Cybersecurity

We implement and support security tools

We design the architecture, deploy the systems, write attack detection rules and connect everything to SIEM and SOC. After launch, we stay on technical support.

Areas

What we do for each class of solutions

EDR · endpoint protection

Endpoint Detection & Response: attack detection and response on workstations and servers.

EDR deployment, configuration, technical support and maintenance
EDR architecture design
Mass agent rollout on Windows, Linux and macOS
Security policy configuration
Device and group segmentation
Integration with AD / Azure AD
Agent performance testing
Attack detection rules
Proactive threat hunting
Integration with sandbox and malware analysis
Log normalization
Data enrichment with Threat Intelligence

NGFW · network security

Next-generation firewalls for perimeter protection and control of traffic inside the network.

NGFW deployment, configuration, technical support and maintenance
Network security architecture design
Perimeter security design
Network segmentation: DMZ and internal zones
High-availability (HA) configurations
East-west traffic control
Integration with a Zero Trust model
Access and traffic control policies
Intrusion prevention systems (IPS)
VPN configuration
Network traffic analysis
Integration with SOC and SIEM

Email Security

Protection of corporate email against phishing, malicious attachments and data leaks.

Deployment, configuration, technical support and maintenance
Email security architecture design
Email security appliance deployment
Filtering configuration
Domain authentication protocols (SPF, DKIM, DMARC)
Attachment scanning
Data leak prevention over email
Email encryption
Integration with Threat Intelligence feeds
Integration with SOC and SIEM

WAF · web application protection

A Web Application Firewall protects websites, customer portals and APIs from web attacks and malicious bots.

WAF deployment, configuration, technical support and maintenance
WAF placement design within the network
Creation and tuning of protection rules
Protection against automated bots
API protection
Web traffic analysis
Performance optimization mechanisms
Integration with SIEM and SOC

DLP · data leak prevention

Data Loss Prevention: control over where and how your confidential data leaves the company.

DLP deployment, configuration, technical support and maintenance
Data protection architecture design
Data classification
Data transfer control policies
Content analysis of files and messages
User activity control on endpoints
Data leak incident handling
Integration with SIEM

PAM · privileged access

Privileged Access Management: control over administrator accounts and access to critical systems.

PAM deployment, configuration, technical support and maintenance
Privileged access management architecture design
Discovery of privileged accounts
Vault configuration for secrets storage
Administrative session control
Least privilege principle
Monitoring of privileged account usage
Automation of privileged access management
Audit readiness

SIEM · security monitoring

Security Information and Event Management: one place to collect events and detect incidents.

SIEM deployment, configuration, technical support and maintenance
Monitoring system architecture design
Onboarding of log sources
Log processing and normalization
Attack detection rules
Incident detection use cases
Monitoring dashboards
Integration of external threat feeds (Threat Intelligence)
Integration with SOAR
Process

How we work

STEP 01

Audit

We review your current infrastructure and security tools and document the weak spots.

STEP 02

Design

We prepare the target architecture based on industry standards, fault-tolerance and information security requirements.

STEP 03

Implementation

We deploy and configure systems and migrate services and data.

STEP 04

Integration

We connect the solutions together: SIEM, SOC, SOAR, Threat Intelligence, monitoring and backup.

STEP 05

Documentation

We hand over architecture and configuration documents with recommendations for further development.

STEP 06

Support

We take systems under technical support, optimize and evolve them.

Related area

IT infrastructure

Networks, servers and storage, monitoring, virtualization and backup.

Let’s discuss protecting your infrastructure

We start with an audit and show which security tools already work and what is missing.

Discuss a project