
Your firewall is active — but does it really protect against modern attacks?
Multi-layered protection against modern cyber threats
Next-generation firewalls, EDR/XDR solutions and centrally managed antivirus protection — for companies of every size.
Anonymized reference caseMid-sized machine builder · Rhine-Main region, 85 employees+
Starting point
Outdated UTM firewall, no EDR on endpoints, email filter letting phishing through.
Solution & result
Replacement with a Fortinet next-gen firewall, CrowdStrike EDR on all 85 endpoints, Microsoft Defender for email.
Within the first 30 days: 1,240 threats blocked, 3 phishing campaigns detected — no infections.
Standard firewalls no longer protect against modern attacks
- Conventional firewalls only analyze ports and IPs — modern attacks disguise themselves as legitimate traffic
- Without EDR on endpoints, the firewall is useless as soon as an employee opens an infected attachment
- Email is the #1 attack vector — without AI-based analysis, phishing emails land in the inbox
Multi-layered protection that leaves no gaps
- Next-gen firewall with deep packet inspection, IPS and application control — detects encrypted attacks too
- EDR/XDR on every endpoint: behavior-based detection stops unknown malware in real time
- Email security with sandboxing: suspicious attachments are executed in an isolated environment before they arrive
Scope of services
What Firewall & Antivirus does for you
Next-Gen Firewall
Modern firewalls with deep packet inspection, intrusion prevention and application control.
EDR/XDR
Extended endpoint detection and response for real-time, behavior-based threat detection.
Email Security
Anti-phishing, anti-spam and sandbox analysis for all incoming and outgoing emails.
DNS Protection
DNS filtering to block malicious domains, malware distribution and C2 communication.
Central Management
A single management console for all security solutions — clear and efficient.
24/7 Alerting
Immediate alerts for detected threats with defined escalation processes.
Approach
How we work
Inventory
Analysis of the existing security architecture and identification of gaps in the protection concept.
Concept
Development of a multi-layered security concept that fits your infrastructure and budget.
Implementation
Installation and configuration of all protection solutions with minimal business disruption.
Operations & Monitoring
Ongoing monitoring, rule updates and proactive response to new threats.
In the first 30 days after switching to CrowdStrike and Fortinet, we counted over 1,200 blocked threats — with the old firewall, all of them would have gotten through.
Defense in Depth
4 layers of protection —
no attack surface
A single firewall is no longer enough. Modern attacks overcome any single layer of protection. Only a multi-layered defense holds up.
Layer 1
Perimeter Firewall
A next-gen firewall with deep packet inspection blocks attacks before they reach your network.
Fortinet · Palo Alto · Sophos
Layer 2
Email Security
Anti-phishing, sandboxing, and DMARC/DKIM/SPF eliminate the No. 1 attack vector.
Microsoft Defender · Proofpoint
Layer 3
Endpoint EDR/XDR
Behavior-based AI detects unknown malware in real time on every device.
CrowdStrike · SentinelOne · Sophos
Layer 4
DNS Protection
DNS filtering blocks connections to malware servers before any damage is done.
Cisco Umbrella · Cloudflare Gateway

Technology Partners
We recommend what fits — not what pays a commission
Vendor-independent advice. We work with the market leaders and make recommendations based on your requirements.
Fortinet FortiGate
Firewall
Best performance, UTM, integrated SD-WAN
Ideal for: SMEs & German mid-sized companies (Mittelstand)
CrowdStrike Falcon
EDR/XDR
AI-based, cloud-native, industry-leading
Ideal for: Companies with 20+ employees
Sophos Central
Firewall + EDR
Synchronized Security, easy management
Ideal for: Entry level & SMEs
Microsoft Defender
Email + Endpoint
Integrated with M365, no extra agent needed
Ideal for: M365 customers
SentinelOne
EDR/XDR
Automated remediation, high detection rate
Ideal for: Security-focused organizations
Palo Alto Networks
Firewall
Enterprise-grade, Zero Trust, SASE
Ideal for: Large enterprises
4 questions you should answer now
?Are legacy authentication protocols disabled?
?Does every endpoint have active EDR protection?
?Are email attachments analyzed in a sandbox?
?Is DNS filtering active for all users (including remote workers)?
If you answer even one question with "No" or "I don't know" — talk to us. Free security check →
Frequently asked questions
Everything you need to know about Firewall & Antivirus at a glance.
01Which firewall solution do you recommend?+
For SMEs with 10–100 employees, we recommend Fortinet FortiGate — best performance, central management and excellent value for money. For special requirements, we also use Sophos, Palo Alto or Check Point. The recommendation depends on your infrastructure.
02What is the difference between antivirus and EDR?+
Classic antivirus compares files against a library of known malware — it cannot detect unknown malware. EDR (endpoint detection & response) analyzes the behavior of all processes in real time and stops attacks even when there is no known signature. For companies with 10 or more employees, EDR is the minimum standard today.
03Can existing devices continue to be used?+
In most cases, yes. EDR agents run on Windows 10/11, macOS and Linux. The new firewall only replaces the existing appliance. In the assessment, we check which components need to be replaced.
04How much does a complete protection package cost?+
For a company with 20 employees: Fortinet firewall from €2,400 one-time + CrowdStrike EDR from €25/endpoint/month. Complete protection including email security typically costs €800–1,500/month. Binding quote after a free assessment.
05How long does implementation take?+
Firewall replacement: a one-day maintenance window (Friday night). EDR rollout to all endpoints: 2–3 hours, fully automated via group policy. For 50 endpoints, the full switchover is completed in 2 business days.
06What happens when an attack is detected?+
EDR automatically isolates the affected device from the network within seconds. You are notified immediately. Our team analyzes the incident and coordinates the response — within 30 minutes, depending on your SLA.
Free assessment workshop — no obligation
In 60 minutes, we analyze your current situation and show you exactly which solution makes sense for your business — with a binding quote within 5 business days.