On site, Southwestern Ontario

Know what is on your network. Stop what should not be.

A proper firewall, intrusion detection, and a record of every connection, for sites where a breach means ransomware, a stolen client list, or an insurer's questionnaire you cannot answer.

Sites where a breach costs more than the fix.

Ransomware and locked machines

One opened attachment should not be able to reach the server, the backups, and the shop floor at once.

Offices holding client data

Accounting, legal, consulting, and clinics. Anyone whose customers would be harmed if their files walked out the door.

Plants and warehouses

Machines, scanners, cameras, and controllers that were never designed to sit on the same network as the office Wi-Fi.

Multi-site and remote teams

More than one location, staff working from home, or contractors who need access to some things and nothing else.

Open tools, professional hardware, nothing rented.

Firewall and segmentation

OPNsense on Protectli hardware, a fanless appliance built for exactly this. The office, the guest Wi-Fi, the cameras, and the machines each get their own segment so one infected laptop cannot reach the rest.

Intrusion detection and prevention

Suricata inspects traffic against continuously updated threat rules and blocks known attacks, scanners, and malware call-homes as they happen.

Traffic records

Zeek keeps a plain-language log of every connection: which device talked to what, when, and how much. When something goes wrong you can answer the question instead of guessing.

Secure remote access

WireGuard VPN for staff and contractors, scoped to what each person needs. No ports left open to the internet for convenience.

Assess, design, install, watch.

  • Assessment. A site visit. I map what is on the network today and what is exposed. You get a written report either way.
  • Design. Segments, rules, and hardware sized to the site, with a fixed price before anything is ordered.
  • Install. Usually one cutover, after hours, with the old router kept on the shelf until everything is proven.
  • Monitoring. Rule updates, alert review, and a monthly summary of what the system caught. Optional, monthly.

What this is and is not.

It is a well-built perimeter and a record of what crosses it. I have run production systems for thirty years and secure my own network the same way.

It is not a compliance certificate or a promise that nothing can ever get in. If you need a formal penetration test or an audit letter, I will say so and point you to people who do that.

You own the hardware. If we part ways, the system keeps running and any competent network person can take it over.

Not sure what is on your network right now?

Most owners are not. Ask for an assessment and find out before someone else does.