CLOUDMECHANIX
Featured Work · Lakeland Dairies

Zero Trust Azure network across two regions in 21 days.

A hub-and-spoke design with Azure Firewall, Network Security Groups and Web Application Firewalls, delivered across two regions — built with the in-house team so they could run it afterwards.

Client
Lakeland Dairies
Engagement
Azure network deployment
Duration
21-day engagement
Regions
North Europe (Ireland) · West Europe (Netherlands)
Azure services
Hub-and-spoke · Azure Firewall · NSGs · Web Application Firewalls
01 · Challenge

Modernise the Azure network for resilience and security.

As part of its digital transformation, Lakeland Dairies set out to modernise its network architecture in Azure to support resilience, security and cross-regional disaster recovery — a foundation robust enough to carry more workloads to the cloud over time.

02 · Constraints & requirements

What shaped the design.

  • Production-ready across two Azure regions, with cross-regional disaster recovery.
  • Centrally managed governance and a policy-driven approach.
  • Security built in — network firewalls, web application firewalls and NSGs.
  • The in-house team had to understand how future workloads would be delivered.
03 · Architecture

Hub-and-spoke, Zero Trust, dual region, governed.

A centrally governed hub-and-spoke model implementing a Zero Trust approach: network firewalls, web application firewalls and NSGs driven by automation. Two regions with availability zones and multiple failover paths, backed by detailed design documentation. A continuously assessed and improved governance system guardrails new workloads and data, with the maximum of automated control.

Lakeland Dairies — Azure governance overview
Lakeland Dairies — Azure governance overview
Azure tenant
Azure tenant
General Azure Policy
Set once at the top and inherited by every subscription below
General Azure Policy...
Framework subscriptions
Framework Azure Policy
Framework subscriptions...
P1 security subscriptions
P1 security Azure Policy
P1 security subscriptions...
P2 security subscriptions
P2 security Azure Policy
P2 security subscriptions...
P3 security subscriptions
P3 security Azure Policy
P3 security subscriptions...
Microsoft Defender for Cloud  ·  Azure Virtual Network Manager  ·  Azure Monitor
Applied across every subscription
Microsoft Defender for Cloud  ·  Azure Virtual Network Manager  ·  Azure Monitor...
General policy is set once and inherited by every subscription. Each security tier adds only the controls it needs.
General policy is set once and inherited by every subscription. Each security tier adds only the controls it needs.
Governance model — general Azure Policy set once and inherited by every subscription
04 · Key decisions

Decision · why · what we rejected.

Hub-and-spoke topology

Why: A central hub for shared services, inspection and policy, with spokes that inherit governance consistently across both regions.

What we rejected: Traditional multi-application networks that weaken security and increase complexity.

Central egress through Azure Firewall

Why: One place to inspect and log outbound traffic, with policy the in-house team can read and audit.

What we rejected: Per-spoke egress that scatters policy and logging across the estate.

Zero Trust segmentation (NSGs + WAFs)

Why: Assume breach: control east-west traffic and protect public entry points rather than trusting internal traffic.

What we rejected: A flat network that trusts anything already inside it.

Versioned, continuously improved governance

Why: A minimum-viable security and governance baseline, assessed and improved continuously — so real protection lands in days rather than weeks, and the controls grow with the environment instead of being frozen on day one.

What we rejected: A large, static Azure Policy implementation that takes weeks to stand up and that the client does not understand.

05 · How we delivered

Mentoring-first, hands-on throughout.

We took a mentoring-first approach with hands-on guidance across the 21-day engagement, involving the client team in the build and delivering pre-training. By handover the team understood the environment — the point was never to leave them dependent on us.

06 · Outcomes

Outcomes

21Day engagement
2Regions
  • A fully operational, production-ready Azure network across two regions.
  • A disaster recovery architecture, validated and documented.
  • A team equipped with practical knowledge to deliver future workloads.
  • Resilient connectivity.
  • Governance & security.

Client quote

“As we continue migrating more workloads to the cloud, we partnered with Cloud Mechanix to establish a robust environment with the right governance, security, and automation in place. Cloud Mechanix's collaborative approach—particularly involving my team in the build process and delivering pre-training—was instrumental in helping us understand how we'll deliver future workloads in Azure.”
Gerry Forde, IT Operations Manager, Lakeland Dairies