Network Segmentation & OS / DB Hardening
Zero-trust that survives contact with production.
Network segmentation and OS/database hardening: design, deployment, and validation across corporate, OT, and cloud networks.
We map actual traffic, design a segmentation model that survives change, harden OS and database baselines, and validate policy in production without breaking the business.
- Traffic map & flow analysis
- Segmentation design (zone architecture)
- OS & database hardening baselines
- Policy validation report
- Break-glass and rollback procedures
- Reduced blast radius and lateral-movement paths
- Hardened OS/DB baselines maintained through change
- Segmentation model that your team can evolve
- Auditor evidence for cardholder / PHI / OT isolation
How the engagement runs. Phase by phase.
Business-flow discovery
Workshops with app owners + passive Zeek capture; reconcile mental model with reality.
Zone architecture design
Logical zones, trust boundaries, east-west policy framework.
Hardening baseline creation
CIS / STIG profiles per OS + DB tier, with tested exceptions.
Lab deployment + validation
Full deployment in a mirrored lab; run ATT&CK tests.
Production cutover (graduated)
Observe → alert → block, wave-by-wave with rollback.
Continuous drift monitoring
OpenSCAP / Wazuh continuous scan; quarterly validation.
What we actually use. No secrets.
Every tool earns its place. We publish our stack so your team can audit, review, and integrate with what we bring.
- ZE
Zeek (formerly Bro)Passive network traffic analysis for flow mapping - NT
ntopng + nProbeReal-time flow visualization and protocol decomposition
- IL
Illumio / Guardicore / VMware NSXHost-based microsegmentation deployment - CICisco ISE / Aruba ClearPassPolicy-based network segmentation via 802.1X
- ANAnsible + STIG / CIS rolesAutomated OS baseline deployment at scale
- OP
OpenSCAP + SCAP contentCompliance scanning against DISA STIG / CIS - LY
Lynis / WazuhContinuous hardening posture and drift detection
- DBDB-specific baselinesOracle CIS, PostgreSQL, SQL Server, MongoDB hardening
- CU
Custom ATT&CK validation scriptsLateral-movement and pivot tests to prove segmentation
How we do the work. Not just what.
Passive traffic learning
Before any firewall change, we run Zeek spans for 10–14 days across business-cycle peaks (week, month-end) to capture real flows.
Zone modeling
Typical target: user, server, DMZ, management, OT. Each zone has explicit ingress/egress policy and break-glass procedure.
Graduated enforcement
Observe → alert → block. No rule goes from zero to block. Minimum 2 weeks in alert mode to find legitimate exceptions.
Hardening baselines
CIS L2 for user workstations, CIS L1 for servers (with justified exceptions), DISA STIG for federal-facing systems.
Break-glass procedures
Every rule has a documented bypass and revert path. Segmentation must be survivable in incident response.
Lateral-movement validation
Post-deploy we run ATT&CK techniques T1021, T1570, T1210 across zones to prove the policy.
Real problems. Real fixes.
Anonymized incidents from actual engagements: what broke, why it mattered, and how we fixed it.
Manufacturing client had 900 undocumented flows between ERP and shop-floor PLCs.
Any segmentation attempt risked halting a production line costing $180k/hour.
Ran 14-day Zeek capture during month-end (worst case). Discovered 180 real flows (not 900, most were retransmits). Built policy from observed reality, not tribal knowledge. Cutover happened with zero production halt.
Legacy HL7 medical device used hardcoded credentials and couldn't authenticate to modern zones.
Hospital risked losing device certification if we changed its auth; risked data exposure if we didn't.
Placed device in an isolated micro-zone with source-IP-locked policy, deployed a broker service for modern protocol translation. Device kept its certification; blast radius reduced to one subnet.
First segmentation wave blocked legitimate backup traffic on night of cutover. SOC got 200 alerts.
On-call rolled back the rule; all progress lost for that zone.
Added a pre-cutover checklist step: 'observe for 2 business cycles including backup window.' Instituted a freeze on cutovers during month-end. Zero rollback events in next 11 waves.
Segmentation lifecycle
Discover → design → validate → enforce → monitor.
Targets, not promises.
Will this break our applications?
Do we need to rip-and-replace our firewalls?
What about OT / ICS networks?
How is this different from a standard NSX / Illumio deployment?
Scope a network segmentation engagement.
30-minute scoping call. You'll talk to an operator, not a BDR.