Skip to main content
NexITC
  • CYBERSECURITY
  • BUILD
  • B9 · ZERO-TRUST CORE BUILD™
  • 12 WEEKS

Zero Trust as fournamed controls precisely.Not a three-year transformation programme.

A UAE healthcare provider approaching an ADHICS v2 audit cycle wanted Zero Trust posture in place — not as a strategic aspiration but as evidence a regulator could inspect. B9 delivered four named controls in twelve weeks with acceptance criteria per control. The audit went ahead with the controls operational. The alternative — a global-SI transformation programme quoted at 18 months — was declined at scoping.

N=1 ILLUSTRATIVE COMPOSITE — representative pattern for a UAE enterprise operating at scale. Details drawn from patterns across NexITC engagements and market data. Not a specific client narrative.

THE SITUATION

The situation

The client is a UAE enterprise operating in a regulated sector, with an operational footprint across multiple UAE emirates and a workforce measured in the low thousands. Regulatory context: an upcoming external audit cycle against a UAE-specific control framework, with Zero Trust posture as one of several evidence areas the audit would inspect.

The security leadership team had received two proposals from global systems integrators. Both proposed multi-year Zero Trust transformation programmes — one at 18 months, one at 24 months — with aggregate spend approaching AED 12M across licensing, implementation, and change management. Both proposals treated Zero Trust as an enterprise architecture initiative rather than a set of controls with acceptance criteria.

The CISO had a specific problem with both proposals: the audit was scheduled for the following calendar year. A 24-month programme would not produce inspection-ready evidence in time. Neither proposal offered a shorter-scope option.

THE SPECIFIC QUESTION

The specific question

The clinic conversation reframed the ask. The CISO did not need "Zero Trust" as a strategic construct. The CISO needed four things: (1) identity-based access enforcement replacing the flat network trust model on the two highest-risk application clusters, (2) network segmentation between the clinical operations zone and the corporate zone, (3) privileged access management for administrative accounts on those same application clusters, and (4) continuous verification logging that produced audit-inspectable evidence.

The Practice Lead's scoping response confirmed B9. Four controls, twelve weeks, acceptance criteria per control, no dependency on broader enterprise architecture work. The security leadership team signed within a week.

APPROACH AND TIMELINE

Approach and timeline

The engagement ran twelve weeks across four control workstreams, sequenced rather than parallel to keep operational disruption bounded.

Weeks 1-3 delivered the identity-based access enforcement on the highest-risk application cluster, with acceptance criteria measured against defined access-pattern evidence. Weeks 4-6 delivered the network segmentation between clinical operations and corporate zones, with acceptance criteria measured against traffic-flow evidence and failure-mode testing. Weeks 7-9 delivered the privileged access management overlay on the same application clusters. Weeks 10-12 delivered the continuous verification logging and validated audit-ready evidence packages against the regulatory framework's specific requirements.

Practice Lead attendance ran across all twelve weeks with weekly acceptance-criteria review sessions with the CISO's team. Independence disclosure named the vendor categories in scope (identity, network segmentation, PAM, SIEM) without commissioned relationships to any.

OUTCOMES

Outcomes

4 / 4
CONTROLS OPERATIONAL AT AUDIT
12 WEEKS
SIGN TO AUDIT-READY
~85%
COST BELOW GLOBAL-SI PROPOSALS

All four controls were operational and audit-inspection-ready by the end of Week 12. The audit itself, conducted the following quarter, proceeded with the four controls as evidence against the relevant framework requirements. No adverse findings were recorded against the Zero Trust evidence area.

The privileged access management workstream surfaced two additional access patterns during acceptance testing that had not been in the original scope inventory — both were resolved as change orders within the twelve-week timeline, authored explicitly rather than absorbed silently. Total change order value: less than 8% of the original engagement fee.

Continuous verification logging is now generating monthly audit-ready evidence packages, consumed both by the internal security operations function and by the compliance team preparing for the following year's audit cycle.

WHAT COMES NEXT

What comes next

The client is evaluating a C7 SecOpsCommand retainer for continuous security operations against the four deployed controls, moving from project-mode security implementation to steady-state operational cadence. Separately, the enterprise-wide identity federation question the engagement recommended parking has been re-opened as a scoping conversation for the following fiscal year.

Adjacent SKUs: B9 · C7 SecOpsCommand™ · C6 ComplianceOps™ UAE

Facing a regulatory audit with Zero Trust in scope?

Book a clinic. Practice Lead attends. Zero Trust delivered as four named controls with acceptance criteria — not a three-year transformation programme priced to fill a resource plan.