Service 04 · Threat & vigilance

You do not need to be a target. You only need to be reachable.

Firewall configuration, network segmentation, monitoring and response — set up properly and then actually watched, rather than installed once and forgotten.

Network security appliance and firewall configuration by Greenstem

The problem

Almost no attack on a business this size is personal. It is automated, it is looking for anything exposed, and it does not care what you do.

The common pattern is not a sophisticated breach. It is a default password on a device facing the internet, a flat network where a single infected laptop can reach the file server, or a staff member who clicked something and nobody noticed for three weeks.

We harden what is exposed, segment the network so one compromised device cannot reach everything, and put monitoring in place so an incident is caught in hours rather than discovered by a client. Where you have compliance obligations under POPIA, we document what was done.

Layers of defence

Firewall and network hardening, monitoring, and incident response.

  1. Hardened

    Firewall & zoning

    Zone-based rules, VLAN segmentation, and intrusion prevention configured, not left on defaults.

  2. Hardened

    Exposure review

    What of yours is reachable from the internet, and what should not be.

  3. Hardened

    Endpoint protection

    Managed protection on workstations and servers, with alerts that reach a human.

  4. Hardened

    Backup verification

    A backup nobody has restored from is not a backup. We test yours.

  5. Hardened

    Access & identity

    Multi-factor authentication, account hygiene, and removing access when people leave.

  6. Hardened

    Incident response

    A written plan for who does what, and us on the end of the phone when it happens.

Response timeline

How an engagement runs.

  1. 01 / Review

    Find what is exposed

    Assessment of the network, devices, accounts and current defences.

  2. 02 / Prioritise

    Fix the cheap wins first

    Ranked by risk against effort, so the worst gaps close immediately.

  3. 03 / Harden

    Implement

    Firewall, segmentation, MFA, endpoint protection and tested backups.

  4. 04 / Watch

    Monitor & respond

    Ongoing monitoring, patching and a response plan on retainer.

Questions we get asked

We are small. Is this really necessary?
Small businesses are targeted more often precisely because the defences are usually weaker. The cost of a week of downtime is almost always higher than a year of getting this right.
Do you do penetration testing?
We do assessment and hardening. For formal penetration testing against a compliance requirement, we scope it separately and give you the report as the deliverable.
What does POPIA require of us?
In short, reasonable steps to secure personal information you hold and a plan for reporting breaches. We are not attorneys — but we implement and document the technical side so your compliance advisor has something to point at.

Start here

Start with the audit. It costs you a morning.

Tell us where things are breaking. We walk the site, map what you have, and come back with a phased plan and a real number.

Book an audit