Incident-Driven Zero Trust Infrastructure
Following a ransomware incident, the work spanned initial forensic response, investigation of initial access and impact, and infrastructure reconstruction across networking, identity, virtualization, backup and vulnerability management.
The goal was not to return to the pre-incident state. Beyond closing the entry point, we redesigned the infrastructure to contain damage, detect compromise and recover if a similar incident occurred again.
Redesign, beyond recovery.
The Transformation
From implicit trust to explicitly verified access paths.
↔ Scroll horizontally to see the full diagram.
View diagram as text
Before: a legacy VPN reaches a broad internal trust zone. After: user and device, identity, conditional access, Zero Trust access, segmentation and firewall inspection govern access to explicitly authorized workloads. Recovery uses a separate trust domain. This conceptual evaluation flow is not a packet routing sequence.
Core Message
One system, beyond individual products.
The work went beyond malware removal, fixing a single vulnerability, replacing one product or restoring encrypted servers.
It transformed the architecture across Identity, Access, Network Trust, Segmentation, Traffic Inspection, Virtualization, Backup, Vulnerability Management and Operations.
- Identity
- Access
- Network Trust
- Segmentation
- Traffic Inspection
- Virtualization
- Backup
- Vulnerability Management
- Operations
01 — Incident Response
Contain the damage. Understand what happened.
A compromise originating through external access affected file servers and virtual servers. The environment contained Linux and Windows servers that had not been updated for an extended period, alongside legacy infrastructure.
Initial response covered:
- Incident containment
- Investigation of initial access
- Impact assessment
- Mapping the existing network
- Server and virtualization inventory
- Determining which assets to retain or replace
↔ Scroll horizontally to see the full diagram.
View diagram as text
Containment and investigation produce findings that inform the subsequent redesign.
Structural Findings
Examine structural risk across the environment.
↔ Scroll horizontally to see the full diagram.
View diagram as text
Eight risks: legacy access, aging Linux and Windows servers, broad internal trust, insufficient East-West inspection, aging virtualization, mutable backup, limited vulnerability visibility and lifecycle debt.
Closing the entry point alone leaves the same structural risks in place.
02 — Trust & Network Redesign
Remove the assumption that the internal network can be trusted.
We moved from a traditional VPN-centered model to identity-centered access using Cloudflare Zero Trust and Microsoft Entra ID Conditional Access.
Internal network trust was redesigned at the same time: VLAN segmentation, inter-segment firewall inspection, East-West traffic controls, explicitly authorized paths, less implicit trust, identity-based access and fewer opportunities for lateral movement.
External Access
↔ Scroll horizontally to see the full diagram.
View diagram as text
Entra ID authenticates the user or device. Conditional Access and Cloudflare Zero Trust policies govern access to authorized resources. This is a conceptual evaluation flow.
Internal Access
↔ Scroll horizontally to see the full diagram.
View diagram as text
A firewall inspects traffic between segments A and B and permits it according to explicit policy.
Zero Trust Architecture
Zero Trust extends beyond replacing remote access.
Identity, device and user context, access policy, segmentation, internal traffic inspection and reduced lateral movement form one architecture.
↔ Scroll horizontally to see the full diagram.
View diagram as text
Identity, policy and access decisions combine with network segmentation, firewall inspection and explicitly allowed East-West paths to govern access to an authorized resource.
03 — Infrastructure Modernization
Use recovery to reconsider the legacy foundation.
We inventoried existing servers and virtualization and rebuilt the infrastructure instead of simply restoring the affected environment. Modernization included migration from VMware to Incus, but extended beyond replacing a hypervisor.
Priorities
- Retire legacy servers
- Move to supported operating systems
- Remove unnecessary systems
- Modernize virtualization
- Redesign network segmentation
- Clarify operational responsibilities
- Reduce infrastructure lifecycle debt
Virtualization
VMware → Incus
Reconsider servers, virtualization, networking and operations as one foundation.
↔ Scroll horizontally to see the full diagram.
View diagram as text
An inventory guides retirement, migration and replacement. Removing unnecessary assets and rebuilding the remaining estate together form the modernized infrastructure.
04 — Recovery & Immutable Backup
Preserve recoverable data through a compromise.
We designed immutable backup using Amazon S3, S3 Object Lock, WORM protection and retention settings. Recovery data should not depend on the same trust assumptions as compromised production infrastructure.
- Amazon S3
- Object Lock
- WORM
- Retention
- Recovery Readiness
The goal was more than backing up to S3: it was to maintain recovery data protected from changes and deletion during retention.
↔ Scroll horizontally to see the full diagram.
View diagram as text
A backup pipeline stores production data in S3. Object Lock applies WORM protection and retention to object versions.
Core Model
- 01Prevent
- 02Detect
- 03Contain
- 04Recover
Incident → Containment → Recovery → Restore from Protected Recovery Point
Object Lock protection depends on retention mode and permissions. Governance retention can be bypassed with the appropriate permission. Compliance retention prevents administrators from deleting or overwriting the protected object version during retention.
Backup Architecture
Strong backup depends on separated trust as well as storage durability.
↔ Scroll horizontally to see the full diagram.
View diagram as text
The design separates credentials and administrative permissions between production and recovery and controls backup writes. Restoration uses a separately authorized procedure. Arrows represent data flow; a one-way arrow alone does not guarantee access control or physical isolation.
05 — Continuous Resilience
Continuously understand the security state.
New vulnerabilities, configuration changes and undiscovered assets continue to change risk after modernization. We introduced an automated vulnerability management loop so security assessment continues beyond the immediate incident.
↔ Scroll horizontally to see the full diagram.
View diagram as text
Repeat asset discovery, vulnerability detection, risk prioritization, remediation, verification and continuous monitoring. Monitoring findings inform the next cycle.
Before / After
From implicit trust to explicit trust, segmentation, inspection and recoverability.
implicit trust → explicit trust + segmentation + inspection + recoverability
Before
Implicit Trust Architecture
- Legacy remote-access VPN
- Broad internal network trust
- Aging Linux / Windows servers
- Limited East-West inspection
- Aging virtualization platform
- Conventional / mutable backup
- Limited vulnerability visibility
- Accumulated infrastructure lifecycle debt
After
Explicit Trust Architecture
- Cloudflare Zero Trust
- Microsoft Entra ID Conditional Access
- Identity-centered access control
- VLAN segmentation
- Inter-segment firewall inspection
- Explicit East-West traffic policy
- Reduced lateral-movement opportunities
- Modernized virtualization with Incus
- S3 Object Lock, WORM-based immutable backup
- Retention policies
- Automated vulnerability management
- Continuous security improvement
Defense & Recovery Layers
Individual controls form one continuous system.
↔ Scroll horizontally to see the full diagram.
View diagram as text
Identity, access, network, workloads, detection and exposure, and recovery form six layers of one system. Recovery uses separate trust and permissions. Vertical connections show architectural relationships, not packet routing.
Outcome
Design for business continuity under compromise.
This was a redesign across Identity, Network, Infrastructure, Backup, Vulnerability Management and Operations as one system, extending beyond deployment of a security product.
- Make unauthorized access harder
- Reduce lateral movement
- Inspect internal traffic
- Limit the scope of damage
- Maintain protected recovery points
- Improve recovery capability
- Continuously discover and reduce new risks
Design to contain, detect and recover from compromise, without assuming that every intrusion can be prevented.
CoRISE Contribution
CoRISE’s contribution
Incident Response
- Initial response
- Containment support
- Initial-access investigation
- Impact assessment
Zero Trust & Identity
- Cloudflare Zero Trust migration
- Entra ID Conditional Access
- Identity-centered access redesign
Network Architecture
- VLAN redesign
- Trust-boundary redesign
- Inter-segment firewall inspection
- East-West traffic control
Infrastructure Modernization
- Legacy-server assessment
- Server lifecycle modernization
- VMware to Incus migration
- Infrastructure redesign
Recovery Architecture
- S3-based backup
- S3 Object Lock / WORM
- Retention policy
- Immutable recovery design
Continuous Security
- Automated vulnerability management
- Continuous security posture improvement
Technical Metadata
- Type
- Incident Response / Infrastructure Modernization
- Identity
- Microsoft Entra ID / Conditional Access
- Zero Trust
- Cloudflare Zero Trust
- Network
- VLAN Segmentation / Firewall Inspection
- Virtualization
- Incus
- Recovery
- Amazon S3 Object Lock / WORM
- Security Operations
- Automated Vulnerability Management