Trust nothing.
Segment everything.
Perimeter One is a wholly US owned and operated company focused on security and network segmentation. We plan and operate network security change: SASE deployments, segmentation programs, firewall policy, and migrations between security platforms. Each engagement starts with the current environment and ends with a tested cutover or operating plan.
Firewall migration and full security platform conversions
A platform decision is only the start. A usable migration also accounts for policy intent, NAT, routing, VPNs, logging, identity, operating procedures, and rollback. We inventory those dependencies, translate what belongs in the target, and test before cutover.
Inventory rules, objects, NAT, routing, VPNs, logging, and the traffic that uses them.
Translate policy with repeatable tooling and record the decisions that require engineering judgment.
Build the target environment in parallel where practical and validate representative traffic.
Move in controlled phases with owners, acceptance checks, and a rollback procedure.
Tune, document, and hand off the platform, or continue under a defined managed-service scope.
The governing idea: automate repeatable translation, keep policy intent reviewable, and require a human decision wherever the source and target models do not match.
Two ways to engage: professional services or managed security services
Use a fixed-scope project for a defined change, or a managed service for recurring operational work. The responsibilities and approval boundary are written down before work starts.
Professional services
Defined engagements from discovery through validation and handoff.
- Platform conversions & migrations — firewall, SASE, and cloud security platform moves, end to end.
- SASE design & deployment — SSE, ZTNA, and SD-WAN architecture based on user, site, and application requirements.
- Segmentation programs — zone strategy, policy design, and phased enforcement for campus, data center, and OT, including host-based microsegmentation where required.
- Security assessments — configuration and architecture reviews with prioritized findings and evidence.
- Policy cleanup & rationalization — shrink rulebases, remove shadowed and unused rules, document what remains.
Managed services
Ongoing operation of network security platforms under a documented responsibility model.
- Managed firewall & SASE operations — policy changes, upgrades, and health management across your fleet.
- Policy lifecycle management — review, stage, document, and periodically recertify rules.
- Monitoring & response — eyes on your edge and segmentation posture, with escalation paths agreed in advance.
- Managed WAF — Akamai-based web application and API policy, monitoring, and change management.
- Co-managed options — shared access and approval boundaries tailored to the customer team.
- Continuous segmentation assurance — verify zones still hold as the network changes underneath them.
Security platforms Perimeter One migrates and operates
Migration planning has to account for the source and target platforms. These are the current areas of focus for Perimeter One services.
A platform not listed here needs a discovery review before scope, schedule, or conversion coverage can be confirmed.
Fractional CTO, CISO, and VP of Security leadership
Not every organization needs a full-time security executive, but every organization needs someone accountable for security direction, budget, and risk. Perimeter One provides that leadership on a fractional or interim basis: a named executive, a fixed number of days per month, and outcomes written into the engagement.
Fractional CTO
Technology direction for organizations without a full-time CTO.
- Technology strategy & roadmap — tied to the business plan and budget cycle, not to vendor calendars.
- Architecture decisions — network, cloud, and security platform choices with the trade-offs written down.
- Vendor & contract oversight — selection, renewals, and negotiation from the buyer's side of the table.
- Engineering leadership — hiring plans, team structure, and mentoring for the people who stay.
Fractional CISO
Executive ownership of the security program without the full-time cost.
- Security strategy & risk register — a prioritized roadmap the board and the engineers both recognize.
- Compliance programs — SOC 2, ISO 27001, PCI DSS, HIPAA, NIST 800-53, FedRAMP, and HITRUST.
- Audit liaison — evidence management and a single accountable voice for internal and external auditors.
- Board, customer & insurer reporting — security posture explained in the language each audience uses.
VP of Security Management
Hands-on leadership of the security engineering and operations function.
- Run the function day to day — firewall, SASE, segmentation, and security operations teams with clear ownership.
- Change governance — approval boundaries, escalation paths, and metrics that show whether controls hold.
- Interim coverage — during an executive search, reorganization, or leave, with no gap in accountability.
- Transition to a permanent hire — documented handoff, staffing plan, and vendor and MSSP oversight in place.
Leadership engagements run on a monthly retainer with a fixed allocation of days, a written boundary between the decisions the fractional executive owns and the ones they recommend, and a defined exit. They can stand alone or sit alongside a platform conversion, segmentation program, or managed service.
Start with an assessment
Tell us what you run, what needs to change, and which constraints cannot move. We will help define a practical next step.