Having security products is not the same as being protected.
Firewalls, endpoints, email and identity — designed, hardened and monitored by named engineers. Including the unglamorous parts most people skip: patching, tested restores, and knowing who to call at 3am.
Ask us what your current setup is not covering. Ten minutes on the phone is usually enough to tell.
What a free security review looks at
How we harden, protect and defend
Securing an environment is six disciplines, not a product. Most companies we take over are strong in one or two of them and have nobody holding the rest.
Perimeter and segmentation
A default-deny firewall policy that names what each rule is for, tuned IPS and web filtering, internal segmentation so a compromised laptop cannot reach the servers, and remote access behind multi-factor.
Endpoint and server hardening
Managed endpoint protection with application, web and device control, disk encryption, secure baselines, legacy protocols switched off, and patching on a schedule that someone actually checks.
Identity and access control
Multi-factor on everything exposed, least privilege, administrative rights reviewed rather than assumed, shared accounts removed, and a documented joiner-mover-leaver process.
Email and collaboration security
Anti-phishing and attachment controls, SPF, DKIM and DMARC enforced so your domain cannot be spoofed, and Microsoft 365 or Google Workspace tenants hardened against the defaults.
Monitoring, alerting and response
Logs collected and actually read, alerts routed to engineers on shift, and an incident process agreed before the incident — including who decides to disconnect.
Vulnerability management
Scheduled scanning, a tracked remediation register with owners and dates, and firmware kept on supported branches. Findings are closed, not filed.
Certification and audit readiness — ISO 27001, PCI DSS, SOC 2 Type II, TISAX and Saudi Aramco CCC — is a separate service. See Information Security and Compliance.
Where it actually goes wrong
Almost none of it is sophisticated. These four account for most of what we are called in to clean up, and all four are preventable.
One convincing email
Not a virus — a message. A supplier bank change, an invoice, a login page that looks right. It arrives at someone in finance who has no reason to be suspicious, and there is no second check.
The edge device nobody patched
The firewall or VPN appliance facing the internet is two or three firmware versions behind, because updating it means a maintenance window and nobody has scheduled one in years.
One admin password, shared
The same account for everyone technical, no multi-factor, and staff who left months ago whose access was never removed. Every action looks like it came from the same person, so nothing can be traced.
A backup nobody has ever restored
The job reports success every night. It writes to a share on the same network, with the same credentials, and no one has attempted a restore. Ransomware encrypts it along with everything else.
Five layers. Each one owned, not just installed.
This is the list we work through on every engagement. You do not have to buy all five from us — but you should know which of them nobody is currently holding.
The perimeter
The firewall is not a box you plug in. It is a policy set, and it needs owning.
- A default-deny policy set, with rules that name what they are for
- IPS and web filtering on tuned profiles, not the shipped defaults
- Internal segmentation so a compromised laptop cannot reach the servers
- Site-to-site and remote-access VPN, with multi-factor on remote access
- Geo and reputation blocking where it genuinely reduces exposure
- Firmware kept on a supported branch, in a planned window
Most often FortiGate — design, licensing and ongoing management — or Sophos XGS.
Endpoints and servers
Antivirus stops what it recognises. That is no longer the threat.
- Endpoint detection and response, not signature scanning alone
- Application and device control, so USB and unknown binaries are a decision
- Disk encryption with the recovery keys held somewhere you can reach
- Exploit prevention and rollback of ransomware file changes
- Patching for the operating system and for third-party applications
- A software inventory that tells you what you are actually running
Usually Kaspersky or Sophos Intercept X.
Email and identity
This is where the money is stolen, and it is the cheapest layer to fix.
- SPF, DKIM and DMARC published and actually enforced
- Anti-phishing, impersonation protection and attachment sandboxing
- Multi-factor on every account — including directors
- Conditional access, and legacy authentication protocols switched off
- Administrative accounts separated from daily-use accounts
- Joiners and leavers processed the same day, not the same quarter
Built on Microsoft 365, with Defender where the licensing supports it.
Monitoring and response
A product nobody reads the alerts from is a licence, not a defence.
- Logs collected centrally, so evidence survives the device
- Alerts that reach a named person on a rota, not an unread mailbox
- An agreed severity scale, with response times written into the contract
- Isolate first: a suspect endpoint comes off the network while we look
- A monthly review of what fired, what it meant, and what we changed
- Around-the-clock cover where the business genuinely needs it
We report what we found and what we did — in language you can hand to a board.
Backup and recovery
Every security plan ends with the same question: how fast can you be running again?
- Three copies, two media, one of them off the network
- Immutable or offline copies, so ransomware cannot reach them
- Restores tested on a schedule, with the result written down
- A documented recovery order for the systems the business cannot trade without
- Recovery time and recovery point agreed with you, not assumed by us
Commonly Veeam, with storage sized to the estate. See Backup & Data Protection.
Environments that could not afford to be wrong
Real Stark programmes. Client identifiers are withheld under confidentiality — sector and scope only.
National e-payment platform
Web application firewall and network access control in front of a national payment service, with the network core and SD-WAN connectivity monitored around the clock.
National data centre
Firewalls, segmentation and access control designed into the build rather than added afterwards, delivered under strict security and confidentiality requirements.
ISO 27001 readiness
Policies, asset and risk registers, access reviews and the evidence trail an auditor or an enterprise client’s security questionnaire actually asks for.
References can be provided directly, on request, with the client’s agreement.
Three things we will tell you not to buy
The questions we get asked most
We already have a firewall and antivirus. What would you actually add?
Usually three things: configuration that matches your business instead of the vendor defaults, someone reading the alerts those products generate, and the identity layer — multi-factor, conditional access and leaver removal — which is where most real losses start. Often we add no new licences at all.
Do you monitor around the clock?
We can, and we do for clients who need it — a national payment platform we support is monitored 24/7. For a company that trades business hours, round-the-clock cover is often not the best use of the budget, and we will say so. The cover level is agreed in writing before you sign.
What does the free security assessment involve?
An engineer reviews what you are running, what is exposed to the internet, what is unsupported or unpatched, how identity and email are configured, and whether your backup would survive a ransomware event. You get a written summary of the gaps, ranked. There is no obligation to proceed.
Can you help with ISO 27001 or a client’s security questionnaire?
Yes. We build the information security management system — policies, asset and risk registers, access reviews and the evidence trail — and we help you answer enterprise security questionnaires without overstating what is in place. See Information Security Management.
What happens if we are attacked while you are managing us?
The response is agreed in advance, not invented on the day: isolate the affected systems, preserve the evidence, work out what was reached, then recover in a documented order from a backup we have already tested. You get a written account of what happened and what changed afterwards.
Ask us what your current setup is not covering.
Tell us what you run and we will tell you where the gaps are — including the ones you do not need to spend money on. Ten minutes on the phone, with an engineer.
Sunday to Thursday, 9am–6pm · Cairo, Alexandria & Assiut
Our other IT services
Every service below is delivered by the same team, under the same agreement.
