Services

Security Audit and Assessment


Many smaller companies have not had an independent audit or assessment completed. This could be from quick growth, lack of time, lack of funding or other aspects. Audits tend to be more in depth tests against your exsisting infrastructure which can involve penetration "pen testing" while assessments tend to be based on more of an overview of your business. In either case I'm here to help and guide you through these tasks. These audits or assessments can also be stored on my independent site for referencing by 3rd parties that might want to do business with you but need an independent hands-on first.

Security Programs


Do not be scared to approach having a security program. There are simple steps and templates that can get you started. You do not have to start full-blown with a complex security template. In my opinion starting early, on a smaller scale, reaps benefits by preparing you for when you really need an intensive program. There are many basics that can be rolled into a security program to start you on the right track. Are your passwords complex, at least 8 characters, or preferably 10 and require to have the user reset them quarterly? Do you have a data and media destruction policy? Are your systems set up for proper authentication so that only those authorized have disclosure of your information?

Get on the right track and get some of these simple basics in place. It is fathoms easier to start with a small skeleton to build larger. Do not be caught in the mess when compliance does come along and you have not done any preliminary planning.

Penetration and External Audit


There are a few ways to do an internal or external network test of your business. These are usually done at both the assessment and audit step, and after putting in security controls. It is important to test both internally and externally due to the fact that even though you might have robust external protection, most attacks come from the inside. This could be from a disgruntled employee, to a external exploit that brought a botnet into your system which is now using internal resources.

Networking Help


Do you have your network carved up in various crazy subnets? Do you have a single login for all devices? I've got this firewall device but where do I put it? All valid questions, and I can help with answers. Due to expansion of small businesses, a significant amount of the time is getting things up and running without having the time to do a proper design. At the end of the day when you have your crazy mess it can become overwhelming to tackle it especially when you need to achieve that 99.999% uptime. Having been exactly in this situation, I can help you at least quantify the confusion and come up with organized steps and advice how to get back on the right track.