Outside exposure
Your public addresses, domains and subdomains are checked for anything listening, such as leftover test servers, admin pages or FTP. Each item is shut, narrowed or documented with a reason.
A surprising share of ransomware cases start with something mundane: remote desktop reachable from the internet, a VPN box nobody has patched, a CCTV recorder on its default password. The intruder then usually finds that nothing inside is separated, so the accounts PC, the production PLCs, guest Wi-Fi and the file server all see one another. Think of a Gebze warehouse where handheld scanners, the WMS, office laptops and security cameras share the same network, while the WMS supplier dials in through a forwarded port. A single weak device can bring the whole site to a standstill. Our job is to break that chain. First we look at your organisation from outside, the way an attacker's scanner does. Then we divide the internal network by purpose, permit only the traffic each part actually needs, and move every inbound connection onto authenticated, logged access. We use your existing firewall and switches and do the work over remote sessions.
If your firewall and switches still get security patches, we keep them. Hardware is only replaced once it is out of support; installation is handled by your own staff or supplier, and configuration by us, remotely.
Your public addresses, domains and subdomains are checked for anything listening, such as leftover test servers, admin pages or FTP. Each item is shut, narrowed or documented with a reason.
Temporary rules that never went away, forwards nobody can account for and allow-everything entries all get reviewed. What survives has an owner and a comment.
Staff devices, shop-floor or warehouse equipment, servers, cameras, printers and guest Wi-Fi each get their own VLAN, and traffic between them is limited to the flows that are genuinely needed.
Published RDP and port forwards disappear. Staff use a VPN protected by a second factor or identity-aware access; suppliers get named, time-boxed and recorded sessions.
Enterprise authentication on the staff network, or at minimum strong, regularly changed keys; client isolation and bandwidth limits for guests. Hotels and clinic waiting rooms get a design of their own.
Firewall, switch, access point and recorder admin panels move to a separate management network. Factory passwords go, and unused services are disabled.
Because network changes can interrupt work, each one comes with a fallback.
We collect existing diagrams and device lists and run an outside scan. Missing diagrams are drawn remotely; if someone needs to follow a cable, we guide them.
A plain table of which zone may reach which, on which ports. After your approval, we set the sequence and agree maintenance windows.
The most dangerous exposures are closed first, then zones are moved one after another, always after a config backup and outside working hours.
A repeat outside scan, tests between zones, and handover of the current diagram, rulebase and list of admin access.
When the network is flat, one infected laptop can reach everything. Zoning will not keep every attacker out, but it slows them down, makes them noisier and caps the damage. Stopping office ransomware at the boundary of the production or warehouse zone can turn a week-long shutdown into a morning's inconvenience.
We leave PLCs and machine controllers untouched and only move them into their own zone with controlled access. Any remote maintenance link from the machine manufacturer is moved to a separate recorded route. The switchover is timed for a break in shifts.
A named VPN login with a second factor, or a time-limited remote session, restricted to that one server and service. Once it works, the forward is closed. We arrange the transition with the supplier.
Not if the vendor still publishes security fixes for it and it keeps up with your traffic. An out-of-support unit, on the other hand, cannot be patched and becomes a liability, which we would report during the survey.
Configuration is fully remote. Physical tasks, like repatching a cable, are done by your staff or a local technician while we direct them over video. Changes are planned so that we never lose management access to a device mid-change.
Share the number of sites, your firewall model and who connects from outside. We will suggest a first exposure review.
We have your enquiry
A reply will reach you by the next working day at the latest. If your message says work has come to a halt, it goes to the top of the pile.
No such city in our list. Try another spelling, or just pick the closest big city: we work entirely over remote connections, so nothing about the service changes from one province to the next.
The only cookies here are the essential ones: they keep the site running and remember the city you picked. Nothing is used for advertising or tracking. See our privacy notice for more.