Skip to content

Cyber Security

Enforcement wherever the user and workload actually are

Enforcement points for an estate whose perimeter now sits at the user, the branch, the workload and the API. Classic firewall, NAC and segmentation work on the ground floor; cloud-delivered edge, protective DNS and encrypted-traffic analytics everywhere else.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Next-Generation Firewall & IPS Engineering

    On-PremCloudHybridBuildRun

    Policy that reflects the applications actually in use rather than a decade of accreted any-any rules.

    • Rule-base rationalisation with shadow, redundant and permissive rule removal
    • High-availability design, deployment and platform migration
    • Application identification, IPS profile and decryption policy tuning
  2. 02

    Secure Access Service Edge Deployment

    CloudHybridAdviseBuild

    One policy following the user to any location, replacing hairpinned backhaul to a datacentre they no longer need.

    • Requirements-led architecture and platform bake-off
    • Phased rollout by site, user population and application class
    • Converged policy across web, SaaS, private application and data controls
  3. 03

    Zero Trust Network Access & VPN Replacement

    CloudHybridBuildRun

    Per-application authorisation that removes the flat, enumerable network a VPN creates.

    • Private application inventory and access policy modelling
    • Broker and connector placement with identity and posture binding
    • Staged VPN decommissioning with fallback and monitoring
  4. 04

    Secure Web Gateway & Protective DNS

    CloudHybridBuildRun

    The first hop of most intrusions - the lookup and the download - blocked before it lands.

    • Category, inspection, tenant-restriction and isolation policy
    • DNS-layer filtering with tunnelling and algorithmic-domain detection
    • Roaming client rollout and bypass-path elimination
  5. 05

    Email Security, DMARC & BEC Defence

    CloudHybridBuildRun

    Business email compromise cut off at the gateway, the domain and the mailbox rule.

    • SPF, DKIM and DMARC to enforcement across all sending sources
    • Impersonation, payload detonation and post-delivery retraction policy
    • Abuse-mailbox triage, takedown and user reporting workflow
  6. 06

    Network Access Control & 802.1X

    On-PremHybridBuild

    Nothing joins the network unidentified, unhealthy or unsegmented.

    • 802.1X, MAB and profiling design across wired and wireless
    • Posture assessment with dynamic VLAN and policy assignment
    • Phased enforcement covering guest, contractor and unmanaged device classes
  7. 07

    Branch, Wireless & SD-WAN Security

    On-PremHybridBuild

    Consistent enforcement at sites with no local security staff and no local rack space.

    • Enterprise wireless security design with modern authentication
    • Secure overlay, local breakout and inspection policy
    • Branch survivability, failover and centralised monitoring
  8. 08

    DDoS Mitigation & Edge Resilience

    On-PremCloudHybridAdviseBuild

    Stay reachable through volumetric, protocol and application-layer floods.

    • Internet-edge exposure profiling and attack surface reduction
    • Scrubbing, anycast, rate-limit and edge WAF architecture
    • Runbook, provider failover and periodic diversion testing
  9. 09

    Network Detection & Response

    On-PremCloudHybridBuildRun

    Visibility into the traffic no endpoint agent will ever cover - appliances, medical devices, controllers, unmanaged hosts.

    • Sensor placement, tap and mirror design with capture strategy
    • Behavioural baselining and protocol-aware detection tuning
    • Encrypted-traffic analytics and SOC triage integration
  10. 10

    Privileged Remote Access for Third Parties & OT

    On-PremCloudHybridBuildRun

    Vendors get precisely the access their contract requires, brokered, recorded and time-bound.

    • Brokered, credential-less access design with approval workflow
    • Session recording, keystroke logging and just-in-time provisioning
    • Removal of standing accounts, shared credentials and inbound tunnels

Technical deep dive

Putting an unpatchable device fleet under policy without touching the devices

Applies to any estate carrying vendor-validated or life-cycle-frozen equipment on a shared network - clinical devices, laboratory instruments, building management, point-of-sale, kiosks, industrial gateways.

What this is

Identity-driven network segmentation. Devices are fingerprinted as they join, placed into a policy group without any change to the device itself, and given exactly the flows their function requires. Vendor access is brokered and recorded rather than granted as a tunnel, and a passive sensor watches the segment because no agent will ever run on these hosts.

The problem being solved

Several hundred devices across multiple sites sit on the same flat network as staff and guest access. Their firmware images are vendor-validated, so patching voids support. Several require inbound access from the manufacturer for diagnostics, currently delivered as a site-to-site tunnel terminating in the core. Nothing can host an endpoint agent. The devices cannot be removed and cannot be secured at the host, so every control has to be imposed by the network around them - while a failed access-control decision has physical consequences, which rules out learning by blocking in production.

Why it is hard

  • The devices cannot authenticate. They have no supplicant, no certificate store and no way to run 802.1X, so classification must be inferred from behaviour and hardware attributes.
  • Vendor access is contractual. Removing it is not an option; narrowing it from a network to a session is.
  • Availability outranks confidentiality. A wrong enforcement decision stops a procedure or a production line, so enforcement has to be earned through a long observation phase.

Reference architecture - step through it

all
ENDPOINTSENFORCEMENTDECISIONVISIBILITY & ACCESSFrozen-image devicesno agent, no supplicantManaged endpointscertificate + postureGuest & BYODuntrusted by defaultVendor engineercontractual remote accessAccess layer802.1X / MAB enforcementWirelessper-SSID policy bindingSegmentation firewallinter-zone policyAccess brokerbrokered, recorded sessionNAC policy engineprofile → group → policyDevice profilingOUI, DHCP, protocol behaviourZone policy modelleast-flow per device classIdentity providerwho the engineer isPassive sensor (NDR)span/tap, protocol-awareSOC pipelinetriage and responseLive device inventorybuilt from observationSession recordingwho touched what, whensingle flowmirroredrefines policy
Policy derived from observation, not from a datasheetyaml
device_class: imaging_modality
  match:                              # classification without touching the device
    oui: ["00:1B:44", "00:80:E1"]
    dhcp_fingerprint: "1,3,6,15,119,252"
    observed_services: [104/tcp, 11112/tcp]     # imaging protocol
    confidence_threshold: 0.92
    on_low_confidence: quarantine_observe       # never guess

  assignment:
    method: mac_auth_bypass           # device has no supplicant
    segment: seg-imaging
    mode: monitor                     # phase 1: log only, 30 days

  derived_policy:                     # generated from 30 days of observed flow
    egress:
      - to: seg-pacs        ports: [104/tcp, 11112/tcp]   # image archive
      - to: svc-ntp         ports: [123/udp]
      - to: svc-dns         ports: [53/udp]
    ingress:
      - from: seg-clinical-workstations  ports: [11112/tcp]
      - from: broker-session             ports: [22/tcp, 3389/tcp]
                                         condition: active_brokered_session
    default: DENY
    exceptions_observed: 0            # 30 days, zero flows outside the set

  hard_denies:
    - from: seg-guest      action: DENY   # no path, in any direction
    - from: seg-byod       action: DENY
    - to:   internet       action: DENY   except: [vendor-update.example]

Measured change

MeasureBeforeAfter
Devices with a known class and ownerunknown - no inventory612, continuously profiled
Reachability from guest networkfull layer-2 adjacencynone, in either direction
Vendor access footprintsite-to-site tunnel to core1 device, 1 window, recorded
Enforcement incidents during rolloutn/a0 - 30-day observation before every deny

The vendor keeps the access its contract requires. A compromised laptop on the guest network can no longer see the device segment at all - and the unpatchable devices stayed unpatched, which was always the immovable constraint.

Talk to a network & edge security specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours