Service · Cybersecurity

Infrastructure security

Most SME networks in Spain grew by accretion: the carrier's router, a firewall someone installed six years ago, a VLAN nobody remembers the purpose of and port 3389 opened so the managing director could work from home during lockdown. It all works, which is exactly why nobody reviews it. The trouble is that on a flat network any compromised machine can reach everything: a salesperson's laptop infected through an email ends up encrypting the file server and the backups that sat on the same network. Here we work on the structure: what comes in from the internet, how internal zones are separated, how people outside get in and where all of it is logged. Always remotely, on the equipment you already have; if a cable needs moving or a box restarting, someone in your office does it following our instructions, or your usual installer does.

0 ports
for administration open to the internet
Zoned
office, servers, guests, devices
One entry point
for remote access, with MFA
Logs
centralised, with defined retention

What falls within the scope of this service

We work with the firewall and switches you already have, whether Fortinet, Sophos, pfSense, Meraki or the carrier's managed router. If something has reached its limits, we explain why before suggesting a replacement.

Pin down the details with one of our engineers

Perimeter review

We scan from outside to see what the internet can see of your company: published services, admin panels, NAS boxes with web access and cameras. Every open port needs a reason and an owner, or it gets closed.

Firewall rules

We clear out duplicate rules, “any to any” permissions that were meant to be temporary and became permanent, and exceptions for suppliers you no longer use. Every rule is left with a comment explaining its purpose.

Segmentation

We place workstations, servers, guest Wi-Fi, printers, cameras and connected machinery in separate zones, with rules that let only what is needed pass between them.

Remote access

Remote desktop exposed directly to the internet is replaced by a VPN or zero-trust access with MFA and a log of every connection, including for the supplier who maintains your business software.

Multiple sites

If you have an office in Málaga and a warehouse in Antequera, or a branch in Las Palmas, we define what traffic flows between sites and what stays isolated at each one.

Central logging

Events from the firewall, the servers and the directory go to a single place with the agreed retention, so an incident can be reconstructed without checking machine by machine.

How the engagement unfolds, one stage at a time

Network changes happen outside working hours with the previous configuration saved. If something misbehaves, it is rolled back in minutes.

01

Current map

An inventory of network devices, rules, address ranges and supplier connections. Quite often it is the first up-to-date diagram the company has had.

02

Quick closures

Internet-facing exposure first: admin services, remote desktop and firmware with known vulnerabilities.

03

Zoned redesign

A segmentation plan with the rules between zones and a timetable of change windows in stages.

04

Validation

We check from outside and inside that what was designed is what exists, and hand over the diagram and the documented rule table.

A zoned network does not keep intruders out, but it decides how far they get. On the day a laptop is infected, the difference between losing one machine and losing the file server along with its backups lies in the rules between zones. It is the measure that turns a serious incident into a morning's work.

Common questions

No. We configure your existing firewall and switches over remote access. If new hardware is needed, we tell you which model to order from your usual supplier, your staff or installer plugs it in following our guidance on a video call, and we configure it remotely.

Not cutting them off, just changing their door. They get a named account with MFA on the VPN or zero-trust service, limited to the server they maintain and, if you prefer, active only when you enable it. Every session is then logged.

In an SME, nobody notices. Traffic between zones passes through the firewall, and current hardware handles it easily. What does appear early on is the odd application that relied on seeing the whole network; those surface in the pilot and are solved with a specific rule.

It goes into its own zone, with no view of anything internal and a bandwidth cap. It is one of the simplest and most worthwhile changes: a patient's phone in the waiting room should not share a network with the computer used to view clinical records.

Find out what the internet can see of your company

Tell us what network equipment you have, how many sites and how staff connect from outside. We will reply with the points we would review first.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.