Services

Business Network Security, Firewalls and Secure Wi-Fi

Design, install and harden the network your business actually runs on: firewalls that are configured rather than just installed, Wi-Fi that separates guests from your servers, and remote access that does not leave a door open.

COVERS
Firewall, Switching, Wi-Fi, VPN
SEGMENTATION
VLAN Design for Staff, Servers, Guests
ON-SITE
Leicester & East Midlands
STANDARD
Aligned to Cyber Essentials Controls
In short

What is network segmentation and why does a small business need it?

Network segmentation divides one flat network into separate zones — staff devices, servers, guest Wi-Fi, payment or operational equipment — so traffic between them is controlled. It matters because on a flat network, one infected laptop can reach every server, printer and file share in the building.

Most SME networks grew rather than being designed

A typical small business network is the accumulated result of ten years of decisions: a router from the broadband provider, a switch added when the office expanded, access points bought separately, a NAS someone plugged in, and a printer with a web interface reachable by everyone. Nobody drew it, and nobody is quite sure what is on it.

We start by finding out. Discovery routinely turns up devices the business had forgotten — an old server still running an end-of-life operating system, a test machine with default credentials, a supplier's remote access box nobody can account for. You cannot secure what you have not documented.

Firewalls: installed is not configured

Almost every business we assess has a firewall. Far fewer have a firewall doing much. The common findings are outbound rules that permit everything, inbound rules created for a project that finished three years ago, remote management exposed to the internet, firmware years behind, and licensed features such as intrusion prevention and web filtering that were never turned on.

We review the ruleset line by line, remove what no longer has a business justification, tighten what remains to specific sources and destinations, enable the protection features you are already paying for, and document why each rule exists so the next review is quicker.

  • Rule-by-rule review with a business justification recorded for each
  • Removal of legacy inbound rules and any-any permissions
  • Firmware currency and vendor advisory check
  • Management interfaces removed from internet exposure
  • Intrusion prevention, content filtering and logging enabled and tuned

Segmentation and secure Wi-Fi

Segmentation is the control that most reliably limits the damage of an incident. Separating staff devices from servers means a compromised laptop cannot enumerate and encrypt your file shares. Separating guest Wi-Fi means a visitor's infected phone is on a network that reaches the internet and nothing else. Separating card payment or operational equipment is often a compliance requirement as well as a sensible one.

On Wi-Fi specifically, we see the same issues repeatedly: a single shared passphrase that has not changed since installation and is known by every former employee, guest access that sits on the same network as the servers, and access points running firmware with published vulnerabilities.

  • Separate VLANs for staff, servers, guests, voice and operational devices
  • Guest Wi-Fi isolated from all internal resources, with client isolation on
  • WPA2/WPA3 Enterprise with per-user authentication rather than a shared passphrase
  • Access point firmware maintenance and rogue access point detection
  • Wired port security so an unknown device cannot simply plug in

Remote access without leaving a door open

Remote desktop published directly to the internet remains one of the most common ransomware entry points in the UK, and it is entirely avoidable. So is an unpatched VPN appliance — several vendors have shipped critical vulnerabilities that were exploited within days of disclosure.

We replace exposed remote desktop with an authenticated VPN or a zero trust access broker, enforce MFA on it, restrict it to the systems each user actually needs, and put the appliance on a patching schedule that treats vendor advisories as urgent rather than routine.

  • No direct internet exposure of RDP or management protocols
  • MFA enforced on all remote access
  • Least-privilege access — users reach only the systems they need
  • Priority patching process for VPN and firewall appliances
  • Session logging so remote access can be audited after the fact
What you receive

Included in every engagement

Fixed scope, agreed in writing before we start. If the scope changes, we stop and re-quote rather than invoicing the difference.

Frequently asked questions

Network Security — your questions answered

Do you install network hardware or just advise?
Both. We design, supply, install and configure firewalls, switches and access points for businesses in Leicester and across the East Midlands, and we also do design and review work for clients whose own provider handles installation.
How often should firewall rules be reviewed?
At least annually, and after any significant change. Rulesets accumulate — rules created for temporary projects almost never get removed, and each one is a standing permission nobody is checking.
Is guest Wi-Fi a security risk?
Only when it is not properly separated. Guest Wi-Fi should sit on its own VLAN with no route to internal systems, with client isolation enabled and a bandwidth limit. Configured that way it presents very little risk.
Do we need network segmentation for Cyber Essentials?
Cyber Essentials does not mandate segmentation outright, but it does require boundary firewalls and secure configuration, and segmentation is often the practical way to bring legacy or unsupported devices into an acceptable position without failing.
Can you work with our existing IT provider?
Yes. We frequently do network design and security review work alongside a client's incumbent IT support company, and write our documentation so they can implement and maintain it.

Question not answered here? Call +44 7424 967568 or email support@cipherknights.com.

Ready to talk about network security?

Book a free, no-obligation consultation with our Leicester team, or call us and we will point you in the right direction whether or not you become a client.