Network Security Services
Your network was designed for connectivity, then patched for security. We review how it's actually built and segmented, find the paths an attacker would take through it, and give you a hardening plan your team — or your MSP — can execute.
Six ways we work on a network
Engaged individually, or as a single review that covers the whole estate — office, data centre, remote workers and the links between them.
Architecture & segmentation review
We map the network as it exists — not as the diagram claims — and identify where a compromised laptop could reach a domain controller or a database it has no business touching.
Firewall & rule base audit
Rule-by-rule review of what's permitted, what's shadowed, what's unused, and what "any-any" survived from a migration three years ago.
Remote access & VPN
How people and vendors get in from outside: MFA coverage, split tunnelling, device posture, and what a stolen credential would reach.
Vulnerability assessment
Authenticated scanning across network devices and servers, with results triaged by exploitability and business exposure — not raw CVSS.
Device hardening
Switches, routers, firewalls and wireless controllers reviewed against vendor and CIS benchmarks, with a prioritized configuration baseline.
Monitoring & detection coverage
Where logs go, what's actually alerted on, and which parts of the network would generate no signal at all during an intrusion.
The perimeter held. The inside is the problem.
Most organizations have a well-defended edge and a flat interior. Once an attacker is inside — through a phished credential, an unpatched appliance, or a vendor's remote session — there's very little standing between them and everything else.
Segmentation is the control that turns a breach into an incident instead of a catastrophe. It's also the one most often deferred, because it touches production and nobody wants to be the person who broke printing. We plan it in stages that can be rolled out and rolled back.
-
Attacker-path thinkingWe trace lateral movement routes, not just a list of open ports
-
Change plans, not just findingsStaged rollout with rollback points, sequenced to avoid production surprises
-
Works with your MSPFindings written so your provider can act on them without a translation layer
-
Feeds your evidence packMapped to ISO/IEC 27001 Annex A so remediation counts toward certification
Review, prioritize, harden, verify
- 01 Discovery Configuration exports, diagrams, and sessions with whoever runs the network day to day — including your MSP.
- 02 Analysis Rule bases, segmentation, access paths and device baselines reviewed against benchmarks and real attacker behaviour.
- 03 Hardening plan A staged change plan with sequencing, expected impact and rollback — written to be handed straight to whoever implements.
- 04 Verification We re-test after implementation and confirm each finding is genuinely closed, not just marked as done.
Network security FAQ
The review itself is read-only — configuration analysis, interviews and passive discovery. Any active scanning is agreed in writing beforehand, scheduled to your window, and excludes anything fragile you tell us about. Changes are always yours to make, on your schedule, from a plan that states expected impact per step.
No — it's the independent check on the environment they operate, which is exactly what an auditor or insurer will ask for. We don't sell managed services or hardware, so we have no incentive to recommend either. In practice most MSPs appreciate a prioritized list that comes from outside the relationship.
We advise and verify rather than take the keys. The plan is written so your team or your MSP can execute it, and we stay available through the work to answer questions and re-test. Keeping assessment separate from implementation is what makes the verification meaningful.
No. A scan enumerates known weaknesses across the estate; a penetration test attempts to chain them into real compromise. The scan tells you what to fix, the test tells you whether your defences hold. We scope which one your situation actually calls for — often the scan and a segmentation review deliver more value first.
Find the path before an attacker does
Send us a rough picture of the estate — sites, users, cloud footprint, who runs it — and we'll come back with a scoped review and a fixed price. We respond within one business day.