Service · Cybersecurity

VPN and encryption

Data stops being safe the moment it leaves the desk: on its way from the warehouse to head office, from a sales rep's home Wi-Fi to the Comarch ERP server, from a laptop forgotten on a train. Both the GDPR and NIS2 list encryption among the safeguards, and when a laptop goes missing, whether the drive was encrypted matters a great deal in assessing the breach.

Branches
permanent tunnel with failover
Remote work
no open ports
Suppliers
access with an expiry date
Disks
BitLocker and FileVault

Included in this service

Joining two sites and letting individuals in from outside are separate problems. We design them separately, so that one mistake in the rules cannot expose the entire network.

Talk the scope through with an engineer

Site-to-site

An IPsec or WireGuard tunnel between head office, branches and the cloud, switching over automatically to a backup link such as LTE when the main carrier goes down.

Staff access

Either a classic VPN app or per-application Zero Trust (Entra Private Access, Cloudflare, Tailscale), with a second factor and a device health check every time.

Supplier access

Named accounts for outside firms, for example the engineer who maintains your practice management system, limited to one server and switching themselves off on a set date.

Device encryption

BitLocker on Windows and FileVault on Macs, with recovery keys held centrally in Entra ID or Intune instead of on a sticky note in a drawer.

Mail and files

TLS enforced on mail transport, Purview-encrypted messages for special category data, and rules for sharing files outside the company.

Certificates and logs

A certificate register with reminders before expiry, a connection log, and idle sessions dropped automatically.

How we work together

We configure everything over remote access. The timeline, failover test included, is agreed once the traffic map is ready.

01

Traffic map

We decide which people and systems have to talk to which. A sales rep needs the CRM and email, not the cameras and printers in the warehouse.

02

Configuration

Gateways, routes and per-group rules are set up remotely. Should a branch need a new router physically plugged in, one of your people or a contractor near the site handles that with our step-by-step guide in hand.

03

Second factor and apps

Intune pushes the VPN app to every laptop, and we run a brief call to help people get the authenticator working on their phones.

04

Testing

We cut the main link and check that the tunnel comes back up on the backup one. Documentation is handed over after that test passes.

A leaver's VPN account is the door into the business most often left unlocked. Mailbox access ends on the final working day, yet the remote desktop login tends to surface half a year on, when someone is piecing together a breach. We tie VPN accounts to Entra ID, so disabling a user in one place locks them out everywhere.

Questions and answers

A classic VPN lets people into the network; Zero Trust grants access to one specific application. If your team works mostly in Microsoft 365 and a single ERP, application access is both safer and more convenient. With many older systems on local servers, a VPN split by group is often the simpler route.

No. An open RDP port is a common entry point in ransomware attacks. Remote desktop should only ever be reachable through a tunnel or a gateway that demands a second factor.

On hardware from the last few years you will not notice, as the processor handles the encryption. The bigger danger is having no copy of the recovery key, which is why we store it centrally.

Not as an ordinary attachment with the password in a follow-up email. A SharePoint link restricted to the named recipient and set to expire works better, as does an encrypted message sent through Purview.

Secure your connections and disks

Let us know how many sites you run, how many people work remotely and which suppliers connect to your systems. We will sketch an access model and set it up over a remote session.

Hours
Mon-Fri 8:00-18:00 CET, reply within one working day
Meetings
Online via Teams or Google Meet

We set strictly necessary cookies only: they keep the site running and remember the city you chose. Nothing here is used for advertising or tracking. More in our privacy policy.