SASE · Segmentation · Platform conversion

Trust nothing.
Segment everything.

Perimeter One is a wholly US owned and operated company focused on security and network segmentation. We plan and operate network security change: SASE deployments, segmentation programs, firewall policy, and migrations between security platforms. Each engagement starts with the current environment and ends with a tested cutover or operating plan.

Zone: Edge SASE architecture Plan access for users, sites, and private applications across SSE, ZTNA, and SD-WAN.
Zone: Internal Network segmentation Build zone models and workload controls around known application dependencies.
Zone: Migrate Full platform conversions Move objects, rules, NAT, routing, logging, and operating procedures—not only licenses.
Zone: Operate Managed services Day-to-day policy, platform health, upgrades, and change work in managed or co-managed form.
Zone: Conversions

Firewall migration and full security platform conversions

A platform decision is only the start. A usable migration also accounts for policy intent, NAT, routing, VPNs, logging, identity, operating procedures, and rollback. We inventory those dependencies, translate what belongs in the target, and test before cutover.

Assess

Inventory rules, objects, NAT, routing, VPNs, logging, and the traffic that uses them.

Translate

Translate policy with repeatable tooling and record the decisions that require engineering judgment.

Stage

Build the target environment in parallel where practical and validate representative traffic.

Cut over

Move in controlled phases with owners, acceptance checks, and a rollback procedure.

Operate

Tune, document, and hand off the platform, or continue under a defined managed-service scope.

The governing idea: automate repeatable translation, keep policy intent reviewable, and require a human decision wherever the source and target models do not match.

Zone: Services

Two ways to engage: professional services or managed security services

Use a fixed-scope project for a defined change, or a managed service for recurring operational work. The responsibilities and approval boundary are written down before work starts.

Professional services

Defined engagements from discovery through validation and handoff.

  • Platform conversions & migrations — firewall, SASE, and cloud security platform moves, end to end.
  • SASE design & deployment — SSE, ZTNA, and SD-WAN architecture based on user, site, and application requirements.
  • Segmentation programs — zone strategy, policy design, and phased enforcement for campus, data center, and OT, including host-based microsegmentation where required.
  • Security assessments — configuration and architecture reviews with prioritized findings and evidence.
  • Policy cleanup & rationalization — shrink rulebases, remove shadowed and unused rules, document what remains.

Managed services

Ongoing operation of network security platforms under a documented responsibility model.

  • Managed firewall & SASE operations — policy changes, upgrades, and health management across your fleet.
  • Policy lifecycle management — review, stage, document, and periodically recertify rules.
  • Monitoring & response — eyes on your edge and segmentation posture, with escalation paths agreed in advance.
  • Managed WAF — Akamai-based web application and API policy, monitoring, and change management.
  • Co-managed options — shared access and approval boundaries tailored to the customer team.
  • Continuous segmentation assurance — verify zones still hold as the network changes underneath them.
Zone: Platforms

Security platforms Perimeter One migrates and operates

Migration planning has to account for the source and target platforms. These are the current areas of focus for Perimeter One services.

Palo Alto Networks Prisma Access Strata Cloud Manager Panorama Zscaler Fortinet Cisco / Meraki Check Point Sophos Juniper Netskope Aruba / HPE Akamai Guardicore Akamai

A platform not listed here needs a discovery review before scope, schedule, or conversion coverage can be confirmed.

Zone: Fractional leadership

Fractional CTO, CISO, and VP of Security leadership

Not every organization needs a full-time security executive, but every organization needs someone accountable for security direction, budget, and risk. Perimeter One provides that leadership on a fractional or interim basis: a named executive, a fixed number of days per month, and outcomes written into the engagement.

Fractional CTO

Technology direction for organizations without a full-time CTO.

  • Technology strategy & roadmap — tied to the business plan and budget cycle, not to vendor calendars.
  • Architecture decisions — network, cloud, and security platform choices with the trade-offs written down.
  • Vendor & contract oversight — selection, renewals, and negotiation from the buyer's side of the table.
  • Engineering leadership — hiring plans, team structure, and mentoring for the people who stay.

Fractional CISO

Executive ownership of the security program without the full-time cost.

  • Security strategy & risk register — a prioritized roadmap the board and the engineers both recognize.
  • Compliance programs — SOC 2, ISO 27001, PCI DSS, HIPAA, NIST 800-53, FedRAMP, and HITRUST.
  • Audit liaison — evidence management and a single accountable voice for internal and external auditors.
  • Board, customer & insurer reporting — security posture explained in the language each audience uses.

VP of Security Management

Hands-on leadership of the security engineering and operations function.

  • Run the function day to day — firewall, SASE, segmentation, and security operations teams with clear ownership.
  • Change governance — approval boundaries, escalation paths, and metrics that show whether controls hold.
  • Interim coverage — during an executive search, reorganization, or leave, with no gap in accountability.
  • Transition to a permanent hire — documented handoff, staffing plan, and vendor and MSSP oversight in place.

Leadership engagements run on a monthly retainer with a fixed allocation of days, a written boundary between the decisions the fractional executive owns and the ones they recommend, and a defined exit. They can stand alone or sit alongside a platform conversion, segmentation program, or managed service.

Start with an assessment

Tell us what you run, what needs to change, and which constraints cannot move. We will help define a practical next step.

Reveal contact email