Infrastructure
IT security
Closing the doors left open by default and preparing the recovery — most incidents we see required no skill at all from whoever caused them.
Almost every incident we handle has the same origin: a reused password, an access never revoked from somebody who left, equipment left on factory settings, an attachment opened. These are not sophisticated attacks; they are doors that were open.
The practical consequence is encouraging: most of the risk reduces with simple, inexpensive measures. Named accounts, a second authentication factor, updates, rights limited to what is necessary, and a backup ransomware cannot reach.
So we do not sell a security product. We close what is open, in order of risk, and we write down what remains. A business that knows precisely what it has not covered is in a far better position than one that believes it has covered everything.
The second half of the work is recovery. The question is not only "how do we avoid this" but "what do we do if". Who gets called, what gets unplugged, how work restarts and from which copy — decided beforehand, not during.
What we usually find
- The same password is used for email, the server and the bank.
- A former employee still has access to your tools.
- Your workstations have not been updated in a long time.
- Nobody knows what to do if a machine displays a ransom demand.
What changes
The obvious doors closed
Accounts, access and updates handled first, because that is how most incidents get in.
A backup out of reach
A copy malicious encryption cannot modify, which turns a catastrophe into an interruption.
A written course of action
Who calls whom, what to unplug, how to restart — decided calmly rather than in a panic.
What you get
Named accounts
One account per person, with the rights needed and nothing more, and immediate removal on departure.
A second factor
Enabled on mail and sensitive access, where it prevents the most incidents for the least effort.
Updates kept up
Systems and network equipment maintained, because most intrusions exploit something already known.
A protected backup
A copy that cannot be written to from the network, tested by restoring.
A short awareness session
A session with your teams about what actually happens, not a theoretical course.
A response plan
What to do in an incident, written on one page and known to more than one person.
Is this the right fit for you?
This is for you if
- You hold customer data, banking access, or documents you cannot lose.
- Several people use the same tools and sometimes the same accounts.
- You would rather close open doors than buy a product.
This is not for you if
- You are seeking a certification. That is different work, heavier and more formal.
- You want software that solves everything. None does, and selling that would be dishonest.
- You do not intend to apply any password rule. Most of the benefit disappears.
What we commit to
We write down what stays open
No report will say you are protected. It will say what is covered, what is not, and why.
Free before paid
We start with what costs nothing — accounts, rights, second factor, updates — before proposing a purchase.
You keep the administrator access
We never hold exclusive access to your own infrastructure.
What we find most often here
Shared accounts are the first finding. One mail or administration session used by three people makes it impossible to know who did what, and impossible to revoke one access without blocking everybody. It is as free to fix as it is common.
Network equipment left on factory passwords comes next. A router or camera installed by a third party and never reconfigured is a permanent door, and they are particularly frequent on installations built by a succession of suppliers.
Finally, unpatched software is the norm rather than the exception, often for a legitimate reason: a business application that only works with an old version. In that case the right answer is to isolate rather than ignore, and that can be designed.
Frequently asked questions
Is antivirus enough?
No, but it is part of the arrangement. Most incidents we handle come through an account or an access, not through a file antivirus would have seen.
What do we do in a ransomware incident?
Isolate the machines, do not pay, and restore from a copy out of reach. That is exactly why the protected backup is handled before everything else.
Does everything need replacing?
Rarely. Most of the gain comes from configuration and habits, not from a purchase. We always start with what costs nothing.
Will our staff accept the constraints?
If they are proportionate, yes. A rule that cannot be followed gets worked around, which is worse than no rule. We design what will actually be applied.
Are we a target?
Most attacks target nobody in particular: they sweep. Being small does not protect you, and that belief is usually what leaves the simplest measures undone.
What about former employees’ access?
Revoke it on the day they leave, which assumes knowing which accounts exist. Building that list is often the first concrete thing we do.
How to start
Tell us how many people use your tools, and whether any accounts are shared.
We come back with the list of open doors we found, ordered by risk, starting with the ones that close without buying anything.
What we have written on this subject
Notifying a breach within five days: the runbook, hour by hour
The clock starts the moment you know, not the moment you are certain. That is the only sentence in this article that changes anything.IT security: four stories, and how long it takes to notice
What costs is almost never the moment of the incident. It is the interval between it happening and somebody noticing.The phone is the workstation: what leaves with it
Orders arrive on a phone the business never bought. The number, the session left open, and what goes on the day somebody leaves.The regional audit divisions: what an inspection asks for, in what order
An inspection begins with a list of documents, not with a visit. There are four, they are known, and nothing stops you producing them first.Banking and finance: the complete file is your real product
What the customer dreads is not your rate, it is the second trip. And it is the only thing you control entirely.The business customer: what your branch has to organise differently
A company is not an individual with more money. Its file is permanent, and its decision is not taken at your desk.
Let us talk about your project
A free audit, no commitment: we look at your online presence and tell you what is holding it back.
- We write down what stays open
- Free before paid
- You keep the administrator access