TCX-SEC-01
Network Architecture & Design
LAN/WAN, SD-WAN, routing and switching designed to a standard.
We design and optimise enterprise networks on Cisco, Juniper and comparable platforms, covering LAN/WAN, SD-WAN, routing and switching architectures for performance, scale and alignment with ISO/IEC 27033 network security guidance.
CiscoJuniperSD-WANISO/IEC 27033
TCX-SEC-02
Firewall & Perimeter Security
Firewall strategy, policy design and configuration review.
Consultancy on firewall strategy, design and configuration across Fortinet, Palo Alto and Check Point. We strengthen perimeter defence, rationalise policy sprawl and align deployments to NIST and CIS benchmarks.
FortinetPalo AltoCheck PointCIS benchmarks
TCX-SEC-03
Secure Access & Zero Trust
ZTNA and secure web gateway adoption without breaking the business.
We guide adoption of Zero Trust Network Access and secure web gateways using Zscaler, Cisco Umbrella and Netskope — securing remote access and cloud application use while keeping day-to-day work workable.
ZTNAZscalerCisco UmbrellaNetskope
TCX-SEC-04
VPN, Remote Access & Identity
Remote access joined up with the identity layer behind it.
Design and optimisation of VPN and remote access on Cisco AnyConnect, FortiClient and Palo Alto GlobalProtect, integrated with IAM frameworks such as Okta and Microsoft Entra ID for standards-based remote work.
AnyConnectFortiClientGlobalProtectOktaEntra ID
TCX-SEC-05
DDoS Protection & Network Resilience
Mitigation architecture tied to continuity requirements.
Consulting on DDoS mitigation with Radware, Arbor and Cloudflare. We assess exposure, design resilient architectures and integrate mitigation controls in line with ISO 22301 business continuity requirements.
RadwareArborCloudflareISO 22301
TCX-SEC-06
Secure Email & Web Gateways
Phishing, malware and data-leakage controls at the gateway.
Design and optimisation of secure email and web gateway solutions against phishing, malware and data leakage, with deployments aligned to NIST SP 800-177 email security guidance.
Email securityDLPNIST SP 800-177
TCX-SEC-07
Wireless & Mobility
Enterprise Wi-Fi designed for density, roaming and control.
Design and optimisation of enterprise wireless on Cisco, Aruba and Meraki — secure, scalable and predictable under load, aligned to Wi-Fi Alliance standards and ISO/IEC 27001 controls.
CiscoArubaMerakiWi-Fi 6/6E
TCX-SEC-08
Cloud Security
Workload protection, identity and cloud compliance posture.
We secure cloud environments using Prisma Cloud, Fortinet Cloud Security and native provider controls, advising on workload protection, identity and compliance frameworks including CSA CCM and ISO/IEC 27017.
Prisma CloudCSPMCSA CCMISO/IEC 27017
TCX-SEC-09
Endpoint Security & EDR
EDR deployment and tuning mapped to real adversary behaviour.
Deployment and optimisation of endpoint security and EDR on CrowdStrike, SentinelOne and FortiEDR, with detection coverage and tuning mapped against MITRE ATT&CK.
CrowdStrikeSentinelOneFortiEDRMITRE ATT&CK
TCX-SEC-10
SIEM & Security Analytics
Detection engineering, not just log collection.
Consulting on SIEM and security analytics across Splunk, IBM QRadar, Elastic and Microsoft Sentinel. We design the ingestion architecture and build detection use cases against MITRE ATT&CK and NIST guidance.
SplunkQRadarElasticMicrosoft Sentinel