Loading

Layer 7 protection. Documented compliance.

We do not filter ports and IP addresses alone. Each control interrupts a concrete stage of the attack, and the measures become verifiable evidence for the obligations NIS2 legislation places on your organisation.

The attack cycle

Four phases, each interrupted by a different control.

  1. Reconnaissance

    The target is profiled from public addresses and information exposed through unencrypted DNS. Encrypted resolution and a reduced footprint make enumeration difficult.

    • Secure DNS
    • DNSSEC
    • Reduced footprint
  2. Scanning

    Open ports are searched for in the range 1–65535. The controls respond with a silent drop, returning nothing useful to the attacker.

    • Silent drop
    • Stateful filtering
    • Geo-blocking
  3. Exploitation

    The attacker exploits a vulnerable service, attempts brute-force or credential stuffing and delivers malicious payloads. The pattern is identified and the source blocked.

    • Layer 7 inspection
    • Behavioural detection
    • Exponential ban
  4. Post-exploitation

    Persistence, Command and Control, and lateral movement towards critical data. This stage is limited by network segmentation and continuous monitoring.

    • Segmentation
    • Monitoring
    • Egress filtering

What we offer

Five areas of work, each delivering the document or the control the law requires, not just a recommendation.

Deliverables, not recommendations

Each stage is clearly delimited, produces a required document and prepares the next step.

Compliance and documentation

Applicability file

An inventory of services, mapping to the annexes, the entity type and the article 9 analysis, with a documented conclusion.

Notification to DNSC

Standard form, supporting documents, electronic signature and correspondence with the competent authority.

Risk register

The risk level in the national platform, the impact of disruption and a register kept up to date.

Roadmap

Maturity self-assessment, gap analysis and remediation priorities, with deadlines approved by management.

Technical measures and operations

Layer 7 firewall

Our own platform installed at a single point of control, through which all traffic between the internet and the internal network passes.

Segmentation and VLANs

Isolated zones that limit lateral movement and the blast radius of a compromise.

Continuous monitoring

Behavioural detection, continuous monitoring and automatic blocking of sources showing attack patterns.

Incident response

Containment, eradication and recovery, with reporting to DNSC within the statutory 24 hours and periodic restore tests.

Not sure whether the law applies to you?

The applicability analysis answers that question and stands as evidence whatever the conclusion. Falling outside the law is not assumed: it has to be documented.