Internet edge
Inbound and outbound firewall rules: what may leave, what may enter, and from which addresses. We also clear out the port forwards opened one afternoon for a supplier and never closed again.
It comes down to one sentence: a compromised machine must not lead to everything. A flat network, where a sales laptop talks straight to the file server, the ERP and the controllers on the shop floor, is the usual backdrop to a ransomware incident. One attachment opened without thinking is then enough to stop production for days, and restarting costs far more than the zoning that would have prevented it.
We work from the outside inwards: the boundary with the internet first, the internal split next, and the servers and workstations themselves last.
Inbound and outbound firewall rules: what may leave, what may enter, and from which addresses. We also clear out the port forwards opened one afternoon for a supplier and never closed again.
Servers, workstations, the guest network, printers, cameras and production equipment move into separate VLANs, with only the traffic that is genuinely needed allowed between them.
Remote desktop published straight onto the internet gives way to a VPN or a gateway with a second factor and conditional access. It is one of the favourite ways in for ransomware crews.
Patching that actually happens, unused services turned off, and administration through dedicated accounts rather than the one somebody uses to read email.
Factory passwords replaced on switches, printers, video recorders and the router supplied by your carrier, and management interfaces lifted out of the user network.
Firewall and server logs land in one place, which makes it possible to raise an alert on something odd, such as an administrator signing in at three in the morning on a Sunday.
Network changes go in by stages, away from the busy hours, and each one has a return configuration ready to apply.
A diagram, an inventory of open ports and a list of every remote access route. For many companies this is the first complete picture of their own infrastructure.
Unneeded ports closed, factory passwords replaced and services nobody uses any more switched off.
Segmentation moves forward in steps so that production and sales keep running. If a cable has to be moved or an appliance fitted, your own staff or your installer does it from our instructions.
We scan from the outside and then from within, and hand over a report comparing the position before and after the work.
The camera, the printer and the air conditioning are on your network too. Devices nobody thinks of as computers usually keep their factory password and the firmware they shipped with. On a flat network they are an ideal foothold; on a zoned network they lead nowhere at all.
Not always. Many switches and firewalls have handled VLANs for years and the feature was simply never turned on. We check that at the start, and if the equipment genuinely cannot cope we give you the specification to order from your usual supplier: we do not sell hardware.
Work is planned so that outages are short and fall outside working hours. Every change carries a return configuration, so if something misbehaves the previous state comes back within minutes.
Firewalls, switches and servers are configured over secure remote access. If a device has to be swapped or a cable run, the physical part is done on site by your team or your electrician, guided step by step by our engineer who then takes the configuration back over.
An encrypted tunnel between the two firewalls, with the same zoning logic applied at both ends. A branch does not need to see every resource at head office, only the ones its work really touches.
Such equipment almost never accepts updates, so we protect it by isolation: a dedicated zone, traffic allowed only from named engineering workstations, and no direct route out to the internet. The manufacturer who maintains the machine remotely comes in through a named, logged account.
Describe your network briefly: how many sites, how many servers and how remote people connect. We will start with a review of what is exposed.
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
Nothing here under that name. Check the spelling, or simply choose the nearest large city instead. Since every engagement runs remotely, whichever you pick changes nothing about what we do for you.