NET-SEC

NET-SEC cyber-security audit

NET-SEC is the rapid auditing of your entire network and infrastructure, using proprietary know-how of PALADIN

Secured network

The service is basically a virtual, fast audit of the entire ICT infrastructure of your company, done or redacted by a Senior Network Technicians, with other 30 years of experience worldwide.

Who needs it?

Any company or organization that:

  • Has even the slightest doubt that their network may not be fully safe;
  • Wants to verify that their network cannot be intruded;
  • Has been attacked before, and not entirely sure how that has happened;
  • For any reason, has some doubts about ICT that wanna clear up;

My network is perfect, I have firewall and antivirus, I don't need this check.

By being veterans of the business, this is the most common answer we get. Let us tell you a real case that has happened, but there may be other 50 stories like this one. One of the production units of a large organization (they have units all over the world) was the affected side. Paladin did not do an audit, but randomly discovered a tiny but important safety concern. This was reported to their HQ ICT, at which the "default" answer above was given. Long story short, after about 1 year they were heavily hacked and lost all information of the past 17 years, including all backups, email, database of their ERP system, drawing archive etc. The entire unit had to be suspended for over 10 days. At the end they had no choice but to pay roughly 60,000 EUR in ransom to decrypt their data. This money just add to the huge damages done to reputation and economic damages due to suspension of production. The moral is: you don't wanna be "that guy", having someone, anyone have a look at your infrastructure and point out the major issues can save so much trouble along the way.

I already have company XYZ who follows me up.

We are fundamentally also an IT service company, but we're often being scrutinized by other consulting companies. This mutual check is what allows both sides to grow up and recommend ever better solutions to our customers, by keeping up to date with state of the art techniques. The client in the middle only has to benefit from this. Hackers do not sleep, they think every day new ways to enter your network. We guess the moral is: do not just sleep on it because you think someone else (your provider) is on it, have some third party sporadically have a spot check. Even quality certification agencies and norms prescribe these kind of checks as mandatory.

How exactly the service is performed?

The Technician organizes a video conference meeting with the company or organization, for two places (China and Italy) we have staff that can eventually meet the client in person. Usually material is required first, like videos and photos of network and IT room, network diagrams (even sketches or temporary ones) and by talking to IT staff of the client. Usually when data provided are sufficient, the onsite inspection is not even necessary as it won't change the value or veridicity of the final report, nor affecting the standards.

Do you need the password or access to any of our devices?

Absolutely not, and let us just add, whoever ask for this you should be extremely wary. Paladin signs a confidential agreement within any of its contract, but for the first report, and even for the eventuality of working for a new implementation, there is very rarely the need to have any access to current devices.

What is the difference between a full inspection and this service?

Thanks to the experience of the techicians involved, this rapid inspection is able to provide a very good approximation of all the weak points (with a guaranteed precision of 99%), all without having to spend an enormous amount of money and time asking for a full-blown inspection. This is usually done in the hope to obtain 100% accuracy, which is never possible anyway. All those who have worked in the industry long enough will vouche for that. Is not only a technical issue, but often an economic one as well.

Is it possible to view the questionnaire in advance?

Because the questionnaire is an integral part of the know-how, it is possible to view it only after having signed the contract and made the down-payment.

What do the customer get receive?

The customer receives a formal report, signed by the company, with all details of the findings and recommendation. The report is signed by the technician who performs it, who remains in touch with the customer for the whole duration of the assessment and reporting.

Is it also possible to recommend a solution?

Paladin does not require the customer to have any sort of additional work or follow up, but it is entirely up to the customer to decide so. If the customer likes to work with Paladin, a formal recommended solution can be quoted and offered, in which new network diagrams and overall ICT structure diagrams may be provided, along side make and model for each device involved. Paladin can also work on standards if the customer has any, such as a preferred brand or set of brands. The customer is free to use the audit report as he pleases, even showing it to other supplier of services.

What is the price of this service?

These are the tariffs as of April 2024:

  • Company/organization with less than 20 people: 15,000 RMB (taxes included)
  • Company/organization with less than 50 people: 29,000 RMB (taxes included)
  • Company/organization with less than 100 people: 59,000 RMB (taxes included)
  • Company/organization with more than 100 people: Contact us directly for an offer.
  • Payment terms are:
    • 50% down-payment at the order
    • 50% settlement before delivery the full report (as evidence, the first 3 pages are delivered first)