Firewall and access management
Firewall rules and access management ensure that only authorised people reach your servers, admin areas and APIs.
Common points of entry
Many security incidents start with an open port, a shared password or a former contractor's access. A data leak may trigger reporting duties under the GDPR.
Network and servers
a firewall that opens only the ports needed, usually 80 and 443
SSH with keys only, no password log-in and no direct root access
databases and other sensitive services closed to outside access
automatic blocking after repeated failed attempts
Admin areas
CMS back ends and admin interfaces are protected with two-factor authentication and, where possible, restricted to specific IP addresses or a VPN. Roles and permissions follow the principle of least privilege.
API security
Interfaces get their own scoped keys rather than personal credentials. Keys can be revoked individually and rotated. Rate limiting caps requests.
Contractor access
Contractors get personal, time-limited access that ends with the contract. Passwords and keys are kept in a password manager.
Approach
We first list all access to servers, CMS, hosting accounts, registrar and external services. Unneeded access is removed, the rest documented and reviewed with you regularly.
The measures follow ISO 27001 processes without requiring certification.