site and non-disruptive test failovers built into SRM's recovery plans — plus a written runbook and scheduled drills so recovery is a rehearsed procedure, not a hope.

  • RPO for core systems reduced from ~24 hours to 15 minutes.
  • Documented recovery target of 4 hours for critical workloads.
  • Failover drills every 6 months using SRM's non-disruptive test mode, with findings folded back into the runbook.
VMware SRM Storage Replication Immutable Backup DR Runbook
Manufacturing · Network Infrastructure

Factory campus network for a three-workshop plant

A manufacturing plant with three production workshops was running office and machine networks on the same flat network — intermittent outages on the floor stopped production lines, and any infected office laptop could reach industrial equipment.

We rebuilt the campus network with FortiGate firewalls in high availability at the core, Aruba switching and Wi-Fi coverage across the workshops, and clean segmentation between office IT and production OT networks.

  • Core firewall failover in under 10 seconds if the primary unit goes down, instead of a full outage.
  • OT equipment isolated from office traffic and internet-borne threats.
  • Wireless coverage across all workshops, ready for barcode/MES rollout.
FortiGate HA Aruba Switching Aruba Wi-Fi OT/IT Segmentation
Retail · Multi-site Security

Security standardization across a 12-branch retail chain

A retail chain had grown to 12 branches, each with its own consumer-grade router and no endpoint protection standard — head office had no visibility into what was happening at any location, and opening a new branch meant a week of ad-hoc IT setup.

We standardized every branch on centrally managed SonicWall firewalls, rolled out Sophos endpoint protection across the fleet, and templated the branch network so new locations come online in a predictable, repeatable way.

  • All 12 branches visible and managed from a single console.
  • Endpoint protection standardized across ~350 devices.
  • IT setup for a new branch reduced from about a week to one day.
SonicWall Sophos Endpoint Central Management Branch Template
Enterprise · Security Operations

Security operations hardening for a financial services firm

A financial services company had no way to tell which devices were connecting to its internal network, no control over sensitive files leaving the company, and no central place to see security events — incidents were often only discovered days later, if at all, usually after the damage was done.

We hardened the environment in layers: FortiGate firewalls in high availability at the perimeter, FortiNAC to identify every device on the network and automatically quarantine anything unrecognized or non-compliant, Trellix DLP to inspect and block sensitive data leaving through email, USB, or cloud uploads, and a Wazuh SIEM deployment to bring firewall, endpoint, and server logs into one place with real-time correlation and alerting.

  • Unrecognized or non-compliant devices are quarantined automatically by FortiNAC instead of joining the network unnoticed.
  • Sensitive files are inspected and blocked at the point of exit, before they leave the company.
  • Security events across the whole environment are visible in one dashboard, in real time, instead of scattered logs discovered after the fact.
FortiGate HA FortiNAC Trellix DLP Wazuh SIEM

Planning a similar project?

Tell us about your environment — we'll walk you through how we approached comparable deployments, including what we'd do differently for your case.

Contact Us