Netwrix integrator in Switzerland
We deploy the Netwrix monitoring and governance solutions — who accesses what, who changed what, and how to prove it on the day of an audit.
Why this vendor
Two questions come up at every audit, and almost nobody can answer them: where is the sensitive data, and who can reach it. Organisations know where their servers are. They rarely know which share holds health data forgotten from a closed project, nor that the group granting access to it has eighty members, half of whom have changed roles.
Netwrix addresses both questions pragmatically, without demanding an overhaul first. There is no governance project to run before starting: you install, you observe, and the findings come. That is a difference in kind from platforms requiring a finished data model to deliver their first result — a model which, for want of exactly this visibility, does not yet exist.
The use that earns its keep daily is Active Directory monitoring. Knowing that an account has just entered the domain administrators group, at what time and by whose hand, is the kind of information whose value is measured on the day it is missing. The native logs hold it in theory; exploiting them under pressure is another matter.
Our contribution is what gets done with the findings. A report showing twelve shares open to everyone is only worth something if somebody decides who should have access, within what deadline, and who revalidates it each year. That part is governance, not tooling, and it is the part we build with you.
- Discovery of the sensitive data actually present
- Monitoring of Active Directory changes
- Periodic access review and revalidation
- Evidence acceptable in an ISO 27001 audit
- Articulation with directory hardening
Know, watch, prove
The products we integrate
Two complementary products: one says where the sensitive data is, the other says what is being done with it.
Discovery and classification
Netwrix Data Classification goes through file shares, SharePoint and mailboxes to identify what qualifies as personal data, health data or payment details. The result is almost always uncomfortable, and that is what makes it valuable: you do not protect what you do not know exists.
Monitoring and auditing
Netwrix Auditor records changes across Active Directory, file servers and Microsoft 365 — who did what, when, from where, and what the previous value was. That last detail is what separates a log from an audit tool: without it, you observe that a right has changed without being able to put it back.
It produces the finding, not the decision. A report flagging twelve shares open to everyone changes nothing until somebody has settled who should have access, within what deadline, and who revalidates it each year. Periodic access review is a process, with named owners and a calendar that holds — that is the part we build with you, and the part the auditor will look at.
How we proceed
Access governance is not a project that ends. It is a cycle, and what keeps it alive is the review calendar, not the tool.
This service in practice
Frequently asked questions
Who can reach your sensitive data?
Describe your environment — the first picture takes only a few days.