Network Security

Network Security · Your IT partner since 2016

A flat network is one bad laptop away from a very bad week.

Segmentation, access control, resilient switching and secure remote access, designed, built and documented, so one compromised device cannot reach everything you own.

Engineering offices in Egypt, delivering on site across Egypt and Saudi Arabia, and supporting clients remotely across the Gulf, Africa, Europe and the United States.

Most people call. It is faster, and you speak to an engineer, not a form.

What a free network review looks at

What is exposedWhich services face the internet, on what firmware, and which of them should not be there at all.

How flat it really isWhether a laptop on the office VLAN can reach the servers, the cameras and the finance PC.

Who gets on the Wi-FiShared passwords, guests on the same network as staff, and access that was never removed.

What happens when a link diesWhether a single switch, uplink or firewall can take the whole floor offline.
2016
Operating since
50+
IT specialists
40+
Projects delivered
25+
Clients
5.0
Rated on Google
What we deploy and supportFortinetCiscoSophosTP-LinkHPEDell
What we see in the field

Where networks actually fail

Rarely anything exotic. These four account for most of what we are called in to fix, and all four are design decisions rather than budget problems.

One flat network

Every device on one subnet because it was quicker. Printers, cameras, guest laptops and the accounting server can all talk to each other. Nothing contains a problem once it starts.

The Wi-Fi password everyone knows

One pre-shared key, shared with visitors, contractors and former staff, and never rotated. Guest traffic sits on the same network as the business.

A single point of failure nobody drew

One uplink, one switch or one firewall holding up the whole site. It usually only becomes visible on the day it fails, because there is no current diagram.

Firmware from three years ago

The switches and access points still run whatever shipped in the box. Updating means a maintenance window, and nobody has ever scheduled one.

What we actually build

Five layers. Designed, built, and written down.

This is what we work through on a network engagement. You do not have to buy all of it, but you should know which parts nobody currently owns.

1

Segmentation, and the rules between segments

Segmentation is not VLANs. It is VLANs plus a policy that says what may cross.

  • Separate zones for staff, servers, guests, voice, cameras and building systems
  • Inter-VLAN traffic filtered by the firewall, not switched blindly
  • A default-deny stance between zones, with rules that name what they are for
  • Management interfaces on their own segment, not reachable from user VLANs
  • Documented address plan, so the next engineer is not guessing
  • Change control, so the design does not quietly erode

Usually enforced on FortiGate or Sophos XGS.

2

Switching and routing that survives a failure

Resilience is a design choice made before the cabinet is populated, not a product you add later.

  • Stacked or paired distribution switches forwarding active-active
  • Redundant fibre uplinks on diverse paths where the building allows
  • Link aggregation sized to real traffic, not to the port count
  • A deliberate spanning-tree design with a defined root, not whatever elected itself
  • Firewall pairs in high availability, tested by actually failing one over
  • Firmware on a supported branch, updated in a planned window

Commonly Cisco, HPE and TP-Link Omada, sized to the site.

3

Wi-Fi people can actually use

Most Wi-Fi complaints are a coverage and channel problem wearing a security costume.

  • A site survey before the access points are bought, not after the complaints
  • A channel and power plan, so your own APs stop competing with each other
  • WPA2/WPA3-Enterprise with per-user credentials where the estate supports it
  • Guest access isolated from the business network, with its own bandwidth limits
  • Roaming that works across a floor without dropping a call
  • Controller and AP firmware kept current

We deploy TP-Link Omada, and Cisco or HPE where the estate calls for it.

4

Remote access and connecting sites

Remote access is now a permanent part of the network, so it gets designed like one.

  • Remote-access VPN with multi-factor authentication, no exceptions
  • Site-to-site tunnels with sensible routing, not a mesh nobody can debug
  • SD-WAN where multiple links or branches justify it
  • Split-tunnel decisions made deliberately and written down
  • Leaver access removed the same day, from the network as well as the mailbox
  • Third-party and vendor access scoped to what they actually need

See also VPN & Remote Work.

5

The physical layer, and the documentation

Half of the faults we are called to are cabling, labelling or a change nobody recorded.

  • Structured cabling, dressed and terminated to standard
  • Every port, patch lead and cabinet labelled and mapped
  • Patch schedules that match the diagram, and a diagram that matches reality
  • As-built documentation handed to you, not kept as leverage
  • Power and cooling checked in the cabinet, not assumed
  • A rebuild plan, so the site can be reconstructed if it is ever lost

If you ever leave us, you leave with all of it. See the as-found and as-built photographs on our homepage.

Where we have done it

Networks that could not afford to drop

Real Stark programmes. Client identifiers are withheld under confidentiality. Sector and scope only.

Global hotel group · contact centre

Campus network in high availability

Stacked distribution pairs forwarding active-active with redundant fibre uplinks, and a firewall pair in HA, designed so no single link, switch or firewall can take the floor offline.

Fintech · national payment platform

Core, SD-WAN, WAF and NAC

Network core and SD-WAN connectivity with web application firewall and network access control in front of a national payment service, monitored around the clock.

Oil & gas · Tier-III data centre

HPC cluster interconnect

Cluster interconnect, high-performance storage networking, routing and firewalls, architected, racked and cabled from bare racks to a production processing cluster.

Government & defence · Egypt

National data centre

Firewalls, segmentation and structured cabling designed into the build rather than added afterwards, delivered under strict security and confidentiality requirements.

References can be provided directly, on request, with the client’s agreement.

How we advise

Three things we will tell you not to buy

Hardware to fix a design problemA faster switch does not fix a flat network or a bad channel plan. We would rather redesign what you own than quote you a replacement that changes nothing.
Resilience you will never testA second firewall that has never been failed over is not redundancy, it is a second invoice. If we build a pair, we test it with you watching.
Wi-Fi you have not surveyedBuying access points before a survey is how sites end up with too many, in the wrong places, interfering with each other. The survey is cheaper than the second purchase.
Before you call

The questions we get asked most

We already have a firewall. Is that not network security?

It is one part of it, and usually the part that is already bought. The gaps we find most often are inside the network rather than at its edge: no segmentation, a shared Wi-Fi key, management interfaces reachable from user machines, and no current diagram. None of those are fixed by the firewall you already own.

Can you work with the equipment we already have?

Usually yes, and we prefer to. If your switches and access points are supported and sized correctly, we will configure them properly rather than replace them. We will tell you plainly when something genuinely is end of life or too small for the job.

Do you have to take the network down to do this?

Segmentation and resilience work is normally staged so the business keeps trading. New structure built alongside the old, then cut over in agreed windows. We tell you before we sign which steps genuinely need an outage and how long each one is.

What do we get at the end?

A working network and the documentation for it: as-built topology, address plan, VLAN and firewall policy, Wi-Fi channel plan, patch schedule and recovery steps. It is yours, and you keep it whether or not you stay with us.

What does the free network review actually involve?

An engineer looks at what is exposed to the internet, how the network is segmented, how Wi-Fi and remote access are configured, and where a single failure would hurt. You get a written summary of the gaps, ranked. There is no obligation to proceed.

Free network review · no obligation

Ask us what your network would do on a bad day.

Tell us what you run and we will tell you where it would break, and where it would spread. Including the parts you do not need to spend money on. Ten minutes, with an engineer.

02 3537 5791

Sunday to Thursday, 9am to 6pm · Egypt, and remote worldwide