Perimeter
Firewall · DNS · Email
Email, DNS and the network edge are the three surfaces an attacker touches first. They're also the cheapest to protect well — most of it is correct configuration, not expensive products.
Attacks on the perimeter
Three classic techniques, all still very effective against anyone who hasn't set up the right defences.
Email spoofing
Without SPF, DKIM and DMARC, anyone can send email pretending to be your domain — to your customers or to your own staff.
Warning signs:Customers receiving fake invoices in your name; your email landing in spam.
DNS hijacking
The attacker changes where your domain points and diverts visitors or email to their own servers.
Warning signs:Site down or altered, email disappearing, certificate warnings.
Man-in-the-middle
On a network without segmentation or encryption, traffic can be intercepted and read — passwords included.
Warning signs:Wi-Fi shared with guests, connections without HTTPS, remote access without a VPN.
How it's closed
Correct, verifiable configuration with no friction for the people using the systems every day.
SPF · DKIM · DMARC
The three records that prove an email is really yours, on a reject policy.
Protected DNS
Locked records, DNSSEC where available and change monitoring.
Network segmentation
Guests, devices and servers kept apart — a problem in one doesn't spread to the rest.
Encryption in transit
HTTPS on everything public and a VPN for remote access.
Is your perimeter properly closed?
We check email, DNS and network and leave everything configured the way it should be.



