Skip to content

What we protect

Infrastructure & cloud.

The systems the business runs on.

Most networks were never designed. They grew as the company grew, one device at a time, and the security was added on top afterwards. This is the work of finding out what you actually have, separating it so one device cannot reach everything else, watching it continuously, and testing whether any of it holds.

Where this gets in

the network grew with the company, and nobody designed it.

If your network was never designed, the useful first step is finding out what you actually have rather than buying a firewall.

  • One flat network

    The printer, the cameras, the laptops, personal phones and the systems holding company data can all reach each other, because nothing ever separated them.

  • Nothing is reading the evidence

    Most companies already collect the evidence of a break-in without anyone reading it, and there are tools running that nobody has time to read.

  • Equipment degrades rather than failing

    A firewall leaking 30 to 40 megabytes of memory a day stops inspecting traffic long before anybody reports an outage, and there is no obvious outward sign.

The services

four services, and what each one covers.

What you actually have, how it is separated, who is reading the evidence, and whether it stands up to a real attempt.

/ 01

cloud & infrastructure review

Find out what you have before you buy anything to protect it.

A look at the infrastructure as it is now: what is exposed, what nothing is inspecting, what nothing is recording, and where updates happen when somebody remembers rather than on a schedule. What comes back is a short list in the order things should be fixed, not an inventory.

  • what is exposed, and what nothing is inspecting
  • who connected and when — or that nothing recorded it
  • a fix order, not a 200-page inventory

/ 02

network design & segmentation

Separation that is still in place months later.

Segmentation is one of the most commonly abandoned security projects, because separating things properly tends to break what people use every day: printers disappear from the list, screen sharing stops working, and within a fortnight it is quietly reversed. We separate the network into distinct segments with traffic between them denied unless there is a reason for it — then make the daily things work across those boundaries deliberately and narrowly.

  • traffic between segments denied unless there is a reason
  • printing, scanning and screen sharing still work
  • a redundant pair rather than one device on its own
  • every event sent to central logging

/ 03

mdr / mxdr — 24/7 detection & response

Someone is watching, and wakes up when it matters.

Most companies already collect the evidence of a break-in without anyone reading it, so we watch it instead and act when something is wrong. Monitoring and responding are two different jobs: monitoring runs continuously, and when something is wrong a person acts on it with enough context to decide rather than leaving a queue to triage later.

  • 24/7 coverage
  • threat detection & containment
  • sla-backed response

/ 04

penetration testing

We try to break in, on purpose.

Real attempts against your apps, cloud and network in the way someone hostile would, followed by a list of what actually worked, worst first. Delivered to published methodology — PTES, NIST SP 800-115, OWASP WSTG and OWASP Wireless — and re-tested once the fixes are in.

  • apps, cloud and network
  • findings engineers can use
  • re-test after fixes

Where to start

where this work usually starts.

Where to start, and two engagements where this work has already been done.

engagement

security posture assessment

Find out where you actually stand: which gaps matter, which don’t, and a short list in the order things should be fixed.

view details
case study

Segmentation nobody notices

Twelve distinct networks with traffic between them denied unless there was a reason — and printing, scanning and screen sharing working exactly as before. Still in place months later.

read the case study
case study

The quiet month when nothing happened

A properly synchronised redundant pair carried a satellite office on 1,310 active connections while we removed a known memory-leak fault. Not one user was disconnected.

read the case study

the other five things we protect.

People

The inbox, and the person reading it.

4 services

Devices

Laptops nobody manages.

2 services

Offices

The front door, and the room behind it.

2 services
See all 18 services in one list

Next step

find out what you actually have.

Buying a firewall before you know what is on the network gets you a well-protected version of the same problem. The order that works is plainer than it sounds: find out what you have, separate it, put somebody on the evidence, then have somebody try to break in.