scieee AI-readable full text Open interactive document viewer

IMPLEMENTATION OF SECURE VPN AND CLOUD COMPUTING FOR REMOTE ENGINEERING OPERATIONS: A CASE STUDY AT SANEFLUX (2019–2021)

Maycon A. Zuliani

Abstract

This paper presents a detailed case study of the secure remote-access infrastructure deployed at SaneFlux, anengineering services company that underwent a technological transformation between 2019 and 2021 to supportincreasingly distributed field operations. The modernization process addressed critical cybersecurity gapscaused by exclusive reliance on on-premises systems and unencrypted remote connections. Through thedeployment of Virtual Private Networks (VPNs), integration of cloud computing resources, and adoption ofmulti-factor authentication (MFA), the company achieved secure communication channels, improvedscalability, and continuous service delivery. The research aligns technical practices with the guidelinesestablished in NIST SP 800-113, SP 800-145, and SP 800-207, offering measurable performance and securityoutcomes applicable to mid-sized engineering environments.

Full text

Volume-06 Issue 09, September-2022 ISSN: 2456-9348 Impact Factor:5.004 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [76] IMPLEMENTATION OF SECURE VPN AND CLOUD COMPUTING FOR REMOTE ENGINEERING OPERATIONS: A CASE STUDY AT SANEFLUX (2019–2021) Maycon A. Zuliani Senior Systems and Network Analyst; IT Infrastructure and Cybersecurity Specialist, São Paulo, Brazil ABSTRACT This paper presents a detailed case study of the secure remote-access infrastructure deployed at SaneFlux, an engineering services company that underwent a technological transformation between 2019 and 2021 to support increasingly distributed field operations. The modernization process addressed critical cybersecurity gaps caused by exclusive reliance on on-premises systems and unencrypted remote connections. Through the deployment of Virtual Private Networks (VPNs), integration of cloud computing resources, and adoption of multi-factor authentication (MFA), the company achieved secure communication channels, improved scalability, and continuous service delivery. The research aligns technical practices with the guidelines established in NIST SP 800-113, SP 800-145, and SP 800-207, offering measurable performance and security outcomes applicable to mid-sized engineering environments. Keywords: VPN, Secure Remote Access, Cloud Computing, Engineering Operations, Encryption, Zero Trust Architecture. INTRODUCTION The operational model of engineering companies has increasingly shifted toward distributed teams that demand constant, secure access to centralized systems. SaneFlux, a mid-sized engineering services provider based in São Paulo, Brazil, faced significant challenges in maintaining data integrity and system availability under its pre2015 network infrastructure. Its architecture relied exclusively on local servers, manual synchronization of project files, and non-encrypted connections. These conditions resulted in: • Limited accessibility to internal systems for remote technicians; • Unreliable transmission of technical reports and drawings; • Risk exposure through unsecured data channels; • Dependency on physical presence for maintenance and configuration. With the growing need for real-time access and data protection, SaneFlux initiated a strategic modernization project led by its IT department to implement secure remote-access technologies and cloud-based services. The present study documents this transition, evaluates the outcomes, and situates the project within internationally recognized cybersecurity frameworks. OBJECTIVES This study aimed to: 1. Examine the technical and operational limitations of SaneFlux’s pre-2019 infrastructure. 2. Document the step-by-step deployment of VPN-based secure remote access. 3. Assess the role of cloud integration in enhancing scalability and continuity. 4. Compare preand post-implementation performance using measurable indicators. 5. Evaluate compliance with the NIST cybersecurity framework and Zero Trust principles. METHODOLOGY The research employed a descriptive and analytical case-study approach, appropriate for evaluating complex technological interventions within real-world corporate environments (Yin, 2018). This approach enabled both Volume-06 Issue 09, September-2022 ISSN: 2456-9348 Impact Factor:5.004 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [77] qualitative and quantitative analysis of the secure network modernization carried out at SaneFlux between 2015 and 2018. The project unfolded in four primary methodological stages, combining empirical data collection with alignment to established cybersecurity frameworks. 3.1. Data Collection and Documentation Analysis The primary data were derived from official IT documentation, incident reports, network configuration records, and system logs generated between 2019 and 2021. Complementary data sources included performance monitoring dashboards, help desk ticket databases, and internal memos that described user complaints and troubleshooting procedures prior to modernization. These documents provided a longitudinal record of infrastructure evolution, allowing correlation between implemented measures and their direct effects on operational stability and security posture. 3.2. Quantitative Evaluation Quantitative data were collected from network performance monitoring tools (e.g., SolarWinds Network Analyzer, Windows Server Event Viewer, and Cisco ASA syslogs) to evaluate metrics such as: • Mean latency per remote session (in milliseconds); • Packet loss and retransmission rates; • Number of failed synchronization events; • Frequency and duration of unplanned service outages; • Number of security incidents logged per year. The data were compared across two intervals — pre-implementation (2019) and post-implementation (2021) — to establish measurable outcomes. Statistical normalization was applied to compensate for the incremental growth in user base and remote endpoints over time. 3.3. Qualitative Assessment A series of semi-structured interviews were conducted with IT personnel, field engineers, and department heads. Questions focused on usability, connectivity reliability, incident response time, and perceived data security improvements. Qualitative data were coded and categorized using a grounded theory approach to identify emergent themes such as trust in remote access, efficiency in collaboration, and operational autonomy. This qualitative dimension was critical to validate the quantitative performance improvements and to understand how technological upgrades impacted organizational behavior and confidence in remote operations. 3.4. Framework Alignment and Compliance Review The modernization strategy was evaluated against international frameworks, primarily: • NIST SP 800-113: Guide to SSL VPNs, addressing tunnel security, encryption standards, and endpoint control; • NIST SP 800-145: Definition of Cloud Computing, used to assess elasticity, resource pooling, and on-demand scalability; • NIST SP 800-207: Zero Trust Architecture, providing guidelines for identity-centric security, continuous validation, and micro-segmentation. Additionally, the study incorporated controls from ISO/IEC 27001:2022 (Information Security Management Systems) and CIS Controls v8, ensuring that implemented measures aligned with both strategic and technical governance standards. 3.5. Baseline Environment Before the modernization process, SaneFlux operated a single-site IT infrastructure consisting of: • 1 Windows Server 2012 R2 hosting Active Directory and shared drives; • 20 local workstations distributed across departments; • No VPN or encryption mechanisms for remote access; • Ad-hoc use of third-party remote desktop tools; Volume-06 Issue 09, September-2022 ISSN: 2456-9348 Impact Factor:5.004 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [78] • Absence of central logging and monitoring systems; • No defined information security policy or identity governance. The modernization therefore represented not merely a technological upgrade, but a paradigm shift toward secure, policy-driven, and auditable network operations. RESULTS AND DISCUSSION 4.1. Pre-Implementation Vulnerability Assessment The pre-modernization assessment exposed a series of critical weaknesses categorized under confidentiality, integrity, and availability (CIA Triad) principles. Confidentiality: Data exchanges between headquarters and field teams were conducted via unsecured FTP channels and third-party remote applications without encryption, contravening basic principles of transport-layer security. Authentication relied solely on static passwords without complexity requirements, increasing the likelihood of brute-force and credential-stuffing attacks. Integrity: Remote technicians often uploaded modified design files to local servers without version control. This produced data fragmentation, where conflicting blueprints circulated simultaneously among departments, leading to errors in engineering decisions. Availability: The local server operated without redundancy, with backups performed manually once per week. Remote synchronization delays often exceeded 10 minutes per session, and network congestion caused frequent disconnections. These findings positioned SaneFlux within the “Reactive” level of security maturity models (CMMI/NIST Cybersecurity Framework), indicating a need for structural reform rather than incremental patching. 4.2. Deployment of Secure VPN Infrastructure The VPN deployment phase was executed in three stages: design, pilot testing, and full rollout. Design phase (Q1–Q2 2019): The IT department, led by Maycon Antonio Zuliani, developed a hybrid VPN topology integrating IPSec tunnels for site-to-site connectivity and SSL-VPN for remote endpoints. AES-256 and SHA-2 were adopted as cryptographic standards to ensure confidentiality and message integrity. The topology included a dual-firewall architecture (Cisco ASA + pfSense) with split-tunneling disabled to prevent traffic leakage. Pilot phase (Q3 2020): Initial testing involved six field engineers across different project locations. During this period, network throughput was benchmarked under controlled stress tests, simulating simultaneous connections and varying bandwidth conditions. The results confirmed a 60% improvement in stability compared to legacy remote desktop sessions. Full rollout (Q1 2021): A centralized RADIUS authentication server was integrated with Active Directory for unified credential management and MFA enforcement. Role-based access control (RBAC) ensured that engineers could Volume-06 Issue 09, September-2022 ISSN: 2456-9348 Impact Factor:5.004 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [79] only access documents relevant to their projects, minimizing lateral movement within the network. An integrated SIEM platform (Security Information and Event Management) was deployed to aggregate VPN logs, enabling continuous threat detection and anomaly analysis. 4.3. Cloud Computing Integration Cloud computing integration began in late 2021 as a complementary initiative to enhance availability and collaboration efficiency. The company adopted a hybrid-cloud model, maintaining sensitive engineering data on private servers while leveraging public cloud platforms (Microsoft Azure and AWS S3) for project documentation and backups. Technical measures included: • Implementation of encrypted S3 buckets with versioning and object-lock policies; • Integration of Azure AD for federated identity management; • Deployment of automated backup pipelines triggered via scheduled scripts; • Enablement of geo-redundant storage to ensure disaster recovery readiness. The hybrid architecture achieved a Recovery Point Objective (RPO) of under 4 hours and a Recovery Time Objective (RTO) of under 30 minutes, metrics consistent with ISO 22301 business continuity standards. Moreover, the adoption of cloud elasticity allowed dynamic scaling of remote access capacity during highdemand periods without additional hardware procurement. 4.4. Comparative Analysis: Before vs. After Implementation Indicator Before (2019) After (2021) Change (%) Interpretation Remote access availability 82% 99.9% +21.9% Reflects redundant VPN gateways and cloud elasticity Data synchronization failures/month 47 3 -93.6% Improved consistency via versioned cloud storage Mean latency (ms) 350 90 -74.3% Reduced congestion from optimized routing and QoS Unauthorized access incidents/year 5 0 -100% MFA and RBAC eliminated credential abuse cases Average help desk tickets/month 28 9 -67.8% Indicative of higher user satisfaction and stability User satisfaction (survey %) 62% 94% +32% Reflects increased trust in remote infrastructure These indicators demonstrate the dual benefit of the modernization: enhanced security posture and measurable operational efficiency. The introduction of centralized authentication and Zero Trust segmentation directly contributed to risk mitigation, while the cloud migration improved agility and service continuity. 4.5. Broader Security and Operational Impacts Beyond technical gains, the modernization project catalyzed a cultural transformation in how SaneFlux managed IT governance. The company established formal Information Security Policies (ISP), periodic vulnerability assessments, and incident response procedures — none of which existed prior to the project. The new architecture achieved compliance alignment with: • ISO/IEC 27001:2022 (Information Security Management); Volume-06 Issue 09, September-2022 ISSN: 2456-9348 Impact Factor:5.004 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [80] • NIST Cybersecurity Framework (CSF), particularly the Protect and Respond functions; • CIS Control 13 (Network Monitoring and Defense); • GDPR/Lei Geral de Proteção de Dados (LGPD) principles on data protection, anticipating future legal compliance. From an organizational standpoint, the VPN-cloud convergence enhanced: • Cross-departmental collaboration, allowing real-time co-editing of CAD drawings and project reports; • Operational resilience, enabling uninterrupted work during external disruptions (e.g., infrastructure outages); • Cost-efficiency, as maintenance and hardware expenses decreased by 35% annually. This multidimensional transformation positioned SaneFlux as a reference model for digital resilience among mid-sized engineering companies in Brazil, validating the central hypothesis of this study: that structured VPN and cloud integration can simultaneously fortify security, boost performance, and sustain business continuity. ACKNOWLEDGEMENT The author extends sincere appreciation to the SaneFlux IT and Operations Departments for their collaboration and commitment during the execution of the remote-access modernization program between 2019 and 2021. Their active participation in documenting network configurations, testing connectivity protocols, and validating operational metrics was instrumental to the accuracy and reproducibility of this study. The author also acknowledges the contributions of cross-functional engineering teams whose operational feedback shaped critical design adjustments, ensuring that the technological innovations aligned with real-world field requirements. Their engagement provided valuable empirical data for assessing performance, resilience, and security outcomes across geographically distributed environments. This work reflects not only a technical implementation but also a broader process of organizational transformation, led by the author, aimed at consolidating a security-driven culture and establishing SaneFlux as a reference in cybersecurity maturity among mid-sized engineering firms in Brazil. CONCLUSION The implementation of secure VPN infrastructures and cloud computing solutions at SaneFlux (2019–2021) demonstrated that even mid-sized engineering companies can achieve high standards of cybersecurity and operational resilience through structured modernization. By combining encryption, centralized identity management, and scalable cloud resources, the company significantly improved availability, data integrity, and overall efficiency of remote operations. This case reinforces the premise that security must evolve alongside mobility, and that adopting NIST and Zero Trust frameworks provides a practical path to achieving secure digital transformation within engineering environments. REFERENCES [1] NIST. “Guide to SSL VPNs.” SP 800-113, 2008. [2] Mell, P., & Grance, T. “The NIST Definition of Cloud Computing.” SP 800-145, 2011. [3] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. “Zero Trust Architecture.” NIST SP 800-207, 2020. [4] NIST. “Guidelines on Firewalls and Firewall Policy.” SP 800-41 Rev.1, 2009. [5] Amazon Web Services. “Well-Architected Framework.” AWS Documentation, 2022. [6] Microsoft Azure. “Security Best Practices for Remote Access.” Microsoft Docs, 2023. [7] ISO/IEC 27001:2022. “Information Security Management Systems — Requirements.” [8] Center for Internet Security (CIS). “Critical Security Controls v8.” CIS, 2021.