Service · Cybersecurity

Infrastructure security

A surprising share of ransomware cases start with something mundane: remote desktop reachable from the internet, a VPN box nobody has patched, a CCTV recorder on its default password. The intruder then usually finds that nothing inside is separated, so the accounts PC, the production PLCs, guest Wi-Fi and the file server all see one another. Think of a Gebze warehouse where handheld scanners, the WMS, office laptops and security cameras share the same network, while the WMS supplier dials in through a forwarded port. A single weak device can bring the whole site to a standstill. Our job is to break that chain. First we look at your organisation from outside, the way an attacker's scanner does. Then we divide the internal network by purpose, permit only the traffic each part actually needs, and move every inbound connection onto authenticated, logged access. We use your existing firewall and switches and do the work over remote sessions.

Outside-in view
what an attacker can see first
Separate VLANs
for staff, machines, guests and cameras
RDP off the internet
inbound access only after authentication
Undo path
prepared before each change

What the work covers in practice

If your firewall and switches still get security patches, we keep them. Hardware is only replaced once it is out of support; installation is handled by your own staff or supplier, and configuration by us, remotely.

Agree the scope with the engineer who will do the work

Outside exposure

Your public addresses, domains and subdomains are checked for anything listening, such as leftover test servers, admin pages or FTP. Each item is shut, narrowed or documented with a reason.

Firewall rulebase

Temporary rules that never went away, forwards nobody can account for and allow-everything entries all get reviewed. What survives has an owner and a comment.

Segmentation

Staff devices, shop-floor or warehouse equipment, servers, cameras, printers and guest Wi-Fi each get their own VLAN, and traffic between them is limited to the flows that are genuinely needed.

Inbound access

Published RDP and port forwards disappear. Staff use a VPN protected by a second factor or identity-aware access; suppliers get named, time-boxed and recorded sessions.

Wi-Fi

Enterprise authentication on the staff network, or at minimum strong, regularly changed keys; client isolation and bandwidth limits for guests. Hotels and clinic waiting rooms get a design of their own.

Device administration

Firewall, switch, access point and recorder admin panels move to a separate management network. Factory passwords go, and unused services are disabled.

How we approach the job, from first call to handover

Because network changes can interrupt work, each one comes with a fallback.

01

Survey

We collect existing diagrams and device lists and run an outside scan. Missing diagrams are drawn remotely; if someone needs to follow a cable, we guide them.

02

Design

A plain table of which zone may reach which, on which ports. After your approval, we set the sequence and agree maintenance windows.

03

Implementation

The most dangerous exposures are closed first, then zones are moved one after another, always after a config backup and outside working hours.

04

Proof

A repeat outside scan, tests between zones, and handover of the current diagram, rulebase and list of admin access.

When the network is flat, one infected laptop can reach everything. Zoning will not keep every attacker out, but it slows them down, makes them noisier and caps the damage. Stopping office ransomware at the boundary of the production or warehouse zone can turn a week-long shutdown into a morning's inconvenience.

Frequently asked questions

We leave PLCs and machine controllers untouched and only move them into their own zone with controlled access. Any remote maintenance link from the machine manufacturer is moved to a separate recorded route. The switchover is timed for a break in shifts.

A named VPN login with a second factor, or a time-limited remote session, restricted to that one server and service. Once it works, the forward is closed. We arrange the transition with the supplier.

Not if the vendor still publishes security fixes for it and it keeps up with your traffic. An out-of-support unit, on the other hand, cannot be patched and becomes a liability, which we would report during the survey.

Configuration is fully remote. Physical tasks, like repatching a cable, are done by your staff or a local technician while we direct them over video. Changes are planned so that we never lose management access to a device mid-change.

See your network the way an attacker does

Share the number of sites, your firewall model and who connects from outside. We will suggest a first exposure review.

Availability
Weekdays 09:00-18:00 Turkey time (GMT+3); an answer follows by the next working day
Calls
By video, over Microsoft Teams or Google Meet

The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.