Security that nobody uses is no use at all. We put in measures that genuinely protect without turning your team’s day into an obstacle course.
The layers we put in
Perimeter and firewall
pfSense and OPNsense in high availability, rules that get reviewed and a log of what goes in and out.
Network segmentation
VLANs by department, isolation for IoT, guests and production. So that one infected machine doesn’t take the company with it.
Access control
Two-factor authentication, role-based permissions and regular reviews of who has access to what.
Protected workstations
Managed antivirus, disk encryption and update policies that are actually enforced.
Email and phishing
Filtering, SPF, DKIM and DMARC properly configured, plus practical training for your people.
Audits
Regular reviews of configuration, permissions and exposed surface, with a prioritised remediation plan.
What it includes
- VPN for remote working with two-factor authentication
- Network segmentation and traffic control between segments
- Password policy and a corporate password manager
- Immutable backups that stand up to ransomware
- An incident response plan written down and rehearsed
- GDPR compliance: record of processing activities and technical measures
How we tackle it
Diagnosis
We review the exposed surface, the firewall configuration, permissions and the state of your workstations. We tell you where they would get in.
Prioritised remediation
High risk and low cost first. There is no need to change everything in the first month.
Continuous monitoring
Monitoring, rule reviews and periodic audits. Security is not a project, it is maintenance.