Skip to content
← Back to Insights Managed IT

How Scouts Rebuilt a Nine-Site Network It Couldn't Fully See

SysGroup · · 3 min read
Two Scouts tying a woggle, one wearing a hoodie with the Scouts logo

Scouts, the charity that supports over half a million young people and volunteers across England, was running its national network on connectivity and hardware that had quietly fallen behind. MPLS circuits were costly and inflexible to change. Firewalls, switches and access points were ageing out of vendor support. Cross-site traffic ran on a security model that trusted any device once it was inside the network. Nobody at Scouts could say with confidence what was actually deployed across the estate, because nothing had mapped it in years.

That last problem came first, and it had to. Before SysGroup touched a single circuit or switch, it ran a VISTA platform assessment across Scouts’ nine locations to find out what was actually there. The answer was 583 devices: 96 of them network infrastructure, 60 already past end-of-sale, and 76 running software versions their vendors no longer recommend. None of that had shown up on a dashboard before. It had been accumulating for years, the way this kind of risk always does, one ageing switch and one skipped refresh cycle at a time.

“Following a thorough tender process, SysGroup demonstrated a strong understanding of our organisation, our values and our requirements in supporting young people and volunteers across England,” Scouts said of the engagement.

With the estate mapped, the rebuild followed in three parts. SysGroup retired the MPLS connectivity and replaced it with dedicated circuits at each site, giving Scouts consistent performance without the cost and lead times of the old network. It refreshed the hardware the assessment had flagged as end-of-sale or unsupported, working from the actual inventory instead of guesswork. And it introduced Zero Trust Network Access, so that a device or user is granted access by identity and verified continuously, instead of being trusted by default because it’s already inside the perimeter. That last change is the one that matters most across nine sites: if one location is compromised, an attacker no longer gets an automatic route to the other eight.

The difference shows up in four places. Connectivity now performs consistently across every location instead of varying site by site. The complexity Scouts’ internal IT team had to carry day to day has dropped. The estate is scalable, so growth doesn’t mean renegotiating another MPLS contract. And for the first time, Scouts has audit-ready visibility: a documented, current record of every asset and configuration across the organisation, not a best guess reconstructed when an auditor asks.

Scouts isn’t unusual in how it got here. Any organisation running IT across a handful of sites or more tends to arrive at the same place: a network that grew site by site, a documentation trail that stopped keeping up, and a security model built on trusting whatever’s already inside the perimeter. What Scouts’ engagement shows is the order that actually works. Start with a VISTA assessment to see the full estate before deciding what to refresh. Replace what the evidence says is failing. Then close the trust gap the old architecture left open, rather than layering new tools on top of it.

S

Written by

SysGroup

network infrastructurezero trust network accesscase studymanaged it servicescharity sector

Want to discuss this topic?

Our team is happy to talk through what this means for your organisation.

Speak to a Specialist