Flat networks are the reason a single compromised endpoint becomes an estate wide incident. I design zone models around data sensitivity and blast radius, then enforce them at the firewall and the fabric.
Work includes rule base rationalisation. The average brownfield firewall I inherit has 30-60 percent shadowed, expired or overly broad rules. I add IPS profile tuning, TLS inspection strategy, and secure remote access.
Every policy change is reviewed, versioned and reversible, with an audit trail suitable for ISO 27001 and PCI evidence.
- Lateral movement contained to a single zone
- Rule base reduced and fully attributed to an owner
- Remote access with enforced MFA and device posture
Can you migrate us between firewall vendors?+
Yes, including rule translation, shadow rule elimination and a parallel run validation window.
Do you provide penetration testing?+
I provide vulnerability assessment and configuration review. Full offensive testing is delivered with an accredited partner.