Cybersecurity, Identity and Secure Access

What We Do

Trybus Solutions assesses, designs and builds the security controls around a network, its users and its devices: firewalls and segmentation, endpoint protection, identity and multi-factor authentication, logging and detection, and secure access for people working outside the office.

Most of this work starts for one of a few reasons. A customer or an insurer has sent a questionnaire the environment cannot answer honestly. A firewall estate is coming up on end of support. An audit has produced findings with dates attached. An acquisition has joined two networks never designed to meet.

Our clients usually have their own IT team, and often somebody who owns security as part of a wider job. We are there for the parts that need people who have built this before.

Officer reviewing information on screen

Why Clients Bring Us In

What You Get

Scope varies. A firewall refresh across two sites does not need the documentation an identity rollout across thirty does. Below is what we produce on a typical mid-size project, and we agree which of it you need at scoping.

Everything we produce is yours. If you take the design elsewhere to be built, it will be complete enough for somebody else to build it.

Engineer monitoring performance in a data center
Security analyst working at a computer

The Security Areas We Work In

Six areas, and most projects touch more than one.

01

Perimeter and Segmentation

Firewall estates at the edge and at branch sites, and the segmentation that decides which parts of the estate can reach each other. Most rule bases we inspect carry entries nobody can explain, so inventory comes first, then a policy that matches how the organization operates, then enforcement in stages.

02

Endpoint

Protection software, hardening baselines, disk encryption, and a patching approach that allows for the machines which cannot be patched on the normal cycle. The number that matters here is the share of machines carrying a healthy agent that reports in, which is never what the console shows on day one.

03

Identity and Access

Single sign-on, multi-factor authentication, access policy by risk and device, privileged accounts, and the joiner, mover and leaver process underneath it, with hardware-backed keys where a phishing-resistant factor is required. Enrollment, the exceptions people ask for in the first two weeks, and what happens when somebody loses a factor while traveling decide how a rollout is remembered.

04

Logging, Detection and Response

Deciding what to collect, how long to keep it and what that costs, then building detections that mean something in your environment rather than leaving a default rule set to produce noise. Each detection gets a runbook, and who watches the resulting queue is a decision of its own.

05

Secure Access for Remote Users and Third Parties

Remote access that grants a person the applications they need rather than a route into the whole network, with the same discipline for contractors, suppliers and support vendors. Third-party access is the part most organizations know is wrong and keep postponing, usually because the vendor at the other end has connected the same way for a decade.

06

Devices That Will Not Take an Agent

Building management systems, cameras, badge readers, medical equipment, lab instruments and industrial controllers. Protection software cannot be installed on most of it and an aggressive scan can knock a controller over, so discovery is passive and segmentation carries the load. The people who own that equipment rarely sit in IT, so we bring them in at scoping.

C6
Education and Collaborations. Cybersecurity.

How a Project Runs

Broadly the same shape whether it is a firewall pair at one site or an identity rollout across the organization. Timescales depend on the size of the estate, the state of the documentation and how much of your team is available.

What Is Quoted Separately

Most of what is below is work we do. It is not part of a security project by default, because each piece carries its own scope, its own schedule and its own cost. If you want any of it included, say so at scoping and we will quote it in. The last item is different: it is work we do not do at all.

Video call under way in a corporate meeting room

Industries We Work In

The controls do not change much between sectors. What changes is which one gets attention first, and what an organization can take offline to fix it.

Technology We Work With

We hold partner relationships across the security industry, and our engineers also work in platforms we do not sell. A security project starts on whatever you are running now, whoever supplied it.

We do not publish comparisons between manufacturers. Which platform suits an organization is something an assessment works out, not something a website should decide.

  • Fortinet logo — Trybus Solutions technology partner
  • Palo Alto logo — Trybus Solutions technology partner
  • Zscaler logo — Trybus Solutions technology partner
  • Duo logo — Trybus Solutions technology partner
  • Yubico logo — Trybus Solutions technology partner
  • Cisco Splunk logo — Trybus Solutions technology partner
  • Cisco logo — Trybus Solutions technology partner
  • Meraki logo — Trybus Solutions technology partner

See all technology partners →

Talk to Us About a Project

Tell us what you are running, what prompted the conversation and what date is driving it. We will tell you what we think needs doing and what does not, and put a scope and a number against it.