Security shows its worth on the day something goes wrong
A firewall cluster of two appliances, two-step sign-in, backups with an offline copy. And an incident plan you have already read before you need it.
Book an intro callMany managing directors assume their company is too small to be of interest to anyone. Plenty of attacks pick nobody in particular: a program works its way through entire IP ranges and takes whatever stands open. When bookkeeping can no longer open its files on a Monday morning and a demand for payment sits on the screen, the question is no longer whether it can happen here. The question is what holds afterwards.
We build the defence in layers. Two firewalls that stand in for one another. Remote access for home working and maintenance that only opens after a second confirmation. Backups following the 3-2-1 rule, plus a copy that is disconnected from the network once it has been written. And an incident plan on paper. Khodor Kassem worked on IT operations in a large German corporate environment and applies the same order of priorities to businesses that have a server cabinet rather than a data centre.
What is included.
Firewall cluster of two appliances
We install two appliances side by side and configure them so the second one takes over the sessions when the first one dies. Rule sets, updates and logging are kept identical on both, because otherwise they drift apart.
Remote access with a second factor
Home working, field staff and your suppliers’ maintenance access all run through encrypted tunnels that require a second confirmation. Every access route gets a name, an expiry date and a reason. Access without a reason is switched off.
Multi-factor sign-in
For Microsoft 365, remote maintenance and the administrator accounts we add a second step, usually through an app on the company phone. We advise against SMS codes, because a number can be hijacked at the mobile operator and redirected to somebody else.
Backups with an offline copy
Three copies, two types of media, one off site. Plus a volume that is disconnected once it has been written and that no account on the network can reach. At fixed intervals we restore a single file and a complete server, and we time how long each takes.
Incident plan on paper
Who disconnects which line, who calls the insurer, who speaks to customers, in what order systems come back. It sits printed out in a folder, because a plan stored on an encrypted file server is missing at exactly the moment you need it.
Tidying up account permissions
Employees who have left, shared accounts in bookkeeping, administrator rights on every other workstation: we work through the list and take away what nobody needs any more. After that it is set down in writing who may grant which permission.
How we work.
Taking stock
We connect a machine to your network and see what answers, and we check from the outside which ports stand open on your internet line. Added to that are accounts without a second factor, and backup jobs that have been ending in errors for months. You receive a list, sorted by the damage each item could cause.
Setting the order
Not everything at once. Together you decide what gets closed first: usually the backups and the administrator accounts, because neither needs new hardware. For the rest we name specific appliances, for example from Fortinet or Ubiquiti, and set out what they do.
Installation and cutover
The cluster goes live in the evening. The second factor becomes mandatory department by department, so that not everyone meets a new sign-in prompt at the same time on Monday morning. Every rule, every password and every exception is written up, and the write-up is yours.
Rehearsal and upkeep
Then we rehearse. We restore a server from backup as a test, walk through the incident plan once, and update the firewalls when the manufacturer reports vulnerabilities. After every change in the business we look at the access routes again.
Common questions.
I have a firewall and a backup. Isn’t that enough?
Usually not, and the reason rarely lies with the hardware. A firewall protects only as well as its rules are kept up to date, and outgoing traffic in particular often runs unfiltered. A backup becomes a backup once somebody has restored something from it. We check exactly those two points first, before anything new is bought.
This sounds like a lot of money for something that may never happen. How do I justify it internally?
Don't build the case on the hardware. Build it on days of standstill. Ask your finance people what a day costs without the ERP system, without quotations and without invoicing, and how long recovery would take without a tested backup. Your own company knows that figure far better than we do. What we can tell you is which measure shortens those days the most, and in what order to take them.
My people already grumble about passwords. Is the second sign-in step really necessary?
Yes, wherever a system can be reached from the outside. A stolen password is one of the most common ways into a network, and a longer password does nothing against that. A second factor does. In daily use that usually means one confirmation on a mobile, often only the first time somebody signs in on a device. Inside the office we leave known machines alone.
If everything is documented at your end, doesn’t that tie me to you?
No, because the documentation sits with you from the start. Credentials, configurations, licences and serial numbers belong to you and are stored in your password vault, not in ours. If you move to another provider, your successor opens the folder and carries on. We also build with standard products rather than one-off setups only we understand.
How long is my business at a standstill while you replace the firewall?
Replacing the firewall needs a window outside working hours, usually an evening or a weekend. During that window the internet connection is down, and depending on the layout so is traffic between individual network segments inside the building. We tell you in advance which systems are affected. Backups and the second factor are set up while you carry on working. We agree each window with you beforehand, and we say what we will do if the cutover does not go cleanly.
Before an emergency decides the order for you
Three things we want to know: how your people get into the network from outside, when somebody last restored a file from backup, and who pulls the plug when things go wrong. After that you know where you stand.
Book an intro call