Engineering Note · EN-008

The contingency became the production platform

A temporary remote access path proved more dependable than the service it had been introduced to protect.

4 min read
Industry
Financial Services
Capability
Security & Identity
Decision
Remote access resilience
Outcome
Contingency service became the primary access platform

A client's primary VPN service became unreliable after firmware updates were applied without a complete assessment of authentication dependencies and compatibility.

The network platform had been upgraded, but the proxy service supporting multi-factor authentication no longer worked correctly. The incumbent supplier could neither establish the cause nor provide a stable fix.

The problem was made harder by the supply chain. Each component had a different owner, and every investigation created another opportunity for responsibility to move elsewhere.

We removed that uncertainty by introducing a separate remote access device and a new multi-factor authentication subscription. The test environment had its own end-to-end path, so it could be validated without relying on the original suppliers agreeing where the fault belonged.

The contingency service worked consistently. It was simpler to understand, easier to support and available while the original platform remained uncertain.

Developers, employees and trusted third parties progressively moved to the contingency service. What had been introduced as a temporary safeguard became the organisation's primary method of remote access.

The replacement left the client with fewer unresolved dependencies and much clearer operational ownership.

Engineering lessons

  • Firmware changes must be assessed against the complete authentication chain, not only the upgraded device.
  • An isolated test path can remove supplier ambiguity and establish facts quickly.
  • A contingency that repeatedly outperforms production may be showing the organisation its future architecture.

Read the engineering principles behind this work →

Confidentiality: Engineering Notes are based on real engagements. Client identities, timelines and identifying details may be changed to protect confidentiality. The engineering decisions and lessons remain representative of the work undertaken.