The network they all run on
Networking
Most networks were built to connect people. Almost none were built to answer questions about them. That difference does not matter until somebody asks. Then it is the only thing that matters, and it is not something you can add afterwards without taking the network apart.
For the reader who arrived at capability first and needs the problem stated before the answer means anything: three buildings, three ordinary days.
And the same standard, applied to us rather than to you: accountability, in our own house.
What this system covers
- Identity and onboarding
- Guest and staff onboarding through captive portals with OTP, sponsor approval or per-stay credentials, so that a session belongs to a person rather than to a device.
- Access control across wired, wireless and VPN
- 802.1X with RADIUS, certificate-based passwordless access, single sign-on and two-factor, integrated with existing directory infrastructure.
- Device profiling and posture
- Detecting what is actually connected (by scan, by SNMP, by manufacturer identifier and by posture agent) and applying policy to it, including BYOD and IoT.
- Logging, retention and residency
- Collection from syslog, NetFlow and other sources, encrypted before storage, personally identifiable information masked, retained in India for the required period and archived to cold storage on policy.
- Monitoring and fault management
- Centralised monitoring across the estate, so a failure is reported rather than discovered, and so uptime is a measured figure rather than an impression.
- Infrastructure
- Access points, switching, gateways and multi-ISP resilience where the physical layer genuinely needs replacing. Deliberately last on this list.
Design decisions
Eight choices that determine whether a network carries a security system or exposes one.
- 01 Keeping the cameras on their own networkCameras are computers. They are cheap, they sit outside, and most of them stopped getting updates years ago. Press the button on both and see how far one of them reaches.
Cameras and door controllersBlocked
- Camera 14
- Camera 22
- Door controller
The company’s own computersBlocked
- Accounts PC
- HR files
- Mail server
Guest wi-fiBlocked
- Visitor laptop
- Visitor phone
One flat networkEverything is on one network because that was the simplest way to wire it. From one camera, everything else is reachable: the accounts computer, the HR files, the mail server, and the visitor sitting in reception.
SeparatedThe same camera, the same problem. It reaches the other two cameras and the door controller, and nothing else. The accounts computer, the HR files and the guest wi-fi are on the other side of a boundary it cannot cross.
The camera was never the target. It was the way in, because it was the least protected thing with a cable to everything else. Separating it afterwards means taking the network apart.
- 02 Knowing which person was on your network, not which roomA request arrives asking who sent something at 22:14. This is the log you hand over.
- 22:14Anil MehtaOne-time code sent to his own phone
- 22:31Ravi ShahSigned in as himself, room 208
- 23:02Contractor, Sunrise AVSponsored by the duty manager, expires at 06:00
Room number and surnameBoth are printed on a luggage tag and audible at reception. Anyone in the building can sign in as room 704. Your log names a guest who may have been asleep, or in another city, and he will say so.
A personThree sessions, three people, each identified by something only they had. If a request arrives about 22:14, you can answer it, and the answer will hold.
- 03 Counting the devices before buying the switchNine things need a cable. The switch has eight sockets.
- Cam 1
- Cam 2
- Cam 3
- Cam 4
- Cam 5
- Cam 6
- Door ctl
- Recorder
- Intercom
- free
- free
- free
Nothing waiting.
Eight portsSomebody plugs a small unmanaged switch into one of the eight to make room. Now two cameras share one cable, nobody wrote it down, and the drawing still says eight devices on eight ports.
Counted firstTwelve ports for nine devices. Three spare, which is what you need when somebody adds a camera in year two, and nobody has to improvise on site.
- 04 Log retention and residency decided at specificationHow long, where, and who can reach them. Logs are personal data, and how they are handled is a design decision rather than an operational habit.
- 05 Administrative access defined and recordedWho can reach the security network, from where, with what credential, and whether the session is logged. Standing remote access is a decision, not a convenience.
- 06 Firmware and patching planned over the system's lifeWhich devices will receive updates, from whom, and for how long. A camera with no update path is a decision being taken by default.
- 07 Power and resilience sized for what must survivePoE budget with headroom, UPS on the switches that matter, and a stated position on what stops when the supply does.
- 08 Monitored as a system, not assumed as a utilityLink state, port state and device reachability reported to somebody. A remote site that has been offline for a fortnight looks identical to one that has not.
None of these is visible once the building is finished. All of them are decided before a cable is pulled.
Standards and approvals
- Digital Personal Data Protection Act 2023 and DPDP Rules 2025 Rules notified 13 November 2025
- Rule 6 requires encryption, access control and a one-year retention floor for logs of access to personal data. Rule 7 requires notification to the Data Protection Board on discovery of a breach and to affected individuals within seventy-two hours. Substantive obligations enforceable from 13 May 2027. Penalties up to ₹250 crore for failure to implement reasonable security safeguards under Section 8(5), and up to ₹200 crore for failure to notify, imposed per violation.
- CERT-In Directions, 28 April 2022 Section 70B, IT Act 2000. Already in force
- Logs enabled across all ICT systems and retained securely for a rolling 180 days within Indian jurisdiction; cyber incidents reported within six hours of being noticed; clocks synchronised to NIC or NPL time servers. Logs produced to CERT-In on request.
- Where the two differ, the longer applies
- One year of logs rather than 180 days. Sectoral regulators in banking and financial services impose longer periods again, and those take precedence over both.
- Telecom and internet-provider obligations
- Where a telecom or internet-provider obligation applies to your operation, internet protocol detail records fall within it. Whether it reaches you is a question for your counsel, not for us.
- Sector and client audit standards
- Studios, card data environments and client vendor assessments impose requirements contractually rather than statutorily. They differ by client and they routinely exceed anything local code asks for.
What we hand over
- Attribution procedure
- The written answer to a lawful request: who produces it, from which system, in what format, within what time.
- Network and VLAN documentation
- Segmentation, what sits on which segment, and why.
- Policy record
- Every access policy, the role or device class it applies to, and what it permits.
- Retention and residency statement
- What is logged, where it physically sits, for how long, and when it is destroyed. The logs remain in your custody throughout.
- Incident reporting SOP
- The six-hour path, with a named coordinator and a designated alternate.
- Currency register
- Firmware, licences and support expiry, tracked with action dates.
| Interface | Normally contracted to | When it is nobody’s |
|---|---|---|
| Every security device on the network | Split between IT and the security vendor | Cameras and controllers sit on the corporate network, unsegmented and unpatched, and become the way in rather than the way of watching. |
| Recording platform residency | Security vendor, unexamined | Footage of an Indian building sitting on a foreign edge, discovered during an audit. |
| Access control to directory | IT, engaged late | Credentials that outlive employment, because the two systems were never joined. |
| Remote support access | Nobody, until it is needed | An unmanaged tunnel opened in a hurry and never closed. |
| Guest network to property system | Hospitality IT and the Wi-Fi vendor | Authentication on a surname and a room number, and a log that says something untrue. |
Across the spine
Networking appears at all six stages. It governs none.
It is the substrate. That is why it sits outside the six on every other page.
Written to be checked
Have a network design you would like reviewed before it goes out?
We review specifications, drawings and cause-and-effect matrices for consultants and project management teams. Findings in writing, no obligation, and no approach to your client.
Findings in writing. No obligation.
Request a design review