Skip to content

Network Security

Design and enforce the boundaries inside your network, not only at its edge.

What this is

Network security here means deciding what may talk to what, proving that decision is enforced, and seeing it when something tries anyway. It covers the firewall estate, the segmentation model behind it, remote access, and the detection layer that watches east-west traffic rather than only the perimeter.

Most networks we are asked to look at were flat when they were built and have been patched toward segmentation since. The work is usually less about new appliances than about a policy model somebody can explain, apply consistently, and change without an outage.

When you need it

If more than one of these is true, this is usually the right place to start.

  • A flat network where a single compromised workstation can reach servers, backups and management interfaces.
  • Firewall rulebases that have grown for years, with rules nobody is willing to delete because nobody knows what they serve.
  • Remote access still on a full-tunnel VPN that places contractors and staff on the same internal network.
  • An audit or cyber-insurance question about segmentation that the current design cannot answer with evidence.

What the scope covers

  • Current-state review: topology, rulebase, routing, remote access and any existing segmentation.
  • A segmentation model — zones, trust boundaries and the traffic each is allowed to originate and receive.
  • Next-generation firewall design and policy: application-aware rules, TLS inspection where it is lawful and useful, and a rule lifecycle.
  • Zero-trust network access to replace or reduce full-tunnel VPN, with device posture as a condition of access.
  • Network detection and flow telemetry feeding your SIEM, including the east-west traffic a perimeter tool never sees.

What you receive

DeliverableWhat it contains
Segmentation modelZone map, trust boundaries, and the allowed flows between them — written so it can be reviewed by someone who was not in the room.
Firewall policy designRule structure, naming, change process, and a cleanup plan for the existing rulebase with each removal justified.
Detection and telemetry planWhat is collected, from where, at what volume, and which detections it is meant to support.
Migration runbookSequenced cutover with rollback at each step, maintenance windows, and the tests that decide whether a step holds.

Reference architecture

A reference, not a template. Your estate decides which parts apply and in what order they arrive.

Network security reference architecture: perimeter, control and visibility layersPerimeter: NGFW, IPS / IDS, Secure Web Gateway. Control: Micro-segmentation, ZTNA, Policy Engine. Visibility: NDR, Flow Telemetry, SIEM FeedPerimeterNGFWIPS / IDSSecure Web GatewayControlMicro-segmentationZTNAPolicy EngineVisibilityNDRFlow TelemetrySIEM Feed
Network security reference architecture: perimeter, control and visibility layers

How success is measured

Targets are agreed with you before the work starts, and reported against for its duration.

  • Reduction in reachable services from a standard user segment, measured before and after.
  • Proportion of firewall rules with a named owner and a documented purpose.
  • East-west traffic coverage: how much internal traffic the detection layer actually sees.

Questions we are asked

  • Do we have to replace our firewalls?

    Usually not. Most of the value is in the policy model and the segmentation behind it, both of which are portable across vendors. We would only recommend replacement where a platform cannot enforce the design — for example where application-aware policy or inspection at the needed throughput is not available.

  • How disruptive is segmentation?

    It is the part that carries real risk, which is why it is sequenced rather than switched on. Zones are introduced in monitor mode first, so you see what would have been blocked before anything is. Enforcement follows zone by zone, each with a tested rollback.

  • Is zero trust a product we need to buy?

    No. It is a design principle: access is granted per session, per application, on the basis of verified identity and device posture, rather than by position on the network. Products implement parts of it. Buying one without the design gets you a VPN with a new name.

  • Where does this stop and SOC begin?

    This capability builds the controls and the telemetry. A SOC watches the telemetry and responds. They are designed together — detections are only as good as the data the network gives them — and they can be delivered together as a managed service.

  • Can you work with our existing SIEM?

    Yes, and that is the normal case. The telemetry plan is written against whatever platform you already own, including the licensing consequence of the volume it will add, because that is where these projects usually get expensive without warning.

  • How long does a first phase take?

    A review and segmentation design for a single site is typically measured in weeks, not months. Enforcement across a multi-site estate is longer and is deliberately staged. We would rather give you a dated plan after the review than a number before it.

Continue reading

  • Cybersecurity

    The full domain, and the other capabilities within it.

  • Endpoint Security & XDR

    EDR deployment, detection engineering and automated containment across endpoints, servers and identities — tuned to your estate, not to a vendor demo.

  • Cloud Security

    Posture management, workload protection and entitlement control for AWS, Azure and GCP — with misconfiguration caught in the pipeline, not in production.

Start with an assessment

The fastest way to a useful answer is a short, scoped look at what you already have.