A firewall that someone actually watches
Installing it isn't enough. Someone has to review the logs, apply the patches and respond when something happens at three in the morning.
Book a 15-min call See all servicesThe cost of leaving it as it is
These are the consequences we see most often when this isn't addressed in time.
One compromised device inside the network reaches all the others
Unapplied patches leave open a door that's already known and published
When the incident happens, nobody knows what happened because nobody was watching
What's included
The scope is set in writing before we start. No surprises at billing time.
- Initial policy configuration by segment and by user
- Firmware and threat signature updates
- Event monitoring and configured alerts
- Remote access and VPN rules for your staff
- Monthly report of what was blocked and why
How we do it
Four steps, in this order, with an assigned owner from start to finish.
We survey what's there today: equipment, version, active rules and who set them
We define the policy by department, not one generic rule for everyone
We apply, document and give you the configuration in writing
It stays under monitoring with an assigned owner
What happens every month, not just on day one
Installing a firewall is a day's work. Keeping it running is what you're buying here. This is what happens month after month, whether or not there are incidents.
You ask, we evaluate and apply
Every new rule is logged with the date, who requested it and why. If a change opens a risk, we tell you before applying it, not after.
There's a written procedure and an assigned person
We don't improvise at three in the morning. Each type of alert has a procedure defined in advance and someone with a name who responds.
Firmware and signatures up to date, in an agreed window
They're applied when due and during the hours you authorized, not whenever someone remembers or in the middle of your month-end close.
Who manages the device and with which account
Named accounts with two-factor authentication, not a shared password. Every quarter we review who still has access and who shouldn't anymore.
Configuration backup before and after
If the device dies, the configuration is restored. It's not rebuilt from memory or started from scratch.
A monthly report you can understand
What was blocked and where it came from, what changes were applied and who requested them, firmware and license status, and what we recommend fixing.
Who does what
Most problems in a managed service aren't technical: they're about expectations. This is written into the contract, not left to a conversation.
We're responsible for
- Designing and applying security policies
- Firmware, threat signatures and expiration tracking
- Event monitoring and alert response
- Configuration backup before and after each change
- Up-to-date documentation of everything that's configured
- The monthly report and the review meeting
You're responsible for
- Approving changes that affect business operations
- Keeping the manufacturer's support and licenses current
- Designating who is authorized to request changes
- Providing site access and stable power for the equipment
- Letting us know when you open a location or change the network
- A reachable contact for after-hours incidents
Managed or co-managed
Not every company needs the same thing. If you already have IT staff, we're not going to replace them.
Managed
We run the firewall from start to finish. For companies without IT staff, or with staff who already have too much on their plate. You ask, we execute and report back to you in writing.
Co-managed
Your IT team keeps access and control. We bring the security expertise, continuous monitoring and a second pair of eyes. Changes are coordinated, not imposed.
Committed response times
We publish the times because they're part of the contract. A provider that doesn't tell you how fast it responds isn't committing to anything.
| Situation | We respond within | We resolve or mitigate within |
|---|---|---|
| Device down or network with no Internet access | 1 business hour | 8 business hours |
| Security incident in progress | 1 business hour | 8 business hours |
| A rule is blocking work | 4 business hours | 2 business days |
| Planned change | 1 business day | In the agreed window |
| Question or report request | 1 business day | 3 business days |
Coverage during Panama business hours: Monday to Friday, 8:00 to 5:00, excluding holidays. These times are written into the contract before you sign anything. We'd rather commit to hours we can sustain than promise a night shift we don't have.
What's not included and which brands we work with
Telling you from the start where the service ends avoids an awkward conversation six months from now.
Out of scope
- Manufacturer licenses and support: quoted separately or maintained by you
- Cabling, switches, access points and anything that isn't the firewall
- Workstation antivirus, server backup and data recovery
- Replacement of out-of-warranty hardware
- Development or support of the applications running behind the firewall
Brands we manage
If you already have equipment with current support, it stays. We don't sell you new hardware just to be able to service it.
- Fortinet
- Sophos
- SonicWall
- Palo Alto
- Cisco / Meraki
- pfSense
- OPNsense
Frequently asked questions
Do I have to buy new equipment?
No, if what you have is still under manufacturer support and gives you the performance you need. In the survey we tell you frankly: if it works, it stays; if it no longer cuts it, we explain why with numbers, not with fear.
Do you see my company's traffic?
We see connection logs and security events — which device connected where and what was blocked. We don't read the content of your emails or files. A confidentiality agreement is signed before the survey.
What happens if one day I want to leave?
We give you the documented configuration and the administration credentials. No holding your configuration hostage and no leaving you dependent on us to be able to change providers.
Does this help me comply with Law 81?
It helps, quite a bit: it gives you demonstrable technical protection measures and a monthly report that serves as evidence in an audit. But Law 81 covers more than the network, so on its own it isn't full compliance. We tell you straight instead of selling you a guarantee nobody can give.
How long does it take to get it running?
Between two and four weeks for one location, depending on how well documented what you have today is. The initial survey is what drives it: if nobody knows what rules exist or who set them, that part takes longer.
And if I already have an IT provider?
We work with them. The co-managed option exists precisely for that: your provider keeps doing their part and we bring the security expertise. We're not there to fight over an account.
Who it's for
Companies with remote staff or connected branches
Operations that handle customer data under Law 81
Those who already bought a firewall but nobody manages it
Let's start by looking at what you already have
We visit your site, survey what's there today and give you in writing what's worth changing, in what order and with what budget. The survey is quoted as consulting and is deducted from the project if you hire us.
Schedule the visitYou're talking to Génesis, Valtriom's AI