When does a network need security?
Problems we help solve
In many companies, everything sees everything: computers, printers, cameras, servers, guests and technical devices run on one flat network. This is convenient until the first incident or failure occurs.
- Guests or private devices have access to the same network as company resources.
- A VPN gives users too much access to internal systems.
- Cameras, printers, IoT and technical devices are not separated from computers.
- Firewall and VLAN rules are not described or regularly reviewed.
- It is not known what traffic between networks is necessary and what is accidental.
Fit
Who is this service for?
Companies with multiple types of devices
We separate computers, servers, printers, cameras, guests and technical devices.
Companies with remote work
We limit VPN access to the resources needed by a given role.
Companies after network expansion
We organise VLANs, addressing, rules and documentation after years of changes.
Companies after the audit
We implement recommendations regarding segmentation, firewall and traffic control.
Service scope
What does network security cover?
Traffic and access overview
We check what areas of the network exist and what can communicate with what.
- addressing and VLAN,
- LAN and Wi-Fi network,
- VPN and remote access.
Segmentation
We divide the network into logical zones that limit the scope of the problem.
- users and servers,
- guests and technical devices,
- cameras, printers and special systems.
Firewall rules
We configure traffic control between networks and to the Internet.
- rules between VLANs,
- access to critical services,
- description of exceptions and ports.
Monitoring and documentation
We make it easier to maintain security after implementation.
- alerts for network devices,
- network and rules map,
- recommendations for further changes.
Outcomes
What will you receive?
- clear division of the network into zones and device roles,
- less unnecessary access between users, servers and devices,
- safer VPN and guest network,
- described firewall rules and exceptions,
- network documentation facilitating audit and further expansion.
Network security can be implemented in stages, starting with the greatest risks and places that have the least impact on users' work.
Delivery approach
How is the service delivered?
- Discovery. We determine locations, devices, users and critical resources.
- Map. We check addressing, VLAN, firewall, Wi-Fi and VPN.
- Project. We define network zones and the necessary communication rules.
- Implementation. We configure VLAN, rules, VPN access and guest network.
- Tests. We check user access and block unnecessary traffic.
- Documentation. We provide a network map, rules and recommendations.
Security standards
How do we reduce risk?
- We do not implement segmentation without checking application dependencies.
- We describe access rules so that it is clear why they exist.
- We separate the guest network from company resources.
- We treat VPN as access to specific services, not the entire company.
- We make changes in stages to easily find any blockages.
Cost
What determines the price?
The price depends on the number of locations, switches, VLANs, firewall rules, VPN users, technical devices and the scope of documentation and testing after changes.
FAQ
Frequently asked questions
Can segmentation block applications?
It can if implemented without dependency analysis. That is why we map communications and test changes first.
Does every company need a VLAN?
Not necessarily on a large scale, but separating guests, servers and technical devices usually improves control significantly.
Can security be improved without replacing hardware?
Often yes, if your current switches and firewall support the features you need.
Do you document firewall rules?
Yes. The description of the rules is important because without it the configuration quickly becomes unreadable.
Does this include Wi-Fi?
Yes, especially guest network, VLAN, employee access and special devices.