← Guardian

Network layer security

Segmentation, patching and monitoring for the network that now carries your cameras, readers and lab machines.

What it does

What it does

  • Puts cameras, access control, lab machines and administrative systems on separate network segments, so a compromised camera cannot reach a finance server.
  • Replaces default credentials on every device we install, and finds the ones already on your network that still have them.
  • Patches the devices we are responsible for, on a schedule you can see.
  • Monitors for a device behaving unlike itself — a camera suddenly talking to an unfamiliar host, for example.
Deployment

How it is deployed

  • We start with an audit and give you the findings in writing, including the problems we cannot fix and the ones you already have.
  • Segmentation is staged over scheduled windows so no system goes down during school hours.
  • Your IT head gets administrative access to everything we configure. There are no accounts you cannot see.
  • We document the network as built and hand over the drawings, so a future vendor is not starting blind.
Day to day

What the school sees

  • A network map showing the segments and what sits in each.
  • A patch status list for every device under our care.
  • Alerts when a device starts behaving abnormally, with what we recommend doing about it.
  • A quarterly report suitable for the trustees.
Data

What data it produces

Device inventory and firmware versions
Life of the contract
Network flow metadata between segments
30 days
Patch and configuration change history
Life of the contract
Security incident records
3 years
Limits

What it does not do

  • It does not inspect the content of student or staff internet traffic. We look at which devices talk to which, not what they say.
  • It does not filter or censor web browsing. If you want content filtering, that is a separate decision and a separate product.
  • It does not read email, files or messages.
  • It does not lock you into us. The configuration is documented and the credentials are yours; you can hand this to another vendor at any time.
  • It does not make your network unbreakable. It reduces what one compromised device can reach, and we will tell you what remains exposed.

See what this would look like on your campus.

We walk the site, tell you what your existing equipment can and cannot support, and put it in writing.

Book a campus assessment