Service · Cybersecurity

VPN and encryption

Encryption is not there to impress an auditor: it decides what happens on the day something slips out of your hands. A laptop left in a station concourse, a link between two warehouses running across a public network, a payroll file sent to an outside accountant. Depending on whether the data was encrypted, the event stays a lost asset or becomes a breach to investigate. We build the tunnels, the remote access and the disk encryption, and we leave behind documentation another provider could pick up.

Site to site
one tunnel per link, its own keys
Second factor
required on roaming access
Disks
encrypted, recovery keys kept safe
Documentation
handed over at the end

Where this service reaches

Three uses are worth separating, because they are not solved the same way: joining sites together, letting a travelling colleague in, and protecting data that moves on a device or inside a message.

Put your scope to an engineer

Links between sites

Encrypted tunnels between the firewalls at your premises, with routes limited to what each site needs. A branch office does not have to reach head office's management server in order to read next week's schedule.

Access for remote people

A modern client or an application access gateway, always with a second factor and a check on the state of the machine. The account is cut off when someone leaves, at the same time as everything else.

Supplier access

Every outside engineer gets a named account, a maintenance window and a scope narrowed to the machine they look after. The generic account shared by an entire maintenance firm disappears.

Disk encryption

BitLocker or FileVault switched on and, more importantly, verified, with recovery keys escrowed in your directory. An encrypted disk whose recovery key nobody can find is an outage, not a protection.

Sensitive exchanges

Encrypted mail for documents that warrant it, drop areas with time-limited links instead of attachments, and an end to archives protected by a password written two lines below.

Certificates

An inventory, renewals actually tracked and legacy protocols disabled. One forgotten expiry on a Saturday morning takes access down more reliably than an attack does.

The way an engagement runs

The switch-over is prepared so that nobody loses their connection during working hours, and the old route stays available until the new one has been signed off.

01

Survey

We list the sites, the links already running, the remote access tools in place and the people using them, including access opened once for a supplier and never revisited.

02

Design

Choosing technology that suits your equipment, an addressing plan, routing rules and a clear statement of what each user profile actually reaches.

03

Commissioning

Tunnels brought up in an agreed window, the client pushed to machines through Intune, and users moved across in stages.

04

Acceptance and handover

Tests from an outside connection, encryption verified machine by machine, old access withdrawn and the technical file handed to you.

An encrypted tunnel is only as good as whatever sits behind it. Many corporate connections, once established, open the whole internal network as though the person were sitting at their desk. A compromised home machine then becomes a complete way in. We therefore limit each profile to the servers and applications it genuinely uses.

Questions and answers

Sometimes, when all traffic is hauled back to head office, video calls and cloud services included. We set access up so that Microsoft 365 and hosted applications go direct and only traffic bound for your internal servers takes the tunnel. The difference shows in the very first video meeting.

Not necessarily. When mail, files and the line-of-business applications are online services, conditional access and device compliance do the job better than a tunnel. It still earns its place for reaching an internal server, a controller or a production scanner, not for opening a browser.

With an encrypted disk and a managed machine, the whole thing takes an hour: sessions revoked, a remote wipe issued, the password changed and recent sign-ins checked. The recovery key stays in your directory, so hardware that turns up later can be reused.

Yes, and it happens often. We start by documenting the configuration as it stands, spotting accounts with no identifiable owner and rules that open wider than they need to, then we propose a staged takeover. Nothing is changed before you agree in writing.

Connect your sites without exposing them

Describe your sites, your equipment and how your people connect today. We will propose an architecture and a timetable.

When we are around
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
Talking it through
A call on Teams or Google Meet, whenever writing is not enough

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.