SCNET · Enterprise IT · Ankara, Türkiye

Sanal Çekirdek

When layers are separate products, the space between them is undefended.

Endpoint, network, email and web are four doors an attacker passes in turn. Sanal Çekirdek treats them as layers of one defense architecture rather than four separate products.

When every layer has its own console, none of them knows what the others saw. That information gap is exactly where an attacker moves.

Endpoint: detection and response

Signature-based blocking is not sufficient on the endpoint; behavioral detection and remote response capability are required. Isolating a device, stopping a process and collecting evidence should all be possible from one interface.

  • Isolation can be applied remotely and quickly
  • Evidence is collected without powering the device down
  • Exception lists carry a reason and an expiry
  • Server and workstation policies stay distinct

Network: segmentation and visibility

On a flat network, one compromised device reaches everywhere. Segmentation raises the cost of lateral movement; traffic between segments opens only in the required direction and on the required ports.

  • Segments follow business function, not floor plans
  • Inter-segment rules are few and each is justified
  • Visibility into encrypted traffic is planned deliberately
  • The management network is separated from the user network

Email: the most used entry point

Most attacks still begin with email. Authentication records, attachment and link analysis, external sender marking and a user reporting path are built together — and a report must land in an analysis queue.

  • SPF, DKIM and DMARC are published and in enforcing mode
  • External senders are marked visibly in the interface
  • One click sends a user report into the analysis queue
  • Messages found late are retracted from mailboxes

Web and cross-layer coherence

Web access and the layer in front of the application must share the same identity and the same event stream as the other three. Coherence comes from events converging in one place, not from products sharing a brand.

  • Events from all four layers converge into one stream
  • Identity context carries across the layers
  • The same indicator does not differ between two consoles
  • Gaps between layers are tested on a regular basis

How we work

  1. Establish what each layer covers today
  2. Identify gaps and overlapping licenses
  3. Design network segmentation around business function
  4. Move email authentication records to enforcing mode
  5. Converge events into a single stream

How success is measured

  • Events from all four layers are visible in one place
  • Inter-segment rules are fewer, and each is justified
  • Email authentication records are enforcing
  • User reports reach the analysis queue

Frequently asked questions

One vendor, or best of breed?

What decides is not the brand but whether events can converge. A single vendor makes coherence easier; if different products are chosen, integration capability has to be a purchasing criterion.

Isn't antivirus enough?

It is necessary against known malware but not sufficient. Attacks that abuse legitimate tooling leave no signature, which is why behavioral detection and response capability matter.

What is the timeline for a segmentation project?

It runs in stages. The management network and critical systems are separated first; full segmentation widens step by step as application dependencies are mapped.

Let's establish what your four layers cover today and close the gaps between them together.

Map what your layers cover