Skip to content

Home Expertise / Network security

NET / NET-03

Network intrusion detection and prevention — IDS/IPS

An IDS observes and alerts on suspicious activity; an IPS can also block traffic when deployed in an enforcement position. The service deploys, tunes and connects these controls to a handling process.

WHEN IT HELPS

A focused response
to a defined need.

CIO with a firewall but limited detailed detection, SOC lacking network visibility or organisation needing interim protection for a vulnerable application.

AT A GLANCE

Family
Network security

Engagement
Implementation

Reference
NET-03

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Collection-point selection
  • passive capture or inline inspection
  • signatures
  • exclusions
  • detection-mode pilot
  • selective blocking
  • alert routing and triage

Deliverables

  • Visibility diagram
  • configuration
  • signature policy
  • exception register
  • non-destructive tests
  • monitoring dashboards
  • response and maintenance instructions

Acceptance evidence

Test events are identified and delivered; expected blocks are verified where included; agreed workflows show no regression; noise thresholds and exception procedures are accepted.

DELIVERY

How the work is structured.

Approach

Map traffic; design and size; pilot; migrate gradually with rollback; test and document operations.

Prerequisites & responsibilities

Customer: networking, applications, carriers, change windows and business acceptance. Provider: design, migration and tests. Third-party access and TLS inspection require suitable approvals.

Scope factors

Sites, actual inspected throughput, traffic, rules, remote users, availability and integrations. Hardware, security subscriptions and recurring operations are separate.

Questions to clarify

Which traffic is visible, including encrypted traffic? Who handles alerts? What business interruption could a false positive cause?

IMPORTANT BOUNDARIES

IPS does not replace patching. Unobserved or undecrypted traffic may remain partly invisible; enforcement must be approved and reversible.

Changes preserve essential services and recovery paths. Sizing, licensing and acceptance tests reflect the features that will actually be enabled.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A legacy application cannot be patched immediately. Project: enable targeted protection and monitor relevant attempts. Target outcome: reduced observed exposure for a defined period while the remediation programme continues.

Scenario 02

A group receives excessive sensor alerts. Project: review placement, deduplicate and tune rules with the SOC. Target outcome: actionable alerts and documented coverage rather than merely higher collection volume.

Technology and reference context

Examples: Palo Alto Networks threat-prevention profiles; IDS/IPS sensors suited to the traffic, subject to support and licensing.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.