Perimeter
Firewall rules for inbound and outbound traffic: what may leave, what may enter and from which addresses.
The aim is simple: one compromised PC must not open the door to everything else. A flat network where the bookkeeper's laptop can talk directly to every server explains many ransomware cases in which a company goes dark overnight. The Danish Centre for Cyber Security (CFCS) rates the threat of cybercrime against Danish businesses as very high.
We work from the outside in: first the edge facing the internet, then the internal split, and finally servers and workstations.
Firewall rules for inbound and outbound traffic: what may leave, what may enter and from which addresses.
Servers, clients, guest Wi-Fi, printers, cameras and production kit each in their own VLAN, with only the traffic that is required between them.
Remote desktop exposed to the internet is replaced by a VPN or a gateway with MFA and conditional access.
Patching, disabling services nobody uses and admin access only through dedicated accounts.
Factory passwords on switches, printers and cameras are changed, and management interfaces are fenced off from the user network.
Firewall and server logs are gathered centrally, so unusual activity raises an alert.
We always begin with a survey, and it nearly always uncovers a forgotten entry point, often one reachable from the internet.
Network diagram, open ports and a list of remote entry points. For many firms this is their first complete picture.
Open ports are closed, default passwords changed and unused services switched off.
The network is split in stages so work never stops. If cables need moving or equipment mounting, your local electrician or IT supplier does it following our instructions.
We scan from outside and inside and present the outcome as a before-and-after report.
Default passwords on network equipment survive the longest. Everyone remembers the PCs, yet the switch in the comms cabinet and the camera by the gate often still use the password printed in the manual. From a switch you can see the whole network, and a camera can become the way in from outside.
What is visible from the internet. A list of your public IP addresses and open ports takes about an hour to compile and almost always contains a couple of items that should be closed at once.
Not in a smaller company. Your IT lead can handle the work with outside support. A dedicated role makes sense when NIS2 or customer contracts impose formal duties, or when the estate grows considerably.
Yes. Firewalls, switches and servers are configured over secure remote access. If hardware must be swapped or a cable pulled, your local supplier does the physical part while our engineer guides and configures.
By repeating the scan and comparing it with the first report. Progress should be measurable: open ports, shared accounts and unsegmented devices, before and after.
We look at what is exposed and how the network is built inside. You get a list of what to close first.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.