How we size, structure, and deliver Palo Alto projects

blog-2-omar-gonzalez

The methodology behind the contract: how sizing, phased delivery, and clearly named delivery models keep a deployment from becoming anyone’s part-time job.

 

 

By Omar Gonzalez, PS Consultant Manager at Netdata Cybersecurity

 

Most under-delivered Palo Alto Networks projects were not badly executed. They were badly sized, sold as a tier, a bundle, or a round number of sessions that had no relationship to the environment they were about to meet.

 

In our companion article we covered why we rewrote the commercial terms around session expiration. This piece covers the other half: what happens before a quote is even issued, and how a project stays on track once it starts. It gets into the operational detail, sizing criteria, project phases, and delivery models that a technical evaluator will want to see.

 

 

 

Sizing is where deployments are won or lost

 

We size on quantity, derived from facts about the environment. Before a quote is issued, a Netdata architect runs a sizing interview that establishes the things that actually drive effort:

  • How many sites are in scope, and under which delivery model each one runs
  • How many data center connections are involved
  • How many deployment waves the customer’s change process requires
  • Whether SSL decryption has to be established
  • Which identity sources and log sources must be integrated

 

Those answers produce quantity, and it covers two things: the fixed spine of the project like kickoff, technical requirements, platform configuration, validation, documentation, and the environment-dependent work that varies wildly between two customers who bought the same license.

 

During discovery, we present a session allocation plan across the project activities and agree it with the customer, as a deliverable, not something produced only on request. The customer sees where their sessions are going before they are spent, and the allocation can be adjusted as the project progresses.

 

banner-cta-blog-2-omar-gonzalez

 

Saying out loud who does what

 

For anything that scales per site or per unit, our scope statements name two delivery models explicitly:

 

  • Full implementation
    Netdata prepares the Method of Procedure, performs pre-cutover validation, executes the cutover in a scheduled maintenance window, and provides post-cutover support.

  • Supported migration
    The customer executes the cutover, and we provide a pre-cutover readiness session plus a post-cutover support session.

 

Units not designated under either model are the customer’s responsibility. That sentence can read as a partner protecting itself; its actual purpose is to stop a customer from discovering in month five that forty branches were never anybody’s job.

 

 

 

A methodology that doesn’t depend on who shows up

 

Every Netdata deployment runs the same five phases, and every phase ends in an artifact, not a status update.

 

  • Kickoff: Objectives, resources, scheduling, communication plan, and the critical success factors both sides own.
  • Discovery: Current architecture, target architecture, any intermediate state, monitoring and policy definition, and the deployment strategy. Exits with a Technical Requirements Document and an implementation plan.
  • Configuration: Platform build, identity integration, policy migration where applicable, management, logging and monitoring. Exits with a fully configured solution ready for cutover and a Method of Procedure.
  • Deployment: The cutover sessions themselves, functional testing, configuration fine-tuning, high-availability testing.
  • Validation: Notification and monitoring checks, final deployment review. Exits with an As-Built document and a knowledge transfer session.

 

Underneath sits a governance layer defined at kickoff rather than improvised later: a weekly status report from the project controller, a recurring follow-up meeting, a written follow-up after every working session, and a named escalation path to technical leaders for decisions that block the work.

 

The critical success factors are equally explicit about the customer-side responsibilities: the MOP defines criticality, acceptable downtime, and rollback criteria; pre- and post-cutover testing is performed and evidenced by the customer’s application owners; change risk is communicated internally and approved.

 

 

 

Go-live starts the next phase, not the last one

 

A deployment ends. The environment doesn’t. Policies drift, the estate grows, the people who were trained move on, and the platform that was perfectly tuned in March is merely adequate by November.

 

So the project model above is only the first of three service models. All three are delivered fully remotely by consultants certified in a single Palo Alto Networks specialization, rather than generalists rotating across products:

  • Network security & SASE
    NGFW and CDSS, Panorama and Strata Cloud Manager, Prisma Access, SD-WAN.

  • Cloud & endpoint security
    VM-Series, CASB, ADEM.

  • Access & isolation
    Remote Browser Isolation.

 

The three service models:

 

  • Deployment Services
    The project-based model described above: defined scope, defined term, documented outcomes.

  • Retainer Consultant
    A named consultant on a recurring cadence across a twelve-month term, with an on-demand session bank for the unplanned, and a summary report after every session. Built for adoption and continuous improvement once the platform is live.

  • Extended Expertise
    A credit-based, high-intensity engagement with a dedicated consultant in a single specialization, for complex environments or accelerated programs.

 

 

The transition between models matters as much as the models themselves. A customer finishing a deployment can continue with the same consultant, in the same specialization, with the context already loaded, moving from getting it built to getting it good. None of the three replaces the customer’s own support organization or Palo Alto Networks’ support channels, and we say so in writing.

 

Talk to a Netdata specialist

 

 

Separador flechas 1-1

Ready to take your Palo Alto products to the next level?

 

Talk to our specialist about what your environment actually needs, and how it should be sized before anyone quotes it.

 

Omar Gonzalez
Omar Gonzalez
PS Consultant Manager at Netdata Cybersecurity.