Case study · Fintech · 140 employees

1,000+ hours saved a year with fewer connectivity issues

A regulated fintech replaced its hardware VPN and branch-office backhaul with OpenVLAN — cutting support load and passing its next audit faster.

Northwind Financial — fintech office with network display

Mornings started in the queue

Two concentrators, 140 staff, and a failure mode everyone could recite: at 9:05 the gateways saturated, connections queued, and the ticket count climbed until lunch. The dashboard below is the "before" the infrastructure team screenshotted for their own post-mortem.

  • ✓A full workday per week spent on triage, per person
  • ✓Branch traffic backhauled through whichever gateway had room
  • ✓Audit prep meant screenshots of firewall rules by hand
vpn-status — the "before" screenshot
vpn-01.corpprimary gateway96% cpuQUEUED
vpn-02.corpfailover gateway91% cpuQUEUED
branch officebackhaul to vpn-01148 msSLOW
remote staff140 connections47 waitingTICKETS
audit prepmanual screenshots3 daysMANUAL

Audit day became a log export

The change auditors noticed first wasn't the network — it was the evidence. Access reviews that once required a week of screenshot assembly became a single command, because every session already carried an identity, a device, and a timestamp.

# SOC 2 evidence, before OpenVLAN
week 1 screenshot 40 firewall rules
week 2 export 3 concentrator configs
week 3 explain split-tunneling to the auditor
 
# after
$ openvlan audit export --since 2026-01-01
→ who, what, when, from where — one file

The challenge

Northwind ran a pair of VPN concentrators across two offices, with every remote employee backhauling through whichever gateway had capacity. Peak mornings meant queueing; quarter-end meant tickets. The two-person infrastructure team spent the equivalent of a full workday each week on connectivity triage — resets, reconnects, and explaining split-tunneling to auditors.

The switch

They connected OpenVLAN to their existing identity provider so access rules inherited the same groups IT already maintained. A pilot of ten engineers ran for two weeks alongside the old VPN. Rollout to all 140 staff finished inside a month, and the concentrators were decommissioned the following quarter.

The results

Connectivity tickets dropped so far that the infrastructure team rebuilt their support dashboard around it: roughly 1,000+ staff-hours per year returned to actual work. Audit prep, previously a scramble of screenshots and firewall exports, became a log export. And employees stopped noticing the network — which is the point.

1,000+

staff-hours saved per year

2

VPN concentrators decommissioned

1 mo

from pilot to full migration

"The network stopped being a topic in our standup. I didn't realize how much of my week it was eating until it was gone."
— Infrastructure lead, Northwind Financial

What's next

Northwind is now moving database maintenance windows onto scoped, expiring privileged sessions — the same identity model, applied to their most sensitive systems.

This case study is an illustrative example with fictional data for demonstration purposes.

Northwind FAQs

How did the two-week pilot actually run?
Ten engineers kept both clients installed — the old VPN for anything that misbehaved, OpenVLAN for everything else. By the end of week one, nobody opened the old client. The parallel-run is the whole trick: there was never a moment of risk to reverse.
Did anything break during migration?
One thing: a printer subnet that only spoke to the office network. It stayed on the old VPN for two extra weeks until a subnet router covered it. That was the entire incident list — a printer.
How does a regulated fintech clear the compliance review?
The data path is peer-to-peer and encrypted; the control plane holds policy, not payload. For auditors, that meant one log stream to review instead of per-appliance exports. Northwind's own audit prep went from three days to a single export.
What happened to the two concentrators?
Powered off at quarter end, rack space reclaimed, maintenance contracts cancelled at renewal. The rack space now hosts the staging cluster — the VPN budget line became a compute line.
Could a team like ours copy this rollout?
Yes — it's the standard playbook: IdP connection on day one, a pilot of ten, subnet router in week two, full rollout by week four. Start with the free plan and keep the old system running until the ticket queue goes quiet.

Ready for your 1,000 hours back?