Zero Public Ingress Network Topology
Isolated all data storage, databases, and container registries behind Azure Private Endpoints inside dedicated VNets. Eliminated all direct public internet gateways.
Comprehensive security re-architecture across 6 Microsoft Azure enterprise subscriptions: Private Endpoints, Azure Policy-as-code, Privileged Identity Management (PIM), and automated HIPAA / SOC 2 compliance guardrails.
The organisation stores protected health information (PHI) for 1.8M patients. Prior to the project, teams lacked centralised identity governance, storage accounts were partially exposed to the internet, and an upcoming SOC 2 Type II audit risked failure.
Isolated all data storage, databases, and container registries behind Azure Private Endpoints inside dedicated VNets. Eliminated all direct public internet gateways.
Defined 48 automated Azure Policies enforced at the Root Management Group level to prevent any engineer from provisioning unencrypted disks or public IPs.
Connected Microsoft Sentinel with automated playbooks to quarantine anomalous logins and send real-time Slack alerts to the SecOps team.