Услуга · Information security

Infrastructure protection

The task is to ensure that getting into one machine does not open access to everything else. A network with no zoning, where the accountant computer sees the servers directly, explains most of the stories about ransomware taking a company overnight.

Zones
instead of the shared network
Boundary
ingress and egress under rules
Remote work
through a secure tunnel
Events
we collect and review

What the work includes

We move from the outside in: first the network boundary, then internal segmentation, then the workstations.

Discuss the scope

The network boundary

Rules on egress and ingress: what is allowed out, what is allowed in and with which addresses.

Zoning

Servers, workstations, the guest network, cameras and equipment each in their own zone, with only what is permitted between them.

Remote access

A secure connection with login confirmation instead of a port open to the internet.

Servers

Current updates, disabling unnecessary services, restricting administrative logon.

Workstations

Antivirus, restricting which programs can run, removing local administrator rights.

Monitoring

Event collection and alerting on unusual activity.

How it goes

We start with a survey, and almost always find access that was long forgotten, and open to the outside at that.

01

Survey

A network diagram, open ports, a list of remote entry points. Often this is the first such document the company has had.

02

Urgent

We close ports exposed to the outside, change factory passwords and disable what is not used.

03

Zones

We separate things into segments and write the rules. It is done in stages so as not to stop the work.

04

Testing

We scan from outside and inside and write the result up as a report.

Factory passwords on cameras, printers and switches outlive everything else. Workstations are remembered, network hardware is forgotten, and it stands for years with the password from the manual. Meanwhile a switch sees the whole network, and a camera can become a way in from outside.

Questions and answers

What you have open to the internet. A list of external addresses and ports is compiled in an hour and almost always contains a couple of items that must be closed immediately. After that you can plan calmly.

In a small company no: the tasks are covered by the system administrator with outside support. A dedicated role appears when there are regulatory requirements or the infrastructure has grown past a hundred servers.

By rescanning and comparing with the first report. The improvement must be measurable: there were this many open ports and shared accounts, now there are this many. Impressions are a poor criterion here.

We will test the infrastructure defences

We will look at what is exposed and how the network is built inside, and hand over a list of what to close first.