Cyber Security Act 2021 Compliance

Firewall, Network Segmentation & Exposed Services

Barakat helps organisations tighten firewall rules, segment flat networks, replace exposed RDP and SSH, and apply DNS controls that reduce avoidable exposure while supporting the technical-control expectations reflected in Sections 33 and 37 of Sierra Leone's Cyber Security and Crime Act, 2021 and the National Cybersecurity Policy 2021.

Network boundary control, clearly defined

For organisations carrying open management ports, over-permissive rules, mixed guest and internal traffic, or undocumented remote access, this engagement turns network hardening into a clear compliance-readiness and risk-reduction programme.

Legal anchor

Sections 33 and 37 of Sierra Leone's Cyber Security and Crime Act, 2021 address unauthorised access and unauthorised interference with computer systems. In practical terms, open management ports, weak remote access controls, overly broad firewall rules, and flat internal networks make those risks harder to contain.

The National Cybersecurity Policy 2021 technical measures pillar reinforces the need for practical technical controls, stronger risk management, and better protection across Sierra Leone's digital ecosystem. This engagement focuses on the preventive controls that reduce exposure before an intrusion or operational disruption forces urgent remediation.

Best for

Banks NGOs Hospitals Law Firms Schools Mid-Sized Companies Ministries

Best suited to organisations where any-any firewall rules, publicly exposed management ports, flat networks, unmanaged branches, mixed guest and internal traffic, or undocumented remote administration paths are still part of the environment.

Deliverables

  • Firewall audit report
  • Cleaned firewall policy
  • Zone and VLAN design
  • VPN and MFA setup
  • DNS filtering deployment
  • Monthly rule-review service

Field work

  • Physically access the firewall or router where needed
  • Review cabling, switching, and current network design
  • Configure VLANs and switch ports
  • Test connectivity after changes so security improvements do not break operations
Firewall Review

Remove permissive rules and reduce exposed pathways before they are abused

Public-facing services, inherited exceptions, and undocumented inbound rules quietly widen the attack surface over time. We review the rule base line by line so exposed pathways are understood, justified where necessary, reduced where possible, and removed where they no longer belong.

Export and analyse the current rule base, identifying any-any rules, legacy exceptions, open management ports, unused NATs, and risky outbound traffic
Tie each surviving rule to a clear business purpose so management can see which exposure is justified and which is simply inherited clutter
Remove obsolete entries and tighten source IP ranges so remote administration and partner access are limited to what is actually needed
Placeholder illustration for firewall review and exposed services cleanup
Segmentation

Limit blast radius so one weak point does not expose the whole organisation

When users, servers, finance systems, CCTV, guest Wi-Fi, and branch links sit on the same trust plane, a single compromise can travel too far too fast. Segmentation limits lateral movement, reduces unnecessary trust relationships, and makes containment more realistic.

Separate departments and system types into zones or VLANs based on operational sensitivity and business need
Isolate finance from general office traffic, server subnets from user devices, guest Wi-Fi from internal systems, and CCTV or IoT devices from business systems
Isolate branches from headquarters where needed so a compromise or failure in one location does not automatically reach the whole network
Placeholder illustration for network segmentation and VLAN design
Secure Remote Access

Replace exposed RDP and SSH with controlled administration paths

Public RDP and SSH remain among the quickest ways to invite unauthorised entry. We move administration behind controlled access paths so remote support remains practical without leaving critical systems openly reachable from the internet.

Replace exposed public RDP and SSH with VPN or bastion access that is easier to govern and monitor
Enforce MFA and restrict admin login sources so privileged access is limited to approved people and approved locations
Document emergency access procedures so urgent maintenance does not create long-term security exceptions
Placeholder illustration for secure remote administration and VPN access
DNS Security

Block known malicious destinations and gain cleaner visibility into risky traffic

DNS control helps stop phishing destinations, malicious callbacks, and fake domains before a full connection is made. It also gives the organisation cleaner investigation data when suspicious traffic needs to be traced quickly.

Point network resolvers to Cloudflare Gateway or an equivalent service and create policy groups by department or site
Block malicious and phishing domains before users and systems complete the connection
Enable DNS logging for investigations and monthly review so management can see repeat exposure patterns and close them

Deliverables: Firewall audit report, cleaned firewall policy, zone and VLAN design, VPN and MFA setup, DNS filtering deployment, and monthly rule-review service.

Urgency: If public management ports, broad firewall rules, and flat internal networks are still in place, the organisation is carrying avoidable exposure that should be closed before the next compromise tests it.

Book Firewall & Segmentation Review
Placeholder illustration for DNS filtering and exposed services reduction

If the network is flat and remote access is exposed, the risk is already inside the perimeter

We can inspect the rule base, redesign the network boundaries, remove unnecessary exposure, and leave your team with a cleaner, safer, and more defensible network posture before the next intrusion turns into a wider operational problem.

Request a Compliance Review