Service · Cybersecurity

Infrastructure security

It comes down to one sentence: a compromised machine must not lead to everything. A flat network, where a sales laptop talks straight to the file server, the ERP and the controllers on the shop floor, is the usual backdrop to a ransomware incident. One attachment opened without thinking is then enough to stop production for days, and restarting costs far more than the zoning that would have prevented it.

3389
the remote desktop port we close first
VLANs
one zone per family of devices
MFA
on every route in from outside
Before and after
a scan report at each end

Where this service reaches

We work from the outside inwards: the boundary with the internet first, the internal split next, and the servers and workstations themselves last.

Put your scope to an engineer

Internet edge

Inbound and outbound firewall rules: what may leave, what may enter, and from which addresses. We also clear out the port forwards opened one afternoon for a supplier and never closed again.

Segmentation

Servers, workstations, the guest network, printers, cameras and production equipment move into separate VLANs, with only the traffic that is genuinely needed allowed between them.

Remote access

Remote desktop published straight onto the internet gives way to a VPN or a gateway with a second factor and conditional access. It is one of the favourite ways in for ransomware crews.

Servers

Patching that actually happens, unused services turned off, and administration through dedicated accounts rather than the one somebody uses to read email.

Network devices

Factory passwords replaced on switches, printers, video recorders and the router supplied by your carrier, and management interfaces lifted out of the user network.

Logs and alerts

Firewall and server logs land in one place, which makes it possible to raise an alert on something odd, such as an administrator signing in at three in the morning on a Sunday.

The way an engagement runs

Network changes go in by stages, away from the busy hours, and each one has a return configuration ready to apply.

01

Network map

A diagram, an inventory of open ports and a list of every remote access route. For many companies this is the first complete picture of their own infrastructure.

02

Urgent items

Unneeded ports closed, factory passwords replaced and services nobody uses any more switched off.

03

Zoning

Segmentation moves forward in steps so that production and sales keep running. If a cable has to be moved or an appliance fitted, your own staff or your installer does it from our instructions.

04

Verification

We scan from the outside and then from within, and hand over a report comparing the position before and after the work.

The camera, the printer and the air conditioning are on your network too. Devices nobody thinks of as computers usually keep their factory password and the firmware they shipped with. On a flat network they are an ideal foothold; on a zoned network they lead nowhere at all.

Questions and answers

Not always. Many switches and firewalls have handled VLANs for years and the feature was simply never turned on. We check that at the start, and if the equipment genuinely cannot cope we give you the specification to order from your usual supplier: we do not sell hardware.

Work is planned so that outages are short and fall outside working hours. Every change carries a return configuration, so if something misbehaves the previous state comes back within minutes.

Firewalls, switches and servers are configured over secure remote access. If a device has to be swapped or a cable run, the physical part is done on site by your team or your electrician, guided step by step by our engineer who then takes the configuration back over.

An encrypted tunnel between the two firewalls, with the same zoning logic applied at both ends. A branch does not need to see every resource at head office, only the ones its work really touches.

Such equipment almost never accepts updates, so we protect it by isolation: a dedicated zone, traffic allowed only from named engineering workstations, and no direct route out to the internet. The manufacturer who maintains the machine remotely comes in through a named, logged account.

See what the internet can see of you

Describe your network briefly: how many sites, how many servers and how remote people connect. We will start with a review of what is exposed.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.