Услуга · Information security

Raising the security of the infrastructure

A service for companies that regulators do not visit but which very much do not want to stand still for a week because of ransomware. We start with a survey and close whatever gives the greatest effect for the least spend, and that is almost always configuration rather than purchase.

A week
for the survey
By configuration
most of the findings
Plan
in priority order
Control
by a re-check

What the work includes

We look not at compliance with paperwork but at whether the infrastructure would withstand a typical attack.

Discuss the scope

The external boundary

What is visible from the internet, which ports are open, which access was forgotten.

Accounts and rights

Shared passwords, live accounts of former staff, surplus administrators, password requirements.

Updates

How far behind the systems are and whether there is any patching procedure at all.

Copies

Whether they exist, where they are held, whether they are protected against encryption, whether a restore was ever tried.

Network segmentation

Whether an infection would spread from one machine to the whole company.

Plan

A list with priority, effort and cost estimates.

How it goes

The survey takes a week; closing the priority items usually another two or three.

01

Collection

We examine the infrastructure from outside and inside and talk to the administrators.

02

Report

Findings with a clear explanation of the consequences rather than a list of technical terms.

03

Fast

First we deal with what configuration can solve: changing passwords, cleaning up rights, closing ports, protecting the archives.

04

The rest

Work that runs into budget limits goes into a separate document with costings and reasoning.

A backup you have never restored from does not count as a backup. It regularly turns out that the job has been failing for three months, that the archive holds the wrong data, or that a restore takes four days. A trial restore once a quarter is the most underrated procedure in IT.

Questions and answers

The survey itself is a fixed sum depending on the size of the infrastructure. Fixing most of the findings is included in the work because it is done through configuration. Only purchases cost extra, and they are always agreed in advance.

It is exactly in such companies that the findings are usually most numerous. We can survey, close what we find and then run the infrastructure under contract. You will not have to do anything with your own hands.

Once a year, and always after major changes: a move, new systems, a change of administrator. Between surveys, regular perimeter scanning is enough and takes little time.

We will carry out a survey

Within a week you have a list of weak points in priority order. A substantial part of them we remove as we go and with no spend on equipment.