Service · IT security

Infrastructure security

Most break-ins into SME networks do not begin with a clever attack. They begin with something that was opened “just for a moment” years ago: a port forward for remote access to the server, the web interface of the phone system, a NAS shared to the internet, a maintenance account for a machine builder with no expiry date. Picture a haulage firm in Wels with office, warehouse and workshop on a single flat network. One infected office laptop can reach the weighbridge, the cameras and the server running route planning without any obstacle. For us, infrastructure security means knowing these paths and shutting them. We look at your public IP addresses from outside, as an attacker would, and from inside at the question of which device may talk to which. Firewall, switch and remote access configuration is done remotely. Where a cable needs moving or a device needs a restart, your own staff handle it following our instructions, or your local electrical and network contractor does.

External view
of every public IP address and service
Segments
for office, production, guests and servers
No RDP
reachable directly from the internet
Remote work
configuration with no site visit

Everything this covers

We work with the firewall and switches you have, as long as they still receive security updates. We only recommend new hardware if the old model has reached end of life.

Settle the details with an engineer

Perimeter check

Which services are reachable from the internet, which of them anyone really needs, and what software version they run. We scan your public addresses and compare the findings with the firewall rules.

Firewall rule set

Removing stale rules, closing port forwards, restricting outbound traffic and updating firmware. Every remaining rule gets a description and an owner.

Network segmentation

Separate VLANs for servers, workstations, printers, production equipment, cameras and guests, with rules between them. A hotel in Tyrol, for example, keeps guest Wi-Fi well away from the reception PC running the booking system.

Secure remote access

Instead of open RDP ports, a VPN with multi-factor sign-in or a zero-trust service that exposes individual applications only. Maintenance access for outside firms is time-limited and logged.

Wi-Fi

WPA3 or WPA2-Enterprise where possible, separate networks for company devices, personal phones and guests, and no shared password that has not changed since the day the business opened.

Management interfaces

Admin pages of firewall, switches, printers and phone system reachable only from a dedicated management network, with personal accounts instead of factory passwords.

Our working method

Network changes can disrupt operations, so we plan them in stages and always with a way back.

01

Outside and inside survey

A scan of public addresses, an export of the firewall configuration and a list of devices on the network. You get a diagram showing who can talk to whom today.

02

Target design

Together we define segments and permitted connections, including which equipment needs special routes, such as a CNC machine the manufacturer maintains remotely.

03

Changes in agreed windows

Work happens in maintenance windows, usually in the evening, over remote access. The configuration is backed up before each change.

04

Verification

A second external scan and tests between segments show whether the rules hold. The network documentation is brought up to date.

A flat network turns any incident into a total loss. When ransomware, cameras and the accounting server share one segment, a single click decides the fate of the whole business. Segmentation does not stop an attack, but it limits how far it spreads, and that is often the difference between a bad day and two weeks of standstill.

Frequently asked questions

What counts is whether the vendor still ships security updates. If not, yes. We then recommend a suitable model, you order it through your reseller, someone on site connects it following our guide, and we migrate and clean up the configuration remotely.

Yes, with limits. The connection ends in its own segment that reaches only that machine, is enabled on request rather than left open, and is logged. Most manufacturers accept this if it is agreed from the start.

Usually with site-to-site VPN tunnels between the firewalls or through an SD-WAN service. The key point is that segmentation carries across sites, so the warehouse network in Wels cannot suddenly reach the office network in Vienna.

At first it often does, because printers like to announce themselves by broadcast. We plan the required openings in advance and set printers up with fixed addresses or through a print server. After the switch-over the team rarely notices any difference.

Find out what the internet sees of your business

Briefly describe your network and how staff connect from outside. If you like, we will start with an external view of your public addresses.

Availability
Monday to Friday, 8:00-17:00 Austrian time (CET/CEST), reply within one working day
Meetings
By video on Microsoft Teams or Google Meet

We only use cookies that are technically required: to run the website and to remember the location you picked. There are no advertising or tracking cookies. Details are in the privacy notice.