Services / Security Engineering

Security Engineering

Security controls,
built to keep up.

Design, implement and run the controls that keep your environment secure as it changes.

  • Design & implementation
  • Cloud & infrastructure engineering
  • EDR / MDR
  • SIEM
  • IAM
  • Email gateway
  • Secure file transfer

Security controls we deploy, connected around the Insyghts shield

  • IdP — Identity provider
  • EDR — Endpoint detection & response
  • PAM — Privileged access management
  • Cloud — Cloud security
  • SIEM — Log monitoring & correlation
  • MFT — Secure file transfer
  • IAM — Identity & access management
  • DLP — Data loss prevention
  • MFA — Hardware security keys
  • PKI — Certificate authority
  • Email — Email security gateway
  • Segmentation — Network segmentation

Technologies and partners

Systems integrator or vendor? We can deliver for your customers.

Design, deployment and ongoing support by our Singapore team, under your brand or ours.

The engineering gap

Installed isn’t the same as working.

Most security tools are bought for good reasons. Many are then left on default settings, half-deployed or unwatched once the project team moves on.

  • Tool purchased
  • Not tuned

Running on defaults

Features you paid for stay switched off, and alerts go unread.

  • Installed
  • Effective
  • Logs collected
  • Not correlated

Data without insight

Logs sit in separate systems, so no one sees the full picture.

  • Collected
  • Correlated
  • Access granted
  • Not reviewed

Accounts that never expire

Leavers’ accounts, shared admin logins and missing MFA quietly widen the attack surface.

  • Granted
  • Controlled

Security engineering keeps your controls configured, connected and current.

What we do

Controls across your environment, built to work together.

From identity to the cloud, we design and implement each control, then connect it to the rest.

Across every engagement

Design & implementation

Architecture, deployment and handover for security controls across on-premises, cloud and hybrid environments.

  • Architecture and build plan
  • Deploy, configure and test
  • Hardening to secure baselines
  • Documentation and runbooks
Isometric illustration: server racks linked to a padlocked security core, with a gear

Cloud & infrastructure engineering

Secure-by-design builds and hardening for servers, networks and cloud platforms.

  • AWS
  • Azure
  • Hybrid

Endpoint detection & response

Deploy and tune EDR across servers and devices, with MDR monitoring if you need it.

  • EDR
  • MDR
  • TrendAI

SIEM & log management

Collect syslog and event data, then correlate it into alerts your team can act on.

  • SIEM
  • Syslog

Identity & access

Strong authentication, least privilege and controlled admin access, including hardware keys and smart-card management.

  • IAM
  • PAM
  • MFA
  • YubiKey
  • vSec:CMS

Email security gateway

Filter phishing, malware and spoofed senders before they reach inboxes.

  • Email gateway
  • Proofpoint

Secure file transfer

Managed, audited file exchange with partners, customers and systems.

  • GoAnywhere MFT

Network segmentation & hardening

Separate critical systems and harden configurations, so an intruder can’t move freely.

  • Firewall
  • Segmentation
  • Zero trust

Data protection & recovery

Data loss prevention, backup and recovery plans for data at rest, in use and in motion.

  • DLP
  • Backup
  • Recovery

Security automation

Automate routine checks and response steps, and build security into DevOps pipelines.

  • SOAR
  • Scripting
  • DevSecOps

In practice

What we’ve implemented, and still run.

Engagements we’ve delivered, from a single control to a managed stack. Select one to see the challenge, what we built and how we run it.

  • Client engagement
  • Challenge
  • What we built
  • How we run it

Financial services

Implemented

Migrating email security to Proofpoint SaaS

  • Proofpoint SaaS
  • Email gateway
  • Rule migration

An on-premises email security gateway was due for replacement, and the business relied on the filtering rules built up in it over the years.

Moved the organisation to a Proofpoint SaaS instance, migrated every rule from the old system and cut mail flow over for more than 3,000 users.

We provided the project manager and deployment engineers, from planning and testing through cutover and handover.

More than 3,000 users moved to Proofpoint with zero downtime, and every rule carried across.

Utilities

Implemented

A new certificate authority and hardware MFA

  • Certificate authority (PKI)
  • YubiKey
  • Hardware MFA

Sign-ins relied on passwords, and there was no internal certificate authority to issue trusted certificates to users, devices and systems.

Designed and built the complete certificate authority (CA) infrastructure for issuing, renewing and revoking certificates, then rolled out YubiKey hardware keys for multi-factor sign-in.

Handed over with documentation and runbooks for issuing certificates and replacing lost keys.

Sign-ins are protected by hardware keys, backed by the organisation’s own trusted CA.

Insurance

Implemented & managed

Endpoint protection, watched 24/7

  • TrendAI EDR
  • MDR
  • 24/7 SOC

Several antivirus products across offices, no central view and nobody watching alerts after hours.

Rolled out TrendAI endpoint detection and response, removed the legacy agents and tuned detection policies for staff devices and servers.

Alerts go to our 24/7 security monitoring, with monthly tuning and health checks.

One console covers every endpoint, and alerts are followed up around the clock.

Manufacturing

Implemented

Splitting a flat network into zones

  • Firewall
  • Segmentation
  • Jump hosts

Office laptops, servers and production systems shared one flat network, so one infected device could reach everything.

Designed user, server, management, production and guest zones, with firewall rules and jump hosts for admin access, rolled out in stages.

The client’s team runs the network day to day, and we review rules and changes each quarter.

Critical systems can only be reached from approved zones and hosts.

Systems integrator

Partner delivery

White-label delivery for an SI’s customer

  • EDR
  • SIEM
  • Email gateway

An integrator had won a security project but didn’t have engineers free to deliver it.

Our team designed and deployed the controls under the integrator’s brand, following their project method and documentation templates.

We provide second-line support behind the integrator’s service desk.

The integrator delivered on time without hiring, and kept the customer relationship.

How it connects

Every control feeds the bigger picture.

We engineer controls to share their data, so your SIEM and our 24/7 security monitoring see the whole environment, not isolated tools. Select a control to see what it contributes.

  • Control
  • Sends to the SIEM
  • Platforms we work with

Identity

IAM · PAM · MFA

Identity & access

Who can sign in, with what, and to which systems.

Sign-ins, privilege use and failed MFA attempts.

  • YubiKey
  • vSec:CMS
  • RCA
  • PKI
  • FIDO2

Endpoints

EDR / MDR

Endpoint detection & response

Protection and visibility on every server and device.

Process, file and threat detections from each endpoint.

  • TrendAI
  • Sophos

Email

Security gateway

Email security gateway

The first filter for phishing and malware.

Blocked phishing, malware and spoofed senders.

  • Proofpoint
  • TrendAI

Network

Firewall · segmentation

Network segmentation & firewalls

Boundaries that limit how far an intruder can move.

Firewall logs, denied connections and unusual internal traffic.

  • Akamai
  • Palo Alto Networks
  • Fortinet

Cloud & servers

AWS · Azure · hybrid

Cloud & infrastructure

Secure builds for servers and cloud platforms.

Audit logs and configuration changes.

  • AWS
  • Azure

File transfer

Managed file transfer

Secure file transfer

Managed, audited exchange with partners and systems.

Transfer audit trail and failed logins.

  • GoAnywhere

Correlate

SIEM

Syslog and events from every control, turned into alerts.

Insyghts Security client dashboard showing tickets by status, resolution reasons, SLA met percentage, status by priority and time to close

Act · 24/7

Security monitoring

Backed by people, supported by AI.

Explore Security Operations →

Ways to work with us

Engineering, the way it fits your team.

Start with a single project, hand us the day-to-day, or bring us in behind your own brand.

Isometric illustration: blocks on a platform under a document

01 · Project

Project delivery

Scoped design, deployment and handover, with documentation your team can run.

Best forNew controls, migrations and upgrades

Isometric illustration: two server racks with a turning gear

02 · Managed

Managed engineering

We keep your controls tuned, patched and reviewed after go-live.

Best forTeams without spare engineering time

Isometric illustration: two blocks linked by a data arc under a handshake

03 · Partner

Partner & white-label delivery

Design, deployment and support for your customers, under your brand or ours.

Best forSystems integrators and vendors

Isometric illustration: four people on a platform under a tick

04 · Augment

Team augmentation

Engineers from our Singapore team, working inside yours for a set period.

Best forPeaks, projects and cover

How it works

From design to day-to-day running.

Engineering doesn’t stop at go-live.

Environments change every week. Each review feeds the next change, so your controls keep matching how you actually work.

Assess

Review your environment, current tools and gaps.

Design

Architecture and a build plan matched to your risks and budget.

Build

Deploy, configure and test, under your change control.

Hand over

Documentation, runbooks and knowledge transfer to your team.

Run & improve

Tune, patch and review, yourselves or through our managed service.

What we do

  • Design and document the architecture
  • Deploy, configure and test each control
  • Tune, patch and review, if you choose managed engineering

What you own

  • Approve designs and change windows
  • Provide access and system owners
  • Decide which risks to accept

Who does the work

Built by our Singapore team.

Singapore-based

Delivered by our Singapore team. No foreign team augmentation.

Held by our team

Partner certifications

Connected and continuous

Controls need direction, and eyes on them.

Engineering builds the controls. Our other services set their direction and watch them around the clock.

Resources

See what an attacker would see.

Start with a quick look at what’s exposed.

Isometric illustration: blocks on a platform under a magnifier

Stage 01 · Just starting

Domain scan

Understand your exposure.

Isometric illustration: buildings on a platform scanned by a radar

Stage 04 · Mature, want to improve

Attack surface assessment

Find and close gaps.

Coming soon

Flowing cyan and blue ribbon artwork

What do you need to build or fix next?

Tell us about your environment and the controls you’re planning, and we’ll suggest a starting point.

Enquiry