# Cybersecurity, Identity and Secure Access

> Firewalls and segmentation, endpoint, identity and multi-factor, logging and detection, secure remote and third-party access. Trybus Solutions, nationwide.

*Source: https://trybussolutions.com/cybersecurity/ · Trybus Solutions · Chattanooga, TN · 423-633-1817 · info@trybussolutions.com*

## What We Do

Trybus Solutions assesses, designs and builds the security controls around a network, its users and its devices: firewalls and segmentation, endpoint protection, identity and multi-factor authentication, logging and detection, and secure access for people working outside the office.

Most of this work starts for one of a few reasons. A customer or an insurer has sent a questionnaire the environment cannot answer honestly. A firewall estate is coming up on end of support. An audit has produced findings with dates attached. An acquisition has joined two networks never designed to meet.

Our clients usually have their own IT team, and often somebody who owns security as part of a wider job. We are there for the parts that need people who have built this before.

## Why Clients Bring Us In

- **We are not tied to one manufacturer.** We carry a range of technology partners, so what we recommend is not decided by what we happen to sell. Sometimes the answer is to consolidate and sometimes it is to leave a control alone.
- **Our engineers have done the rollouts.** Our security staff hold credentials including CISSP and CISM, with delivery history behind them. Knowing which questions to ask before a policy goes into enforcement keeps a change window from becoming an outage.
- **One team sees the network and the security on it.** Segmentation, secure access and identity all depend on how the network is actually built, and the diagram is rarely the whole story. One team across both closes the gap that opens between separate vendors.
- **We start from what is running now.** Rule bases that grew over a decade, accounts nobody owns, exceptions opened for a project that finished years ago. That inventory is unglamorous, and it is where the risk sits.
- **Design and procurement in one place.** We design the environment and supply the hardware and licensing for it, and our procurement works with your purchasing system rather than outside it.
- **We will tell you what does not need buying.** A security proposal is easy to pad. Some findings are worth fixing this quarter, some are worth scheduling, and some are worth writing down and living with. We say which is which, even when it costs us a line on the quote.

## What You Get

Scope varies. A firewall refresh across two sites does not need the documentation an identity rollout across thirty does. Below is what we produce on a typical mid-size project, and we agree which of it you need at scoping.

Everything we produce is yours. If you take the design elsewhere to be built, it will be complete enough for somebody else to build it.

- **Assessment of the current environment:** Rule bases, identity sources, agent coverage and remote access paths, read out of the live systems rather than the documentation.
- **Findings, priorities and recommendation:** What we found, ordered by exposure and by effort to fix, what we suggest, and what the environment has to satisfy in regulation, contract terms and insurer questions.
- **Design documentation:** A high-level design on most projects, and a low-level design where the build warrants one, covering segmentation, policy structure and naming.
- **Access and identity model:** Who gets access to what, how it is granted and removed as people join and leave, and what happens to privileged and service accounts.
- **Bill of materials:** Hardware, licensing and services itemized, so procurement works from real numbers and renewals are visible early.
- **Migration and cutover plan:** Stages, dependencies, change windows, and the way back out of each stage if it goes wrong.
- **Test plan and acceptance criteria:** What has to work before a stage is signed off, agreed at the start so sign-off is a check rather than a negotiation.
- **As-built documentation and handover pack:** What was built, how it is configured, runbooks for the routine tasks, and what your team needs to run it.

## The Security Areas We Work In

Six areas, and most projects touch more than one.

### Perimeter and Segmentation

Firewall estates at the edge and at branch sites, and the segmentation that decides which parts of the estate can reach each other. Most rule bases we inspect carry entries nobody can explain, so inventory comes first, then a policy that matches how the organization operates, then enforcement in stages.

### Endpoint

Protection software, hardening baselines, disk encryption, and a patching approach that allows for the machines which cannot be patched on the normal cycle. The number that matters here is the share of machines carrying a healthy agent that reports in, which is never what the console shows on day one.

### Identity and Access

Single sign-on, multi-factor authentication, access policy by risk and device, privileged accounts, and the joiner, mover and leaver process underneath it, with hardware-backed keys where a phishing-resistant factor is required. Enrollment, the exceptions people ask for in the first two weeks, and what happens when somebody loses a factor while traveling decide how a rollout is remembered.

### Logging, Detection and Response

Deciding what to collect, how long to keep it and what that costs, then building detections that mean something in your environment rather than leaving a default rule set to produce noise. Each detection gets a runbook, and who watches the resulting queue is a decision of its own.

### Secure Access for Remote Users and Third Parties

Remote access that grants a person the applications they need rather than a route into the whole network, with the same discipline for contractors, suppliers and support vendors. Third-party access is the part most organizations know is wrong and keep postponing, usually because the vendor at the other end has connected the same way for a decade.

### Devices That Will Not Take an Agent

Building management systems, cameras, badge readers, medical equipment, lab instruments and industrial controllers. Protection software cannot be installed on most of it and an aggressive scan can knock a controller over, so discovery is passive and segmentation carries the load. The people who own that equipment rarely sit in IT, so we bring them in at scoping.

## How a Project Runs

Broadly the same shape whether it is a firewall pair at one site or an identity rollout across the organization. Timescales depend on the size of the estate, the state of the documentation and how much of your team is available.

- **Scoping and kickoff:** Agree what is in scope, the deliverables, who is involved and how decisions get made. This is also where we set the change process, so a surprise later has a route through it.
- **Discovery:** Sessions with the people who run the environment now, plus configuration pulled from the live systems. Discovery usually turns something up, and when it changes the scope we price it and you decide before we carry on.
- **Design and review:** Design documented, then walked through with your team and whoever owns the applications it touches. Better to argue about it on paper than during a change window.
- **Procurement and staging:** Hardware and licensing ordered, configured and staged. Lead times are the usual reason a date moves, so we order as early as the design allows.
- **Pilot:** On larger projects a site or a group of users goes first, with a way back if it goes badly. On smaller ones this stage often is not worth the time, and we will say so.
- **Rollout:** Site by site, or group by group. A policy being enforced for the first time sits in monitor mode long enough for the exceptions to surface.
- **Handover:** A period of closer support while the snags come out, then documentation, training, and a decision about the equipment being replaced.

## What Is Quoted Separately

Most of what is below is work we do. It is not part of a security project by default, because each piece carries its own scope, its own schedule and its own cost. If you want any of it included, say so at scoping and we will quote it in. The last item is different: it is work we do not do at all.

- [Frameworks, control mapping and audit evidence. Choosing a framework, mapping controls to it, writing policy and assembling the evidence an assessor asks for is its own engagement, run by our governance and compliance team.](https://trybussolutions.com/governance-risk-compliance/)
- [Ongoing monitoring and day-to-day operation. Running the environment after handover and watching the alert queue is a separate agreement with its own service levels. Plenty of clients keep that in house.](https://trybussolutions.com/managed-services-and-support/)
- **[Network design and physical infrastructure.](https://trybussolutions.com/networking-connectivity/)** Segmentation often exposes a network design question underneath it, and sometimes physical work as well. We have written up [how to phase segmentation without stopping the business](https://trybussolutions.com/network-segmentation-without-stopping-the-business/). Design is ours; cable is installed by the cabling partners we bring in. Each piece is priced on its own because each runs to a different schedule.
- [Device fleet and workplace rollout. Getting an agent onto every machine, setting device standards and running the fleet afterwards is a workplace project, usually owned by a different part of IT.](https://trybussolutions.com/digital-workplace/)
- [Custom development and integration. Connecting security tooling to a service desk, an identity source or an internal application past what the documented connectors cover. That work gets its own scope and testing.](https://trybussolutions.com/architecture-solution-design/)
- **Formal certification and attestation.** A certificate comes from an independent assessor, and it has to, because the document means something only if the person signing it did not build the environment.

[Start a conversation](https://trybussolutions.com/contact-us/?service_solution=cybersecurity)

## Industries We Work In

The controls do not change much between sectors. What changes is which one gets attention first, and what an organization can take offline to fix it.

### [Healthcare →](https://trybussolutions.com/healthcare/)

Clinical systems and connected equipment that cannot be patched or taken down at will, which pushes work toward segmentation and access control.

### [Public Sector →](https://trybussolutions.com/public-sector/)

Procurement rules, records retention, and a duty to keep services running for people with no alternative provider.

### [Tribal Government and Enterprises →](https://trybussolutions.com/tribal-organization/)

Sovereignty over data and systems, funding cycles outside the commercial year, and estates spanning government, health, education and gaming on shared infrastructure.

### [Financial Services →](https://trybussolutions.com/financial-services/)

Supervision and retention obligations, third-party access regulators expect to see governed, and little tolerance for unplanned downtime.

### [Education →](https://trybussolutions.com/education/)

Open networks carrying unmanaged personal devices, a seasonal turnover of accounts, and budgets that follow an academic year.

### [Retail →](https://trybussolutions.com/retail/)

Payment environments that have to stay separated, and many small sites with no local IT.

### [Enterprise →](https://trybussolutions.com/enterprise/)

Multi-site estates at different stages of modernization, often still carrying the network and accounts inherited from an acquisition.

## Technology We Work With

We hold partner relationships across the security industry, and our engineers also work in platforms we do not sell. A security project starts on whatever you are running now, whoever supplied it.

We do not publish comparisons between manufacturers. Which platform suits an organization is something an assessment works out, not something a website should decide.

[See all technology partners →](https://trybussolutions.com/partners/)

## Talk to Us About a Project

Tell us what you are running, what prompted the conversation and what date is driving it. We will tell you what we think needs doing and what does not, and put a scope and a number against it.

[Start a conversation](https://trybussolutions.com/contact-us/?service_solution=cybersecurity)

[Insights and guides](https://trybussolutions.com/resources/)

## Related guides

- [Network segmentation without stopping the business](https://trybussolutions.com/network-segmentation-without-stopping-the-business/)
