Servicio

Cybersecurity

pfSense and OPNsense firewalls, two-factor VPN, network segmentation and access control. Security that really protects without slowing work down.

Security that nobody uses is no use at all. We put in measures that genuinely protect without turning your team’s day into an obstacle course.

The layers we put in

Perimeter and firewall

pfSense and OPNsense in high availability, rules that get reviewed and a log of what goes in and out.

Network segmentation

VLANs by department, isolation for IoT, guests and production. So that one infected machine doesn’t take the company with it.

Access control

Two-factor authentication, role-based permissions and regular reviews of who has access to what.

Protected workstations

Managed antivirus, disk encryption and update policies that are actually enforced.

Email and phishing

Filtering, SPF, DKIM and DMARC properly configured, plus practical training for your people.

Audits

Regular reviews of configuration, permissions and exposed surface, with a prioritised remediation plan.

What it includes

  • VPN for remote working with two-factor authentication
  • Network segmentation and traffic control between segments
  • Password policy and a corporate password manager
  • Immutable backups that stand up to ransomware
  • An incident response plan written down and rehearsed
  • GDPR compliance: record of processing activities and technical measures

How we tackle it

Diagnosis

We review the exposed surface, the firewall configuration, permissions and the state of your workstations. We tell you where they would get in.

Prioritised remediation

High risk and low cost first. There is no need to change everything in the first month.

Continuous monitoring

Monitoring, rule reviews and periodic audits. Security is not a project, it is maintenance.

Frequently asked questions

We’ve been asked for a pen test. Do you do those?
We coordinate technical audits and, above all, we take care of fixing whatever comes out of them. A pen test report with no remediation plan protects nobody.
And if we have already been hit by ransomware?
The first thing is to contain it and assess the scope; then restore from clean backups. If you call us in the middle of it, we switch to incident mode: get the business back first, do the analysis afterwards.
Is user training actually worth anything?
It has one of the best cost-benefit ratios there is. Short sessions and phishing drills cut clicks on malicious emails enormously.

Shall we look at your specific case?

30 minutes with an engineer, no strings attached. We will tell you what we would improve and what we would leave alone.