Firewall Management01 / 08
Next-generation firewall
Design, deploy, and manage Palo Alto, Fortinet, Cisco Meraki or Firepower, or pfSense / OPNsense for SMB environments. Rule hygiene, app-ID tuning, signature updates, signed change control, and 24x7 monitoring. We handle the vendor — you read the quarterly report.
PAN-OS · FortiOS · Meraki · Firepower · pfSense
Network Segmentation02 / 08
VLAN + microsegmentation
Tiered VLAN architecture between trust zones — users, servers, printers, IoT, door controllers, cameras, guest — plus identity-based microsegmentation inside production where a flat L2 would otherwise give any compromise total reach. Diagrams delivered; configs live in your repo.
802.1Q · 802.1X · pxGrid · Illumio-class tooling
Zero Trust Architecture03 / 08
ZTA, NIST SP 800-207
Identity-based segmentation, continuous authentication, least-privilege authorization, and device-posture enforcement. Deployed in the five phases NIST describes — discovery, identity foundation, policy engine, enforcement, iteration. Nothing breaks on day one; nothing stays the same by month six.
NIST SP 800-207 · Entra CA · Okta · Duo
Remote Access04 / 08
VPN modernization + ZTNA
Site-to-site IPSec for branch and OT connectivity — kept where genuinely needed. Remote-user migration from traditional VPN concentrators to ZTNA brokers (Cloudflare Access, Zscaler Private Access, Twingate, Tailscale) for per-application, identity-aware access without inbound port exposure.
Cloudflare · Zscaler · Twingate · Tailscale · IPSec
Endpoint Hardening05 / 08
CIS + STIG baselines
CIS Benchmark Level 1 or Level 2 baselines for Windows, macOS, and Linux endpoints; DISA STIG where regulated work requires it. Deployed via Intune, Jamf, Kandji, Ansible, or Puppet depending on platform, with drift monitored and documented exceptions tracked.
CIS · DISA STIG · Ansible · Puppet · Intune CIS templates
MDM / UEM06 / 08
Mobile + endpoint management
Microsoft Intune for Windows-heavy environments, Jamf Pro or Kandji for Apple fleets, Hexnode for mixed estates. Enrollment flows, compliance policies, conditional access integration, kiosk and shared-device configurations, and a quarterly compliance posture review.
Intune · Jamf Pro · Kandji · Hexnode
Patch Orchestration07 / 08
Managed patch rings
Windows via Intune + WSUS or Autopatch; Mac via Kandji or Jamf; Linux via Ansible or distribution-native tooling. For smaller fleets, Automox, NinjaOne, or PDQ Deploy. Every ring has a test cohort, a production cohort, a rollback plan, and a monthly report on actual coverage.
Intune · Kandji · Jamf · Automox · NinjaOne
DNS · WAF · BYOD · MTD08 / 08
Edge + BYOD + mobile
DNS filtering at the edge (Cisco Umbrella, NextDNS, DNSFilter), WAF in front of public web (Cloudflare, AWS WAF, Imperva), IDS / IPS on segment boundaries, MAM-without-MDM containerization for BYOD and contractors, and mobile threat defense (Lookout, Zimperium) where risk warrants.
Umbrella · NextDNS · Cloudflare · Lookout · Zimperium