Site-to-site
A permanent IPsec tunnel between locations with automatic failover to a backup line if the main one drops.
Anything leaving the office needs protecting in transit: the link between the Aarhus branch and head office in Copenhagen, home working, and access for your IT supplier. GDPR and NIS2 both point to encryption as a core measure, and it has to be solved in technology, not with a rule on paper.
There are different models: a fixed link between two offices and access for individuals are built differently and should not be mixed up.
A permanent IPsec tunnel between locations with automatic failover to a backup line if the main one drops.
VPN client or Zero Trust access from home and on the road, always with MFA.
Separate accounts with limited rights and an expiry date after which access shuts by itself.
BitLocker on devices, encrypted backups and TLS on mail connections, so data is protected at rest and in transit.
A register of certificates and their expiry dates, so no connection dies because a certificate lapsed on a Friday.
Who connected when, and automatic disconnection of idle sessions.
A project covering two or three locations takes one to two weeks, including a failover test.
We establish who needs to reach what. Almost nobody needs access to the whole network.
Gateways, routes and group access rules are configured remotely. If a new firewall must be mounted, your local supplier does it from our checklist and we take over from there.
We enable MFA and help users set up the app on their phones in a short online session.
Failover to the backup line is tested, and users receive a brief guide.
Remote access accounts outlive their owners' employment more often than any other kind. Internal access is withdrawn, but the VPN account is remembered six months later during an incident investigation. Closing external access belongs at the top of the leaver checklist, not at the bottom.
That depends on the job. If they need full access to files and systems, a VPN client with group-based rights. If it is one or two applications, publishing just those through a secure gateway is often enough, with no network access at all.
With personal accounts limited in time and scope: only the server they work on and only for the contract period. A shared »supplier« login leads to an incident sooner or later.
Technically yes, but we strongly advise against it. A guessed or stolen VPN password gives an attacker the same as a key to your office. MFA shuts that scenario down almost entirely.
Traffic between mail servers is normally protected with TLS, but that does not guarantee encryption all the way to the recipient. For confidential or sensitive personal data, use Microsoft Purview Message Encryption or a similar service.
Tell us how many sites and remote workers you have. We will propose a design with a backup line and configure it remotely.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.