Deutsch

Defensive Services

Firewall and Intrusion Detection

Everyone has a firewall at the internet boundary today. The question that decides the damage is a different one: what can an attacker reach once they are already inside? In a network without internal boundaries the answer is: everything.

01

The starting point

The damage happens after the break-in

Initial access is an incident. What it turns into is decided in the hours that follow: moving from system to system, across a network that grew historically and in which everything may talk to everything. Lateral Movement is the name for that part of an attack — and it is the part you can genuinely prevent at reasonable cost.

A compromised workstation in accounting should be technically incapable of reaching the controllers on the shop floor. In most networks we see, it is not. Not through negligence — but because nobody ever asked which connections are actually needed.

A wide dark field divided by walls into separate closed compartments. A single compartment is brightly lit; the light stops at its walls and reaches none of its neighbours.

The approach

Segmentation is the real lever

Zones are cut along protection requirements, not along the org chart and certainly not along the cabling as it grew. Production, administration, building services, guest network, admin access: each of these has its own protection requirement and its own list of what may enter and leave.

Name the permitted connections, do not collect the forbidden ones

A ruleset that collects prohibitions grows with every incident and is never finished. A ruleset that names permissions is laborious at first and manageable afterwards. We always work in that direction — the same idea behind Zero Trust, only without the promise of implementing it over a weekend.

Observe first, block second

No ruleset comes out right on the drawing board. New rules therefore run in monitoring mode first: what would be blocked, and would that be a problem? Only once that list stays empty for weeks does anything get enforced. It costs time and saves the phone call that production has stopped.

Rules have a shelf life

Every exception made in day-to-day work stays there forever unless somebody maintains it. After three years nobody can explain what rule 214 was for, and it does not get deleted either. So a ruleset needs, from day one, a named owner, a review date and a decision about rules nobody can justify any more.

  1. 01

    Inventory

    which systems actually talk to each other today — measured, not assumed

  2. 02

    Zone model

    cut by protection requirement, with named ownership per zone

  3. 03

    Ruleset

    name the permitted connections, each with a purpose and an owner

  4. 04

    Transition

    monitoring mode before blocking, zone by zone rather than all at once

  5. 05

    Detection

    assessment of what happens inside the permitted connections

  6. 06

    Maintenance

    a fixed review, without which any ruleset decays within two years

It is not the break-in that decides, but how far it gets.

02

The complement

Detection inside the network, not only at its edge

A firewall decides whether a connection is established. It says nothing about what happens inside a permitted one — and that is exactly where an attacker with credentials operates. An internal IDS/IPS closes that gap, and NDR analysis widens it to the whole of the network traffic: systematic probing of internal address ranges, data leaving at an unusual hour, connections to infrastructure registered only hours ago.

The assessment is done by NeoI, so that not every deviation ends as an alert — the same logic as in AI-driven threat detection, applied here to network traffic. The result is visible in Strider.

weeks
of monitoring mode before the first block
per zone
one named owner, not a shared mailbox
annually
a review of the entire ruleset
ISO 27001
where segmentation is a requirement
03

The appliance

Hardware firewall solution — made in Europe

Where you want to run the appliance yourself, we supply it as Valar: four graded models from the single branch office to the distributed corporate network, with the same management logic throughout and a documented supply chain.

The solution is developed in Europe, and that is the part that matters: operating system, ruleset, detection and management come from us, and data residency is in the EU. The appliances themselves are manufactured to our specification — we evidence the supply chain, but we do not claim it is European.

For operators of critical facilities and for the public sector, that distinction is exactly what counts. What a tender requires you to evidence is control over software, updates and data — and that can be evidenced, before the contract is awarded rather than after.

But we also work with what you already have. Changing vendor is a decision of its own with costs of its own, and it does not belong in a segmentation project as a precondition.

A single precisely machined metal device on a workbench in a dark room. Only its front edge is caught by a narrow line of light.

A firewall is not a project but a state.

04

The honest view

Where we slow you down

The most common reason segmentation projects stall is a first step that is too large. A zone model for the whole organization, designed in one workshop, implemented in one maintenance window — that fails reliably, and afterwards the topic is burnt for years.

So we start with one zone, usually the one with the clearest protection requirement and the fewest dependencies. It produces the method, the numbers and the experience for all the others. If you want the grand design, we will tell you why we advise against it.

And segmentation replaces neither updates nor multi-factor authentication. It limits the damage; it does not prevent the entry. Where the fundamentals are missing, they get fixed first.

05

Afterwards

Operation and evidence

A firewall is not a project but a state. Rules go stale, applications change their behaviour, exceptions stay. We take on the ongoing maintenance under SOC Co-Managed if you want us to — or we hand over cleanly documented to your team, with zone model, rule rationale and review plan.

Segmentation is a requirement in ISO 27001 and a central point of NIS2 implementation. We document it so that it holds up in an audit — embedded in the ISMS build-up if you need the evidence as a whole.

A tall stack of thin dark plates, each offset slightly against the one below. One plate near the top is lit brighter than the rest.
06

In closing

The first step costs nothing

Before zones or appliances are discussed, there is a plain question: do you know which systems in your network actually talk to each other today? In most organizations the answer is not on file — and measuring it is no great effort.

That is where we start. The result is yours, whether or not you carry on with us afterwards.

FAQ

Frequently asked questions

We already have a firewall. Is that not enough?

For the internet boundary, yes. But it says nothing about what happens inside your network. That is exactly where an attacker who got in operates, and where the real damage occurs. So the question is not whether you have a firewall, but how many internal boundaries sit behind it.

Does segmentation not bring operations to a halt?

If you enforce it over a weekend, yes. That is why every new rule first runs in monitoring mode for weeks and produces a list of what would be blocked. Everything on that list is resolved before anything takes effect. The route is slower and therefore the only one that arrives.

How long does a project like this take?

The first zone usually takes several weeks, the whole organization considerably longer depending on size. We deliberately cut it so that each zone delivers value on its own rather than only the whole thing at the end. A schedule promising everything in one maintenance window is not realistic.

Do we have to buy new hardware for this?

No. By far the largest part of the work is the zone model and the ruleset, and both are vendor-independent. If you are procuring anew or have to evidence provenance, we supply Valar, a hardware firewall solution developed in Europe — as an option, not a precondition.

What is the difference between IDS and IPS?

An IDS reports, an IPS intervenes. The difference is organisational more than technical: an intervening system can also cut off legitimate traffic, and then somebody has to be reachable. So we almost always start in reporting mode and only enforce where the rule is certain enough and operations are behind it.

Defensive Services

More in this area

Instant Response

24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…

View

Quantum Cryptography (QaaS)

Harvest now, decrypt later already affects data encrypted today. Cryptographic inventory, assessment by lifetime and hy…

View

AI Threat Detection

Signatures catch what is known. NeoI catches what deviates from your normal state — including attackers who use nothing…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.