Skip to content

Cyber Security

Designing so one compromise stays one compromise

The structural layer - trust boundaries, segmentation, hardening standards, cryptographic agility and recoverability. Work here decides whether an intrusion is contained to a workload or becomes an enterprise event.

What we deliver

Services in this focus area

Every engagement is scoped to your environment - deploy a single capability or the full stack.

  1. 01

    Zero Trust Architecture & Maturity Roadmap

    On-PremCloudHybridAdvise

    A staged, measurable path from implicit network trust to per-request authorisation across identity, device, network, workload and data.

    • Maturity assessment across the five zero trust pillars
    • Target architecture with policy decision and enforcement point placement
    • Migration sequence with dependency map and per-stage exit criteria
  2. 02

    Secure Reference Architecture & Patterns

    On-PremCloudHybridAdvise

    Approved patterns engineers build against, so security is a library call rather than a review queue.

    • Reference designs per workload class with control annotations
    • Paved-road templates in infrastructure-as-code and pipeline form
    • Architecture review board charter, criteria and enablement
  3. 03

    Threat-Led Architecture Review

    On-PremCloudHybridAdvise

    An independent read on a major design while changing it is still cheap.

    • Structured threat model of the proposed architecture
    • Findings with attack-path narrative and severity rationale
    • Sign-off conditions, compensating controls and residual risk statement
  4. 04

    Network & Workload Microsegmentation

    On-PremCloudHybridAdviseBuild

    Blast radius bounded by policy, with east-west movement stopped at the workload rather than the perimeter.

    • Flow discovery and application dependency mapping
    • Zone model, label schema and policy authoring standard
    • Phased enforcement from observe to alert to deny with rollback
  5. 05

    Host Hardening & Secure Baseline Engineering

    On-PremCloudHybridBuildRun

    Golden images and enforced baselines that survive a benchmark audit and a reboot.

    • Benchmark-aligned baselines per operating system and platform
    • Automated enforcement through configuration management or image pipelines
    • Continuous drift detection with exception register
  6. 06

    Virtualisation & Platform Isolation

    On-PremHybridAdviseBuild

    The layer underneath everything else, separated properly and administered out of band.

    • Hypervisor and management-plane hardening and isolation
    • Tenant, workload and storage isolation design
    • Snapshot, template and escape-risk control review
  7. 07

    Cyber Recovery Vault & Immutable Backup

    On-PremCloudHybridAdviseBuild

    A clean copy an attacker with domain privilege cannot reach, and a rehearsed path back from it.

    • Isolated recovery environment with independent credential domain
    • Immutability, retention-lock and air-gap or logical-gap design
    • Timed recovery rehearsal against a full-compromise scenario
  8. 08

    Physical & Facility Security Design

    On-PremHybridAdvise

    Facility controls that satisfy assessors, insurers and the people who actually work in the building.

    • Layered perimeter, access control and surveillance design
    • Environmental, power and fire-suppression resilience review
    • Visitor, media handling and equipment disposal procedures
  9. 09

    M&A, Divestiture & Migration Assurance

    On-PremCloudHybridAdviseBuild

    Integrate a network without inheriting an unknown compromise, or separate one without leaving a door open.

    • Pre-integration security due diligence and control gap analysis
    • Compromise assessment of the target or divested estate
    • Staged interconnection, consolidation or separation plan

Technical deep dive

Recovering from a domain-wide compromise when the backups were reachable too

Applies to any organisation whose backup infrastructure shares an identity domain with production - which is the default configuration almost everywhere.

What this is

An isolated recovery environment. Backup data is pushed one-way into a vault that has its own identity domain, its own credentials, retention-locked storage and no inbound network path from production. Recovery runs into a clean room where images are scanned and validated before anything is promoted back.

The problem being solved

An operator obtains domain administrative privilege on a Friday evening. Encryption starts at 02:00 across file services, virtualisation and the database tier. Recovery should be routine - the images exist and the retention policy is four weeks. It is not routine, because the backup server is joined to the same directory, its console authenticates against the same identity provider, and its storage target is reachable on the same flat management network. The attacker reached it forty minutes before the encryption began, deleted the catalogue and expired the retention policy. What remains is three-week-old tape and no confidence about what is in it.

Why it is hard

  • Backup infrastructure is conventionally administered by the same team, with the same directory, for entirely reasonable operational reasons. That convenience is the single point of failure.
  • Restoring quickly and restoring safely are opposed: the fastest restore reinstates the same implant, and the safest restore takes long enough that the business improvises around it.
  • Nobody knows the real recovery time. The documented RTO was derived from a single-server restore test, never from a full-domain rebuild with dependency ordering.

Reference architecture - step through it

all
PRODUCTION · compromised identity domainONE-WAY BOUNDARYRECOVERY DOMAIN · separate identity, separate credentialsAdversaryholds domain adminProduction workloadshypervisors, file, databaseDirectory / identitythe credential blast radiusBackup proxyread-only source accessManagement networksegmented, jump-hostedOne-way replicationpush only · no inbound routeImmutable vaultretention lock, versionedVault identity domainown accounts, own MFAClean roomisolated restore targetValidation pipelinemalware, integrity, configdriftPromotion gatesigned-off images onlyRebuilt productiondependency-orderedencryptsescalatesblocked inbound
The boundary, expressed as policy rather than intentionyaml
recovery_vault:
  identity:
    domain: vault.local              # NOT joined to production directory
    federation: none                 # no trust, no sync, no SSO
    admins: 3                        # named, hardware-token, offline break-glass
    production_credentials_accepted: false

  network:
    ingress:
      - from: any
        action: DENY                 # no inbound path exists, at all
    egress:
      - to: production.backup_proxy
        ports: [443]
        mode: pull_initiated_by_vault   # vault reaches out; nothing reaches in

  storage:
    object_lock: compliance          # not "governance" - cannot be lifted
    retention_days: 35
    versioning: enabled
    delete_capability:
      vault_admin: false             # deletion is not a permission anyone holds
      provider_root: false

  recovery:
    target: clean_room               # isolated, no route to production
    gates: [malware_scan, integrity_hash, config_drift, service_account_diff]
    promotion: signed_approval_required
    order: [identity, dns, database, application, presentation]

  rehearsal:
    scenario: full_domain_compromise
    frequency: quarterly
    measured_rto: true               # the plan records the measured number

Measured change

MeasureBeforeAfter
Credentials that can reach backupsevery domain admin3 vault-only identities
Recoverable point after compromise3 weeks, unverifiedunder 24 hours, validated
Measured full-domain recovery timenever measured19 hours, rehearsed quarterly
Reinfection risk on restoreunmitigatedclean-room gated, 4 validation checks

The question stopped being "do we have backups" and became "how long to production" - with a number behind it that had been measured under adversarial conditions rather than assumed in a document.

Talk to a security architecture & zero trust engineering specialist.

Schedule a free consultation and our team will connect within 12 hours to understand your environment and map out the right approach.

We respond within 12 hours