SEC.ARCHSecurity Architecture

    Secure by Design

    Zero Trust segmentation, IAM on Keycloak, EntraID or AD, and a PKI you can still operate in ten years. Governance mapped to NIST CSF, ISO 27001 and SABSA.

    Why Security Architecture Matters?

    Architecture decisions compound. Segmentation, identity-first design and a PKI built to last a decade all pull in the same direction.

    01

    Defense in Depth

    Layered controls at every boundary. L2/L3 segmentation, identity-bound device trust and per-application MFA. One failure stops at the layer it happens in.

    02

    Zero Trust Identity

    Modern identity and access management with zero trust principles

    03

    Scalable Design

    Architecture that grows with your business while maintaining security

    04

    User Experience

    Passwordless authentication and risk-based MFA. Users sign in faster and IT handles fewer password resets.

    Our Security Architecture Services

    Architecture, identity and PKI work, from the design through to running it

    01

    Enterprise Security Architecture

    • Security framework design and implementation
    • Risk-based architecture planning
    • Security control selection and mapping
    • Compliance architecture alignment
    • Security governance and oversight
    02

    Identity & Access Management

    • Modern IAM platform implementation
    • Single Sign-On (SSO) solutions
    • Multi-Factor Authentication (MFA)
    • Role-based access control (RBAC)
    • Identity governance and lifecycle management
    03

    Zero Trust Architecture

    • Zero trust security model design
    • Microsegmentation strategies
    • Continuous verification implementation
    • Identity-based perimeter security
    • Adaptive access controls
    04

    PKI & Certificate Management

    • Multi-level Certificate Authority (CA) hierarchies
    • Root and Intermediate CA deployment
    • Certificate lifecycle management and automation
    • Hardware Security Module (HSM) integration
    • Private PKI infrastructure design and implementation

    Security Frameworks We Follow

    Every design decision is mapped to NIST CSF, ISO 27001, CIS Controls or SABSA. The mapping is written down while the design happens, so it is auditable from day one.

    • 01

      NIST CSF

      Risk-based posture across the five core functions: identify, protect, detect, respond and recover.

    • 02

      ISO/IEC 27001

      Global certification baseline for information-security management systems and continuous-improvement controls.

    • 03

      NIST 800-207 (Zero Trust)

      Reference architecture for identity-centric, deny-by-default access enforcement across every resource.

    • 04

      SABSA

      Business-driven security-architecture methodology spanning context, conceptual, logical, physical, and component layers.

    • 05

      TOGAF

      Enterprise-architecture framework with scope, governance, and the Architecture Development Method (ADM).

    • 06

      OWASP

      Application-security testing guides and verification standards. ASVS for requirements, the Top 10 for prevalence, SAMM for maturity.

    FAQ

    Frequently asked questions

    Straight answers to what clients ask us most.

    Zero Trust is a security model in which network location grants no trust. Access to each resource is authorised separately, on a per-session basis, by a policy that takes in identity, device posture and the context of the request. NIST published the reference architecture in August 2020 as SP 800-207. It sets out seven tenets and three logical components. The policy engine makes the decision, the policy administrator carries it out, and the policy enforcement point actually passes or blocks the traffic. In practice the VPN and the internal network stop being the trust boundary, and verified identity and device state take over that role. The document is free to download at csrc.nist.gov.

    Identity and access management (IAM) covers the lifecycle of an account from creation to removal, and the rules by which access is granted. It includes single sign-on, multi-factor authentication, joiner-mover-leaver processes with automated offboarding, PAM for privileged accounts and risk-based conditional access. The NIS2 Directive names multi-factor authentication outright in Article 21(2)(j), which makes it a statutory requirement. For factors we recommend FIDO2 or WebAuthn, because the key is bound to the origin and a phishing page cannot use it. SMS codes and push prompts have no such property. We work with Microsoft Entra ID, Keycloak and classic Active Directory. The directive text is on EUR-Lex.

    PKI is the system that issues, renews and revokes the certificates behind TLS, mTLS, device authentication and code signing. Manual management is running out of road because certificate lifetimes keep shrinking. In April 2025 the CA/Browser Forum adopted a schedule under which the maximum validity of a public TLS certificate is 200 days from 15 March 2026, 100 days from March 2027 and 47 days from March 2029. By 2029 a single service needs roughly eight renewals a year. Without automation through ACME or cert-manager that ends in a production outage. For a private CA, protecting the root key in an HSM belongs to the same job. Ballot SC-081v3 is published at cabforum.org.

    A move to Zero Trust is not a project with a deadline, it is a roadmap. We start with an audit and a target-state design, which takes 4 to 8 weeks. Then we go layer by layer through identity, device posture, microsegmentation, data and applications. First measurable results usually land inside three months, full coverage in 12 to 24 months.

    Yes, and it is visible in the text. Article 21(2) of NIS2 lists ten measures and most of them are architectural. Access control and asset management sit in point (i), cryptography in point (h), supply chain security in point (d) and multi-factor authentication in point (j). In the Czech Republic the same content is spelled out in the decrees to Act No. 264/2025 Coll., separately for the higher and lower obligation regimes. We therefore structure the architecture deliverable around those measures, so an auditor finds a concrete design decision against each one. The directive is on EUR-Lex, the Czech legislation on zakonyprolidi.cz.

    Build Security Into Your Foundation

    Don't bolt security on as an afterthought. Our architects design segmentation, identity and PKI into the build itself.