Atlas Blueprint
Network & Security Architecture + Hardware Leasing
A documented network architecture you own outright — every VLAN, IP range, and firewall zone version-controlled in Git, on hardware you lease instead of sinking into CapEx.
Why this exists
Without Atlas Blueprint
The network was never designed — it grew organically. Nobody knows the full IP range in use. The asset register is a stale spreadsheet. Hardware is purchased ad-hoc from whichever supplier has stock, resulting in 6 different switch models from 4 vendors. When an auditor asks for the architecture document, someone creates one from memory in 2 days.
With Atlas Blueprint
A professional network architecture produced before anything is deployed. Every VLAN, IP range, and firewall zone is documented and version-controlled in Git. Hardware is standardised — one switch model, one AP model, one firewall appliance. Leasing eliminates the CapEx spike: hardware arrives configured, is refreshed on schedule, and replaced without a procurement cycle.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(a) | Documented network architecture is the prerequisite for all other risk controls | Architecture design document · zone model · Git version history |
| BSI NET.1.1 | Network must be architecturally designed before deployment, not evolved ad hoc | Architecture document · VLAN register · IP address plan |
| DORA Art. 9(2) | Architecture document + hardware inventory provides complete ICT asset register | Hardware BOM · NetBox inventory · leasing register |
| BSI OPS.1.2.1 | Architecture document is the change baseline — all changes tracked against it | Git history · change log · approval trail |
| NIS2 Art. 21(2)(g) | Hardware from validated vendors, leasing contracts with security requirements | Vendor vetting record · leasing contract · hardware spec |
| ISO 27001 A.8.9 | Standardised hardware configurations reduce attack surface | Configuration baseline · deviation log · review schedule |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
Network architecture design
LAN/WAN topology document. VLAN register (name, ID, subnet, purpose, ACL summary). IP address plan. Zone model diagram generated from NetBox with netbox-topology-views (draw.io / PNG export), kept in sync with the CMDB rather than hand-drawn. Firewall placement. Redundancy strategy. Document only — no implementation.
€ 1,490
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteHardware leasing setup
Source and configure leasing for 1 rack unit (switch, firewall, or server). Partners: Grenke, DLL Group, Deutsche Leasing. 24/36/60-month terms. Hardware arrives configured to baseline. Delivery + cabling included.
€ 890
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 7,200
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 18,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 36,000
Net, excl. VAT · fixed price scoped by audit
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz