# Retail chain — VPN incidents cut from hours to minutes

12 Ontario stores — Amir KH led VLAN segmentation and firewall cleanup; Pouya K rolled out MFA and store runbooks.

> retail · 2026-07-08T22:55:43.770Z

Project overview

A 12-location Ontario retail chain was losing after-hours revenue whenever VPN or POS back-office links failed — and nobody owned the full stack. Amir KH led network segmentation, firewall policy cleanup, and 24/7 monitoring design across stores; Pouya K standardized remote-access MFA rollout and built internal runbooks the store managers could actually follow.

Client context

  - Industry: Retail

  - Client size / environment: 12 stores · Ontario

  - Primary stakeholders: IT lead, regional operations managers, store managers

Challenge

Flat network between POS and back-office, shared VPN credentials, and a previous MSP that blamed the firewall vendor during every overnight incident.

Scope delivered

  - VLAN design separating POS, cameras, and back-office traffic

  - Firewall rule audit + MFA on all remote access

  - SOC-style alerting with named escalation to Amen NOC

  - Store manager one-page “what to do when VPN is red” playbook

Before / after

  - Before: Flat network, shared VPN passwords, 2–4 hour average after-hours response, no single owner.

  - After: Segmented VLANs, per-user MFA, and mean time to acknowledge under 15 minutes on VPN/POS alerts during the first 90 days.

Before: flat network — POS, cameras, and back-office on one switch fabric
After: dedicated VLANs per zone with firewall rules between segments

Visual proof placeholders

  - Firewall policy diff — before/after rule count and deny-by-default posture

  - VPN health dashboard used by NOC

  - Back-office rack photo for each region’s reference site

Delivery timeline

  - Phase 1: Network assessment across 3 reference stores

  - Phase 2: VLAN + firewall rollout to all 12 locations (staggered nights)

  - Phase 3: Monitoring, alerting, and store manager handoff training

Outcome

Overnight “nobody knows who to call” incidents stopped. The IT lead now gets a single thread with root cause, not vendor ping-pong.

"Our old MSP blamed the firewall vendor. Amir owned the rack, the VPN, and the escalation path end to end." — IT lead, anonymized retail client

Technology stack

Fortinet firewall, segmented VLANs, MFA, SIEM-style alerting, Amen 24/7 MSP.

Visual evidence

Fortinet firewall stack — remote-access VPN tunnels for store managers
POS lane on segmented network — no shared credentials across stores
Per-user MFA on VPN — regional IT reaches any store in minutes

---
Source page: https://amensecurity.ca/en/projects/retail-pos-hardening
Markdown version for AI agents · Amen Security
Email: info@amensecurity.ca
Phone: +1 (204) 514-3536
