Federal agency accelerates zero trust adoption
A federal agency under EO 14028 with an open-access network, no traffic baseline, and no segmentation. ModernCyber assessed it against the CISA Zero Trust Maturity Model and turned the gaps into a sequenced three-year rollout — year one is in adoption now.
Background
A US federal agency is required by Executive Order 14028 and OMB Memorandum M-22-09 to adopt zero trust principles. Its production network had grown up under a perimeter model: open access, overlapping point solutions, and no shared identity or telemetry to build policy on.
Challenges
- Federal mandate on the clock — EO 14028 and OMB M-22-09 require zero trust adoption on a fixed timeline, with reporting.
- Incomplete visibility — no baseline for normal network behavior, so deviations could not be identified.
- Undefined access policies — the agency ran an open access model spread across multiple solutions.
- No segmentation — no group- or identity-based policy, and neither macro nor micro segmentation.
- Limited automation — manual processes left little resilience against sophisticated attacks.
Solution
The assessment produced an incremental three-year rollout plan, sequenced so each year's controls stand on the previous year's data:
- Zero trust assessment mapped to the CISA Zero Trust Maturity Model — a survey plus detailed analysis of the network, devices, and security policies, fixing the agency's real architecture, maturity, and strategy rather than an aspirational one.
- Year 1 — establish visibility and define use cases: Cisco Secure Network Analytics and Cisco ISE for network and user-access visibility, then dynamic group policy with ISE and Software-Defined Access.
- Year 2 — access policy controls and macrosegmentation: enforce network access control, collect identity and device-health context, and feed identity into the visibility stack for user attribution and enforcement.
- Year 3 — microsegmentation and automation: host- and network-based segmentation (Cisco TrustSec, Cisco ACI, VMware NSX), SIEM-driven incident response, and orchestration for dynamic policy at lower operating cost.
Outcomes
- Year 1 moved straight into adoption — the agency committed to a broad deployment of Cisco Secure Network Analytics and Cisco ISE, exactly as the plan sequenced it.
- Mandates aligned — the program meets the requirements of EO 14028 and OMB Memorandum M-22-09.
- Reduced attack surface — least-privilege access replaced open access as the default.
- Operational efficiency — dynamic policy and automation, with visibility and identity tooling turning telemetry into actionable enforcement.
- A framework that scales — an architecture that absorbs new threats and new mandates without another redesign.
Get the same outcome.
ModernISE Platform and Expert, and Cisco Security Expert as a Service — Cisco Security experts operating as an extension of your team.