Projects & case studies

How Invictus secured enterprise networks

Firewalls, segmentation, secure wireless, SD-WAN and 24x7 SOC monitoring — delivered by certified engineers, documented end to end, and measured on outcomes rather than effort.

01100+Infrastructure projects
0215+Years in enterprise IT
0399.9%Managed uptime SLA
0424/7SOC coverage

Selected work

Security outcomes, not just installations

Each engagement below started with an audit and finished with documentation, handover and a measurable result the client's board could see.

01 / Chemical manufacturingVadodara, Gujarat · 2025

Shreeji Chemicals Pvt. Ltd.

Next-gen firewall rollout across a two-plant estate

Challenge

A flat network joined shop-floor OT devices, ERP servers and guest Wi-Fi on one broadcast domain. The perimeter firewall was end-of-life, outbound traffic was uninspected, and a single infected workstation could reach production PLCs.

Solution

Invictus designed an HA next-generation firewall pair per plant with IPSec tunnels between sites, then rebuilt the address plan into OT, IT and guest zones with least-privilege inter-zone policy. Inspection was enabled in monitor mode first and tuned over a 30-day traffic baseline before enforcement.

  • HA firewall pair at each plant with site-to-site IPSec tunnels
  • OT / IT / guest segmentation with least-privilege policy
  • SSL inspection, IPS and application control tuned over 30 days
  • Documented rule base, change process and quarterly review cadence

Outcome

4,100+ malicious outbound connections blocked in the first quarter, with zero production downtime during cutover and a rule base the internal team can now audit itself.

0 min OT downtime

02 / Financial servicesAhmedabad, Gujarat · 2025

Anand Capital Services

SOC and SIEM onboarding for a regulated back office

Challenge

An audit required continuous log retention, correlated alerting and a documented incident-response path. The in-house team of three could not staff detection around the clock, and logs were scattered across appliances with no central retention.

Solution

We deployed a SIEM with ingestion from firewalls, Active Directory, endpoints and VPN, wrote correlation rules for the threat scenarios their regulator cared about, and wrapped it in 24x7 SOC triage with named escalation contacts and severity-based response times.

  • SIEM deployment with firewall, AD, endpoint and VPN log ingestion
  • Correlation rules for privilege escalation, impossible travel and brute force
  • 24x7 SOC triage with severity-based escalation to named engineers
  • Monthly compliance reporting pack for the audit committee

Outcome

Mean time to detect fell from several days to under 12 minutes, and every open audit finding on monitoring was closed in a single review cycle.

12 min MTTD

03 / EducationVadodara, Gujarat · 2024

Parul Vidya Campus

High-density secure Wi-Fi for a 3,000-user campus

Challenge

Lecture halls dropped connections whenever a class went online together, and one shared passphrase gave students exactly the same network access as staff and administration systems.

Solution

After a predictive and on-site RF survey across nine blocks, Invictus deployed controller-managed Wi-Fi 6 access points with band steering and fast roaming, then split access by identity using 802.1X with role-based SSIDs and a policy-acceptance captive portal for guests.

  • Predictive and on-site RF survey across nine blocks
  • Wi-Fi 6 access points with controller-based roaming and band steering
  • 802.1X with role-based SSIDs for staff, students and guests
  • Captive portal with usage policy acceptance and bandwidth shaping

Outcome

Peak-hour disconnects were eliminated across all nine blocks and guest traffic is now fully isolated from administrative systems.

3,000 users

04 / LogisticsWestern India · 2024

Sagar Logistics Group

SD-WAN and routing refresh for eight branch sites

Challenge

Every branch backhauled all traffic through a single head-office link. Cloud ERP was slow at the far sites, and any head-office outage took all eight branches offline at once.

Solution

Invictus replaced the hub-and-spoke design with dual-uplink SD-WAN edges at each branch, added application-aware steering so cloud ERP and voice take the healthiest path, and centralised policy, monitoring and firmware management under one console.

  • Dual-uplink SD-WAN edges with automatic per-site failover
  • Application-aware routing for cloud ERP and voice traffic
  • Central policy, monitoring and firmware management
  • Runbooks and on-site handover training for branch IT staff

Outcome

Twelve months with no branch WAN outage, and cloud ERP latency down roughly 60% at the furthest sites.

-60% latency

05 / HealthcareGujarat · 2024

Sterling Multispeciality Hospital

Segmentation and endpoint hardening for a hospital network

Challenge

Biomedical devices, clinical workstations and public waiting-room Wi-Fi all shared one network. Nobody could say what was connected, and device-to-device traffic was completely unmonitored.

Solution

We profiled every connected asset, then carved the estate into clinical, biomedical, corporate and public zones with enforced inter-zone rules. Endpoint protection and centralised patching followed, plus an incident-response playbook written around 24-hour hospital operations.

  • Device discovery and profiling across all connected assets
  • Clinical, biomedical, corporate and public segmentation zones
  • Endpoint protection rollout with centralised patch management
  • Incident-response playbook aligned to hospital operating hours

Outcome

Lateral movement between clinical and public networks is now blocked by policy, and a live asset inventory is maintained continuously.

4 secure zones

06 / Corporate groupVadodara & Surat · 2023

Rajhans Group

Managed IT and AMC for a multi-office group

Challenge

Three offices ran three different vendors, patching was ad hoc, backups were unverified and there was no single accountable contact when something broke.

Solution

Invictus standardised switching, routing and firewall hardware across all three sites under one AMC, added 24x7 monitoring with proactive patch and backup management, and introduced quarterly service reviews with measured uptime and incident reporting.

  • Standardised switching, routing and firewall stack across all sites
  • 24x7 monitoring with proactive patch and backup management
  • Single AMC covering hardware, cabling and support SLAs
  • Quarterly service reviews with uptime and incident reporting

Outcome

Support tickets fell 45% year on year against a measured 99.9% uptime across the three offices.

-45% tickets

Project enquiry

Request a case study or scope your own

Ask for the full write-up of any engagement above — including architecture, hardware and timelines — or tell us about your own network and we'll come back within one business day.

  • Full case study PDF including topology and hardware list
  • Reference call with a comparable client where permitted
  • Indicative scope and timeline for your own environment