Tufin integrator in Switzerland
We deploy the Tufin Orchestration Suite to keep the filtering policy of a heterogeneous estate under control — visibility, compliance and change request automation.
Why this vendor
A firewall estate ages badly. A rule is added for a project, the project stops, the rule stays. Ten years later the base holds several thousand entries and nobody knows which ones still serve a purpose. Deleting them is risky, keeping them is too, and the subject stays at the bottom of the list until an audit brings it back up.
Tufin attacks the problem through modelling. The platform reads the configurations of several vendors — firewalls of different makes, routers, cloud security groups — and builds one map from them. What becomes possible then is asking a question in business terms: can this server reach that one, and by which path. The answer accounts for every device crossed, which no manufacturer's console can do.
The contribution network teams notice fastest lies elsewhere, in handling change requests. A request to open a flow usually passes through several people, several weeks and a degree of guesswork about which devices are involved. The platform computes the path, proposes the exact rule, checks that it breaks no internal policy, and implements it.
Our contribution is defining what compliance means at your organisation. The platform applies the rules it is given; it does not decide which flows are forbidden, nor which zones must never talk to each other. That matrix is written with your network and security teams, and it is what gives the tool its value.
- Writing the matrix of authorised flows
- Gradual cleanup of inherited rules
- Automation of change requests
- A unified view over a multi-vendor estate
- Compliance evidence produced continuously
Three tiers, one platform
The tiers we integrate
The vendor sells three tiers of one suite, not three separate products. Each assumes what the previous one brings.
Visibility and compliance
SecureTrack+ reads the estate's configurations and builds one map from them. It flags rules never used, rules that overlap, rules that breach your internal policies. It is the tier that finally allows an inherited rule base to be cleaned, relying on observed usage rather than on the memory of the team.
Change automation
SecureChange+ handles flow opening requests end to end: computing the network path, proposing the exact rule on the right devices, checking compliance automatically, then implementing it. The gain is measured in weeks on requests that used to take several, and the number of useless rules created out of caution drops.
Scaling up
Enterprise is the tier for the largest estates, where policy is designed by zones and intent rather than rule by rule. It is also what makes a Zero Trust approach workable on an existing network: segmenting assumes a reliable model of what talks to what, without which the project stays theoretical.
The Tufin Orchestration Suite does not replace your firewalls: it administers them together. That is what makes it relevant on a heterogeneous estate, where each manufacturer's console sees only its own devices and nobody can answer the one question that matters — does this flow pass, and by which route.
How we proceed
No rule is deleted before we know what it carries. Cleanup comes after observation, never before.
This service in practice
Frequently asked questions
Thousands of rules, and nobody knows
Describe your estate — an inventory of the rules actually in use is the first deliverable.