A modern attack is rarely stopped by a single protection tool. A phishing email slips past the perimeter, a compromised account opens access to the internal network — and from there everything hinges on whether the next lines of defence stand in the attacker’s way. That is why NVP «Plasmotekhnika» builds cyber defence as a multi-layered system: each layer, from the network edge to the individual user, has its own mechanisms for detecting and containing threats, and together they form a single security perimeter for the information system.
We are a full-cycle systems integrator in restricted-information protection and a manufacturer of our own certified TPI tools. We design cyber defence not in isolation but together with technical information security, the client’s basic IT infrastructure and engineering systems. This line of work covers the full lifecycle: risk assessment, security-architecture design, deployment of protection tools, monitoring and support. We work with government bodies and enterprises, as well as with medium and large businesses.
Layers of protection: perimeter, network, endpoints, data, users
The multi-layered (defence-in-depth) model starts from the premise that any single line of defence can be breached. The task of the security architecture is to ensure that the compromise of one layer does not mean the compromise of the whole system. We build and maintain five layers:
- Perimeter — the boundary between the internal infrastructure and external networks: firewalls, protection of public services, traffic filtering, secure remote access for employees and contractors.
- Network — segmentation of the internal network, access separation between segments, detection of intrusions and traffic anomalies. Correct segmentation localises an incident within a single segment instead of the whole infrastructure.
- Endpoints — protection of workstations and servers against malicious code, control of installed software and external media, detection and response at host level.
- Data — separation of access to information, encryption, backup with recovery verification, prevention of data leakage beyond the organisation.
- Users — management of accounts and privileges, multi-factor authentication, raising staff awareness, countering phishing and social engineering.
For secure data exchange between networks with different access levels, we implement our own PLASMA DD data diode — a one-way gateway that physically blocks traffic in the reverse direction.
Information-security risk assessment
Building protection starts not with purchasing equipment but with answering three questions: what exactly we are protecting, from whom, and what happens if the protection fails. Risk assessment provides a justified basis for decisions: which threats are critical for a specific organisation, which measures to implement first and how to allocate the budget.
The work includes:
- inventory of information assets, systems and data flows;
- building a threat model and an intruder model for the specific organisation;
- analysis of infrastructure vulnerabilities and existing protection measures;
- assessment of the likelihood of threats materialising and of the potential consequences;
- prioritisation of risks and formation of a plan for treating them.
| Deliverable | What it gives the client |
|---|---|
| Risk-assessment report | A complete picture: assets, threats, vulnerabilities and an assessment of each risk |
| Risk-treatment plan | A prioritised list of measures — where to start and why in exactly that order |
| Justification of security spending | Arguments for management: which investments close which risks |
Building and supporting the protection system
Implementation
Based on the risk-assessment results we design the security architecture, select and supply solutions, carry out configuration and integration with the existing infrastructure, prepare operational documentation and train the client’s administrators. As a full-cycle integrator we also cover the adjacent work — server platforms, networks, uninterruptible power — without handing the project between several contractors.
Monitoring and response
A protection system works only as long as it is watched. We implement systems for collecting and analysing security events, monitoring protection-tool updates, and detecting incidents.
Support model
The format of support depends on the maturity of the client’s own IT service: one-off work with handover of the system into operation; periodic support — scheduled checks, updates, consultations; extended support with incident response. The scope of work and the response time are fixed in the contract.
Can protection be implemented in stages rather than the whole system at once?
Yes. The multi-layered model lends itself well to phased implementation: first risk assessment, then closing the most critical layers, followed by planned expansion. This path spreads the costs over time and delivers a visible result at each stage.
We already have an antivirus and a firewall. Is that enough?
These are elements of two of the five layers — endpoints and the perimeter. They do not cover the protection of the network, data and users. A risk assessment will show which lines of defence are missing and which of them are critical specifically for your system.
For the public sector: the link with TPI and authorization under Resolution No. 712
In government bodies and at enterprises that process restricted information, cyber defence does not exist separately from the requirements of the law. We support the transition from a CIPS to ICS security authorization under Cabinet of Ministers Resolution No. 712: defining target security profiles, assessment, inclusion of the system in the register of authorized systems. We design the cyber-defence measures from the outset with the target profile in mind — so that the implemented solutions are credited during assessment rather than reworked after the fact. More detail on the authorization under Resolution No. 712 page.
Where needed, we complement cyber defence with technical information security measures — from audit and design to certification and instrumental control — and with our own products holding expert conclusions from the State Service of Special Communications (conclusion numbers — [TBC]): the secure workstation PLASMA-ZV-ARM/MONO with passive protection against leakage via technical channels and PLASMA-ZARM/AZ with active protection.
Discuss a cyber-defence task
If you are not sure what state the protection of your information system is in, start with a risk assessment: it will give an objective picture and a plan of action with no obligation regarding further implementation. If the task is already formulated, describe it and we will propose an architecture and a format of work.
Leave a request via the form at the bottom of the page or call: +38 (044) 204-83-62. Details for counterparty verification: LLC «Scientific and Production Enterprise „Plasmotekhnika”», 03056, Kyiv, vul. Politekhnichna 16, office 021; EDRPOU code — 30023446; TPI licences and permits — details [TBC].