Virtuoso Technologies · Firewall & network security

Firewall and network security for small business in Surrey, BC

Your business line is being scanned right now — not by anyone who knows your name, but by machines working through every address on the internet looking for a door left open. A managed firewall is what decides which of those attempts ever reaches your floor.

blocked at the edge

Services › Firewall & network security

The internet, from your side

Someone is knocking, constantly.

A business line gets scanned around the clock by machines that have never heard of you. It is not personal, and it never stops.

Automated scanning24/7

01 — Volume

Most of it is noise. Some of it isn't.

Every one of those arcs is a connection attempt. You cannot sort them by hand, and the one that matters looks exactly like the rest until it lands.

Port scansCredential stuffing

02 — The perimeter

So nothing reaches the floor unfiltered.

A managed firewall inspects every connection before it touches a workstation. Known-bad is dropped outright; the rest is matched against policy.

Stateful inspectionIPSContent filtering

03 — Blocked

Blocked is a log line, not an incident.

Each one that dies at the perimeter costs you nothing. The same attempt past it costs you the week — which is the entire argument for the box.

Dropped at edgeLogged

04 — Quiet

And your staff never see any of it.

Reviewed monthly, in plain English, by the people who installed it. You get the summary, not the firehose.

Monthly reviewSurrey, BC

What you get

What a managed firewall includes

A firewall is not a box you buy once. It is a policy that has to be written, deployed and then kept current.

blocked at the edge

Business-grade firewall

Sized to your connection and your user count, configured to a written policy rather than shipped on defaults, and kept on current firmware.

Intrusion prevention

Traffic inspected against known attack signatures and dropped at the edge, before it reaches a workstation where it becomes your problem.

Content filtering

Categories you choose blocked for staff, with a report of what was blocked and why — not a silent block nobody can explain.

Secure remote access

A proper VPN for staff working off-site, so remote work never means exposing a desktop directly to the internet.

Network segmentation

Staff, guest, payment terminals and cameras separated, so one compromised device cannot reach everything else in the building.

Logging and monthly review

Logs retained and actually read, then summarised in plain English by the same people who configured the rules.

How it runs

How we secure a small network

Assessment first. We will not quote hardware before we know what is exposed.

01

Security assessment

We look at what is reachable from outside, what is unpatched, and which rules nobody can explain any more.

02

Design the policy

We write down what should be able to talk to what, and what should never be able to.

03

Deploy and cut over

Installed and switched over out of hours where a daytime cut would interrupt trading.

04

Monitor and review

Logs reviewed monthly, rules revisited as the business changes, firmware kept current.

Symptoms

What leaves a small business exposed

Almost none of these are exotic. They are the ordinary gaps attackers scan for, all day, automatically.

The difference

ISP router versus a managed firewall

The box your provider supplied is designed to give you internet, not to defend a business.

 ISP-supplied routerManaged firewall
InspectionBasic address translationStateful inspection plus IPS
UpdatesRarely, if everOn a schedule
PolicyWhatever the defaults wereWritten for your business
Remote accessPort forwardingProper VPN
VisibilityNoneMonthly plain-English report
When something happensYou hear about it from a customerWe see it in the log

Service area

Where we install and manage firewalls

On-site installation across the Lower Mainland, with monitoring, rule changes and reporting handled remotely from Surrey.

SurreyLangleyDeltaWhite RockBurnabyRichmondVancouverCoquitlamAbbotsford

Questions

Network security questions we get asked

Do small businesses in Surrey really get attacked?

Not targeted by name, no — which is exactly why it happens. Automated scanners work through every address on the internet looking for an open port or an unpatched service. Being small does not make you invisible to a machine.

Is the firewall built into my internet router enough?

For a household, usually. For a business it lacks intrusion prevention, meaningful logging, network segmentation and a proper VPN, and its firmware is often years behind.

What is a managed firewall?

A business firewall that somebody is responsible for: rules written to a policy, firmware kept current, logs reviewed, and changes made when your business changes rather than left as they were on install day.

What does intrusion prevention actually do?

It inspects traffic against signatures of known attacks and drops matches at the edge. It is the difference between a threat arriving at a workstation and never reaching your network at all.

Can staff still work from home safely?

Yes, over a VPN, which is the safe way to do it. The unsafe way — forwarding remote desktop straight to a PC — is one of the most common causes of ransomware in small business.

How often should firewall rules be reviewed?

Monthly for the logs and at least annually for the rules themselves, plus any time staff, premises or systems change. Rules accumulate, and old ones quietly become holes.

Next step

Let's see what you're running now.

One visit. We map what you have, tell you what is fine, and put a number against what is not. Nothing owed afterwards.

Book an assessment → or call 604-375-2629

Virtuoso Technologies Ltd.
Surrey, British Columbia
604-375-2629
virtuoso.services