Service · Cybersecurity

Infrastructure security

We work towards one principle: a single compromised laptop must not unlock the rest of the business. When a sales machine can reach the file server, the ERP and the controllers on the shop floor directly, you have the typical setting of a ransomware incident. One opened attachment in such a network can halt operations for days.

3389
RDP port, first to be shut
VLAN
one zone per device type
MFA
on every route in from outside
Before/after
scan comparison

Included in this service

The order runs from the edge inwards: the internet boundary first, then internal separation, finally the servers and workstations.

Talk the scope through with an engineer

Perimeter

A firewall policy stating which traffic may leave, which may arrive and from where. Along the way we remove port forwards set up years ago and long forgotten.

Segmentation

Separate VLANs for servers, staff PCs, visitors, printers, CCTV and production kit, with only essential connections permitted between zones.

Remote access

Remote Desktop published directly online is swapped for a VPN or an access gateway protected by MFA and conditional access. Exposed RDP remains a favourite entry point for ransomware crews.

Servers

Patches, unused services turned off and administration only via dedicated admin identities, never the account someone reads email with.

Network devices

Factory passwords changed on switches, printers, camera recorders and ISP-supplied routers, with their management pages hidden from the staff network.

Logs and alerting

Firewall and server events are gathered centrally, so anything odd, such as an administrator signing in at 3 a.m., triggers a notification.

How we work together

Changes are staged, scheduled outside busy hours and always paired with a ready rollback configuration.

01

Mapping

A diagram of the network, its open ports and every remote entry route. Many firms see a complete picture of their own setup for the first time.

02

Urgent fixes

Unneeded ports closed, default credentials replaced, idle services disabled.

03

Zoning

Segmentation goes in gradually so production and sales keep running. Any recabling or device mounting is carried out by your staff or a local installer following our directions.

04

Verification

External and internal scans produce a report that sets the starting point against the finished state.

CCTV cameras, printers and even air conditioning controllers sit on your network. Kit nobody regards as a computer often runs default passwords and ancient firmware. In a flat network it makes an ideal foothold; in a zoned one it is a dead end.

Questions and answers

Not necessarily. Plenty of switches and firewalls have supported VLANs for years without anyone enabling the feature. We check early on, and only if the equipment truly falls short do we specify requirements for a purchase you make through your own supplier.

Work is planned so any interruption is brief and happens outside business hours. Each change has a prepared rollback, so if something misbehaves we quickly restore the previous state.

Firewalls, switches and servers are managed over secure remote connections. Should hardware need replacing or cable pulling, your local supplier does the physical part while our engineer talks them through it and handles the configuration.

We join them with an encrypted tunnel between firewalls and apply the same zoning logic at every site. A branch should reach only the head office resources it needs for its work.

Such devices often cannot be patched, so isolation protects them: a dedicated zone, traffic only from named engineering stations and no direct path to the internet.

Find out what outsiders can see

Describe your network briefly: sites, servers and how remote staff connect. We will begin by reviewing your exposure to the internet.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.