Services / Access & Networking

The right people in.Everyone else out.

Firewalls, VPNs, Tailscale, MFA and zero-trust networking.

Most breaches we see are not clever. Someone reuses a password, an old account is never closed, an admin panel is open to the whole internet. Access control is the cheapest security work there is, and the most consistently skipped.

What you get

Private access to private things

Admin panels, databases and internal tools reachable over a private network rather than published to the internet and protected by a password.

A modern VPN that people will use

Tailscale and similar: connections that just work from a laptop at home, without the helpdesk ritual of the old corporate VPN.

Multi-factor authentication

On email, on hosting, on the domain registrar, on anything that can reset something else.

Least privilege

People get the access their job needs. Not everyone is an administrator, and the shared login everyone knows gets broken up.

Leavers closed off the same day

A written list of what to switch off when someone goes, so it takes minutes and nothing is missed.

Firewall rules that mean something

What can reach what, written down and reviewed, rather than accumulated over years by whoever needed something urgently.

How it works

  1. Find out who has whatAccounts, shared passwords, old logins, third parties. This list is almost always longer than expected.
  2. Close the obvious doorsUnused accounts removed, admin interfaces taken off the public internet, multi-factor turned on.
  3. Set up private accessSo the people who genuinely need the internal systems can reach them from anywhere, safely.
  4. Break up the shared loginsIndividual accounts, so you can tell who did what and remove one person without changing everyone's password.
  5. Write the joiners and leavers listOne page. What to create on day one, what to close on the last day.

Left alone, this is how it goes

What we get called about

None of these are hypothetical. They are the calls that come in, and every one of them is cheaper to prevent than to fix.

  • A shared password ends up in a chat message, then in a former contractor's notes.
  • Someone leaves under a cloud and still has the keys a month later.
  • The database is reachable from the whole internet because it was quicker that way once.
  • Nobody can tell which of five people made the change that broke something.
  • An old supplier account is still in your systems years after the contract ended.

Questions we get asked

What does "zero trust" actually mean?

That being on the office network doesn't automatically make you trusted. Every person and device proves who they are for each thing they reach. In practice, for a small business, it means private access and multi-factor authentication rather than a big product purchase.

Do we still need a VPN?

You need a private way to reach private systems. Modern tools like Tailscale do that without the old VPN's hassle, and they're usually easier for staff than what they replace.

Someone is leaving this week. Can you help?

Yes, and it's worth doing before the last day rather than after. Get in touch and we'll work through what they can reach.

Can you work with our existing IT support?

Yes. We do this alongside in-house staff and other providers regularly. We'll agree who owns what so nothing falls between you.

Got a technical mess?

Excellent. We like those.

Tell us what's going on. You'll hear back from a real person at Purple Imp.