CASE STUDY · ZERO TRUST ASSESSMENT

Federal agency accelerates zero trust adoption

A federal agency under EO 14028 with an open-access network, no traffic baseline, and no segmentation. ModernCyber assessed it against the CISA Zero Trust Maturity Model and turned the gaps into a sequenced three-year rollout — year one is in adoption now.

Background

A US federal agency is required by Executive Order 14028 and OMB Memorandum M-22-09 to adopt zero trust principles. Its production network had grown up under a perimeter model: open access, overlapping point solutions, and no shared identity or telemetry to build policy on.

Challenges

  • Federal mandate on the clock — EO 14028 and OMB M-22-09 require zero trust adoption on a fixed timeline, with reporting.
  • Incomplete visibility — no baseline for normal network behavior, so deviations could not be identified.
  • Undefined access policies — the agency ran an open access model spread across multiple solutions.
  • No segmentation — no group- or identity-based policy, and neither macro nor micro segmentation.
  • Limited automation — manual processes left little resilience against sophisticated attacks.

Solution

The assessment produced an incremental three-year rollout plan, sequenced so each year's controls stand on the previous year's data:

  • Zero trust assessment mapped to the CISA Zero Trust Maturity Model — a survey plus detailed analysis of the network, devices, and security policies, fixing the agency's real architecture, maturity, and strategy rather than an aspirational one.
  • Year 1 — establish visibility and define use cases: Cisco Secure Network Analytics and Cisco ISE for network and user-access visibility, then dynamic group policy with ISE and Software-Defined Access.
  • Year 2 — access policy controls and macrosegmentation: enforce network access control, collect identity and device-health context, and feed identity into the visibility stack for user attribution and enforcement.
  • Year 3 — microsegmentation and automation: host- and network-based segmentation (Cisco TrustSec, Cisco ACI, VMware NSX), SIEM-driven incident response, and orchestration for dynamic policy at lower operating cost.

Outcomes

  • Year 1 moved straight into adoption — the agency committed to a broad deployment of Cisco Secure Network Analytics and Cisco ISE, exactly as the plan sequenced it.
  • Mandates aligned — the program meets the requirements of EO 14028 and OMB Memorandum M-22-09.
  • Reduced attack surface — least-privilege access replaced open access as the default.
  • Operational efficiency — dynamic policy and automation, with visibility and identity tooling turning telemetry into actionable enforcement.
  • A framework that scales — an architecture that absorbs new threats and new mandates without another redesign.
3-yr
Sequenced zero trust rollout plan, mapped to the CISA maturity model
2
Federal mandates aligned — EO 14028 and OMB M-22-09
Yr 1
Adopted: Cisco ISE and Secure Network Analytics for visibility

Get the same outcome.

ModernISE Platform and Expert, and Cisco Security Expert as a Service — Cisco Security experts operating as an extension of your team.

Integrated · Agile · Zero Trust · AI