Your people reach their work, and nothing else reaches in.

Staff get to the apps they need from any shop, home or site, on a device you trust. A lost laptop or a contractor who left in March is no longer a way in. We map what you run today, redesign it around who should reach what, and run it for you if that suits.

Every door in, and a lock that fits it.

Most businesses have several ways in, each opened at a different time to solve a different problem, and rarely closed again. We pull them into one design you can explain, built around who should reach what.

Route 01

The internal network.

Split into zones so a foothold in one area cannot spread across the rest of the network.

Route 02

Remote and home working.

Staff get to internal systems from a kitchen table, a shop floor or a hotel room, on a connection that is checked at every sign-in, not trusted once and forgotten.

Route 03

Links between your sites.

Shops, the warehouse and head office stay connected to each other and to what they share. Every link is documented and reviewed, so you know what it carries and can retire any that no longer earns its place.

Route 04

Contractor and third-party access.

Cut to the handful of systems the job actually needs, and set to switch off on the date the job ends.

Route 05

Internal apps, published externally.

The apps people need from outside the office, opened up one at a time so a user gets the app and never the network behind it. We do it with the tools already in your Microsoft subscription, no extra kit on site.

Route 06

Conditional access, the lock itself.

Who connects, from where, and on what device, settled before any of the five above will open. A personal laptop that misses your standard is turned away at the door, not cleaned up after it is already inside.

The network, remote working, contractor access. All designed together.

One set of rules you can read top to bottom.

Access decided by who you are, what your device looks like and where you are signing in from, written as one Entra policy instead of years of one-off exceptions. When a device shows signs of compromise, its access is withdrawn automatically, before anyone needs to report it.

The VPN wound down, one app at a time.

Staff open an app and they are in, with no client to launch, no tunnel that drops, and no waiting to reconnect when they move between home, a shop and the office. Each app opens on its own rather than handing over the whole network at sign-in. Where a tunnel still has to run for a while, we keep it tightly held on the kit you already own until the last thing that needs it has moved across.

Access that ends when the work does.

Contractors and partners get only the apps named in their agreement, on a device that meets your standard. Access closes automatically on the date you set at the outset, with no reliance on anyone remembering to remove it.

A straight read on every way in, and what to fix first.

No forms to complete first. We agree the direction on the call, and provide a quote once the scope is settled.

A contractor starts Monday, and is gone the day the job ends.

Invite

Added under their own company, not a personal email address.

They sign in with their own company account, so there is nothing of yours to hand over and nothing to take back. The apps they will touch are named in the invitation, and the end date is set before a single thing is opened.

Compliance

The device requirement is matched to the work, neither stricter nor looser than the job needs.

A quick task on one web app gets browser-only access, checked at sign-in. A longer stint that needs the code repository gets a managed device.

During

Only the apps they came in for will open.

They open the apps they were granted, from wherever they are. The rest of your network stays out of view.

Expiry

Access closes automatically on the date set in the invitation, with nothing left to remember.

The log holds what they opened, and when, with everything closing on the agreed date. Answering who had access, and over what period, becomes a quick query rather than a lengthy manual search.

Factor1 supplies and runs Fortinet firewalls at the network edge, watched around the clock.

The network is one piece. We look after the whole.

Under one agreement, the estate is watched, maintained and documented as a single thing, by the team behind this page.

Microsoft 365Networks & accessWindows ServerIdentityEndpoint securityBackup & DREmailDevices

…and everything between.

What a review leaves you with.

We assess every route into your systems against how the business actually operates, and give you three things you can act on within the week.

01
An up-to-date map of every way into your systems.
02
A set of access rules to assess every future request against.
03
A plan to close the old routes, the riskiest one first.
Centraline logo Built from scratch & fully managed by Centraline