Case Study
Global Network Access Control for a BioPharma Company
A biopharmaceutical company worked with AHEAD to implement Aruba ClearPass and role-based policies to strengthen security and improve audit readiness.

The Trial 

In biopharma, the network runs on contradiction: move quickly but trust slowly. For this global biopharmaceutical company, users, devices, applications, and labs all needed reliable access to the network. However, that access had to be deliberate, policy-driven, and easy to explain after the fact. That’s a tough balance to strike when every site uses different authentication methods, and endpoint policies live in separate places. 

The Control Group 

The company needed a platform that could manage access for an expanding global network. 

Inconsistent Authentication and Access. Because different sites and user groups had different methods to connect, it was creating an uneven experience for users and uneven control for security teams. This was further complicated by the company not having one central policy engine, which made it difficult to apply the same access rules across headquarters, labs, manufacturing areas, and other network environments. 

Compliance Pressure. That lack of control was at odds with the company’s heavily regulated industry, where everything needs to be controlled and enforced. Access decisions had to be traceable and enforceable. 

Endpoint Uncertainty. The lack of control extended beyond access, to endpoints as well. Devices could connect to the network without giving the security team context about their identity, role, or compliance posture. 

Enterprise Integration. Any solution for control had to work with Active Directory and the applications that employees already depended on. Security could not become a separate login obstacle course. 

The company’s work developing therapies had already given it a fine-tuned approach to validating small batches, confirming that it held up to standard, then releasing at scale without cutting corners. It had to take a similar approach to the technology driving it, with a partner who could help it build and implement a repeatable operating model for network access. 

The Protocol 

This engagement aligned with two areas of AHEAD’s expertise. 

  • Secure & Resilient Architecture: Establishing a policy-driven access layer to reduce the attack surface, enforce least-privilege access, and make endpoint decisions more consistent. 
  • Operational Excellence: Translating access control into a staged delivery and operating model that could be tested, documented, and extended across sites. 

The work unfolded across three phases: 

Advise 

AHEAD started with the access model itself, reviewing how wired and wireless requests were handled, where policies were currently being applied, and how endpoints were classified. The design established the need for a central network access control platform, integration with Active Directory, and required posture checks for endpoint access. A rollout plan accounted for the many different environments where the company’s access policies would apply. 

Why the Groundwork Mattered: The company brought access decisions about identity, device context, policy, and compliance into one conversation. 

Build 

AHEAD designed and deployed an Aruba ClearPass cluster as the central NAC platform. Integration with Active Directory meant existing identity information could support access decisions without users learning a new set of credentials. Policy rules could be applied according to the person, device, and context of the connection. 

AHEAD also built and deployed a parallel environment that ran alongside the new ClearPass environment for testing and safeguarding the transition. Policies were synchronized between the environments, with network access requests directed to the new cluster in controlled waves. Pilot devices represented the range of endpoints the company needed to support, ranging from phones to laboratory and manufacturing equipment. The parallel environment was an escape hatch; if a pilot exposed a policy or device-compatibility issue, affected traffic could be returned to the existing environment so the team could course correct. And biopharma knows better than most not to skip the validation step. 

How It Came to Life: Authentication, endpoint classification, and role-based policy enforcement all became part of the same operating model. Pairing that centralized policy with a deliberately incremental rollout meant security modernization could continue to proceed, even when it hit bumps during the process. 

Run 

After successfully piloting the role-based NAC, AHEAD extended the model to additional sites, with additional waves for research and production locations. These early waves included first-day support and hypercare so endpoint issues could be addressed right away.  

How It Kept Delivering: By treating NAC as an ongoing operating capability, the company could improve control without making access management harder to run.

Phase Three 

The company now has a standardized, policy-driven model for network access. 

Improved Authorization. Unauthorized access attempts have already been reduced by approximately 30%. Access control is no longer a reactive function, but a deliberate, proactive security control. 

Compliance Readiness. Centralized policies, endpoint posture checks, and traceable access decisions make it easier for the company to demonstrate how network access is being governed. 

A Global Model. The pilot-and-wave approach made it easier to extend the NAC to research and development facilities, manufacturing plants, and other sites.

What’s Next 

The company plans to automate compliance enforcement across endpoints and feed ClearPass logs into its security operations center. Strong access control isn’t just saying no, but making the right yes based on identity, device posture, and context. AHEAD helps organizations build resilient architectures that are ready to operate, audit, and scale. 

Top Takeaways

AHEAD:

  • Standardized network access control across headquarters and initial sites. 
  • Reduced unauthorized access attempts by approximately 30%. 
  • Added role-based access and endpoint posture checks before granting network access.