Cybersecurity & Compliance

Managed cybersecurity & ISO 27001.

Grünex protects, monitors, detects, responds to and recovers from cyber threats — a managed Security Operations capability built on internationally recognised frameworks and delivered by a certified team.

What we offer

Cybersecurity services, end-to-end.

From offensive testing to fully managed protection and the compliance roadmap that gets you certified.

🎯

Penetration Testing

Ethical, real-world attack simulations on your apps, networks and infrastructure. Vulnerabilities are found, risk-prioritised and closed — with clear remediation guidance and re-testing to confirm the fix.

🛰

Managed Cybersecurity (SOC)

A fully managed Security Operations Centre as a service — continuous monitoring, threat detection & hunting, and rapid incident response, operating as an extension of your IT team.

🎓

ISO 27001 Training

Practical, accredited ISO/IEC 27001 ISMS training and security-awareness programmes that build internal capability and turn your team into your strongest line of defence.

📋

GAP Assessments

A clear-eyed audit of your current posture against ISO/IEC 27001 Annex A. We map exactly where you stand and produce a prioritised roadmap to close every gap.

🏅

ISO 27001 Certification Support

Hands-on guidance through the full journey — ISMS design, policies and procedures, risk treatment, controls and audit readiness — until your organisation is certified.

🛡

Hardening & Incident Response

System and network hardening, firewall management and structured incident response aligned to ISO/IEC 27035 and NIST SP 800-61 — to contain, eradicate, recover and learn.

SOC-as-a-Service

Your dedicated Security Operations capability.

We assume incidents are inevitable: controls prevent attacks where possible, while we rapidly detect and respond to threats that evade prevention — across the lifecycle of Prevent, Detect, Respond, Recover, Comply and Continuously Improve.

Prevent Detect Respond Recover Comply Improve

What's included

An integrated capability combining people, process, governance and technology into a single managed service.

  • 24/7 security monitoring & SIEM event correlation
  • Threat detection & hunting — MITRE ATT&CK mapped
  • Firewall, network & perimeter security management
  • Vulnerability management + penetration testing
  • Incident response — ISO/IEC 27035 & NIST SP 800-61
  • Endpoint & email security — anti-phishing, EDR, anti-BEC
  • Backup & disaster recovery — 3-2-1-1-0, immutable copies
  • Security governance, advisory, metrics & reporting
Threats we defend against

Modern attacks, mapped to controls.

Perimeter-only security is no longer enough — attackers exploit credentials, trusted apps, cloud and human error. We counter each with layered, defence-in-depth controls.

ThreatHow Grünex defends you
RansomwareIPS, endpoint protection (EDR), network segmentation, network detection & response, immutable/offline backups, patch management, tested incident-response & DR, and security awareness.
Phishing & BECEmail hardening (SPF, DKIM, DMARC), secure email gateway, URL protection & attachment sandboxing, MFA, executive-impersonation protection and user-awareness training.
Insider threatsRole-based access control, least privilege, network segmentation, user-activity & directory auditing, MFA and behavioural analytics.
Identity-based attacksZero-Trust identity, MFA, conditional access, ZTNA and endpoint-compliance verification.
Cloud risksSecure identity management, cloud-platform security hardening, continuous monitoring and centralised policy enforcement.
Advanced persistent threatsBehavioural network detection & response, proactive threat hunting and MITRE ATT&CK-mapped detection.
Business-continuity risksHigh-availability design, secure & immutable backups, disaster-recovery planning and testing, with RTO/RPO validation.
How we deliver

A controlled, phased methodology.

Our delivery follows PMBOK and ITIL service-management practice with ISO/IEC 27001, the NIST Cybersecurity Framework and ISO/IEC 27035 — a controlled path from initiation to a fully operational managed service.

  1. 01

    Initiation

    Kick-off, governance, communication plan, schedule and risk register established.

  2. 02

    Discovery & Assessment

    Network, firewall, server, identity, cloud, backup and policy review; asset inventory, security gap analysis and risk assessment.

  3. 03

    Solution Design

    Security & network architecture, segmentation, Zero-Trust, MFA, monitoring and disaster-recovery design — documented as high- and low-level designs.

  4. 04

    Implementation

    Hardened baselines and security controls implemented under formal change control, with minimal business disruption.

  5. 05

    Testing & Validation

    Firewall, VPN, authentication, segmentation, backup-recovery, incident-response and vulnerability validation, with an acceptance report.

  6. 06

    Knowledge Transfer & Go-Live

    Administrator training, SOPs, run-books and operational-readiness review so your team is confident from day one.

  7. 07

    Managed Security Service

    Continuous monitoring, response, threat hunting, vulnerability management, reporting, governance and DR reviews — with continuous improvement.

Technologies we operate

Best-in-class security platforms.

We design, operate and optimise the leading enterprise security technologies — managing what you already own and recommending enhancements only where they strengthen your posture.

Next-gen firewallsFortinet Security Fabric — FortiGate HA, FortiWeb (WAF), SD-WAN
SIEM & log analyticsFortiSIEM / FortiAnalyzer — correlation, alerting, forensics
Endpoint & EDREndpoint protection, FortiClient EMS, posture & compliance
Network detection & responseBehavioural analytics & proactive threat hunting
Identity & Zero TrustMicrosoft 365 / Entra ID, MFA, conditional access, ZTNA
Email securityMicrosoft 365 hardening & secure email gateway (anti-BEC)
Backup & DRImmutable / air-gapped backups, tested RTO/RPO recovery
Vulnerability managementScanning, patch verification, risk-based remediation

Technology names are referenced as platforms we operate and integrate; Grünex is vendor-independent and recommends the right fit for your environment and budget.

Standards & people

Aligned to global frameworks, delivered by certified experts.

Aligned to ISO/IEC 27001 27002 27035 NIST CSF NIST SP 800-61 CIS Controls v8 OWASP ITIL PMBOK

Delivered by a certified security team — CISM · ISO/IEC 27001 Lead Auditor · PECB Lead Cloud Security Manager · Fortinet NSE · Certified API Security Analyst · MSc Cyber Security & Digital Forensics.

Need to get certified, monitored or stress-tested? Talk to our security team →