Before
Flat network, shared VPN passwords, 2–4 hour average after-hours response, no single owner.
12 magasins en Ontario — segmentation VLAN et durcissement pare-feu par Amir KH; MFA et playbooks par Pouya K.

Industry
retail
Services involved
2
Delivery record
Published case study
A 12-location Ontario retail chain was losing after-hours revenue whenever VPN or POS back-office links failed — and nobody owned the full stack. Amir KH led network segmentation, firewall policy cleanup, and 24/7 monitoring design across stores; Pouya K standardized remote-access MFA rollout and built internal runbooks the store managers could actually follow.
Flat network between POS and back-office, shared VPN credentials, and a previous MSP that blamed the firewall vendor during every overnight incident.
Before
Flat network, shared VPN passwords, 2–4 hour average after-hours response, no single owner.
After
Segmented VLANs, per-user MFA, and mean time to acknowledge under 15 minutes on VPN/POS alerts during the first 90 days.





Phase 1
Phase 1: Network assessment across 3 reference stores
Phase 2
Phase 2: VLAN + firewall rollout to all 12 locations (staggered nights)
Phase 3
Phase 3: Monitoring, alerting, and store manager handoff training
Overnight “nobody knows who to call” incidents stopped. The IT lead now gets a single thread with root cause, not vendor ping-pong.
"Our old MSP blamed the firewall vendor. Amir owned the rack, the VPN, and the escalation path end to end." — IT lead, anonymized retail client
Fortinet firewall, segmented VLANs, MFA, SIEM-style alerting, Amen 24/7 MSP.