Campus Network Security Upgrade — CIO Proposal

A conceptual enterprise UniFi segmentation and monitoring design, developed from real-world observations and scoped for executive approval.
Timeline:
14
Days
Projected Cost: $
42000
LinkedInGitHub

A conceptual design proposal based on real-world observations. The institution and any identified shortcomings remain fully anonymized; the upgrade is a proposed architecture developed as a design case study — not a deployed system.

This project is a conceptual network security upgrade designed for a university environment, based on operational needs I observed firsthand and framed as a formal recommendation to a CIO. It's a design case study built on a realistic scenario — the proposal assumes approval to proceed, allowing a complete architecture to be designed end to end on Ubiquiti's UniFi enterprise platform.

Status: Planned — design work begins later this week.

The scenario: From a campus safety operations vantage point, I identified recurring gaps in how a campus network could be segmented, monitored, and protected — particularly where physical-security systems intersect with the broader network. This proposal turns those observations into a prioritized, defensible upgrade plan suitable for executive review.

Proposed scope:

  • Network segmentation (VLANs) — would isolate administrative, academic, student/residential, guest, IoT, and physical-security systems (surveillance, access control) so a breach in one domain can't move laterally into another.
  • Inter-VLAN firewall policy — least-privilege rules governing traffic between segments.
  • Threat management (IDS/IPS) — network-wide intrusion detection and prevention with anomaly monitoring.
  • Centralized visibility — a UniFi Network controller for logging, monitoring, and alerting across the deployment.
  • Converged security — treating the physical-security network as a hardened, monitored segment, bridging physical-security experience with network defense.
  • Scalability & resilience — a design intended to scale across buildings, with redundancy considerations.
  • Secure WiFi at scale — WPA3/enterprise authentication, role-based SSIDs, and guest isolation.

Proposed platform (Ubiquiti UniFi enterprise): UniFi security gateway (routing, firewall, IDS/IPS); UniFi aggregation and access switches (VLAN-aware, PoE); UniFi enterprise access points (multi-SSID); UniFi Network controller (centralized management and logging).

What this demonstrates: enterprise network segmentation and VLAN design, security architecture, IDS/IPS, requirements analysis and risk-based prioritization, executive-level communication, and converged physical/cyber security.