Skip to content
ORMUS

Operations and support

Cybersecurity

Finding and closing the weak points, and being ready for the incident.

ID
OP-01
Rollout stages
05

What the client gets

  • A prioritised vulnerability report and a remediation plan
  • An access-rights audit, with excess permissions revoked
  • Backup and restore procedures tested for real
  • A written incident response plan

The business problem

Security usually gets taken seriously after an incident. Until then the picture is familiar: old versions never updated, everyone sharing one admin password, a departed employee’s access still live, and nobody has ever checked whether the backup restores.

What we build

We start by assessing where things stand: which systems exist, who has access to what, which data is most valuable. Weak points are then ranked by priority — instead of fixing everything at once, we close the ones carrying real risk first. Finally an incident plan is written: who does what, when, and who gets told.

Rollout stages

  1. 01

    Audit and analysis

    We assess the state of the infrastructure, the access rights and the applications.

  2. 02

    Architecture and design

    We rank the risks and agree the fix order against business priorities.

  3. 03

    Development

    We apply the fixes: updates, access control, network segmentation, logging.

  4. 04

    Pilot operation

    We rehearse an incident scenario and check that the plan actually works.

  5. 05

    Handover and training

    Documentation, procedures and team training are handed over.

Possible integrations

  • Active Directory / LDAP
  • Keycloak
  • Two-factor authentication
  • Nginx / WAF
  • Prometheus / Grafana
  • SIEM systems

Security approach

Assessment work runs inside an agreed scope and on the basis of written authorisation. Findings go only to the people you designate. Testing environments take priority; work on live systems happens outside business hours and with a rollback plan.

Ongoing support

Security is not a one-off: periodic reassessment, patch tracking and a quarterly review of access rights run continuously.

Related services

Consultation on this practice

Describe your situation briefly — we will outline the options and the first step.