Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Technology partner

Netwrix integrator in Switzerland

We deploy the Netwrix monitoring and governance solutions — who accesses what, who changed what, and how to prove it on the day of an audit.

Why this vendor

Two questions come up at every audit, and almost nobody can answer them: where is the sensitive data, and who can reach it. Organisations know where their servers are. They rarely know which share holds health data forgotten from a closed project, nor that the group granting access to it has eighty members, half of whom have changed roles.

Netwrix addresses both questions pragmatically, without demanding an overhaul first. There is no governance project to run before starting: you install, you observe, and the findings come. That is a difference in kind from platforms requiring a finished data model to deliver their first result — a model which, for want of exactly this visibility, does not yet exist.

The use that earns its keep daily is Active Directory monitoring. Knowing that an account has just entered the domain administrators group, at what time and by whose hand, is the kind of information whose value is measured on the day it is missing. The native logs hold it in theory; exploiting them under pressure is another matter.

Our contribution is what gets done with the findings. A report showing twelve shares open to everyone is only worth something if somebody decides who should have access, within what deadline, and who revalidates it each year. That part is governance, not tooling, and it is the part we build with you.

Netwrix
What we bring
  • Discovery of the sensitive data actually present
  • Monitoring of Active Directory changes
  • Periodic access review and revalidation
  • Evidence acceptable in an ISO 27001 audit
  • Articulation with directory hardening
Vendor website
Diagram

Know, watch, prove

Netwrix chain: from scope to audit evidence KnowWatchProve01ScopeActive Directory, file shares, SharePoint, Microsoft 36502Discovery and classificationNetwrix Data Classification03Activity monitoringNetwrix Auditor04Alerting and investigationSensitive changes, abnormal behaviour05Audit evidenceDefensible reports, dated access review
The three stages follow one another: you only usefully monitor what you have classified, and you only prove what you have monitored.

The products we integrate

Two complementary products: one says where the sensitive data is, the other says what is being done with it.

Discovery and classification

Netwrix Data Classification goes through file shares, SharePoint and mailboxes to identify what qualifies as personal data, health data or payment details. The result is almost always uncomfortable, and that is what makes it valuable: you do not protect what you do not know exists.

Netwrix Data Classification

Monitoring and auditing

Netwrix Auditor records changes across Active Directory, file servers and Microsoft 365 — who did what, when, from where, and what the previous value was. That last detail is what separates a log from an audit tool: without it, you observe that a right has changed without being able to put it back.

Netwrix Auditor
What the tool does not do

It produces the finding, not the decision. A report flagging twelve shares open to everyone changes nothing until somebody has settled who should have access, within what deadline, and who revalidates it each year. Periodic access review is a process, with named owners and a calendar that holds — that is the part we build with you, and the part the auditor will look at.

Netwrix AuditorNetwrix Data Classification
Our approach

How we proceed

Access governance is not a project that ends. It is a cycle, and what keeps it alive is the review calendar, not the tool.

Access and data governance cycle 01Scope andsources02Classification03Monitoring04Accessreview05AuditevidenceContinuous cycle
The cycle closes on the review: without it, granted rights accumulate and the inventory becomes wrong again within months.
Frequently asked questions

Frequently asked questions

They hold part of the information, scattered across the domain controllers, in a format designed for machines, with retention that is often short. Reconstructing the history of a right from those logs is feasible, but not under the pressure of an incident nor under an auditor's gaze. The added value is in retention, correlation and readability.

No, and it is the reverse order that works. Automatic classification produces a first picture to discuss, where a governance project run on paper first bogs down for want of knowing the ground. You then refine the rules with the business, on real cases.

They supply the material; what the auditor assesses is the process. They will ask who reviews access, how often, what was removed at the last review and on whose decision. A report without a documented review proves nothing. We build both together.

Yes, through our support and managed service offering: running the review campaigns, qualifying alerts and producing the indicators. Or through a handover, if your teams keep the cycle running themselves.

Who can reach your sensitive data?

Describe your environment — the first picture takes only a few days.