Skip to content
Atlas
GET IN TOUCH

C://SECURE33Network Security

Not one flat
network.

Network security covers firewalls, segmentation, secure remote access, and wireless, arranged so that a compromise in one place cannot reach everything else. It is for organisations whose network grew by addition, where everything can still reach everything.

A flat network means one compromised device has line of sight to every other one. Most networks are flat.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Firewall management

    Rules reviewed, documented, and owned, with the ones added temporarily in 2019 finally removed.

  • 02

    Segmentation

    Guests, staff, servers, cameras, and payment devices separated, so an incident is contained by design rather than by luck.

  • 03

    Secure remote access

    Access tied to identity and device health rather than to a shared VPN password that four former staff still know.

  • 04

    Wireless security

    Separate networks for corporate, guest, and devices, each with controls that suit what is on them.

Baseline, remediate, monitor, evidence

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Week 1

    Baseline

    What is configured today, measured against a recognised standard, with gaps ranked by real-world risk rather than vendor score.

  2. 02Weeks 2 – 6

    Remediate

    Gaps closed in the order that buys the most safety fastest, with each change recorded.

  3. 03Ongoing

    Monitor

    Tuned to your environment so alerts mean something, and every alert has a named owner.

  4. 04Quarterly

    Evidence

    A written report you can hand to an insurer, a customer, or your board without translating it first.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is network security?

Network security covers firewalls, segmentation, secure remote access, and wireless, arranged so that a compromise in one place cannot reach everything else. It is for organisations whose network grew by addition, where everything can still reach everything.

02What does network segmentation mean, and why does it matter?

It means dividing your network into zones that cannot freely reach each other, so the guest Wi-Fi, the office computers, the servers, and the security cameras are separated. It matters because attacks spread sideways. Without segmentation, one compromised laptop can reach your file server and your backups. With it, the same compromise is contained to one zone while you deal with it.

03Is our firewall enough on its own?

It is necessary and it is no longer sufficient. A firewall controls traffic at the boundary, and most modern attacks do not come through the boundary. They arrive in an email, or through a legitimate login from somewhere else, both of which the firewall has no reason to stop. It is one layer of several rather than the answer.

04Should staff and guests be on the same Wi-Fi network?

No, and this is one of the cheapest improvements available to most businesses. A guest network should reach the internet and nothing else. Anything less means a visitor’s infected laptop, or a contractor’s unmanaged machine, is sitting on the same network as your file server.

05Do we still need a VPN if everything is in the cloud?

Often not, and continuing to run one can make things worse rather than better. If your applications are cloud-based, access should be controlled by identity and device health at the application itself. A VPN whose only purpose is to put people inside the network reintroduces exactly the flat trust model you are trying to get away from. Where you still have on-premise systems, the VPN stays, but it should be tied to identity rather than to a shared password.

06How often should firewall rules be reviewed?

At least annually, and after any significant change. Firewall rule sets accumulate. Almost every one we review contains rules added for a project that finished years ago, for a supplier no longer engaged, or for a person who has left. Nobody removes them because nobody is sure what they do, which is precisely the argument for documenting them as they are added.

07How much does network security cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with network security?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver network security alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to move our whole IT contract to Atlas?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Can you support us if we are not based in Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who will we be dealing with when something actually happens?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What happens after it is in place?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services