Skip to content
All services
Cloud foundations & networkingBuild

Zero Trust network build

A Zero Trust network for the AWS, Azure or Google Cloud estate you already run, with a hub, private endpoints, central DNS and egress through a cloud firewall, built in 3 to 6 weeks without downtime.

When you need it

Your workloads reach the internet and each other over paths nobody designed. Databases have public endpoints, every network has its own way out, and one compromised workload could reach almost everything else.

What sets the quote

  • One cloud and one region per build: AWS, Microsoft Azure or Google Cloud.
  • Sized from your Zero Trust network review, or from a free read-only inventory query you run (AWS Resource Explorer, Azure Resource Graph or Google Cloud Asset Inventory).
  • Essentials, 3 to 4 weeks: a hub plus up to 3 spokes, up to 10 private endpoints, central private DNS, one egress path through the cloud firewall with FQDN allow-lists, and flow logs.
  • Standard, 5 to 6 weeks, adds firewall inspection (TLS inspection and IDPS where the firewall tier supports it), segmentation for up to 3 tiers, an IP address plan and one site-to-site VPN.
  • Standard also adds private access to up to 10 internal apps through your existing Zero Trust access product, such as Microsoft Entra Private Access, Zscaler Private Access, Cloudflare Access or Google Identity-Aware Proxy.
  • More regions, spokes, endpoints or hybrid links are quoted after sizing.

What changes

  • Workloads reach cloud services over private endpoints, not over the internet.
  • Outbound traffic leaves through one firewall path, and only to domains you have approved.
  • Spokes are isolated from each other unless you allow a path between them.
  • Your team adds a spoke, a private endpoint or an allow-list entry through a pull request.

What you get

  • Hub network with the cloud firewall and one controlled egress path
  • Up to 3 spokes moved onto the hub one at a time, each with a tested rollback
  • Up to 10 private endpoints for cloud services, resolved through central private DNS
  • FQDN allow-lists for egress, built from observed traffic and then enforced
  • Flow logs sent to your central log store
  • Standard adds: TLS inspection and IDPS policies, segmentation rules for up to 3 tiers, an IP address plan, one site-to-site VPN and private access to up to 10 apps
  • All changes as Terraform in your repository, reviewed as pull requests
  • Runbooks for adding a spoke, an endpoint or an allow-list entry, and a handover session

What we build on each cloud

ComponentAWSAzureGoogle Cloud
Hub and spokesTransit Gateway with an inspection VPCVirtual WAN secured hub, or hub VNet with peered spokesNetwork Connectivity Center hub, or Shared VPC
Private endpoints and DNSInterface VPC endpoints, Route 53 Resolver and private hosted zonesPrivate Endpoints, Azure Private DNS and DNS Private ResolverPrivate Service Connect and Cloud DNS private zones
Egress allow-listsNAT gateway and AWS Network Firewall domain listsAzure Firewall application rulesCloud NAT with Cloud NGFW or Secure Web Proxy
Inspection (Standard package)AWS Network Firewall TLS inspection and threat signaturesAzure Firewall Premium TLS inspection and IDPSCloud NGFW Enterprise TLS inspection and intrusion prevention
Flow logsVPC Flow LogsVNet flow logsVPC Flow Logs

This package is for estates that already run workloads, so we change the network one spoke at a time, without downtime. New estates get a basic network in the landing zone sprint.

Not included

  • Firewall and licence running costs, which your cloud provider or vendor bills to you
  • A network for a new, empty estate (a basic one is part of the landing zone sprint)
  • Buying or first-time set-up of a Zero Trust access product
  • Changes to on-premises devices; we give your network team the settings for their side of the VPN

What we need from you

  • AWS: an IAM Identity Center permission set or pipeline role that can change VPC, Transit Gateway, Network Firewall and Route 53 Resolver resources in the network and spoke accounts.
  • Azure: Network Contributor on the hub and spoke subscriptions, plus Private DNS Zone Contributor where the private DNS zones live.
  • Google Cloud: Compute Network Admin, Compute Security Admin and DNS Administrator on the hub and spoke projects.
  • A network owner who approves each change window, and app owners who test their workloads after each move.

How it works

  1. Free 30-minute call, then the sizing query (or your network review) and a written fixed quote.

  2. Design the hub, spokes, DNS, egress path and IP ranges, and agree change windows with your team.

  3. Build the hub next to your current network, then move one spoke at a time with a tested rollback.

  4. Log egress traffic first, enforce the allow-lists, then hand over the code, runbooks and a walkthrough.

At a glance

Duration
3–6 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect and a cloud engineer
Assess Popular

Cloud foundation check

In 1–2 weeks, we review your AWS, Azure or Google Cloud foundation against the CIS benchmark and tie every finding to evidence, the affected resources and a fix.

Duration:1–2 weeks
Assess

Zero Trust network review

A one-week review of how traffic enters, leaves and crosses your AWS, Azure or Google Cloud networks, with evidence for every finding, a target Zero Trust design and a prioritised roadmap.

Duration:1–2 weeks
Assess

Migration check

In 1–2 weeks, we assess what you run on-premises or in another cloud, with a migration approach per application, a wave plan and a cost estimate for AWS, Azure or Google Cloud.

Duration:1–2 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.