شركة أمن البيانات للأمن السيبراني

DataSec — Zero Trust SecurityRequest a consultation

Solutions & infrastructure

Network security & micro-segmentationA segmented network that limits the blast radius of any breach

We design, deploy and operate network protection layers from the perimeter down to the single workload, so one compromised device does not become a compromised organisation.

At a glance

Frameworks

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • CIS Controls
  • ISO 27001

Deliverables

  • Traffic flow and dependency map
  • Segmentation and zoning design document
  • Documented access policies and rule sets
  • Phased implementation plan with rollback
  • Operations documentation and knowledge transfer

The challenge

The NCA Essential Cybersecurity Controls (ECC) require network isolation, restricted inter-segment access and perimeter protection, and the Critical Systems Cybersecurity Controls (CSCC) require critical systems to sit in dedicated network zones. The SAMA Cyber Security Framework (CSF) expects internal, not just external, traffic to be monitored.

Most networks are flat inside: a strong firewall at the edge, then free movement behind it. That is why an attacker or ransomware moves from one workstation to every server within hours.

We build the network on zero trust: every device is identified before it connects, every zone is isolated, every sensitive workload has its own access policy, and the logs feed the SOC.

How we work

  1. 1

    Assess and design

    We map actual traffic flows between systems, define zones and trust levels, and design the segmentation architecture, access policies and logging requirements.

  2. 2

    Phased implementation

    We start in monitor-only mode to discover dependencies, then enforce policies zone by zone, with a rollback plan for each phase.

  3. 3

    Operate and review

    We hand over documentation, connect devices to the SOC, run or support day-to-day administration, and review rules periodically to remove what is no longer used.

What is included

  • Next-generation firewalls (NGFW)

    Design, deployment and management of firewalls with application and threat inspection and TLS decryption, plus periodic rule reviews.

  • IDS/IPS and NDR

    Intrusion detection and prevention plus network detection and response (NDR) to spot lateral movement and malicious connections inside the network.

  • Network access control (NAC)

    Device and user identification through 802.1X, with automatic classification and placement into the right network, including IoT and xIoT devices.

  • Micro-segmentation

    Workload-level access policies between applications and databases in data centres and cloud, to stop lateral movement.

  • SD-WAN and secure access

    Branch connectivity over software-defined WAN with unified security inspection, and VPN or ZTNA for remote access.

  • WAF, load balancing and email security

    Web application firewalls and load balancers, and email gateways with SPF, DKIM and DMARC plus attachment and link inspection.

  • Wireless security

    Wireless design with enterprise authentication, guest isolation and rogue access point detection.

  • SOC integration

    Forwarding firewall, NAC and NDR logs to SIEM, and building detection use cases for lateral movement.

Frameworks and regulations

We align the service with the frameworks your organisation is subject to.

  • NCA ECC
  • NCA CSCC
  • SAMA CSF
  • CIS Controls
  • ISO 27001

Frequently asked questions

Does micro-segmentation require replacing network hardware?

Usually not. Modern solutions work at the workload or hypervisor level, independent of hardware. We confirm this during assessment.

How do you avoid breaking systems when policies are enforced?

We start in monitor-only mode to record every real flow, then enforce gradually with a rollback plan and an observation period per zone.

Which vendors do you work with?

We work with several leading firewall, NAC and segmentation platforms, and choose based on your environment, your team's skills and existing investments.

Do you manage the devices after deployment?

Yes, through managed IT services and the NOC, or we hand over to your team with documentation and training.

What affects the cost and effort of a network security project?

The main drivers are the number of sites, zones and workloads in scope, how many firewalls, switches and access points are involved, and whether existing equipment can be reused. Undocumented traffic flows and legacy applications add discovery time, as does the number of phases you choose. Operation after deployment is scoped and priced separately.

What do you need from us to start?

Current network diagrams, firewall rule exports and an inventory of applications and the servers they run on, with critical systems marked. We also need read access to flow data or logs, contacts in the network and application teams, and your approved change windows.

Which NCA ECC requirements does this work support?

The Networks Security Management subdomain of the NCA Essential Cybersecurity Controls (ECC) sets minimum requirements that include physical or logical segmentation using firewalls and defence in depth, isolating production from development and test networks, intrusion prevention, wireless security, DNS security and protection against DDoS attacks. We document how the design and rule sets address each control that applies to you; whether you comply is decided at assessment.

  • Solutions & infrastructure

    Identity & access

    Unified identity, managed privileged access and MFA with a zero-trust approach.

  • Solutions & infrastructure

    Infrastructure

    Data centres, servers, storage and networks built to security standards from day one.

  • Detect & respond

    Network Operations Center (NOC)

    Network availability and performance monitoring, handling faults before users notice.

  • Detect & respond

    Managed SOC

    24/7 monitoring, analysis and response under an NCA licence.

Contact

Let's talk about what you need

We answer enquiries through the form, WhatsApp, a call or email.