Services

Every layer of the estate, one accountable team.

Four services that cover the physical layer, the security perimeter and the cloud edge, each delivered by the engineers who designed it.

01

Network & Security Consultation

Independent advisory for organisations running Cisco and Fortinet estates. We audit what is deployed, map it against how the business actually operates and return a prioritised plan that separates what must change now from what can wait. No product is recommended before the requirement is written down.

  • Infrastructure audit and gap analysis
  • Zero-trust segmentation design
  • Firewall policy review and hardening
  • SD-WAN architecture (Viptela, FortiSD-WAN)
  • Remote access design (AnyConnect, FortiClient)
  • IPS/IDS tuning and false-positive reduction
  • Wireless security and NAC strategy
  • High-level and low-level design documentation
AssessmentZero TrustSD-WANHardening

02

Managed Security

A security operations capability without the headcount. We run Splunk-based detection, own the alert queue around the clock and take incidents through containment, eradication and a written post-incident report. Findings close with evidence, not with a status change.

  • Splunk SIEM implementation and detection tuning
  • 24/7 monitoring, triage and escalation
  • Incident response and digital forensics
  • Firewall management (Cisco FTD/FMC, FortiGate)
  • Vulnerability assessment and penetration testing
  • Endpoint detection and response rollout
  • Security policy and standards development
  • POPIA and ISO 27001 evidence reporting
SIEMFTD/FMCFortiGateMXDR

03

Network Infrastructure

Everything that carries traffic, from the cable in the wall to the WAN overlay between sites. Campus, branch, wireless and SD-WAN are designed to stay up on their worst day, then managed as code so the estate stays consistent between projects. Building systems and IoT ride the same governed fabric rather than an unmanaged network beside it.

  • Enterprise LAN and WAN design
  • VLAN segmentation and inter-VLAN routing
  • Advanced routing: OSPF, EIGRP and BGP
  • High availability with HSRP/VRRP and LACP
  • Wireless design and site survey (Aruba, Cisco, Ubiquiti)
  • SD-WAN overlay design and staged rollout
  • Quality of service for voice and video
  • Ansible, pyATS and CI/CD change pipelines
  • Golden configuration and drift detection
  • Structured cabling design and certification
  • IoT segmentation, IP access control and surveillance
  • Monitoring with SNMP, NetFlow, Grafana, ThousandEyes
CiscoArubaMikroTikSD-WANAnsibleCabling

04

Microsoft 365 & Cloud

Microsoft 365 and public cloud governed as one identity model rather than two disconnected estates. Tenancy, conditional access and retention are configured against a written policy; Azure and AWS workloads are provisioned from Terraform so what runs in production matches what is committed to the repository. The administrators who inherit it are trained on it before we hand over.

  • Microsoft 365 tenant design and staged migration
  • Azure AD identity, conditional access and MFA
  • SharePoint Online intranet development
  • Teams deployment and governance
  • Power Automate and Power Apps development
  • Exchange Online and email security
  • Data loss prevention and Defender for Office 365
  • Azure virtual networks and ExpressRoute
  • AWS VPC architecture and workload migration
  • Hybrid connectivity and site-to-site VPN
  • Infrastructure as Code with Terraform
  • Cloud cost optimisation and disaster recovery
AzureAWSAzure ADSharePointTerraform

How We Engage

Three ways to work with us.

Scope, ownership and reporting are agreed before work starts, so the commercial model matches the outcome you need.

Project

Fixed-scope delivery

A defined build with a design pack, an agreed acceptance test and handover documentation. Priced on scope, not on hours.

DesignBuildHandover

Managed

Ongoing operations

Monitoring, patching, incident response and monthly reporting under an SLA with defined response and resolution targets.

24/7 SOCSLAReporting

Advisory

Retained engineering

A standing block of senior engineering time for design reviews, escalations and roadmap work, drawn down as you need it.

ReviewEscalationRoadmap

Ready When You Are

Not sure which service you need?

Send us the environment and the constraint. We will tell you what we would do first and what we would leave alone.