The network boundary
Rules on egress and ingress: what is allowed out, what is allowed in and with which addresses.
We move from the outside in: first the network boundary, then internal segmentation, then the workstations.
Rules on egress and ingress: what is allowed out, what is allowed in and with which addresses.
Servers, workstations, the guest network, cameras and equipment each in their own zone, with only what is permitted between them.
A secure connection with login confirmation instead of a port open to the internet.
Current updates, disabling unnecessary services, restricting administrative logon.
Antivirus, restricting which programs can run, removing local administrator rights.
Event collection and alerting on unusual activity.
We start with a survey, and almost always find access that was long forgotten, and open to the outside at that.
A network diagram, open ports, a list of remote entry points. Often this is the first such document the company has had.
We close ports exposed to the outside, change factory passwords and disable what is not used.
We separate things into segments and write the rules. It is done in stages so as not to stop the work.
We scan from outside and inside and write the result up as a report.
Factory passwords on cameras, printers and switches outlive everything else. Workstations are remembered, network hardware is forgotten, and it stands for years with the password from the manual. Meanwhile a switch sees the whole network, and a camera can become a way in from outside.
What you have open to the internet. A list of external addresses and ports is compiled in an hour and almost always contains a couple of items that must be closed immediately. After that you can plan calmly.
In a small company no: the tasks are covered by the system administrator with outside support. A dedicated role appears when there are regulatory requirements or the infrastructure has grown past a hundred servers.
By rescanning and comparing with the first report. The improvement must be measurable: there were this many open ports and shared accounts, now there are this many. Impressions are a poor criterion here.
We will look at what is exposed and how the network is built inside, and hand over a list of what to close first.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.