Cyber Security

Cyber Security · Cairo · Alexandria · Assiut

Having security products is not the same as being protected.

Firewalls, endpoints, email and identity — designed, hardened and monitored by named engineers. Including the unglamorous parts most people skip: patching, tested restores, and knowing who to call at 3am.

Ask us what your current setup is not covering. Ten minutes on the phone is usually enough to tell.

What a free security review looks at

The perimeterFirewall rules, VPN, firmware age, and what is exposed to the internet that should not be.

The endpointsWhat is actually installed, what is unpatched, and whether anyone reads the alerts.

Email and identitySPF, DKIM and DMARC, MFA coverage, admin accounts, and who still has access after leaving.

Backup and recoveryWhether the backup is off the network, and whether a restore has ever actually been tested.
2016
Operating since
50+
IT specialists
40+
Projects delivered
25+
Clients
5.0
Rated on Google
Security we deploy and supportFortinetSophosKasperskyMicrosoftCiscoVeeam
Security solutions

How we harden, protect and defend

Securing an environment is six disciplines, not a product. Most companies we take over are strong in one or two of them and have nobody holding the rest.

Perimeter and segmentation

A default-deny firewall policy that names what each rule is for, tuned IPS and web filtering, internal segmentation so a compromised laptop cannot reach the servers, and remote access behind multi-factor.

Endpoint and server hardening

Managed endpoint protection with application, web and device control, disk encryption, secure baselines, legacy protocols switched off, and patching on a schedule that someone actually checks.

Identity and access control

Multi-factor on everything exposed, least privilege, administrative rights reviewed rather than assumed, shared accounts removed, and a documented joiner-mover-leaver process.

Email and collaboration security

Anti-phishing and attachment controls, SPF, DKIM and DMARC enforced so your domain cannot be spoofed, and Microsoft 365 or Google Workspace tenants hardened against the defaults.

Monitoring, alerting and response

Logs collected and actually read, alerts routed to engineers on shift, and an incident process agreed before the incident — including who decides to disconnect.

Vulnerability management

Scheduled scanning, a tracked remediation register with owners and dates, and firmware kept on supported branches. Findings are closed, not filed.

Certification and audit readiness — ISO 27001, PCI DSS, SOC 2 Type II, TISAX and Saudi Aramco CCC — is a separate service. See Information Security and Compliance.

What we see in the field

Where it actually goes wrong

Almost none of it is sophisticated. These four account for most of what we are called in to clean up, and all four are preventable.

One convincing email

Not a virus — a message. A supplier bank change, an invoice, a login page that looks right. It arrives at someone in finance who has no reason to be suspicious, and there is no second check.

The edge device nobody patched

The firewall or VPN appliance facing the internet is two or three firmware versions behind, because updating it means a maintenance window and nobody has scheduled one in years.

One admin password, shared

The same account for everyone technical, no multi-factor, and staff who left months ago whose access was never removed. Every action looks like it came from the same person, so nothing can be traced.

A backup nobody has ever restored

The job reports success every night. It writes to a share on the same network, with the same credentials, and no one has attempted a restore. Ransomware encrypts it along with everything else.

What we actually build

Five layers. Each one owned, not just installed.

This is the list we work through on every engagement. You do not have to buy all five from us — but you should know which of them nobody is currently holding.

1

The perimeter

The firewall is not a box you plug in. It is a policy set, and it needs owning.

  • A default-deny policy set, with rules that name what they are for
  • IPS and web filtering on tuned profiles, not the shipped defaults
  • Internal segmentation so a compromised laptop cannot reach the servers
  • Site-to-site and remote-access VPN, with multi-factor on remote access
  • Geo and reputation blocking where it genuinely reduces exposure
  • Firmware kept on a supported branch, in a planned window

Most often FortiGate — design, licensing and ongoing management — or Sophos XGS.

2

Endpoints and servers

Antivirus stops what it recognises. That is no longer the threat.

  • Endpoint detection and response, not signature scanning alone
  • Application and device control, so USB and unknown binaries are a decision
  • Disk encryption with the recovery keys held somewhere you can reach
  • Exploit prevention and rollback of ransomware file changes
  • Patching for the operating system and for third-party applications
  • A software inventory that tells you what you are actually running

Usually Kaspersky or Sophos Intercept X.

3

Email and identity

This is where the money is stolen, and it is the cheapest layer to fix.

  • SPF, DKIM and DMARC published and actually enforced
  • Anti-phishing, impersonation protection and attachment sandboxing
  • Multi-factor on every account — including directors
  • Conditional access, and legacy authentication protocols switched off
  • Administrative accounts separated from daily-use accounts
  • Joiners and leavers processed the same day, not the same quarter

Built on Microsoft 365, with Defender where the licensing supports it.

4

Monitoring and response

A product nobody reads the alerts from is a licence, not a defence.

  • Logs collected centrally, so evidence survives the device
  • Alerts that reach a named person on a rota, not an unread mailbox
  • An agreed severity scale, with response times written into the contract
  • Isolate first: a suspect endpoint comes off the network while we look
  • A monthly review of what fired, what it meant, and what we changed
  • Around-the-clock cover where the business genuinely needs it

We report what we found and what we did — in language you can hand to a board.

5

Backup and recovery

Every security plan ends with the same question: how fast can you be running again?

  • Three copies, two media, one of them off the network
  • Immutable or offline copies, so ransomware cannot reach them
  • Restores tested on a schedule, with the result written down
  • A documented recovery order for the systems the business cannot trade without
  • Recovery time and recovery point agreed with you, not assumed by us

Commonly Veeam, with storage sized to the estate. See Backup & Data Protection.

Where we have done it

Environments that could not afford to be wrong

Real Stark programmes. Client identifiers are withheld under confidentiality — sector and scope only.

Fintech · 24/7

National e-payment platform

Web application firewall and network access control in front of a national payment service, with the network core and SD-WAN connectivity monitored around the clock.

Government & defence

National data centre

Firewalls, segmentation and access control designed into the build rather than added afterwards, delivered under strict security and confidentiality requirements.

Standards · ISMS

ISO 27001 readiness

Policies, asset and risk registers, access reviews and the evidence trail an auditor or an enterprise client’s security questionnaire actually asks for.

References can be provided directly, on request, with the client’s agreement.

How we advise

Three things we will tell you not to buy

A product you will not monitorBuying a tool nobody watches does not reduce risk. It adds cost and a false sense of safety. We would rather sell you fewer licences and the monitoring to go with them.
A rebuild you do not needIf the firewall you own is supported and sized correctly, we will configure it properly rather than quote you a replacement. We will tell you plainly when it genuinely is end of life.
Certification before the basicsISO 27001 work is wasted effort while multi-factor is off and nothing is patched. We do it in the order that actually reduces risk, then help you evidence it.
Before you call

The questions we get asked most

We already have a firewall and antivirus. What would you actually add?

Usually three things: configuration that matches your business instead of the vendor defaults, someone reading the alerts those products generate, and the identity layer — multi-factor, conditional access and leaver removal — which is where most real losses start. Often we add no new licences at all.

Do you monitor around the clock?

We can, and we do for clients who need it — a national payment platform we support is monitored 24/7. For a company that trades business hours, round-the-clock cover is often not the best use of the budget, and we will say so. The cover level is agreed in writing before you sign.

What does the free security assessment involve?

An engineer reviews what you are running, what is exposed to the internet, what is unsupported or unpatched, how identity and email are configured, and whether your backup would survive a ransomware event. You get a written summary of the gaps, ranked. There is no obligation to proceed.

Can you help with ISO 27001 or a client’s security questionnaire?

Yes. We build the information security management system — policies, asset and risk registers, access reviews and the evidence trail — and we help you answer enterprise security questionnaires without overstating what is in place. See Information Security Management.

What happens if we are attacked while you are managing us?

The response is agreed in advance, not invented on the day: isolate the affected systems, preserve the evidence, work out what was reached, then recover in a documented order from a backup we have already tested. You get a written account of what happened and what changed afterwards.

Free security assessment · no obligation

Ask us what your current setup is not covering.

Tell us what you run and we will tell you where the gaps are — including the ones you do not need to spend money on. Ten minutes on the phone, with an engineer.

02 3537 5791

Sunday to Thursday, 9am–6pm · Cairo, Alexandria & Assiut