Modernisation of IT infrastructure in a small company - case study
Modernising the IT infrastructure in a small company did not start with choosing a router. It started with determining what eight workstations, several printers and the server with the ERP system were actually working on, since the Internet was regularly disconnected, there was no Wi-Fi, and no one had a full picture of the network. We show the existing condition, the scope of work performed and the project boundaries without providing the client's name and without adding results that we did not measure.

In short: starting point, scope and result
| Area | State before work | Scope made by NexaIT |
|---|---|---|
| Users and systems | 8 workstations, several printers, server with ERP system | Inventory of dependencies and organisation of the network layer |
| Internet | According to the documentation, the link reaches approximately 1-5 Mb/s and regularly drops the connection | New 5G connection with an external device |
| Cabling | Unlabeled cables, no tidy distribution point | New structured cabling, terminations, port descriptions, patch panel and 19-inch RACK cabinet |
| Local network | Old devices, lack of central management and documentation | UniFi network gateway, managed PoE switch, i.e. powered via a network cable, and central management |
| Wi-Fi | No business wireless network | 3 access points Wi-Fi 7, i.e. devices distributing the wireless network; range inside and outside the building |
| Traffic separation | No documented device division | VLANs, i.e. logical segments for office, management and server, monitoring, IoT and guests |
| Power supply and operating conditions | Lack of consistent infrastructure security | UPS and temperature and humidity monitoring in the cabinet |
| CCTV | No target managed solution included in the project | 6 4K cameras, UniFi Protect local recorder and 12 TB disk |
This is important: the scope described in this case study concerns network infrastructure and monitoring. Modernisation of the ERP server and implementation of a confirmed backup process are a separate stage. We do not present them as completed.
“Somehow it works” was a problem statement, not an IT strategy
A starting point like this looks like an extreme case, yet setups like it rarely come from a single bad deployment. They usually build up over years. Someone adds a new router, someone else extends a cable, the next device ends up wherever a free socket happens to be, and knowledge of the connections lives only in one person's memory.
The outside is a mess. From the company's perspective, the problem is more serious because daily operations depended on this infrastructure:
- eight workstations had to use the Internet and the ERP system,
- several printers required constant access to the network,
- the server supported a key business system,
- backups were reported to exist, but we did not have a confirmed, tested recovery process,
- the connection was slow and disconnected regularly,
- the company did not have a consistent network Wi-Fi,
- lacked central management, port descriptions and up-to-date documentation.
So simply placing the devices on the windowsill above the radiator was not the biggest risk. The biggest risk was not knowing what would happen if one of the wires was disconnected and how quickly work could be restored.
If similar symptoms occur in your company, there may be several reasons. We also described their arrangement in the guide why the corporate network is slow and where to start diagnosing.
Why didn't we start by replacing the router
The new router wouldn't fix unlabeled wires, wouldn't create logical points in rooms, and wouldn't answer the question of where the ERP server was connected. It would also not provide power, documentation, or Wi-Fi coverage protection throughout the facility.
The first task was therefore an inventory of the existing condition. We checked the devices, connections, arrangement of workstations, Internet connection and dependencies important for the company's operation. In parallel, we analysed the available link variants, because in this location the traditional solution did not provide the expected parameters.
Only after this analysis could the sequence of works be arranged. The project included the passive layer, active devices, wireless network, emergency power supply, monitoring of conditions in the rack and a camera system. Thanks to this, there was not another single element attached to the old system, but one managed infrastructure with clearly defined functions.
How the IT infrastructure was modernised in a small company
1. New structured cabling and one distribution point
We installed new structured cabling to the stations and devices covered by the project. We finished the tracks in a patch panel, described them on both sides and organised them in a 19-inch RACK cabinet, 20U high. The cabinet contains network devices, emergency power supply and monitoring elements.
Each track made has been checked for connection continuity. We consciously do not call it a cabling certification measurement, because such a measurement requires an appropriate procedure, a meter and a report with transmission parameters. This distinction is important when accepting the installation.
The choice of rack cabinet itself did not come down to aesthetics. Space was needed for devices, cable management, ventilation, service access and reserves for further expansion. More practical criteria are described in the material how to choose a RACK cabinet for a small company.
2. New 5G connection instead of continuing to patch the old access
In the initial documentation, we noted transfer rates of approximately 1-5 Mb/s and repeated connection drops. Before choosing a solution, we performed an availability analysis and measurements, and then launched a 5G connection with an external receiving device.
The use of an external device was not accidental. In cellular networks, the result is determined by the conditions in a specific location, the level and quality of the signal, the station load and the correct positioning of the device. Therefore, 5G should not be selected solely on the basis of the coverage map or the speed declaration in the operator's offer.
For this case study, we do not publish the post-deployment speed test result because we do not have a validated measurement for public before-and-after comparison. However, we can confirm that the analysis has been performed, the solution has been selected and the new link has been launched as an element of the target architecture.
3. Centrally managed network UniFi and three access points Wi-Fi 7
We have launched a centrally managed UniFi network, including a UDM-Pro network gateway, a USW-Pro-24-PoE switch and three Wi-Fi 7 access points: two indoors and one intended for outdoor use.
The gateway provides routing, firewall and environment management functions. The switch powers PoE-compatible devices, so access points and some monitoring do not require separate power supplies for each device. We selected access points based on the facility's layout and required zones, and not solely on the number of users. The manufacturer publishes detailed information U7 Pro access point specifications, but the quality of implementation is still determined by the deployment, configuration and radio conditions.
Central management gives the administrator a common view of devices, clients, ports and events. It does not eliminate failures, but it significantly changes the way they are diagnosed: instead of checking several independent devices with no history, you can start with a consistent topology and the current state of the network.
4. Split traffic instead of one common network
We have implemented a logical division into VLANs, separating office traffic, server and management devices, video monitoring, IoT and the guest network. This division limits the flow of traffic between groups of devices and allows you to build access rules consistent with their function.
However, segmentation is not automatically synonymous with security. Its effectiveness depends on firewall rules, account management, updates and communication tests between segments. In this project, the segment architecture and the basis for further hardening of the configuration were created. We do not describe the entire environment as having a complete cybersecurity audit because that was not the scope of this stage.
5. UPS and control of conditions in the cabinet
Network devices and the recorder were provided with emergency power supply from the UPS. We also added temperature and humidity sensors to monitor conditions inside the cabinet.
The UPS does not replace a generator or redundant power supply, but it allows you to survive short outages, limits the effects of voltage fluctuations and gives you time for controlled shutdown of devices. In turn, environmental monitoring allows you to notice an increase in temperature before the problem manifests itself in unstable operation of the equipment.
6. Six 4K cameras with local recording
The last part of the described scope was the launch of the UniFi Protect monitoring system. We have implemented six 4K cameras, including two dome cameras and four tube cameras, and the recordings are stored locally on a 12 TB surveillance disk.
Local save means that the material is not automatically backed up off-site. The manufacturer explains that UniFi Protect recordings are stored locally by default. If the company requires additional copy, longer retention or an export procedure after an event, this must be planned separately and confirmed with a test.
What actually changed after implementation
The most important result is not the removal of neatly laid cables. It is the transition from an infrastructure that no one has been able to fully describe, to an environment that can be managed and further developed.
| Before modernisation | After executing the range NexaIT |
|---|---|
| Devices and cables placed ad hoc | One distribution point in a RACK cabinet |
| No consistent call description | Marked tracks, ports and as-built documentation |
| Old, independent devices | One centrally managed network platform |
| No corporate Wi-Fi | Three access points Wi-Fi 7 for indoor and outdoor zones |
| No documented device separation | Separate VLANs by function and trust level |
| No consistent power protection | UPS and monitoring of conditions in the rack |
| No target monitoring covered by the project | Six 4K cameras with 12 TB local storage |
| Diagnosis based on guesswork | Central view of devices, ports and clients |
We do not publish percentage improvements in availability, failures avoided, or time savings because the project did not have a prior measurement base to honestly calculate such metrics. However, the result can be assessed operationally: it is known what elements make up the network, where they are connected, how they are powered, which devices belong to a given segment and who has administrative access.
What we have prepared beyond devices
Equipment without documentation may lead to the same starting point after a few years. Therefore, the prepared package also included information needed for subsequent maintenance:
- list of devices and their roles,
- description of network segments,
- port and logical point designations,
- information about configuration and administrative access,
- as-built documentation,
- scope of tests performed and list of elements requiring further work.
The documentation should enable the environment to be operated also by a person who did not participate in the installation. This is one of the reasons we treat acceptance protocol and as-built documentation of the network as part of the implementation, not an optional add-on.
What we do not consciously add to this case study
A good implementation description should show not only the work performed, but also the limits of responsibility. In this case we do not claim that:
- we modernised the ERP server because its reconstruction was planned as a separate stage,
- we implemented and tested a complete backup system, because the previous backup required separate verification and recovery test,
- we performed continuity tests on each cable track; the scope did not include certification measurements or a certification report,
- we conducted a full cybersecurity audit and complete hardening of the entire environment,
- a specific speed, recording retention or UPS run time has been achieved if such value has not been confirmed by a documented test.
These reservations do not detract from the modernisation performed. They show which risks have been closed and which require another task, budget and acceptance criteria.
What can a business owner check out of this project?
You don't have to wait for a complete failure to assess the condition of your infrastructure. Just answer a few questions:
- Do you know where each wire goes to at the main network point?
- Do active devices have current support and a single configuration owner?
- Are the guest network, monitoring, IoT devices and employee computers logically separated?
- After a power outage, do you know how long the router, switches and recorder work?
- Is there a current network diagram and a list of administrative accesses belonging to the company?
- Has the server ever been backed up in a controlled test?
- Can a link failure be distinguished from a problem with Wi-Fi or a specific switch port?
If the answer to most of these questions is "I don't know", the problem is not only the aesthetics of the cabling. The company has no control over the system on which its daily operations depend.
Frequently asked questions about a similar modernisation
With eight seats, do you really need a managed network?
The number of computers is not the only criterion. Printers, an ERP server, cameras, access points and technical devices also worked in this environment. Management becomes necessary when a company wants to see the condition of the infrastructure, distribute traffic, control access and diagnose problems faster.
Can 5G be the main internet connection in the company?
Maybe, if preceded by measurements in a specific location, proper selection of the device and assessment of stability. The mere availability of 5G on the map is not enough. For companies that are particularly Internet-dependent, it's worth considering a second connection and automatic failover separately.
Does Wi-Fi 7 solve the range problem?
Not alone. The newer standard provides certain technical capabilities, but the range and quality of the connection depend on the location of access points, building structure, interference, configuration and capabilities of customer devices. In this implementation, three properly placed points were important, including the outdoor unit, and not only the inscription "Wi-Fi 7" on the box.
Are local camera recordings a backup?
No. The disk in the recorder is the basic place for storing recordings. The loss of a device, disk, or entire object may mean loss of material, so additional copy requirements must be determined separately.
Where to start a similar project?
From inventory and diagnosis, not from a shopping list. First, you need to determine business dependencies, cabling condition, critical devices, connection issues, and expected coverage. Only then can the architecture, devices, work sequence and acceptance criteria be selected.
Infrastructure needs to be predictable, not just functional
In a small company, one incorrectly described plug-in can disconnect the printer, workstations or ERP system. That's why professional modernisation does not end with replacing the device. It includes cabling, power supply, logical network division, monitoring, documentation and transfer of control to the infrastructure owner.
NexaIT designs, builds and maintains corporate networks, combining the cable layer, active devices, Wi-Fi and documentation into one coherent scope.
Book a free IT reviewif you want to check whether your company's network is actually managed or whether it has just not disconnected yet. We prepared the description for
How this case study was created
We prepared this description from the initial documentation, the inventory, the as-built documentation, the list of completed work and corrections from the person leading the project at NexaIT. We removed the client name, address and any details that could identify the site.
We did not use estimated results as implementation results. Where there was no approved measurement or a given stage was not performed, we inform about it directly.