Palo Alto Networks integrator in Switzerland
We design and operate Palo Alto Networks architectures, from the perimeter firewall to endpoint detection. Three certifications in the team, including PCNSE and PSE Strata Pro.
Why this vendor
Palo Alto Networks built its reputation on one precise technical point: application identification. Where a classic firewall reasons in ports and addresses, App-ID names the application whatever port it travels on, and User-ID attaches an identity to it rather than a machine. A policy then stops being a list of flows and becomes a readable sentence: who is allowed to use what.
That is what makes segmentation sustainable over time. A rule written in applications and user groups survives a change of addressing, a server migration, the arrival of a new application version. A rule written in ports survives nothing, and that is how policies become, within a few years, a pile nobody dares touch.
The downside is well known: that precision has a design cost. A poorly scoped Palo Alto deployment produces a verbose policy that is slow to evaluate. This is exactly where we come in — the value is not in powering up the appliance, it is in the structure of the policy and the discipline of maintaining it.
We cover the full cycle: audit of the existing estate, design, proof of concept, migration in waves, then operations or a handover.
- PCNSE, PCNSA and PSE Strata Pro in the team
- Policy design in App-ID and User-ID
- Migration from a third-party firewall, in waves
- Taking over policies that have become unmanageable
- Central administration through Panorama
The architecture, from perimeter to cloud
The products we integrate
From the firewall to the cloud, under a shared policy. Not every building block is justified on the same project — sorting them is part of the work.
Next-generation firewalls
The PA-Series covers the physical perimeter, from the branch office to the data centre, with TLS decryption and application inspection. The VM-Series carries the same policy into virtualised and cloud environments — which is what lets you write a rule once and apply it everywhere, rather than maintain two sets that drift apart.
Central administration
Panorama pushes configuration across the estate, keeps the change history and allows rollback. It also aggregates logs, which is the precondition for correlating a perimeter event with an endpoint event. Without it, each firewall becomes an island — and configuration debt settles in without anyone seeing it.
Remote access and SASE
Prisma SASE applies the corporate policy to users outside the walls without backhauling their traffic to headquarters, which settles both the latency and the load on the central link. Prisma Browser handles unmanaged endpoints — contractors, personal devices — by confining access to a corporate browser rather than opening a tunnel into the network.
Detection and response
Cortex XDR correlates endpoint, network and cloud signals into one timeline. The point is not to multiply alerts but to bring them together: one incident stops appearing as three unrelated events in three different consoles.
Cloud security
Cortex Cloud covers the chain from code to runtime: application security upstream, cloud posture, and protection at the moment the container runs. The value lies in the shared context — a vulnerability in an image becomes a wholly different priority depending on whether that image is deployed in production and exposed, or sleeping in a registry.
Artificial intelligence security
Prisma AIRS answers a recent and real need: applications built on language models expose a surface that classic controls do not see — prompt injection, leakage through the response, undeclared use of an external service. We treat it as an architecture question, not as a product to install.
On an existing estate we always start with Panorama and with the policy audit: rules never triggered, orphaned objects, duplicates, rules that shadow one another. It is the least spectacular and most profitable work — everything else depends on it, and it often reveals that the problem was never the appliance.
Our Palo Alto Networks certifications
Three badges held within the team, including the PCNSE engineer certification and the PSE Strata Pro pre-sales track.



How we proceed
A firewall migration is not decided on cutover night but in the weeks before it, on the rule mapping table.
This service in practice
Frequently asked questions
A policy to design or to take over?
Describe your situation — on an existing estate, we always start by looking at the policy in place.