Skip to content
CoRISE
CASE / 04Security & Resilience · Architecture & Modernization

Incident-Driven Zero Trust Infrastructure

Following a ransomware incident, the work spanned initial forensic response, investigation of initial access and impact, and infrastructure reconstruction across networking, identity, virtualization, backup and vulnerability management.

The goal was not to return to the pre-incident state. Beyond closing the entry point, we redesigned the infrastructure to contain damage, detect compromise and recover if a similar incident occurred again.

Redesign, beyond recovery.

From implicit trust to explicitly verified access paths.

↔ Scroll horizontally to see the full diagram.

From implicit trust to explicit access controlBefore: a legacy VPN reaches a broad internal trust zone. After: user and device, identity, conditional access, Zero Trust access, segmentation and firewall inspection govern access to explicitly authorized workloads. Recovery uses a separate trust domain. This conceptual evaluation flow is not a packet routing sequence.BEFORE — IMPLICIT TRUSTAFTER — EXPLICIT ACCESS CONTROLPROTECTED RECOVERYEXTERNALACCESSLEGACY VPNBROAD INTERNALTRUSTLEGACY SERVERSFILE / VIRTUALINFRASTRUCTUREUSER / DEVICEIDENTITYCONDITIONALACCESSZERO TRUSTACCESSSEGMENTEDNETWORKFIREWALL INSPECTIONEXPLICITLY AUTHORIZEDWORKLOADSIMMUTABLE RECOVERYSEPARATE TRUST DOMAIN
Fig. 01 — Identity, policy and inspection govern access; recovery has a separate trust domain.

One system, beyond individual products.

The work went beyond malware removal, fixing a single vulnerability, replacing one product or restoring encrypted servers.

It transformed the architecture across Identity, Access, Network Trust, Segmentation, Traffic Inspection, Virtualization, Backup, Vulnerability Management and Operations.

  • Identity
  • Access
  • Network Trust
  • Segmentation
  • Traffic Inspection
  • Virtualization
  • Backup
  • Vulnerability Management
  • Operations

Contain the damage. Understand what happened.

A compromise originating through external access affected file servers and virtual servers. The environment contained Linux and Windows servers that had not been updated for an extended period, alongside legacy infrastructure.

Initial response covered:

↔ Scroll horizontally to see the full diagram.

Incident findings inform redesignContainment and investigation produce findings that inform the subsequent redesign.CONTAINMENTINVESTIGATIONFINDINGSREDESIGN INPUT
Fig. 02 — Initial response findings inform architectural redesign.

Examine structural risk across the environment.

↔ Scroll horizontally to see the full diagram.

Eight structural risk surfacesEight risks: legacy access, aging Linux and Windows servers, broad internal trust, insufficient East-West inspection, aging virtualization, mutable backup, limited vulnerability visibility and lifecycle debt.ONE UNDIFFERENTIATED ENVIRONMENTLEGACY REMOTE-ACCESS MODELAGING LINUX /WINDOWS SERVERSBROAD INTERNALTRUSTINSUFFICIENTEAST-WEST INSPECTIONAGING VIRTUALIZATIONENVIRONMENTMUTABLE /CONVENTIONAL BACKUPSINSUFFICIENTVULNERABILITY VISIBILITYACCUMULATEDLIFECYCLE DEBT
Fig. 03 — Multiple structural risk surfaces across one environment.

Closing the entry point alone leaves the same structural risks in place.

Remove the assumption that the internal network can be trusted.

We moved from a traditional VPN-centered model to identity-centered access using Cloudflare Zero Trust and Microsoft Entra ID Conditional Access.

Internal network trust was redesigned at the same time: VLAN segmentation, inter-segment firewall inspection, East-West traffic controls, explicitly authorized paths, less implicit trust, identity-based access and fewer opportunities for lateral movement.

↔ Scroll horizontally to see the full diagram.

Identity-centered external accessEntra ID authenticates the user or device. Conditional Access and Cloudflare Zero Trust policies govern access to authorized resources. This is a conceptual evaluation flow.USER / DEVICEENTRA IDCONDITIONAL ACCESSCLOUDFLARE ZERO TRUSTAUTHORIZED RESOURCE
External access starts with identity.

↔ Scroll horizontally to see the full diagram.

Explicit inspection between segmentsA firewall inspects traffic between segments A and B and permits it according to explicit policy.SEGMENT ASEGMENT BSOURCEFIREWALLINSPECTIONExplicit PolicyRESOURCE
Segmentation defines trust boundaries and inspection paths.

Zero Trust extends beyond replacing remote access.

Identity, device and user context, access policy, segmentation, internal traffic inspection and reduced lateral movement form one architecture.

↔ Scroll horizontally to see the full diagram.

Identity and network evaluations convergeIdentity, policy and access decisions combine with network segmentation, firewall inspection and explicitly allowed East-West paths to govern access to an authorized resource.IDENTITY DIMENSIONNETWORK DIMENSIONIDENTITYPOLICYACCESS DECISIONNETWORK SEGMENTFIREWALL INSPECTIONEXPLICITLY ALLOWEDEAST-WEST PATHAUTHORIZED RESOURCE
Fig. 04 — Identity and network evaluations converge on access to an authorized resource.

Use recovery to reconsider the legacy foundation.

We inventoried existing servers and virtualization and rebuilt the infrastructure instead of simply restoring the affected environment. Modernization included migration from VMware to Incus, but extended beyond replacing a hypervisor.

Priorities

VMware → Incus

Reconsider servers, virtualization, networking and operations as one foundation.

↔ Scroll horizontally to see the full diagram.

Inventory, retire, migrate and replaceAn inventory guides retirement, migration and replacement. Removing unnecessary assets and rebuilding the remaining estate together form the modernized infrastructure.LEGACY ESTATEINVENTORYRETIREMIGRATEREPLACEMODERNIZEDINFRASTRUCTURE
Fig. 05 — Inventory guides retirement, migration and replacement.

Preserve recoverable data through a compromise.

We designed immutable backup using Amazon S3, S3 Object Lock, WORM protection and retention settings. Recovery data should not depend on the same trust assumptions as compromised production infrastructure.

  • Amazon S3
  • Object Lock
  • WORM
  • Retention
  • Recovery Readiness

The goal was more than backing up to S3: it was to maintain recovery data protected from changes and deletion during retention.

↔ Scroll horizontally to see the full diagram.

Creating protected recovery pointsA backup pipeline stores production data in S3. Object Lock applies WORM protection and retention to object versions.WORM / RETENTIONPRODUCTIONDATABACKUPPIPELINEAMAZON S3OBJECT LOCKIMMUTABLERECOVERY POINT
Fig. 06 — Production Data → Backup Pipeline → S3 → Object Lock → Immutable Recovery Point
  1. 01Prevent
  2. 02Detect
  3. 03Contain
  4. 04Recover

Incident → Containment → Recovery → Restore from Protected Recovery Point

Object Lock protection depends on retention mode and permissions. Governance retention can be bypassed with the appropriate permission. Compliance retention prevents administrators from deleting or overwriting the protected object version during retention.

Strong backup depends on separated trust as well as storage durability.

↔ Scroll horizontally to see the full diagram.

Separate production and recovery trustThe design separates credentials and administrative permissions between production and recovery and controls backup writes. Restoration uses a separately authorized procedure. Arrows represent data flow; a one-way arrow alone does not guarantee access control or physical isolation.PRODUCTION TRUST DOMAINRECOVERY TRUST DOMAINBACKUP WRITEAUTHORIZED RESTOREPRODUCTION CREDENTIALSSEPARATE RECOVERY PERMISSIONSFILE SERVEROPERATIONALCREDENTIALSPRODUCTION INFRASTRUCTUREBACKUP PROCESSAMAZON S3OBJECT LOCKRETENTION POLICYIMMUTABLE RECOVERY POINTS
Fig. 07 — Separate credentials and permissions; control backup and restoration paths.

Continuously understand the security state.

New vulnerabilities, configuration changes and undiscovered assets continue to change risk after modernization. We introduced an automated vulnerability management loop so security assessment continues beyond the immediate incident.

↔ Scroll horizontally to see the full diagram.

Six-stage continuous vulnerability managementRepeat asset discovery, vulnerability detection, risk prioritization, remediation, verification and continuous monitoring. Monitoring findings inform the next cycle.CONTINUOUS ASSESSMENT & IMPROVEMENTASSETDISCOVERYVULNERABILITYDETECTIONRISKPRIORITIZATIONREMEDIATIONVERIFICATIONCONTINUOUSMONITORING
Fig. 08 — Continuous assessment and improvement beyond a one-off incident review.

From implicit trust to explicit trust, segmentation, inspection and recoverability.

implicit trust → explicit trust + segmentation + inspection + recoverability

Implicit Trust Architecture

Explicit Trust Architecture

Individual controls form one continuous system.

↔ Scroll horizontally to see the full diagram.

Six defense and recovery layersIdentity, access, network, workloads, detection and exposure, and recovery form six layers of one system. Recovery uses separate trust and permissions. Vertical connections show architectural relationships, not packet routing.ONE COHERENTSYSTEMIDENTITYEntra ID / Conditional AccessACCESSCloudflare Zero TrustNETWORKVLAN Segmentation / Firewall InspectionWORKLOADSModernized Servers / IncusDETECTION & EXPOSUREAutomated Vulnerability ManagementRECOVERYS3 Object Lock / WORM / Retention
Fig. 09 — Six layers form one coherent system.

Design for business continuity under compromise.

This was a redesign across Identity, Network, Infrastructure, Backup, Vulnerability Management and Operations as one system, extending beyond deployment of a security product.

  • Make unauthorized access harder
  • Reduce lateral movement
  • Inspect internal traffic
  • Limit the scope of damage
  • Maintain protected recovery points
  • Improve recovery capability
  • Continuously discover and reduce new risks

Design to contain, detect and recover from compromise, without assuming that every intrusion can be prevented.

CoRISE’s contribution

  • Initial response
  • Containment support
  • Initial-access investigation
  • Impact assessment
  • Cloudflare Zero Trust migration
  • Entra ID Conditional Access
  • Identity-centered access redesign
  • VLAN redesign
  • Trust-boundary redesign
  • Inter-segment firewall inspection
  • East-West traffic control
  • Legacy-server assessment
  • Server lifecycle modernization
  • VMware to Incus migration
  • Infrastructure redesign
  • S3-based backup
  • S3 Object Lock / WORM
  • Retention policy
  • Immutable recovery design
  • Automated vulnerability management
  • Continuous security posture improvement
Incident Response / Infrastructure Modernization
Microsoft Entra ID / Conditional Access
Cloudflare Zero Trust
VLAN Segmentation / Firewall Inspection
Incus
Amazon S3 Object Lock / WORM
Automated Vulnerability Management

Contact

Connect incident response to the next architecture.

Discuss infrastructure redesign across ransomware resilience, Zero Trust migration, network architecture, immutable backup, vulnerability management and legacy modernization, with ongoing operations in mind.

Start a conversation

Back to all work