Cybersecurity and Firewalls

Firewall policy, segmentation and endpoint protection designed around how your organisation actually operates.

A rack-mounted firewall appliance seen close up in a dark server rack — a 1U chassis with a row of ethernet and fibre ports and small status LEDs along the front.
Firewall and segmentation reference designInternet traffic reaches a next-generation firewall that enforces policy between zones. Published services sit in a DMZ; users, servers and CCTV each occupy a separate internal segment so a compromise in one does not reach the others. Endpoints run managed protection, backups are held apart from the production segment, and firewall and endpoint logs are retained for review.DMZINTERNAL SEGMENTSDeniedINTERNETUntrustedFIREWALLPolicy and inspectionPUBLISHEDExternally reachableUSER SEGMENTManaged endpointsSERVER SEGMENTLine-of-businessCCTV SEGMENTIsolated by policyBACKUPHeld separately

Reference system

A trust-zone diagram showing internet, firewall, users, servers, CCTV, guests, remote access and backups.

Symptoms

When this matters

If any of these describe your environment, this is the conversation to have.

  1. 01The current firewall was sized for a smaller team or was never properly configured.
  2. 02Guest Wi-Fi, CCTV and core business systems all sit on the same trust zone.
  3. 03Remote staff connect back to the office without a defined secure-access method.
  4. 04Backup exists, but nobody has tested whether a restore actually works.
  5. 05Security subscriptions and licence renewals are tracked by nobody in particular.

Scope

What KINNEX delivers

Security is treated as an architecture decision, not a single appliance. KINNEX designs trust zones around how users, servers, CCTV and guests actually move through your network, so a compromise in one area does not become a compromise of everything.

  • Next-generation firewall sizing, policy, web filtering, application control, VPN and reporting.
  • Network segmentation for users, servers, CCTV, guest Wi-Fi, OT or sensitive systems.
  • Endpoint protection, secure configuration, patching and identity controls.
  • ZTNA or secure remote access, email security, backup and recovery readiness.
  • Security posture reviews, incident readiness and remediation planning.
  • Licensing and renewal visibility — an active SOC or round-the-clock monitoring is only implied when contracted and staffed.

Capability catalogue

Everything this covers

157 capabilities, scoped, sourced and delivered under one contract. Search for the exact term you use.

Assess and audit20

Know where you stand before you spend. Scope, test, report, remediate.

  • Vulnerability assessment (VA): network, web, API, mobile and cloud configuration
  • Authenticated and unauthenticated scanning, with risk-rated reports
  • Penetration testing (VAPT): black-box, grey-box and white-box
  • Internal and external perimeter penetration testing
  • Web application, mobile app and API penetration testing (OWASP Top 10, ASVS)
  • Wireless penetration testing and rogue access point hunts
  • Red team and assumed-breach exercises; purple-team collaboration
  • Social engineering and phishing simulation
  • Active Directory and Entra ID security assessment
  • Secure configuration review against CIS Benchmarks
  • Firewall rule-base audit and cleanup
  • Source-code review: SAST, DAST and software composition analysis
  • Cloud security posture review (AWS, Azure, GCP) and tenant hardening
  • Architecture review, threat modelling (STRIDE, PASTA) and zero-trust readiness
  • Security maturity assessment against NIST CSF 2.0 and CIS Controls v8
  • Third-party and vendor risk assessment
  • Business impact analysis and risk register
  • Mock audits and audit-evidence preparation
  • Virtual CISO (vCISO) advisory and board-level reporting
  • Policy authoring: information security, acceptable use, access, BYOD, incident response, retention
Governance, risk and compliance (GRC)18

Designs and procedures aligned to the frameworks your regulator, customer or auditor asks for.

  • ISO/IEC 27001 ISMS implementation and readiness
  • ISO/IEC 27701 privacy and ISO 22301 business continuity readiness
  • SOC 2 Type I and Type II readiness and audit support
  • PCI-DSS scoping, segmentation and remediation
  • HIPAA safeguards for health data and PHI handling
  • GDPR gap analysis and data-protection practices
  • India DPDP Act 2023 readiness: notices, consent, data mapping, breach process
  • IT Act and IT Rules compliance practices
  • CERT-In directions: incident reporting readiness, log retention and time synchronisation
  • RBI cyber-security framework and IT governance directions
  • SEBI CSCRF and IRDAI information-security guidelines
  • NIST CSF, NIST SP 800-53 and CIS control mapping
  • IT general controls (ITGC) and internal-audit support
  • Record of processing activities (ROPA) and data-protection impact assessments
  • DPO-as-a-service and privacy operations
  • GRC platform setup and audit-evidence automation
  • Cyber-insurance readiness: control evidence and questionnaires
  • Sector regulator and customer-audit response support
Network and perimeter security19

Next-generation firewalls and the controls around them, tuned to your applications.

  • Next-generation firewall (NGFW) and unified threat management (UTM)
  • Application control, intrusion prevention (IPS, IDS) and anti-malware
  • SSL and TLS inspection and certificate management
  • URL, web and DNS filtering and secure web gateway (SWG)
  • Sandboxing for unknown files and zero-day threats
  • Site-to-site IPsec and remote-access SSL VPN
  • Zero-trust network access (ZTNA), SASE and SSE
  • Secure SD-WAN for multi-site networks
  • High availability: active-active and active-passive clusters
  • Rule-base optimisation, shadow-rule removal and change control
  • Network segmentation and micro-segmentation
  • DMZ design, jump hosts and bastion access
  • Network access control (NAC) and 802.1X
  • DDoS protection and web application firewall (WAF)
  • Network detection and response (NDR) and IDS tooling
  • Wireless intrusion detection and prevention
  • Deception technology and honeypots
  • Threat-intelligence feeds and geo-blocking
  • Vendor and third-party remote access with session control
Endpoint and server protection15
  • Endpoint protection platform (EPP) and next-generation antivirus
  • Endpoint detection and response (EDR), XDR and MDR
  • Ransomware protection and rollback
  • Application control and allow-listing
  • Device and USB control, and removable-media policy
  • Disk encryption: BitLocker, FileVault and Linux LUKS
  • Patch management and endpoint vulnerability management
  • Local-administrator removal and LAPS
  • Server hardening to CIS Benchmarks
  • Workload protection for virtual and cloud servers (CWPP)
  • File-integrity monitoring (FIM)
  • Anti-exploit, browser isolation and sandboxing
  • Mobile threat defence for Android and iOS
  • VDI and remote-desktop security
  • Centralised management console and policy baselines
Email, web and data protection15
  • Email security gateway: anti-spam, anti-phishing and anti-malware
  • Sandboxing, URL rewriting and time-of-click protection
  • Business email compromise (BEC) and impersonation defence
  • SPF, DKIM and DMARC setup and monitoring
  • Email encryption (TLS, S/MIME), archiving and journaling
  • Data loss prevention (DLP): endpoint, network, email and cloud
  • OCR and content inspection, with policy-based controls
  • Data discovery, classification and labelling
  • Rights management (IRM) and secure document sharing
  • Cloud access security broker (CASB) and SaaS controls
  • Database activity monitoring, masking and tokenisation
  • Encryption at rest and in transit; key management and HSMs
  • Secrets management and certificate lifecycle
  • Insider-risk monitoring and user-behaviour analytics (UEBA)
  • E-discovery and legal-hold support
Identity and access management13
  • Single sign-on (SSO) with SAML and OIDC
  • Multi-factor authentication: authenticator apps, push, FIDO2, passkeys, hardware tokens
  • Adaptive and conditional access policies
  • Privileged access management (PAM): vaulting, rotation, session recording
  • Just-in-time (JIT) and just-enough access
  • Identity governance: joiner-mover-leaver, access reviews, role design (RBAC, ABAC)
  • Active Directory cleanup, tiering and hardening
  • Entra ID, Okta and Google identity configuration
  • Self-service password reset and passwordless sign-in
  • Smart cards, PKI and certificate-based authentication
  • Service-account and machine-identity management
  • Privileged remote access for vendors and contractors
  • Directory services: LDAP, Kerberos and federation
Security operations and response19

Detection and response run as a managed service under an SOP and an SLA agreed with you. Coverage hours depend on the client and the contract.

  • Security operations centre (SOC) monitoring with L1, L2 and L3 analysts
  • Managed detection and response (MDR)
  • SIEM: log ingestion, parsing, correlation rules and use-case authoring
  • SOAR playbooks and automated response
  • MITRE ATT&CK-aligned detection coverage
  • Alert triage, escalation and tuning
  • Threat intelligence: IOCs, TTPs and sector feeds
  • Hypothesis-driven threat hunting and IOC sweeps
  • Incident response: preparation, containment, eradication, recovery, lessons learned
  • Incident-response retainer with pre-agreed hours
  • Digital forensics: disk, memory, mobile, email and cloud
  • Malware analysis and chain-of-custody handling
  • Vulnerability-management programme: scan, prioritise (CVSS, EPSS), remediate, verify
  • External attack-surface management and dark-web monitoring
  • Breach and attack simulation and purple-team testing
  • Phishing takedown and brand protection
  • Security metrics: mean time to detect and respond, trends and dashboards
  • Monthly health reports and quarterly review meetings
  • Log retention and time-synchronisation practices designed for CERT-In directions
Cloud, application and DevSecOps10
  • Cloud security posture management (CSPM) and CNAPP
  • Container and Kubernetes security
  • Infrastructure-as-code scanning and policy-as-code
  • API security and web application firewall
  • CI/CD pipeline security: SAST, DAST, SCA and SBOM
  • Secrets scanning and rotation
  • SaaS security posture management (SSPM) and shadow-IT discovery
  • Microsoft 365 and Google Workspace hardening and secure-score improvement
  • Cloud logging, monitoring and data-residency controls
  • Secure software development lifecycle (SSDLC) advisory
OT, IoT and surveillance-network security8
  • IT and OT segmentation using the Purdue model
  • Industrial firewalls and unidirectional gateways
  • Passive ICS and SCADA monitoring and asset discovery
  • IEC 62443-aligned zone and conduit design
  • Vendor remote access through jump hosts, with session recording
  • Air-gap and removable-media hygiene
  • CCTV, access-control and building-system network isolation
  • Medical and IoT device segmentation
Resilience and recovery6
  • Backup and business-continuity and disaster-recovery (BCDR) design
  • Immutable and air-gapped backups, with offsite and cloud tiers
  • RPO and RTO targets and commitments
  • Ransomware recovery planning and clean-room restores
  • Disaster-recovery drills and playbook authoring
  • Business-continuity plan and crisis-communication templates
Awareness, training and exercises6
  • Phishing simulations with follow-up training
  • Role-based security awareness modules
  • Tabletop exercises for leadership and IT
  • Executive and board briefings
  • Secure-coding training for developers
  • Onboarding and offboarding security hygiene
Managed security operations8
  • Firewall management: policy lifecycle, rule audits, firmware updates
  • EDR, email-security and DLP platform management
  • Quarterly vulnerability scans and penetration tests
  • Configuration backup and change management
  • Licence, subscription and renewal tracking
  • OEM case handling and hardware replacement
  • Escalation and reporting under an agreed SOP and SLA
  • Annual security review and roadmap

The site, in 3D

A perimeter that inspects everything coming in

Next-generation firewalls at the edge, segmented networks inside, and monitoring that does not sleep.

  • Firewall perimeter
  • Segmentation
  • Threat inspection
  • Monitoring

Real-time 3D illustration of a typical site, not a specific client project.

Use cases

Where this shows up

Typical situations that lead an organisation to this work.

01

A business whose firewall has never been reviewed since initial installation.

02

An organisation isolating CCTV and guest Wi-Fi from core business systems for the first time.

03

A team moving from ad-hoc remote access to a managed secure-access solution.

Delivery method

How the work runs

Architecture before equipment. Validation before handover.

  1. Stage 01 of 6

    Assess

    Posture review across network, endpoints, remote access and backup readiness.

  2. Stage 02 of 6

    Design

    Firewall policy, segmentation plan and remote-access architecture.

  3. Stage 03 of 6

    Implement

    Firewall deployment, endpoint rollout and secure remote-access configuration.

  4. Stage 04 of 6

    Validate

    Policy testing, segmentation verification and backup restore tests.

  5. Stage 05 of 6

    Document

    Trust-zone diagram, policy reference and renewal calendar.

  6. Stage 06 of 6

    Support

    Ongoing licence and renewal management, plus periodic posture reviews.

How we take this on

One contract. The right specialist for every part

Your project is wider than any single team. We scope all of it, source all of it and carry the responsibility for all of it.

  1. 01

    Scope

    We survey, size and specify against standards and your operating reality, not against a brochure.

  2. 02

    Source

    Any make, any model, from the manufacturer, distribution or registered importers. GST-compliant invoicing, warranty and returns handled for you.

  3. 03

    Deliver

    KINNEX engineers do the work we do every day. Where a job needs a specialist, we bring in the right expert team as a sub-order under your single contract.

  4. 04

    Own

    One scope, one SOP, one SLA and one point of accountability, whoever is on site.

Standards and terms

Standards we design to, and the terms you will hear

Specifications are written against recognised standards. Here is the vocabulary, in plain language.

  • ISO/IEC 27001, 27002, 27005, 27017, 27018, 27701
  • ISO 22301 (business continuity)
  • NIST CSF 2.0
  • NIST SP 800-53, 800-61, 800-115, 800-207
  • CIS Controls v8 and CIS Benchmarks
  • MITRE ATT&CK
  • OWASP Top 10 and ASVS
  • PCI-DSS
  • SOC 2 (AICPA Trust Services Criteria)
  • HIPAA Security Rule
  • GDPR
  • India DPDP Act 2023
  • IT Act 2000 and IT Rules
  • CERT-In directions (2022)
  • RBI cyber-security framework
  • SEBI CSCRF
  • IRDAI information-security guidelines
  • IEC 62443 (industrial security)
  • ITIL 4 service management
  • CVSS and EPSS scoring
VA vs VAPT
A vulnerability assessment finds and ranks weaknesses. Penetration testing goes further and tries to exploit them, the way an attacker would.
Red, blue and purple team
Red teams attack, blue teams defend, purple teams work together so every attack improves a detection.
NGFW
A firewall that understands applications, users and threats, not just ports and addresses.
EDR / XDR / MDR
Detection and response on endpoints, extended across email, network and cloud, or run for you as a managed service.
ZTNA
Zero-trust network access: each user and device is verified for each application, instead of trusting anyone inside the network.
SASE / SSE
Security services delivered from the cloud, close to users and branches, replacing a stack of appliances.
SIEM and SOAR
SIEM collects and correlates logs to detect threats. SOAR automates the response with playbooks.
SOC
Security operations centre: the team and tooling that watch for threats and respond. Coverage hours are agreed per contract.
DLP
Data loss prevention: rules and tools that stop sensitive data leaving through email, USB, cloud or print.
PAM
Privileged access management: controlling, recording and rotating the most powerful accounts.
MFA and passkeys
A second proof of identity beyond a password. Passkeys and hardware keys resist phishing best.
SPF, DKIM, DMARC
Three DNS-based checks that prove an email really came from your domain, and tell receivers what to do with fakes.
CSPM / CNAPP
Tools that continuously check cloud accounts for misconfiguration and risk.
CVSS and EPSS
Scores for how severe a vulnerability is, and how likely it is to be exploited. Used together to decide what to patch first.
MTTD and MTTR
Mean time to detect and to respond: the two numbers that show whether security operations are improving.
Purdue model
A layered way to separate factory-floor networks from business IT, so a breach in one does not reach the other.
BEC
Business email compromise: fraud using a convincing email, often impersonating a director or supplier, to move money.
Immutable backup
A backup that cannot be altered or deleted for a set period, even by an administrator, which defeats ransomware.
RPO and RTO
How much data you can afford to lose, and how long you can afford to be down. They set the backup and recovery design.
IR retainer
A pre-agreed arrangement with an incident-response team and a pool of hours, so help starts without procurement delay.
SOP and SLA
The documented procedures for running security operations, and the response and reporting targets agreed for them.

Brands

Any make. Sourced, supplied and supported

We specify against your requirement and standards, then source the right product from the manufacturer, distribution or registered importers. Delivered, installed and supported under one contract.

Firewalls and network security

Next-generation firewalls, UTM, VPN, secure web and zero trust access.

  • Sophos
  • Fortinet
  • Palo Alto Networks
  • WatchGuard
  • Barracuda Networks
  • Cisco Secure
  • Juniper Networks
  • SonicWall
  • Cloudflare
  • pfSense
  • OPNsense
  • Forcepoint
  • Netgear
  • Huawei
  • Ubiquiti
  • Tailscale
  • OpenVPN
  • WireGuard
Show 14 more brands
  • Array Networks
  • Kerio
  • Cisco Umbrella
  • Akamai
  • Imperva
  • F5
  • Radware
  • Check Point
  • Zscaler
  • Cato Networks
  • Netskope
  • Versa Networks
  • Stormshield
  • Untangle

Endpoint protection, EDR and XDR

Antivirus, EDR, XDR, MDR and ransomware protection.

  • SentinelOne
  • CrowdStrike
  • Sophos
  • Trend Micro
  • Microsoft Defender
  • Bitdefender
  • ESET
  • Kaspersky
  • Symantec
  • Trellix
  • VMware Carbon Black
  • Malwarebytes
  • Acronis
  • McAfee
  • Webroot
  • Broadcom
  • Elastic
  • Cisco Secure Endpoint
Show 10 more brands
  • Avast
  • G DATA
  • Quick Heal
  • Seqrite
  • Cybereason
  • Cynet
  • Huntress
  • Arctic Wolf
  • Tanium
  • F-Secure

Email security and data loss prevention

Anti-phishing, sandboxing, encryption, archiving and DLP.

  • Proofpoint
  • Barracuda Networks
  • Sophos
  • Forcepoint
  • Trellix
  • Symantec
  • Microsoft Purview
  • Trend Micro
  • Cisco Secure Email
  • Google Workspace
  • Cloudflare
  • Mimecast
  • Netskope
  • Safetica
  • Digital Guardian
  • Zscaler
  • Ironscales
  • Abnormal Security
Show 9 more brands
  • KnowBe4
  • Egress
  • Virtru
  • Varonis
  • Titus
  • Seclore
  • Cyberhaven
  • Tessian
  • Hornetsecurity

Identity, MFA and privileged access

SSO, MFA, IAM, password vaulting and privileged session control.

  • Okta
  • BeyondTrust
  • ARCON
  • Microsoft Entra
  • Ping Identity
  • Thales
  • Entrust
  • Auth0
  • OneLogin
  • Keeper
  • 1Password
  • Bitwarden
  • LastPass
  • RSA
  • Yubico
  • Teleport
  • Zoho Vault
  • Google Authenticator
Show 13 more brands
  • Microsoft Authenticator
  • CyberArk
  • Ekran System
  • Duo Security
  • ForgeRock
  • JumpCloud
  • Delinea
  • HashiCorp Vault
  • SailPoint
  • Saviynt
  • Imprivata
  • StrongDM
  • ManageEngine PAM360

SIEM, SOC, vulnerability and testing tools

Log analytics, detection, vulnerability management, penetration testing and forensics.

  • Splunk
  • Microsoft Sentinel
  • IBM QRadar
  • Elastic
  • Wazuh
  • Graylog
  • Sumo Logic
  • Tenable
  • Qualys
  • Nessus
  • Burp Suite
  • Metasploit
  • Wiz
  • Google Chronicle
  • Shuffle
  • Autopsy
  • Wireshark
  • Kali Linux
Show 23 more brands
  • OWASP ZAP
  • Checkmarx
  • Snyk
  • Mandiant
  • LogRhythm
  • Exabeam
  • Rapid7
  • OpenVAS
  • Cobalt Strike
  • Nmap
  • Prisma Cloud
  • Darktrace
  • TheHive
  • MISP
  • Velociraptor
  • Volatility
  • FTK
  • EnCase
  • Acunetix
  • Invicti
  • SonarQube
  • Recorded Future
  • Group-IB

Product names, logos and brands are property of their respective owners and are used for identification only. Don't see what you need? We can usually source it, including through registered importers.Ask us.

Technology fit

The technology categories this work draws on.

  • Next-generation firewall (NGFW) platforms
  • Endpoint protection and patch management
  • ZTNA and VPN secure remote-access gateways
  • Backup and recovery platforms

Questions

Frequently asked questions

By throughput needs, user and device count, VPN concurrency and the number of segments required — sized from your actual environment, not a generic recommendation.

Policy is tuned to your traffic, segments are defined, and reporting is set up — a firewall is a starting point for ongoing policy management, not a one-time appliance swap.

Yes, through VLAN segmentation and firewall policy that keeps each traffic class on its own trust zone.

Scope is defined per contract — from basic alerting to more active monitoring — and KINNEX will not describe a service as round-the-clock SOC coverage unless it is actually staffed and contracted that way.

Licence terms and renewal dates are tracked centrally and flagged ahead of expiry, so protection does not lapse silently.

Review your security architecture

Tell us the site, the constraint or the outcome you need, and we will come back with the right next step.