Skip to main content
NexITC
C14 · CYBERSECURITY · 12-MONTH MIN · RUN · OUTCOME · SECURE

Least privilege,
kept least privileged.

C14 · Zero-Trust AccessOps™ is NexITC's managed Zero Trust access operations subscription for UAE organisations securing workforce, contractors and approved third parties across private applications, SaaS, cloud and on-premises resources. Not a Zero Trust architecture build. Not IAM administration. Not endpoint security. A 12-month subscription running application-access policy operations, user/application onboarding, device-context enforcement, contractor and unmanaged-device access, exception governance, policy optimisation and monthly executive Zero Trust access scorecard — with Practice Lead — Cybersecurity as named account owner. C14 is the Run layer after foundational Zero Trust controls and a supported ZTNA/SASE or application-access platform are operational.

COMMITMENT
12 mo min
SERVICE ELEMENTS
5 named
COMMERCIAL
Managed access subscription
C14 · PROJECTION / ZERO TRUST ACCESS
C14
BASELINE
Access technology deployed
ACCESS TECHNOLOGY DEPLOYED
C14
TARGET
Least privilege sustained
LEAST PRIVILEGE SUSTAINED
ONBOARD
BASELINE
STEADY
REVIEW
APPLICATION ACCESS
SPECIFIC
DEVICE CONTEXT
ENFORCED
THIRD-PARTY ACCESS
CONSTRAINED
EXCEPTIONS
TIME-BOUND
C14 · ZERO-TRUST ACCESSOPS™
ILLUSTRATIVE
§ 00 · THESIS
01
ZERO TRUST DRIFTS
AFTER IMPLEMENTATION.

Zero Trust can be implemented successfully and still degrade operationally.

Users change jobs. Contractors come and go. Applications are added. New subsidiaries connect. Devices fall out of compliance. Emergency exceptions become permanent. Entitlement groups expand. Teams request broader access because it is easier than designing application-specific policy. The architecture has not failed. The operating discipline has. Zero Trust is therefore not sustained by an architecture diagram or a completed implementation project. It is sustained through continuous access operations. C14 provides that cadence.

STATE · ACCESS-ENABLED
ZTNA/SASE or remote-access technology deployed. Identity integrated. Policies exist. Application onboarding occurs project-by-project. Contractors receive exceptions. Device posture is available but not consistently enforced. Access reviews happen periodically.
STATE · ACCESS-OPERATED
Application-specific access continuously governed. Identity and device context incorporated into policy. Contractors constrained. Unmanaged-device pathways defined. Exceptions expire or are explicitly renewed. Broad access progressively reduced. Executive access-risk posture measurable.
§ 01 · OPERATING STREAMS

Six operating streams,
keeping Zero Trust from becoming yesterday's architecture.

STREAM 01
CONTINUOUS

Application-access policy operations

Operate least-privilege access policy across in-scope applications and resources. Policies are reviewed against: identity; user group; application; location/context where appropriate; device posture; business requirement; and agreed security classification. The objective is application access. Not broad network presence.

STREAM 02
AS NEEDED / MONTHLY

User, group & application onboarding

Bring new applications, authorised groups and relevant resources into the Zero Trust operating model. New access does not default to broad connectivity. The onboarding question becomes: “Which specific application should this identity reach, under which conditions?”

OUTCOME
SUSTAINED
LEAST PRIVILEGE
ACCESS DRIFT GOVERNED
STREAM 03
CONTINUOUS

Device-context enforcement

Consume approved endpoint and device-compliance signals as access-policy inputs. A healthy managed device may receive normal access. An unmanaged or materially non-compliant device may receive restricted, browser-isolated, read-only or denied access depending on architecture. C14 consumes device context. [[C11|C11 SecureWorkplace™]] owns the underlying workforce-protection posture.

STREAM 04
CONTINUOUS

Contractor & unmanaged-device access governance

Contractors, partners, temporary workers and approved unmanaged-device scenarios receive constrained access according to explicit policy. The objective is to avoid creating broad permanent network access for users who require only a small set of applications. External-user access is reviewed as a distinct risk class.

STREAM 05
MONTHLY

Access exception & policy optimisation

Review: over-broad policies; dormant entitlements; expired projects; aged contractor access; unused application groups; exceptions; persistent access failures; recurring policy workarounds. Every material exception should have owner, rationale and expiry.

STREAM 06
MONTHLY

Executive Zero Trust access scorecard

Monthly reporting covers: application-specific coverage; broad-access reduction; device-context use; external-user access; aging exceptions; inactive access; policy-health trend.

EXPLICITLY NOT COVERED
Zero Trust foundation build
That's B9 Zero-Trust Core Build™. B9 establishes the foundational identity, MFA/PAM, segmentation and security-control architecture. C14 runs access continuously afterwards.
ZTNA/SASE implementation where no supported platform exists
C14 assumes an operational access-enforcement platform. Platform selection and implementation are separately scoped.
Endpoint protection
That's C11 SecureWorkplace™. C14 uses posture. C11 operates posture.
IAM/PAM platform administration
C14 does not replace enterprise identity lifecycle, HR-driven joiner/mover/leaver processes or privileged-access administration. It consumes identity context.
Incident response
Suspicious or malicious access becomes a security event and escalates to C7 SecOpsCommand™ or the customer's SOC.
§ 02 · ANNUAL CADENCE

Twelve-month subscription.
Access policy under continuous ownership.

M01 · Onboard — applications/resources inventoried, protected-user and external-user classes defined, identity groups mapped, existing ZTNA/SASE policies reviewed, device-context sources confirmed, exception inventory captured, first scorecard issued. M02–03 · Baseline — broad policies identified, application-specific coverage measured, contractor access reviewed, aging exceptions classified, policy optimisation backlog established, target trajectories agreed. M04–12 · Steady state — continuous access operations, application/user onboarding, device-context enforcement, third-party access governance, monthly exception review, quarterly entitlement/policy optimisation, monthly executive scorecard. M11 · Annual review — access-model trajectory reviewed, dormant and broad access reduction measured, year-two applications/populations agreed, renewal gate against measurable operating value.

Q 01Q 02Q 03Q 04M01 · OnboardM02–12 · Baseline → steady stateM11 · Annual reviewAccess baseline & first scorecard issuedEND M 01Access-model trajectory reviewedM 11 · ANNUAL REVIEWRenewalEND M 12OPERATING RHYTHMContinuous access operations · Monthly exception review & scorecard · Quarterly policyoptimisationNAMED ACCOUNTABILITYPractice Lead — Cybersecurity (CEO escalation within 24hours)
§ 03 · OPERATING MODEL

Zero Trust,
operated after the architecture is built.

OPERATING MODEL · SIX STEPS
INVENTORY → REPORT
Zero Trust, operated after the architecture is built.
01
Inventory application access
Understand which users require which resources.
02
Operate least-privilege policy
Access is specific by default.
03
Consume identity & device context
Trust is evaluated continuously.
04
Govern external access
Contractors and unmanaged devices receive purpose-specific pathways.
05
Expire exceptions
Temporary access should remain temporary.
06
Report access posture
Executive leadership sees whether Zero Trust remains real after implementation.
!
DISCLOSURE · INDEPENDENCE
C14 is not a ZTNA/SASE licence resale. NexITC operates application-access policy across an approved architecture/platform where operational access and integrations are available. Where the platform itself is unsuitable, that is surfaced as a Build/architecture issue rather than quietly worked around inside the retainer.
§ 04 · BASELINE VS MANAGED

From Zero Trust implemented
to Zero Trust sustained.

BASELINE
M01
STATE_01
ZTNA/SASE deployed
PROJECT COMPLETE
STATE_02
Broad access groups remain
LEAST PRIVILEGE PARTIAL
STATE_03
Contractors accumulate
EXCEPTIONS AGE
STATE_04
Device posture available
POLICY USE INCONSISTENT
STATE_05
Application onboarding varies by team
DRIFT RETURNS
C14 · CADENCE
MANAGED
M04+
PLATFORM_01
Context-Aware Application Access
Identity · Application · Device · External User · Business Need
PLATFORM_02
Access Governance
Onboard · Optimise · Expire · Review · Report
↓ SPECIFIC · CONTEXTUAL · TIME-BOUND · MEASURED ↓

Steady-state outcome: application-specific access grows. Broad network-level access decreases. Device posture becomes an operational input. Contractor access is constrained. Exceptions expire. Dormant access is reduced. Executive leadership sees whether least privilege is improving.

§ 05 · REPRESENTATIVE SCENARIO

A 1,200-user UAE multi-site organisation,
from implemented Zero Trust to operated Zero Trust.

Illustrative composite — not a specific client.

SCENARIO / C14 / UAE MULTI-SITE · ILLUSTRATIVE COMPOSITE
COMMITMENT · 12 MO
USERS
1,200
APPLICATIONS IN INITIAL SCOPE
40
APPLICATION-SPECIFIC ACCESS COVERAGE
45% → >85%Representative target
AGED ACCESS EXCEPTIONS
65% ↓Representative target by Q3
SITUATION

A multi-site UAE organisation has implemented identity integration and ZTNA/SASE for a hybrid workforce. The technology works. However, many access policies were created during migration under time pressure. Some application groups remain broad. Contractors are managed through recurring exceptions. Device posture is technically available but inconsistently used. Application owners request access through manual processes.

ENGAGEMENT

C14 establishes the application-access baseline. Policies are classified according to specificity. Contractor and external-user access is separately reviewed. Device-context enforcement is standardised where architecture permits. Exceptions receive owner and expiry. Quarterly policy optimisation progressively reduces broad access. New applications enter through a consistent onboarding process.

OUTCOME

Application-specific coverage rises materially. Broad access decreases. Aged exceptions reduce. Contractor access becomes time-bound. Device posture becomes an operational access input. The organisation no longer treats Zero Trust as an implementation completed last year. It becomes a continuously operated access posture.

§ 06 · SERVICE ELEMENTS

Five service elements,
with continuous and monthly cadence.

E_01

Application Access Operations

Least-privilege access-policy governance. SLA / CADENCE — Policy operated continuously; application-specific coverage reviewed monthly.

E_02

Device-Context Enforcement

Use of approved endpoint/device posture in access decisions. SLA / CADENCE — Device/compliance signals consumed as policy inputs continuously, per agreed architecture.

E_03 · CORE

Third-Party & Unmanaged Access

Controlled access pathways for contractors and approved external scenarios. SLA / CADENCE — Governed continuously; material exceptions reviewed monthly.

E_04

Policy & Exception Optimisation

Broad access, dormant entitlements and aging exceptions. SLA / CADENCE — Reviewed monthly; policy optimisation quarterly.

E_05 · MONTHLY SCORECARD

Zero Trust Access Scorecard

Executive access-posture reporting. SLA / CADENCE — Delivered monthly with security/infrastructure sponsor review.

CADENCE
MONTHLY
§ 07 · OUTCOMES

Six outcome metrics,
measured baseline to steady state.

Representative targets — not guaranteed results for a specific client.

01 · APPLICATION-SPECIFIC ACCESS COVERAGE
TRENDING ↑
02 · BROAD ACCESS
TRENDING ↓
03 · DEVICE-CONTEXT COVERAGE
MEASURED
04 · THIRD-PARTY ACCESS
GOVERNED
05 · ACCESS-EXCEPTION AGING
SLA-MANAGED
06 · REVIEW CADENCE
MONTHLY
§ 08 · FIT

Honest scoping.

PREREQUISITES
Move fast when these conditions are in place at onboarding.
01
Security/IAM sponsor

Owns access-policy decisions.

02
Identity architecture established

C14 consumes identity context. It does not build the identity foundation.

03
Supported ZTNA/SASE/application-access platform operational

The service runs access. It does not hide platform implementation inside a Run retainer.

04
Application/resource inventory available

Perfect inventory is not required. Enough must exist to govern application-specific access.

05
12-month commitment appetite

Access drift is a recurring operating problem. The service is designed to manage it over time.

NOT SUITABLE IF
These patterns indicate a different engagement is a better fit.
You need foundational Zero Trust design/build

→ B9 Zero-Trust Core Build™

You need endpoint protection

→ C11 SecureWorkplace™

You need IAM/PAM implementation

You only need remote-access licences

§ 09 · COMMERCIAL

Managed Zero Trust access subscription.
Monthly cadence. No surprises.

COMMERCIAL MODEL
Managed access subscription, 12-month minimum

Pricing based on: protected-user population; application/resource count; sites; external-user complexity; device-context integrations; and agreed SLA.

COMMITMENT & CADENCE

12-month minimum subscription with monthly delivery cadence. Renewal negotiated at annual review gate (M 11). Scope amendments negotiated through the Practice Lead.


INCLUDED IN SUBSCRIPTION
  • ✓Five named service elements
  • ✓Monthly executive access scorecard
  • ✓Named Practice Lead
  • ✓Quarterly policy optimisation
  • ✓Named exception-governance SLA
  • ✓30/60/90-day onboarding milestones

OUT OF SUBSCRIPTION
  • —Identity migration
  • —PAM implementation
  • —Major network redesign
  • —ZTNA/SASE platform implementation
  • —Large-scale application remediation
  • —Security incident response
COMMERCIAL PRINCIPLES
01

Managed access outcome, not platform administration hours

The unit is the operated access posture and agreed operating responsibility.

02

12-month minimum

Access drift is a recurring operating problem; the service is designed to manage it over time.

03

Scope growth transparent

User/application scope growth is handled through transparent change order.

§ 10 · QUESTIONS

The five questions security and infrastructure leaders actually ask.

Q_01Isn't this just managed SASE?
No. SASE or ZTNA may be the enforcement technology. C14 is the operating discipline around: application-specific policy; device context; external access; exceptions; onboarding; optimisation; and executive reporting. The customer buys a sustained Zero Trust access posture.
Q_02How is C14 different from B9?

B9 builds foundational Zero Trust controls.

C14 operates access afterwards.

B9 may implement architecture once.

C14 prevents the access policy from drifting back toward broad trust over the following years.

Q_03How is this different from SecureWorkplace?

C11 asks: “Is this user/device protected?”

C14 asks: “Given the identity, device and context, what should this user/device be allowed to access?”

C11 provides posture.

C14 consumes posture.

Q_04Does C14 replace IAM or PAM?
No. IAM establishes identity. PAM manages privileged-access lifecycle/control. C14 consumes identity and privilege context to operate application-level access policy.
Q_05What happens when suspicious access is detected?

An access anomaly can become a security event.

At that point, C7 or the customer's SOC/IR process owns investigation and response.

C14 may provide access-policy context and execute approved policy changes following the incident.

§ 11 · NAMED ACCOUNTABILITY

One name.
Six accountabilities.

Specialist managed services mean the person accountable for onboarding remains accountable for the cadence — with escalation to CEO on any material issue within 24 hours.

THE ROLE

Practice Lead — Cybersecurity

Named account owner for the duration of the subscription. Present at monthly executive reviews and material access escalations.

SIX ACCOUNTABILITIES
01
Commercial arrangement

User/application scope and renewal.

02
Access operating cadence

Signs off monthly policy review.

03
Monthly executive reviews

With security/infrastructure sponsor.

04
Change orders

Authorised for scope growth.

05
Escalation path

CEO within 24 hours for material delivery issues.

06
SLA accountability

Named commitment to access-operations thresholds.

§ 13 · BOOK A CLINIC

30 minutes.
One Zero Trust access question.

Bring the specific problem: Zero Trust implemented but policies have become broad; contractor access difficult to govern; device posture available but not consistently enforced; application onboarding inconsistent; access exceptions accumulating without expiry. C14 is scoped in the clinic — identity readiness, enforcement platform, application estate, external-user patterns and sponsor.

CLINIC · C14
  • —Current ZTNA/SASE state
  • —Identity/application inventory check
  • —Contractor/BYOD exception pattern
  • —Fit assessment against B9, C11 and C7
Practice Lead — Cybersecurity attends every clinic.