vandenbunt.com
Infrastructure / Secure

Infrastructure & application security

It doesn't get you breached.

Hardening, audits, access control and a written path for the day something goes wrong. Applied per layer, and re-checked whenever the system changes — because that is when it slips.

01

Where security is applied

Defence in depth, from the OS firewall up to application access. Each layer is built assuming the one below it has already failed.

Hardening
OS firewalling, SSH key policy, network isolation and service sandboxing.
Vulnerability audits
Dependency scanning, configuration review and patch management on an agreed rhythm.
Access control
Least privilege, multi-factor authentication, and access logs someone actually reads.
Incident response
A written containment path, forensic logging, and a follow-up that says what changed.
02

Our security baseline

What we apply by default, before anything specific to your environment. All of it is re-checked whenever the system changes.

Zero-trust network boundaries
Encrypted in transit and at rest
Automated patch monitoring
A written incident path, agreed before it is needed

An audit costs less than an incident.

We look at what is exposed, what is unpatched and who has access, then write it down. We do not run a 24/7 security operations centre and will not pretend to — what we do is make the system harder to get into, and the path clear when someone tries.