• Industry Sector: Financial Services & Asset Management
  • Core Technology Partners: Cisco (Catalyst SD-Access, DNA Center, ISE), Palo Alto Networks (Next-Generation Firewalls), Multi-Site Cisco Software Defined Data Centre Architecture using Nexus Leaf / Spine and VxLAN / EVPN
  • Engagement Model: Ongoing Managed Support

Key facts


2,500+

active users supported seamlessly

Wi-Fi 6E

Ultra-low latency mobility deployed campus-wide

Leaf-and-Spine

Resilient VxLAN / EVPN data centre architecture

Zero-Downtime

Migration completed with zero business disruption

The Challenge: Building Secure, Uninterrupted Digital Operations at Scale


The client required a modern, highly resilient network for its new flagship headquarters. The firm needed to eliminate legacy operational silos, enforce Zero Trust access, and guarantee zero service disruption for 2,500+ investment professionals handling time-critical financial operations.

As part of its move to state-of-the-art facility, the client needed infrastructure that moved away from static, manual configurations.

To achieve this, they required a partner that could integrate closely with its internal IT and security teams, providing independent design assurance, elite Cisco and Palo Alto engineering, and a calm, risk-aware delivery plan. They chose Sword.

With stringent financial compliance obligations and high-mobility working patterns, their technical teams faced three essential requirements:

  1. Strict Zero Trust Network Segmentation: Sensitive financial environments required micro-segmentation at the user and device level, ensuring policy enforcement without introducing management friction.
  2. Multi-Site Data Centre Resilience: Legacy Layer-2 extension technologies (such as OTV) were no longer suitable for the organisation’s high-availability demands across data centres.
  3. Continuous Trading Continuity: Any cutover or migration window carried significant financial and reputational risk; daily operations had to run without compromise throughout the build.

The Solution: Software-Defined Campus & Multi-Site Data Centre


Sword applied a structured top-down methodology to design and deliver an automated Cisco Software-Defined Access (SDA) campus paired with a high-performance Leaf-and-Spine data centre fabric, protected end-to-end by Palo Alto Networks next-generation firewalls.

Working hand-in-hand with the clients engineers, Sword managed the full lifecycle from early proof-of-concept testing to live migration and 24/7 ongoing network operations centre (NOC) support.

1. Cisco Software-Defined Access (SDA) Campus

  • Intent-Based Networking: Centrally deployed and automated via Cisco DNA Center (Catalyst Center), removing repetitive manual switch configurations.
  • Granular Zero Trust Security: Implemented Cisco Identity Services Engine (ISE) and TrustSec with Scalable Group Tags (SGTs), providing continuous identity and device verification across the entire estate.
  • Campus-Wide Wi-Fi 6E: Deployed high-density access points to support secure, high-speed mobile collaboration for staff and visitors across every floor.

2. High-Availability Multi-Site Data Centre

  • Modern Fabric Architecture: Replaced legacy interconnects with a Cisco Leaf-and-Spine topology running VxLAN with BGP EVPN, providing resilient Layer 2 extension across physical data centre locations.

3. Integrated Perimeter & Fusion Security

  • Palo Alto Networks Next-Gen Firewalls: Positioned strategically at the network perimeter and between virtual routing instances (VRF/VN fusion points) to inspect east-west and north-south traffic without choking throughput.
  • Pragmatic Partner Governance: Sword led coordination between Cisco and Palo Alto, securing commercial transparency, clean licensing structures, and verified technical interoperability.

"Sword worked as a natural extension of our team from day one. Their engineering depth across Cisco and Palo Alto gave us total confidence in our architecture, and their pragmatic approach to cutover ensured our people experienced zero disruption during a landmark headquarters transition."

Business outcomes


Automated Network Agility

Centralised software-defined policies allow IT administrators to provision services, onboard secure endpoints, and isolate threats in minutes instead of days.

Continuous Operational Resilience

The modernised VxLAN EVPN data centre fabric provides active-active multi-site redundancy, mitigating the risk of site-wide outages.

Assured Hybrid Mobility

High-density Wi-Fi 6E provides seamless voice, video, and data access throughout the new headquarters, matching the clients flexible, collaborative culture.

Future-Proof Security Compliance

Identity-driven micro-segmentation satisfies stringent regulatory auditing standards while keeping infrastructure adaptable for future cloud integration.

24/7 Managed Operational Stability

Supported by Sword's NOC services, the client retains continuous oversight, proactive lifecycle patching, and rapid incident triage.

More Information

Sword utilised a dual-run staging methodology where the new Cisco Software-Defined Access (SDA) campus network and VxLAN EVPN data centre fabric were designed, configured, and tested in parallel with the active legacy systems. Thorough risk modelling and staggered migration windows allowed user groups and services to be transitioned incrementally, ensuring continuous trading operations and zero downtime.

The architecture relies on Cisco Identity Services Engine (ISE) and Palo Alto Networks Next-Generation Firewalls to implement Zero Trust micro-segmentation. By utilising Scalable Group Tags (SGTs), user and device identities are continuously verified, isolating sensitive financial environments to satisfy stringent financial compliance, security auditing standards, and operational risk policies.

Wi-Fi 6E was chosen to support high-density, low-latency mobile collaboration for more than 2,500 active users. By utilising the newly opened 6 GHz spectrum, the wireless network avoids congestion from legacy devices, delivering highly secure, ultra-reliable gigabit speeds across all campus floors for voice, video, and data traffic.

More case studies

Need help?

Whether you are strengthening operational resilience, securing critical infrastructure, or improving organisational preparedness, our UK-based experts are ready to support your mission-critical operations

Speak to a subject matter expert

Privacy Preference Center