Cybersecurity and Firewalls
Firewall policy, segmentation and endpoint protection designed around how your organisation actually operates.

Reference system
Symptoms
When this matters
If any of these describe your environment, this is the conversation to have.
- 01The current firewall was sized for a smaller team or was never properly configured.
- 02Guest Wi-Fi, CCTV and core business systems all sit on the same trust zone.
- 03Remote staff connect back to the office without a defined secure-access method.
- 04Backup exists, but nobody has tested whether a restore actually works.
- 05Security subscriptions and licence renewals are tracked by nobody in particular.
Scope
What KINNEX delivers
Security is treated as an architecture decision, not a single appliance. KINNEX designs trust zones around how users, servers, CCTV and guests actually move through your network, so a compromise in one area does not become a compromise of everything.
- Next-generation firewall sizing, policy, web filtering, application control, VPN and reporting.
- Network segmentation for users, servers, CCTV, guest Wi-Fi, OT or sensitive systems.
- Endpoint protection, secure configuration, patching and identity controls.
- ZTNA or secure remote access, email security, backup and recovery readiness.
- Security posture reviews, incident readiness and remediation planning.
- Licensing and renewal visibility — an active SOC or round-the-clock monitoring is only implied when contracted and staffed.
Capability catalogue
Everything this covers
157 capabilities, scoped, sourced and delivered under one contract. Search for the exact term you use.
157 capabilities
Assess and audit20
Know where you stand before you spend. Scope, test, report, remediate.
- Vulnerability assessment (VA): network, web, API, mobile and cloud configuration
- Authenticated and unauthenticated scanning, with risk-rated reports
- Penetration testing (VAPT): black-box, grey-box and white-box
- Internal and external perimeter penetration testing
- Web application, mobile app and API penetration testing (OWASP Top 10, ASVS)
- Wireless penetration testing and rogue access point hunts
- Red team and assumed-breach exercises; purple-team collaboration
- Social engineering and phishing simulation
- Active Directory and Entra ID security assessment
- Secure configuration review against CIS Benchmarks
- Firewall rule-base audit and cleanup
- Source-code review: SAST, DAST and software composition analysis
- Cloud security posture review (AWS, Azure, GCP) and tenant hardening
- Architecture review, threat modelling (STRIDE, PASTA) and zero-trust readiness
- Security maturity assessment against NIST CSF 2.0 and CIS Controls v8
- Third-party and vendor risk assessment
- Business impact analysis and risk register
- Mock audits and audit-evidence preparation
- Virtual CISO (vCISO) advisory and board-level reporting
- Policy authoring: information security, acceptable use, access, BYOD, incident response, retention
Governance, risk and compliance (GRC)18
Designs and procedures aligned to the frameworks your regulator, customer or auditor asks for.
- ISO/IEC 27001 ISMS implementation and readiness
- ISO/IEC 27701 privacy and ISO 22301 business continuity readiness
- SOC 2 Type I and Type II readiness and audit support
- PCI-DSS scoping, segmentation and remediation
- HIPAA safeguards for health data and PHI handling
- GDPR gap analysis and data-protection practices
- India DPDP Act 2023 readiness: notices, consent, data mapping, breach process
- IT Act and IT Rules compliance practices
- CERT-In directions: incident reporting readiness, log retention and time synchronisation
- RBI cyber-security framework and IT governance directions
- SEBI CSCRF and IRDAI information-security guidelines
- NIST CSF, NIST SP 800-53 and CIS control mapping
- IT general controls (ITGC) and internal-audit support
- Record of processing activities (ROPA) and data-protection impact assessments
- DPO-as-a-service and privacy operations
- GRC platform setup and audit-evidence automation
- Cyber-insurance readiness: control evidence and questionnaires
- Sector regulator and customer-audit response support
Network and perimeter security19
Next-generation firewalls and the controls around them, tuned to your applications.
- Next-generation firewall (NGFW) and unified threat management (UTM)
- Application control, intrusion prevention (IPS, IDS) and anti-malware
- SSL and TLS inspection and certificate management
- URL, web and DNS filtering and secure web gateway (SWG)
- Sandboxing for unknown files and zero-day threats
- Site-to-site IPsec and remote-access SSL VPN
- Zero-trust network access (ZTNA), SASE and SSE
- Secure SD-WAN for multi-site networks
- High availability: active-active and active-passive clusters
- Rule-base optimisation, shadow-rule removal and change control
- Network segmentation and micro-segmentation
- DMZ design, jump hosts and bastion access
- Network access control (NAC) and 802.1X
- DDoS protection and web application firewall (WAF)
- Network detection and response (NDR) and IDS tooling
- Wireless intrusion detection and prevention
- Deception technology and honeypots
- Threat-intelligence feeds and geo-blocking
- Vendor and third-party remote access with session control
Endpoint and server protection15
- Endpoint protection platform (EPP) and next-generation antivirus
- Endpoint detection and response (EDR), XDR and MDR
- Ransomware protection and rollback
- Application control and allow-listing
- Device and USB control, and removable-media policy
- Disk encryption: BitLocker, FileVault and Linux LUKS
- Patch management and endpoint vulnerability management
- Local-administrator removal and LAPS
- Server hardening to CIS Benchmarks
- Workload protection for virtual and cloud servers (CWPP)
- File-integrity monitoring (FIM)
- Anti-exploit, browser isolation and sandboxing
- Mobile threat defence for Android and iOS
- VDI and remote-desktop security
- Centralised management console and policy baselines
Email, web and data protection15
- Email security gateway: anti-spam, anti-phishing and anti-malware
- Sandboxing, URL rewriting and time-of-click protection
- Business email compromise (BEC) and impersonation defence
- SPF, DKIM and DMARC setup and monitoring
- Email encryption (TLS, S/MIME), archiving and journaling
- Data loss prevention (DLP): endpoint, network, email and cloud
- OCR and content inspection, with policy-based controls
- Data discovery, classification and labelling
- Rights management (IRM) and secure document sharing
- Cloud access security broker (CASB) and SaaS controls
- Database activity monitoring, masking and tokenisation
- Encryption at rest and in transit; key management and HSMs
- Secrets management and certificate lifecycle
- Insider-risk monitoring and user-behaviour analytics (UEBA)
- E-discovery and legal-hold support
Identity and access management13
- Single sign-on (SSO) with SAML and OIDC
- Multi-factor authentication: authenticator apps, push, FIDO2, passkeys, hardware tokens
- Adaptive and conditional access policies
- Privileged access management (PAM): vaulting, rotation, session recording
- Just-in-time (JIT) and just-enough access
- Identity governance: joiner-mover-leaver, access reviews, role design (RBAC, ABAC)
- Active Directory cleanup, tiering and hardening
- Entra ID, Okta and Google identity configuration
- Self-service password reset and passwordless sign-in
- Smart cards, PKI and certificate-based authentication
- Service-account and machine-identity management
- Privileged remote access for vendors and contractors
- Directory services: LDAP, Kerberos and federation
Security operations and response19
Detection and response run as a managed service under an SOP and an SLA agreed with you. Coverage hours depend on the client and the contract.
- Security operations centre (SOC) monitoring with L1, L2 and L3 analysts
- Managed detection and response (MDR)
- SIEM: log ingestion, parsing, correlation rules and use-case authoring
- SOAR playbooks and automated response
- MITRE ATT&CK-aligned detection coverage
- Alert triage, escalation and tuning
- Threat intelligence: IOCs, TTPs and sector feeds
- Hypothesis-driven threat hunting and IOC sweeps
- Incident response: preparation, containment, eradication, recovery, lessons learned
- Incident-response retainer with pre-agreed hours
- Digital forensics: disk, memory, mobile, email and cloud
- Malware analysis and chain-of-custody handling
- Vulnerability-management programme: scan, prioritise (CVSS, EPSS), remediate, verify
- External attack-surface management and dark-web monitoring
- Breach and attack simulation and purple-team testing
- Phishing takedown and brand protection
- Security metrics: mean time to detect and respond, trends and dashboards
- Monthly health reports and quarterly review meetings
- Log retention and time-synchronisation practices designed for CERT-In directions
Cloud, application and DevSecOps10
- Cloud security posture management (CSPM) and CNAPP
- Container and Kubernetes security
- Infrastructure-as-code scanning and policy-as-code
- API security and web application firewall
- CI/CD pipeline security: SAST, DAST, SCA and SBOM
- Secrets scanning and rotation
- SaaS security posture management (SSPM) and shadow-IT discovery
- Microsoft 365 and Google Workspace hardening and secure-score improvement
- Cloud logging, monitoring and data-residency controls
- Secure software development lifecycle (SSDLC) advisory
OT, IoT and surveillance-network security8
- IT and OT segmentation using the Purdue model
- Industrial firewalls and unidirectional gateways
- Passive ICS and SCADA monitoring and asset discovery
- IEC 62443-aligned zone and conduit design
- Vendor remote access through jump hosts, with session recording
- Air-gap and removable-media hygiene
- CCTV, access-control and building-system network isolation
- Medical and IoT device segmentation
Resilience and recovery6
- Backup and business-continuity and disaster-recovery (BCDR) design
- Immutable and air-gapped backups, with offsite and cloud tiers
- RPO and RTO targets and commitments
- Ransomware recovery planning and clean-room restores
- Disaster-recovery drills and playbook authoring
- Business-continuity plan and crisis-communication templates
Awareness, training and exercises6
- Phishing simulations with follow-up training
- Role-based security awareness modules
- Tabletop exercises for leadership and IT
- Executive and board briefings
- Secure-coding training for developers
- Onboarding and offboarding security hygiene
Managed security operations8
- Firewall management: policy lifecycle, rule audits, firmware updates
- EDR, email-security and DLP platform management
- Quarterly vulnerability scans and penetration tests
- Configuration backup and change management
- Licence, subscription and renewal tracking
- OEM case handling and hardware replacement
- Escalation and reporting under an agreed SOP and SLA
- Annual security review and roadmap
Nothing listed under that term yet. If you need it, ask: we can usually source or deliver it through a specialist team. Tell us what you need.
The site, in 3D
A perimeter that inspects everything coming in
Next-generation firewalls at the edge, segmented networks inside, and monitoring that does not sleep.
- Firewall perimeter
- Segmentation
- Threat inspection
- Monitoring
Real-time 3D illustration of a typical site, not a specific client project.
Use cases
Where this shows up
Typical situations that lead an organisation to this work.
01
A business whose firewall has never been reviewed since initial installation.
02
An organisation isolating CCTV and guest Wi-Fi from core business systems for the first time.
03
A team moving from ad-hoc remote access to a managed secure-access solution.
Delivery method
How the work runs
Architecture before equipment. Validation before handover.
Stage 01 of 6
Assess
Posture review across network, endpoints, remote access and backup readiness.
Stage 02 of 6
Design
Firewall policy, segmentation plan and remote-access architecture.
Stage 03 of 6
Implement
Firewall deployment, endpoint rollout and secure remote-access configuration.
Stage 04 of 6
Validate
Policy testing, segmentation verification and backup restore tests.
Stage 05 of 6
Document
Trust-zone diagram, policy reference and renewal calendar.
Stage 06 of 6
Support
Ongoing licence and renewal management, plus periodic posture reviews.
How we take this on
One contract. The right specialist for every part
Your project is wider than any single team. We scope all of it, source all of it and carry the responsibility for all of it.
- 01
Scope
We survey, size and specify against standards and your operating reality, not against a brochure.
- 02
Source
Any make, any model, from the manufacturer, distribution or registered importers. GST-compliant invoicing, warranty and returns handled for you.
- 03
Deliver
KINNEX engineers do the work we do every day. Where a job needs a specialist, we bring in the right expert team as a sub-order under your single contract.
- 04
Own
One scope, one SOP, one SLA and one point of accountability, whoever is on site.
Standards and terms
Standards we design to, and the terms you will hear
Specifications are written against recognised standards. Here is the vocabulary, in plain language.
- ISO/IEC 27001, 27002, 27005, 27017, 27018, 27701
- ISO 22301 (business continuity)
- NIST CSF 2.0
- NIST SP 800-53, 800-61, 800-115, 800-207
- CIS Controls v8 and CIS Benchmarks
- MITRE ATT&CK
- OWASP Top 10 and ASVS
- PCI-DSS
- SOC 2 (AICPA Trust Services Criteria)
- HIPAA Security Rule
- GDPR
- India DPDP Act 2023
- IT Act 2000 and IT Rules
- CERT-In directions (2022)
- RBI cyber-security framework
- SEBI CSCRF
- IRDAI information-security guidelines
- IEC 62443 (industrial security)
- ITIL 4 service management
- CVSS and EPSS scoring
- VA vs VAPT
- A vulnerability assessment finds and ranks weaknesses. Penetration testing goes further and tries to exploit them, the way an attacker would.
- Red, blue and purple team
- Red teams attack, blue teams defend, purple teams work together so every attack improves a detection.
- NGFW
- A firewall that understands applications, users and threats, not just ports and addresses.
- EDR / XDR / MDR
- Detection and response on endpoints, extended across email, network and cloud, or run for you as a managed service.
- ZTNA
- Zero-trust network access: each user and device is verified for each application, instead of trusting anyone inside the network.
- SASE / SSE
- Security services delivered from the cloud, close to users and branches, replacing a stack of appliances.
- SIEM and SOAR
- SIEM collects and correlates logs to detect threats. SOAR automates the response with playbooks.
- SOC
- Security operations centre: the team and tooling that watch for threats and respond. Coverage hours are agreed per contract.
- DLP
- Data loss prevention: rules and tools that stop sensitive data leaving through email, USB, cloud or print.
- PAM
- Privileged access management: controlling, recording and rotating the most powerful accounts.
- MFA and passkeys
- A second proof of identity beyond a password. Passkeys and hardware keys resist phishing best.
- SPF, DKIM, DMARC
- Three DNS-based checks that prove an email really came from your domain, and tell receivers what to do with fakes.
- CSPM / CNAPP
- Tools that continuously check cloud accounts for misconfiguration and risk.
- CVSS and EPSS
- Scores for how severe a vulnerability is, and how likely it is to be exploited. Used together to decide what to patch first.
- MTTD and MTTR
- Mean time to detect and to respond: the two numbers that show whether security operations are improving.
- Purdue model
- A layered way to separate factory-floor networks from business IT, so a breach in one does not reach the other.
- BEC
- Business email compromise: fraud using a convincing email, often impersonating a director or supplier, to move money.
- Immutable backup
- A backup that cannot be altered or deleted for a set period, even by an administrator, which defeats ransomware.
- RPO and RTO
- How much data you can afford to lose, and how long you can afford to be down. They set the backup and recovery design.
- IR retainer
- A pre-agreed arrangement with an incident-response team and a pool of hours, so help starts without procurement delay.
- SOP and SLA
- The documented procedures for running security operations, and the response and reporting targets agreed for them.
Brands
Any make. Sourced, supplied and supported
We specify against your requirement and standards, then source the right product from the manufacturer, distribution or registered importers. Delivered, installed and supported under one contract.
Firewalls and network security
Next-generation firewalls, UTM, VPN, secure web and zero trust access.
Sophos
Fortinet
Palo Alto Networks
WatchGuard
Barracuda Networks
Cisco Secure
Juniper Networks
SonicWall
Cloudflare
pfSense
OPNsense
Forcepoint
Netgear
Huawei
Ubiquiti
Tailscale
OpenVPN
WireGuard
Show 14 more brands
Array Networks
Kerio
Cisco Umbrella
Akamai
Imperva
F5
Radware
- Check Point
- Zscaler
- Cato Networks
- Netskope
- Versa Networks
- Stormshield
- Untangle
Endpoint protection, EDR and XDR
Antivirus, EDR, XDR, MDR and ransomware protection.
SentinelOne
CrowdStrike
Sophos
Trend Micro
Microsoft Defender
Bitdefender
ESET
Kaspersky
Symantec
Trellix
VMware Carbon Black
Malwarebytes
Acronis
McAfee
Webroot
Broadcom
Elastic
Cisco Secure Endpoint
Show 10 more brands
Avast
G DATA
- Quick Heal
- Seqrite
- Cybereason
- Cynet
- Huntress
- Arctic Wolf
- Tanium
- F-Secure
Email security and data loss prevention
Anti-phishing, sandboxing, encryption, archiving and DLP.
Proofpoint
Barracuda Networks
Sophos
Forcepoint
Trellix
Symantec
Microsoft Purview
Trend Micro
Cisco Secure Email
Google Workspace
Cloudflare
- Mimecast
- Netskope
- Safetica
- Digital Guardian
- Zscaler
- Ironscales
- Abnormal Security
Show 9 more brands
- KnowBe4
- Egress
- Virtru
- Varonis
- Titus
- Seclore
- Cyberhaven
- Tessian
- Hornetsecurity
Identity, MFA and privileged access
SSO, MFA, IAM, password vaulting and privileged session control.
Okta
BeyondTrust
ARCON
Microsoft Entra
Ping Identity
Thales
Entrust
Auth0
OneLogin
Keeper
1Password
Bitwarden
LastPass
RSA
Yubico
Teleport
Zoho Vault
Google Authenticator
Show 13 more brands
Microsoft Authenticator
- CyberArk
- Ekran System
- Duo Security
- ForgeRock
- JumpCloud
- Delinea
- HashiCorp Vault
- SailPoint
- Saviynt
- Imprivata
- StrongDM
- ManageEngine PAM360
SIEM, SOC, vulnerability and testing tools
Log analytics, detection, vulnerability management, penetration testing and forensics.
Splunk
Microsoft Sentinel
IBM QRadar
Elastic
Wazuh
Graylog
Sumo Logic
Tenable
Qualys
Nessus
Burp Suite
Metasploit
Wiz
Google Chronicle
Shuffle
Autopsy
Wireshark
Kali Linux
Show 23 more brands
OWASP ZAP
Checkmarx
Snyk
Mandiant
- LogRhythm
- Exabeam
- Rapid7
- OpenVAS
- Cobalt Strike
- Nmap
- Prisma Cloud
- Darktrace
- TheHive
- MISP
- Velociraptor
- Volatility
- FTK
- EnCase
- Acunetix
- Invicti
- SonarQube
- Recorded Future
- Group-IB
Product names, logos and brands are property of their respective owners and are used for identification only. Don't see what you need? We can usually source it, including through registered importers.Ask us.
Technology fit
The technology categories this work draws on.
- Next-generation firewall (NGFW) platforms
- Endpoint protection and patch management
- ZTNA and VPN secure remote-access gateways
- Backup and recovery platforms
Reading
Related insights
Cybersecurity and Firewalls
A security and IT checklist for bank branches and ATMs
Network, CCTV, vault access, alarms, logging and failover. What a standard branch design covers, and how to keep many branches consistent.
Cybersecurity and Firewalls
Firewall renewals and end-of-life: plan before support lapses
Subscriptions, hardware lifecycles and firmware support dates. How to avoid running a security device that no longer receives updates.
Cybersecurity and Firewalls
Logs and SIEM for mid-size firms: what to collect and why
Firewall, identity, endpoint and email logs answer most investigations. How to start small and avoid drowning in data.
Cybersecurity and Firewalls
A startup security baseline for the first 90 days
Startups are targets because they hold code, data and cloud keys with few defences. Twelve steps that cover most real risk.
Cybersecurity and Firewalls
Protecting patient data: practical controls for clinics and hospitals
Encryption, role-based access, audit trails and secure links between laboratories and doctors. Aligning to HIPAA-style safeguards and India's DPDP Act.
Cybersecurity and Firewalls
Passwords, password managers and privileged access in a business
Shared admin passwords and spreadsheets are still common. Vaults, rotation and session recording make privileged access safer and auditable.
Questions
Frequently asked questions
By throughput needs, user and device count, VPN concurrency and the number of segments required — sized from your actual environment, not a generic recommendation.
Policy is tuned to your traffic, segments are defined, and reporting is set up — a firewall is a starting point for ongoing policy management, not a one-time appliance swap.
Yes, through VLAN segmentation and firewall policy that keeps each traffic class on its own trust zone.
Scope is defined per contract — from basic alerting to more active monitoring — and KINNEX will not describe a service as round-the-clock SOC coverage unless it is actually staffed and contracted that way.
Licence terms and renewal dates are tracked centrally and flagged ahead of expiry, so protection does not lapse silently.
Review your security architecture
Tell us the site, the constraint or the outcome you need, and we will come back with the right next step.


