UTM firewall appliance mounted in a server rack, with network cables connected
← All solutions

Network, identity and data security

Security built on solid architecture and strict procedures.

We design and deploy multi-layered protection for IT environments. We combine hardware perimeter firewalls in HA clusters, network segmentation (VLANs), independent directory services (Active Directory, Samba), strict identity policies with multi-factor authentication (MFA) and immutable 3-2-1 backup. We build operational resilience — from the cabling in the server rack to your employees’ everyday habits.

Explore the pillars of protection
Multi-layered protectionHardware firewall, secure domains, isolated off-site backup and team training.
A hand touching a U2F/FIDO2 hardware security key plugged into a laptop’s USB port

The PCS approach to security

Security isn’t just another antivirus. It’s a tightly sealed network, controlled access and a security-aware team.

Most incidents and crippling ransomware attacks don’t start with sophisticated code-breaking but with mundane mistakes: passwords sent by email or written down on scraps of paper, no second login factor (MFA), a flat network with no zoning, and user accounts with excessive administrative privileges.

At PCS, we build security in layers. We match the technology to your budget — we deploy directory services based on Windows Server as well as on Linux servers free of costly licenses (Samba AD). We help organizations define and implement realistic security policies, eliminate plaintext password sharing with dedicated tools (such as Password Pusher) and train users to recognize phishing attempts.

Layers of protection

Four pillars of security engineering.

Protection is effective when the layers reinforce one another instead of working as isolated tools.

01

Hardware perimeter and isolated zones (Perimeter & VLAN)

We deploy advanced UTM / NGFW firewalls, often configured as redundant high-availability clusters (HA failover). We divide the infrastructure into logically separated networks (VLANs) — isolating workstations from production servers, databases, building automation (IoT/AV) and guest networks, and blocking lateral movement in the event of an infection.

  • UTM / HA clusters
  • VLAN segmentation
  • IPS / IDS
  • VPN tunnels with MFA
02

Directory services and strict access rules (AD, Samba, Policy)

We introduce centralized identity and permission management based on the principle of least privilege. We deploy and configure domain controllers on Windows Server or on Linux-based Samba — the latter removes the need to buy expensive CALs. We enforce password complexity policies and account lockouts after failed login attempts.

  • Samba AD
  • Windows Server
  • Least privilege principle
  • Restrictive GPOs
03

MFA, secure password handling and security hygiene

We close human and communication gaps. We enforce mandatory two-factor authentication (2FA / MFA) for email, cloud systems and VPN connections. We replace insecure ways of sharing credentials with encrypted, expiring links (such as Password Pusher). We help management define information security policies and run hands-on anti-phishing training for employees.

  • 2FA / MFA
  • Password Pusher
  • Procedure audit
  • Anti-phishing training
04

Immutable 3-2-1 backup and Disaster Recovery readiness

We build a backup policy that genuinely protects against encryption by ransomware. We follow the strict 3-2-1 rule: production data, a local copy and an immutable repository at a separate physical location (off-site / immutable storage / air gap). We regularly run test restores of systems, verifying in practice that the agreed recovery targets (RTO and RPO) are achievable.

  • 3-2-1 rule
  • Off-site / air-gap backup
  • Ransomware protection
  • RTO / RPO testing

Methodology and implementation process

From vulnerability audit to resilient architecture.

We don’t deploy tools blindly. We start with an inventory of the physical and logical state of your infrastructure, identify real threat vectors and harden the environment according to business priorities.

  1. 01Inventory and baseline audit

    We map the complete network topology, perimeter devices, workstations and servers. We verify firewall configurations, the permission structure in the domain (Active Directory / Samba), the state of physical network wall ports and whether network device firmware is up to date.

  2. 02Vulnerability and attack vector analysis

    We test the network’s resilience to lateral movement. We verify the actual isolation of guest networks, automation devices (IoT) and meeting rooms (AV). We assess credential hygiene, password-sharing procedures and the organization’s susceptibility to phishing.

  3. 03Hardening plan and gap remediation

    We categorize risks: from critical vulnerabilities requiring immediate action (no MFA on email and VPN, open high-risk ports, no isolated off-site backup) to long-term upgrades. We schedule the work so that the rollout doesn’t disrupt day-to-day office operations.

  4. 04Hardened configuration, deployment and testing

    We deploy firewall clusters, separate VLAN zones and introduce strict access policies, secure password handling and two-factor login. We close the project with hands-on backup restore tests (Disaster Recovery) and staff training.

+
What you receive after the audit

Every audit ends with a report: a description of your infrastructure’s current state, a list of identified vulnerabilities ranked by risk, and specific recommendations — from urgent fixes to a modernization plan. Depending on the scope of the contract, we can start implementing the recommendations right away.

Security architecture

One consistent policy.
Full zone isolation.

We integrate office devices, multimedia and critical
server infrastructure into one controlled ecosystem.
Between potential entry points and your key
data, we build a multi-layered barrier of filtering, inspection
and strict access rules.

Touchpoints and entry vectors
AV systems and Smart Office

Video conferencing cameras, codecs, touch panels and IoT devices.

Digital Signage and public displays

Media players, information kiosks and public information screens.

Workstations and remote access

Employee laptops, smartphones, VPN tunnels and internet traffic.

Control and inspection layerPCS SecureCoreHardware HA cluster · VLAN segmentation · MFA and domain policies (Samba / AD)

A central UTM firewall that filters every packet, blocks lateral movement and verifies user identity.

Protected assets and outcome
Server clusters and databases

Virtual environments (Proxmox/Hyper-V), ERP systems and sensitive SQL databases.

Immutable 3-2-1 backup (off-site)

Physically and logically separated (air-gapped) backup repositories that withstand ransomware.

Operational continuity (segmentation)

An environment that resists disruption — an incident in a meeting room doesn’t reach the servers.

A terminal running ZFS backup snapshot verification commands, with a server rack in the background
Tested RTO / RPOTested data restores from isolated repositories.

Business continuity and Disaster Recovery

A failure can happen. Downtime doesn’t have to.

A fire, a power outage, a failed storage array controller or a ransomware attack doesn’t have to paralyze your organization. We verify security in practice — we build contingency plans, design isolated repositories and regularly test system recovery procedures under time pressure.

  • Precisely defined RTO and RPO targetsTogether with management, we define two critical parameters: how much data the organization can lose without operational harm (RPO), and the maximum time within which key services must be back up after a disaster (RTO).
  • Immutable backups (WORM) and physical isolation (air gap)We use write technologies that prevent data from being modified or deleted (Write Once, Read Many). The off-site copy is separated from the domain, so compromising an administrator account alone is not enough to encrypt or delete it.
  • Regular restore tests in an isolated environment (sandbox)A backup that hasn’t been tested doesn’t exist. On a scheduled cycle, we boot virtual machines from backup in a separate, cut-off network, verifying SQL database consistency, file integrity and system startup times.
  • Incident response procedures (runbook)We create precise step-by-step instructions for the technical team and management. When a failure hits, nobody improvises — every engineer knows exactly which servers start first and who is responsible for communication.

When to start

Get security in order before an incident forces you to.

Most organizations call in specialists only after ransomware has encrypted their drives or the company database has leaked. We help you close vulnerabilities on your own terms — methodically, without panic and without bringing the office to a standstill.

01

Uncertainty about backups and DR procedures

Situation

Backups supposedly run, but no one has checked in months whether the virtual machines and SQL databases can actually be started from them.

What PCS does

We implement the strict 3-2-1 rule with an isolated (air-gapped) repository and run a trial restore of the environment, measuring the actual RTO and RPO.

02

A distributed team, no MFA and unchecked password sharing

Situation

Employees sign in to email and the corporate network with nothing but a password, and system credentials are sometimes sent by email or instant messenger.

What PCS does

We introduce mandatory multi-factor authentication (MFA), deploy secure password-sharing tools (Password Pusher) and put identity policies in order in Samba / Active Directory.

03

Expanding meeting rooms, Digital Signage or building automation

Situation

New conference codecs, information kiosks, IP cameras and presentation systems appear in the office, plugged into the same flat network as the computers and finance servers.

What PCS does

We configure physical and logical VLAN segmentation — isolating multimedia devices and the guest network, and blocking lateral movement to critical assets.

04

Regulatory requirements, cyber insurance or a business partner’s audit

Situation

A corporate client, an insurer or regulations (e.g., NIS2, GDPR) require formal documentation of security procedures, segmentation and network link redundancy.

What PCS does

We perform a baseline audit, harden hardware configurations, eliminate single points of failure (SPOF) and prepare complete technical documentation.

IT security auditLet’s talk about the resilience of your network and data.

Planning to roll out two-factor authentication, want to isolate meeting-room devices, or need a no-compromise backup policy that stands up to ransomware? Talk directly to one of our engineers.

  • MFA and network segmentation (VLAN)
  • Ransomware-resistant backup
  • Compliance with GDPR and KRI (Poland’s National Interoperability Framework)
  • Post-audit report with recommendations

Confidential conversation with an engineer
SLA clients:
emergency contact outside business hours