Details
Most organisations we survey already own a firewall. Rather fewer have a firewall that constitutes a control, because the rule set has accumulated permissions faster than it has removed them.
What actually protects a network
Segmentation first. A flat network means anything reaching one device reaches all of them. Separating corporate users, guests, voice and radio infrastructure, cameras, building systems and process equipment limits what any single compromise can touch. The firewall enforces the boundaries that segmentation creates; without segmentation there is nothing for it to enforce.
A rule set with intent. Every rule should have a stated purpose, an owner and a review date. Rules added at midnight to solve an urgent problem are the ones still permitting traffic three years later, for a system that was decommissioned two years ago.
Default deny. Permit what is required, block the rest. The reverse — block known threats, permit everything else — has never worked and does not scale.
Controlled remote access. Named accounts, multi-factor authentication, scoped to the specific systems each person supports. Shared vendor credentials on a permanently open path are the most common route by which industrial systems are reached by people who should not reach them.
Logging that is read. Logs nobody looks at establish only what happened after the fact, and only if retention was configured. Alerting on the events that matter is what makes logging a control rather than an archive.
Choosing equipment
| Consideration | Question |
|---|---|
| Throughput | With inspection enabled, not the headline figure |
| Feature need | Which inspection features will genuinely be used and maintained |
| Management | Can your team operate it, or is it managed for you |
| Licensing | What recurs annually, and what stops working if it lapses |
| Support | Response time and replacement terms |
| Growth | Does it still fit in three years |
The specification that matters is throughput with inspection turned on. A device sized on its raw figure becomes the bottleneck the moment the features it was bought for are enabled.
Industrial and radio infrastructure
Process networks, SCADA and radio infrastructure need a different approach from office IT. Many industrial protocols carry no authentication, having been designed for isolated networks, and much of the equipment cannot be patched or safely scanned.
Security therefore comes from architecture: strict segmentation, a controlled path between the industrial and corporate zones, monitoring rather than active scanning, and remote access that is scoped and logged.
Radio dispatch servers, repeater management interfaces and recording systems belong on their own segment. They are reachable from the corporate network for the people who need them, and from nowhere else.
What TechnoRF does
Review of the existing rule set and topology, segmentation design, firewall selection and installation, VPN and remote access, logging and alerting, and ongoing management with firmware updates and periodic rule review.
The rule review is usually where the value is. It typically removes more risk than the new appliance would have. See network installation or get in touch.
Frequently Asked Questions
We already have a firewall — is that not enough?
Only if its rules are restrictive and reviewed. Most firewalls we survey have accumulated permissive rules added to solve urgent problems and never removed, remote access opened for a vendor years ago, and logging that nobody reads. The device is present and the control is not. A rule review is usually more valuable than a new appliance.
How should remote access for vendors be handled?
Through named accounts with multi-factor authentication, restricted to the specific systems that vendor supports, time-limited where possible, and logged. What should never exist is a shared credential on a permanently open path — which is the single most common way industrial systems are reached by people who should not reach them.
Do industrial and SCADA networks need different treatment?
Yes, in an important way. Many industrial protocols have no authentication at all, because they were designed for isolated networks, and much of the equipment cannot be patched or even scanned safely. Security there comes from segmentation and strictly controlled access paths rather than from agents on the endpoints.
What does KVKK require of us here?
That personal data is protected by appropriate technical measures and that breaches are notified. In practice that means access control, encryption where warranted, logging sufficient to establish what happened, and documentation showing the measures were considered and implemented. A network with no records cannot demonstrate compliance even where its practice is sound.