Barakat helps organisations tighten firewall rules, segment flat networks, replace exposed RDP and SSH, and apply DNS controls that reduce avoidable exposure while supporting the technical-control expectations reflected in Sections 33 and 37 of Sierra Leone's Cyber Security and Crime Act, 2021 and the National Cybersecurity Policy 2021.
For organisations carrying open management ports, over-permissive rules, mixed guest and internal traffic, or undocumented remote access, this engagement turns network hardening into a clear compliance-readiness and risk-reduction programme.
Sections 33 and 37 of Sierra Leone's Cyber Security and Crime Act, 2021 address unauthorised access and unauthorised interference with computer systems. In practical terms, open management ports, weak remote access controls, overly broad firewall rules, and flat internal networks make those risks harder to contain.
The National Cybersecurity Policy 2021 technical measures pillar reinforces the need for practical technical controls, stronger risk management, and better protection across Sierra Leone's digital ecosystem. This engagement focuses on the preventive controls that reduce exposure before an intrusion or operational disruption forces urgent remediation.
Best suited to organisations where any-any firewall rules, publicly exposed management ports, flat networks, unmanaged branches, mixed guest and internal traffic, or undocumented remote administration paths are still part of the environment.
Public-facing services, inherited exceptions, and undocumented inbound rules quietly widen the attack surface over time. We review the rule base line by line so exposed pathways are understood, justified where necessary, reduced where possible, and removed where they no longer belong.
When users, servers, finance systems, CCTV, guest Wi-Fi, and branch links sit on the same trust plane, a single compromise can travel too far too fast. Segmentation limits lateral movement, reduces unnecessary trust relationships, and makes containment more realistic.
Public RDP and SSH remain among the quickest ways to invite unauthorised entry. We move administration behind controlled access paths so remote support remains practical without leaving critical systems openly reachable from the internet.
DNS control helps stop phishing destinations, malicious callbacks, and fake domains before a full connection is made. It also gives the organisation cleaner investigation data when suspicious traffic needs to be traced quickly.
Deliverables: Firewall audit report, cleaned firewall policy, zone and VLAN design, VPN and MFA setup, DNS filtering deployment, and monthly rule-review service.
Urgency: If public management ports, broad firewall rules, and flat internal networks are still in place, the organisation is carrying avoidable exposure that should be closed before the next compromise tests it.
Book Firewall & Segmentation Review