Background
A leading Energy Utility Company in East Africa operates a hybrid revenue model where electricity is sold through:
These external partners access backend systems through VPNs, making network availability, cybersecurity, and identity-based access control critical.
The environment supports 24/7 high-volume token generation, meaning any downtime directly affects revenue collection nationwide.
As the organization expanded geographically, it faced serious challenges:
To transform reliability and security, the company partnered with our engineering team for a complete network overhaul.
Solution Overview
1. Cisco VSS Collapsed Core (High-Availability Core Network)
We designed and deployed a Cisco VSS (Virtual Switching System) architecture at the headquarters to eliminate downtime and provide:
This collapsed core became the backbone supporting all services, applications, and security controls.
2. Branch Connectivity with Cisco Access Switches
Over 40 Cisco access switches were deployed across multiple branches, providing:
This created a uniform enterprise-grade LAN across the entire country footprint.
3. Identity-Based Security with Cisco ISE (LAN, WAN, and WiFi)
We introduced Cisco Identity Services Engine (ISE) across HQ and all branches to enforce:
802.1X network access control (NAC)
Centralized policy management
Guest WiFi + BYOD control
Visibility into endpoints
ISE enabled zero-trust network access, vital for a utility company whose operations affect millions of households.
4. Perimeter Security with Firewall (HA Cluster)
At the HQ, we deployed two Firewalls in High Availability (HA) mode acting as:
This ensured always-on connectivity for:
Most importantly, the HA setup eliminated downtime for token vending systems, which process thousands of transactions per hour.
Business Impact
1. Increased Network Uptime
2. Improved Security & Compliance
3. Higher Revenue Protection
Reliable network → uninterrupted token generation → no revenue loss during outages.
4. Better Operational Transparency
5. Scalable for Future Smart-Grid and Digital Services
The architecture now supports:
Summary of Technologies Deployed
| Layer | Technology | Purpose |
|---|---|---|
| Core Network | Cisco VSS | High-availability, fast switching, collapsed core |
| Access Layer | 30+ Cisco Access Switches | Standardized secure LAN for branches |
| Identity & Access | Cisco ISE (LAN, WAN, WiFi) | NAC, 802.1X, role-based access, BYOD, visibility |
| Perimeter / Security | Sophos Firewall (HA) | VPN, UTM, IPS, malware defense |
| Partners Connectivity | Sophos IPsec/SSL VPN | Secure access for banks, agents, and vendors |