Site-to-site
An IPsec or WireGuard tunnel between head office, branches and the cloud, switching over automatically to a backup link such as LTE when the main carrier goes down.
Joining two sites and letting individuals in from outside are separate problems. We design them separately, so that one mistake in the rules cannot expose the entire network.
An IPsec or WireGuard tunnel between head office, branches and the cloud, switching over automatically to a backup link such as LTE when the main carrier goes down.
Either a classic VPN app or per-application Zero Trust (Entra Private Access, Cloudflare, Tailscale), with a second factor and a device health check every time.
Named accounts for outside firms, for example the engineer who maintains your practice management system, limited to one server and switching themselves off on a set date.
BitLocker on Windows and FileVault on Macs, with recovery keys held centrally in Entra ID or Intune instead of on a sticky note in a drawer.
TLS enforced on mail transport, Purview-encrypted messages for special category data, and rules for sharing files outside the company.
A certificate register with reminders before expiry, a connection log, and idle sessions dropped automatically.
We configure everything over remote access. The timeline, failover test included, is agreed once the traffic map is ready.
We decide which people and systems have to talk to which. A sales rep needs the CRM and email, not the cameras and printers in the warehouse.
Gateways, routes and per-group rules are set up remotely. Should a branch need a new router physically plugged in, one of your people or a contractor near the site handles that with our step-by-step guide in hand.
Intune pushes the VPN app to every laptop, and we run a brief call to help people get the authenticator working on their phones.
We cut the main link and check that the tunnel comes back up on the backup one. Documentation is handed over after that test passes.
A leaver's VPN account is the door into the business most often left unlocked. Mailbox access ends on the final working day, yet the remote desktop login tends to surface half a year on, when someone is piecing together a breach. We tie VPN accounts to Entra ID, so disabling a user in one place locks them out everywhere.
A classic VPN lets people into the network; Zero Trust grants access to one specific application. If your team works mostly in Microsoft 365 and a single ERP, application access is both safer and more convenient. With many older systems on local servers, a VPN split by group is often the simpler route.
No. An open RDP port is a common entry point in ransomware attacks. Remote desktop should only ever be reachable through a tunnel or a gateway that demands a second factor.
On hardware from the last few years you will not notice, as the processor handles the encryption. The bigger danger is having no copy of the recovery key, which is why we store it centrally.
Not as an ordinary attachment with the password in a follow-up email. A SharePoint link restricted to the named recipient and set to expire works better, as does an encrypted message sent through Purview.
Let us know how many sites you run, how many people work remotely and which suppliers connect to your systems. We will sketch an access model and set it up over a remote session.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.