Skip to content
IT White GloveManaged IT support · Advisory · Canada
Menu

Network decision guide · Canada · EN / FR

Confirm the network before you approve anything that depends on it.

Ce guide est aussi tenu en français. Décisions réseau →

Cloud migrations, remote work, VoIP, backups, and security controls all quietly assume the network underneath them already works: enough bandwidth, a firewall configured on purpose, Wi-Fi that reaches every workstation, and a VPN that actually gets used. Leadership rarely revisits that assumption until something built on top of it fails.

The decision to enable

Decide whether the current network can support what leadership is about to approve—before approving it, not after it fails.

Treat the firewall as a configured decision, not a box that was installed once

A firewall bought years ago and left on factory or default rules protects less than its name implies. Confirm who last reviewed the rule set, what traffic it actually blocks, and whether anyone would notice if a rule were quietly disabled.

  • Date of the last rule review, and who performed it
  • Remote management access and who can reach it
  • Logging that would show an attempted intrusion, not just a successful one

Separate Wi-Fi convenience from Wi-Fi coverage and segmentation

Reliable Wi-Fi in the boardroom does not confirm reliable Wi-Fi at every desk, and one flat network for staff, guests, and devices removes a layer of containment that costs little to add. Test coverage where people actually work, and confirm guest and internal traffic are genuinely separated, not just labelled differently.

Confirm the VPN or remote-access path is actually used correctly

A VPN that exists on paper but is skipped whenever it is inconvenient provides no protection during the moments it matters most. Check who has remote access, whether multi-factor authentication applies to it, and what happens to that access when someone leaves the organization.

  • Who currently holds active remote-access credentials
  • Whether multi-factor authentication is enforced, not optional
  • How quickly access is removed after departure

Decide bandwidth and redundancy against what the business actually depends on

A single internet connection is a single point of failure for cloud email, VoIP, backups, and remote work all at once. Decide deliberately whether a backup connection, SD-WAN, or a simpler redundancy plan is worth its cost against what an outage would actually stop.

Decision frame

What leadership should be able to verify.

These criteria do not produce a score. They expose the questions that need resolution before a responsible decision.

CriterionUseful signalLeadership question
ConfigurationFirewall rules are reviewed on a known cadence, not left at default.Who last reviewed the firewall rules, and what did they change?
SegmentationStaff, guest, and device traffic are genuinely separated.What could a guest network device actually reach today?
Remote accessVPN or remote access is enforced, verified, and removed on departure.How is remote access confirmed to require multi-factor authentication?
ResilienceBandwidth and redundancy are sized to what depends on the network.What stops working the moment the internet connection drops?

Practical scenarios

The same discipline applied to different decisions.

A new cloud platform is proposed without checking the network first

Situation: Leadership is ready to approve a cloud migration that assumes reliable bandwidth and VPN access for a partly remote team.

Useful response: Confirm current bandwidth, VPN reliability, and Wi-Fi coverage against the new platform’s real requirements before approving the migration timeline, not after users start reporting problems.

Boundary: This guide does not size a specific firewall, router, or SD-WAN product; it frames what leadership should confirm before approving one.

Remote staff routinely bypass the VPN because it is slow

Situation: Staff have found the VPN inconvenient and increasingly connect directly to company systems without it.

Useful response: Treat this as a control that has quietly failed rather than a minor inconvenience, and decide whether to fix performance, enforce the requirement, or replace the approach—rather than leaving the gap unaddressed.

Boundary: This guide does not evaluate specific VPN products or guarantee a performance improvement from any change.