Perimeter
A firewall policy stating which traffic may leave, which may arrive and from where. Along the way we remove port forwards set up years ago and long forgotten.
The order runs from the edge inwards: the internet boundary first, then internal separation, finally the servers and workstations.
A firewall policy stating which traffic may leave, which may arrive and from where. Along the way we remove port forwards set up years ago and long forgotten.
Separate VLANs for servers, staff PCs, visitors, printers, CCTV and production kit, with only essential connections permitted between zones.
Remote Desktop published directly online is swapped for a VPN or an access gateway protected by MFA and conditional access. Exposed RDP remains a favourite entry point for ransomware crews.
Patches, unused services turned off and administration only via dedicated admin identities, never the account someone reads email with.
Factory passwords changed on switches, printers, camera recorders and ISP-supplied routers, with their management pages hidden from the staff network.
Firewall and server events are gathered centrally, so anything odd, such as an administrator signing in at 3 a.m., triggers a notification.
Changes are staged, scheduled outside busy hours and always paired with a ready rollback configuration.
A diagram of the network, its open ports and every remote entry route. Many firms see a complete picture of their own setup for the first time.
Unneeded ports closed, default credentials replaced, idle services disabled.
Segmentation goes in gradually so production and sales keep running. Any recabling or device mounting is carried out by your staff or a local installer following our directions.
External and internal scans produce a report that sets the starting point against the finished state.
CCTV cameras, printers and even air conditioning controllers sit on your network. Kit nobody regards as a computer often runs default passwords and ancient firmware. In a flat network it makes an ideal foothold; in a zoned one it is a dead end.
Not necessarily. Plenty of switches and firewalls have supported VLANs for years without anyone enabling the feature. We check early on, and only if the equipment truly falls short do we specify requirements for a purchase you make through your own supplier.
Work is planned so any interruption is brief and happens outside business hours. Each change has a prepared rollback, so if something misbehaves we quickly restore the previous state.
Firewalls, switches and servers are managed over secure remote connections. Should hardware need replacing or cable pulling, your local supplier does the physical part while our engineer talks them through it and handles the configuration.
We join them with an encrypted tunnel between firewalls and apply the same zoning logic at every site. A branch should reach only the head office resources it needs for its work.
Such devices often cannot be patched, so isolation protects them: a dedicated zone, traffic only from named engineering stations and no direct path to the internet.
Describe your network briefly: sites, servers and how remote staff connect. We will begin by reviewing your exposure to the internet.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.