Use Cases and Prerequisites
We assess the systems involved in the proposed access scenario.
- Record platforms and management status
- Define Wi-Fi, LAN and VPN scope
- Identify authentication services and owners
- Document dependencies before the pilot
Architecture, implementation and traceable evidence
ADVISORI supports certificate use for selected device, Wi-Fi, LAN and VPN access scenarios.
This service focuses on how endpoints and network access services use an existing PKI. We examine device management, authentication services and the actual platforms. The design identifies which certificate represents which participant and what separate access decision is made. Foundational CA implementation and a comprehensive PKI security review remain distinct work packages.
ADVISORI supports certificate use for selected device, Wi-Fi, LAN and VPN access scenarios. We connect provisioning, trust validation and access policies in a tested pilot and a documented rollout.
6 service modules
Bookable individually or as an end-to-end programme.
We assess the systems involved in the proposed access scenario.
We describe how a participant is associated with a certificate.
We support tested delivery to selected platforms.
We test procedures after initial authentication.
We make failures traceable for operators and support teams.
We plan implementation and fallback options for the agreed scope.
5 phases
Inputs include a platform inventory, access policies, certificate profiles and device-management and network contacts. The pilot tests authentication, renewal, device replacement and failures. Handover records the tested combination of device, profile and access service, including exceptions. Universal device support or a disruption-free rollout is not assumed.

Your contact
Sarah Richter
Head of Information Security, Cyber Security
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
A valid device certificate alone does not decide whether access should be allowed. Test identity mapping, certificate trust and the actual access policy together.
8 QUESTIONS, BRIEFLY ANSWERED
We need the device platforms, management status, access services and intended identities. Supported certificate profiles and trust anchors are checked. The pilot starts with a named combination; its success is not treated as proof that every device is supported.
No. Alongside certificate validation, the access service must decide whether the mapped identity is entitled to the requested access. That decision depends on the actual configuration. The pilot therefore also tests rejected identities and certificate profiles that should not be accepted.
The choice follows the access scenario. We record whether a device, person or another identity should be authenticated and how that association is established. Names and intended uses are aligned with the participating services. Similar-looking certificates can lead to different access decisions.
A limited pilot checks the agreed configuration and relevant failure cases. Acceptance criteria, support routes and suitable fallback options are then defined. Existing access paths are not removed without a tested alternative. Sequencing depends on the actual network and device dependencies.
We test whether replacement certificates arrive in time and are accepted by the access service. Device replacement or re-enrollment should not create unintended identity associations. Old certificates and permissions follow the agreed retirement procedure. Failed renewal needs a visible support route.
The procedure connects device management, certificate status and access permissions. Revocation alone is insufficient if the access service does not check status or checks it only later. We examine actual behaviour, including existing sessions, and agree appropriate responses for the platform in use.
We correlate client and server evidence for the same attempt. Checks can include time, certificate chain, profile, identity mapping and access policy. Observed facts are separated from suspected causes. Personal information in logs is used only within the authorised review scope.
PKI implementation provides certification authorities and foundational certificate processes. This engagement tests their use in device and network access. Missing CA capabilities or broader security questions become separate work packages with explicit ownership and acceptance criteria.










Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance