Instant Response
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewDefensive Services
Everyone has a firewall at the internet boundary today. The question that decides the damage is a different one: what can an attacker reach once they are already inside? In a network without internal boundaries the answer is: everything.
The starting point
Initial access is an incident. What it turns into is decided in the hours that follow: moving from system to system, across a network that grew historically and in which everything may talk to everything. Lateral Movement is the name for that part of an attack — and it is the part you can genuinely prevent at reasonable cost.
A compromised workstation in accounting should be technically incapable of reaching the controllers on the shop floor. In most networks we see, it is not. Not through negligence — but because nobody ever asked which connections are actually needed.

The approach
Zones are cut along protection requirements, not along the org chart and certainly not along the cabling as it grew. Production, administration, building services, guest network, admin access: each of these has its own protection requirement and its own list of what may enter and leave.
A ruleset that collects prohibitions grows with every incident and is never finished. A ruleset that names permissions is laborious at first and manageable afterwards. We always work in that direction — the same idea behind Zero Trust, only without the promise of implementing it over a weekend.
No ruleset comes out right on the drawing board. New rules therefore run in monitoring mode first: what would be blocked, and would that be a problem? Only once that list stays empty for weeks does anything get enforced. It costs time and saves the phone call that production has stopped.
Every exception made in day-to-day work stays there forever unless somebody maintains it. After three years nobody can explain what rule 214 was for, and it does not get deleted either. So a ruleset needs, from day one, a named owner, a review date and a decision about rules nobody can justify any more.
which systems actually talk to each other today — measured, not assumed
cut by protection requirement, with named ownership per zone
name the permitted connections, each with a purpose and an owner
monitoring mode before blocking, zone by zone rather than all at once
assessment of what happens inside the permitted connections
a fixed review, without which any ruleset decays within two years
It is not the break-in that decides, but how far it gets.
The complement
A firewall decides whether a connection is established. It says nothing about what happens inside a permitted one — and that is exactly where an attacker with credentials operates. An internal IDS/IPS closes that gap, and NDR analysis widens it to the whole of the network traffic: systematic probing of internal address ranges, data leaving at an unusual hour, connections to infrastructure registered only hours ago.
The assessment is done by NeoI, so that not every deviation ends as an alert — the same logic as in AI-driven threat detection, applied here to network traffic. The result is visible in Strider.
The appliance
Where you want to run the appliance yourself, we supply it as Valar: four graded models from the single branch office to the distributed corporate network, with the same management logic throughout and a documented supply chain.
The solution is developed in Europe, and that is the part that matters: operating system, ruleset, detection and management come from us, and data residency is in the EU. The appliances themselves are manufactured to our specification — we evidence the supply chain, but we do not claim it is European.
For operators of critical facilities and for the public sector, that distinction is exactly what counts. What a tender requires you to evidence is control over software, updates and data — and that can be evidenced, before the contract is awarded rather than after.
But we also work with what you already have. Changing vendor is a decision of its own with costs of its own, and it does not belong in a segmentation project as a precondition.

A firewall is not a project but a state.
The honest view
The most common reason segmentation projects stall is a first step that is too large. A zone model for the whole organization, designed in one workshop, implemented in one maintenance window — that fails reliably, and afterwards the topic is burnt for years.
So we start with one zone, usually the one with the clearest protection requirement and the fewest dependencies. It produces the method, the numbers and the experience for all the others. If you want the grand design, we will tell you why we advise against it.
And segmentation replaces neither updates nor multi-factor authentication. It limits the damage; it does not prevent the entry. Where the fundamentals are missing, they get fixed first.
Afterwards
A firewall is not a project but a state. Rules go stale, applications change their behaviour, exceptions stay. We take on the ongoing maintenance under SOC Co-Managed if you want us to — or we hand over cleanly documented to your team, with zone model, rule rationale and review plan.
Segmentation is a requirement in ISO 27001 and a central point of NIS2 implementation. We document it so that it holds up in an audit — embedded in the ISMS build-up if you need the evidence as a whole.

In closing
Before zones or appliances are discussed, there is a plain question: do you know which systems in your network actually talk to each other today? In most organizations the answer is not on file — and measuring it is no great effort.
That is where we start. The result is yours, whether or not you carry on with us afterwards.
FAQ
For the internet boundary, yes. But it says nothing about what happens inside your network. That is exactly where an attacker who got in operates, and where the real damage occurs. So the question is not whether you have a firewall, but how many internal boundaries sit behind it.
If you enforce it over a weekend, yes. That is why every new rule first runs in monitoring mode for weeks and produces a list of what would be blocked. Everything on that list is resolved before anything takes effect. The route is slower and therefore the only one that arrives.
The first zone usually takes several weeks, the whole organization considerably longer depending on size. We deliberately cut it so that each zone delivers value on its own rather than only the whole thing at the end. A schedule promising everything in one maintenance window is not realistic.
No. By far the largest part of the work is the zone model and the ruleset, and both are vendor-independent. If you are procuring anew or have to evidence provenance, we supply Valar, a hardware firewall solution developed in Europe — as an option, not a precondition.
An IDS reports, an IPS intervenes. The difference is organisational more than technical: an intervening system can also cut off legitimate traffic, and then somebody has to be reachable. So we almost always start in reporting mode and only enforce where the rule is certain enough and operations are behind it.
Defensive Services
24/7 immediate response to cybersecurity incidents. Minimize damage with our professional instant response service — ex…
ViewHarvest now, decrypt later already affects data encrypted today. Cryptographic inventory, assessment by lifetime and hy…
ViewSignatures catch what is known. NeoI catches what deviates from your normal state — including attackers who use nothing…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.