S-SHIELD

Segmentation and Zero Trust, taken all the way to production.

A boutique security consultancy for enterprises across EMEA. We design the architecture, build the policy, run the rollout, and stay until it holds.

Ring-fence one application, permit only the flows it actually needs, and lateral movement has nowhere to go.
20+ yearsIn enterprise security, infrastructure and solution architecture across EMEA, the US and Israel.
GCSA & GCSEGuardicore Certified Segmentation Administrator and Engineer, earned inside Akamai.
30+ partners enabledBuilt and ran the partner enablement programme used by resellers and systems integrators.

What we do

Five practices, deliberately narrow. Each runs from discovery through to a working, documented, supportable deployment — not a slide deck and an invoice.

Segmentation & Zero Trust

Our deepest practice. Dependency discovery, application mapping, policy design, ring-fencing, phased enforcement, migration off legacy controls, and optimisation of environments that stalled partway through.

  • Akamai Guardicore
  • Policy design
  • Dependency mapping
  • Phased enforcement
  • Posture review

Identity & access security

IAM and identity security architecture, Active Directory and Entra ID, single sign-on, MFA and passwordless rollouts, least-privilege design, and the machine and service identities most programmes forget about.

  • SAML / OIDC / OAuth2
  • Entra ID & AD
  • Passwordless & MFA
  • RBAC
  • Non-human identity

Cloud & infrastructure security

Security architecture and posture reviews across AWS, Azure and GCP, hybrid estates, network security, and secure cloud migration — including the unglamorous work of making segmentation and identity behave consistently on both sides of the boundary.

  • AWS / Azure / GCP
  • Hybrid estates
  • Network security
  • Terraform & Ansible

Security architecture & advisory

Architecture assessments, Zero Trust strategy, target-state design and roadmaps, HLD and LLD documentation, and technical advisory for security leadership who need a defensible plan rather than a maturity score.

  • HLD / LLD
  • Target-state design
  • Roadmaps
  • Executive readouts

Vendor & channel services

Delivery and pre-sales capacity for vendors, distributors and integrators without enough local hands. Technical discovery, PoC and PoV execution, implementation, partner enablement, curriculum and demo assets, and RFI/RFP technical tracks.

  • PoC / PoV delivery
  • Partner enablement
  • Professional services
  • Technical presales
  • RFx

The Guardicore practice

Most segmentation projects don't fail on the technology. They stall at the point where someone has to decide what a business-critical application is genuinely allowed to talk to — and nobody wants to be the person who breaks production.

Built from the inside

Between 2021 and 2024, our founder led enterprise Zero Trust and microsegmentation engagements at Akamai Technologies and Guardicore, working with Fortune 500 customers across Europe and Israel. That included directing more than ten migration programmes valued above one million euros, standardising deployment patterns and runbooks across regions, and building the partner enablement programme used by over thirty resellers and integrators.

Where we help

New deployments that need to reach enforcement rather than stopping at visibility. Existing estates where policy has drifted or coverage plateaued. Migrations off legacy internal firewalls and VLAN-based controls. And incident-driven work, where containment has to happen first and the architecture follows.

  • Discovery to enforcement
  • Stalled rollouts
  • Legacy migration
  • Breach containment
  • Operational handover

How we work

Map before you block. Enforce in stages with a rollback path at every step. Document the policy so the customer's own team can own it after we leave. Every engagement ends with runbooks and an enabled internal team, because a segmentation deployment only one consultant understands is a liability.

Track record

Selected outcomes from two decades of enterprise engagements, in-house at security vendors and independently.

  • Ransomware containment, global enterprise. Identified lateral movement through segmentation analytics during a live incident, supported isolation and full containment; the customer subsequently standardised on the platform across more than 4,000 additional licences.
  • Ten-plus Fortune 500 migrations. Directed enterprise moves to Zero Trust microsegmentation, each valued above one million euros, across European and Israeli estates.
  • 40% higher technical win rate. Structured discovery, customer-specific validation plans and executive readouts, applied consistently across a PoC and PoV portfolio.
  • 30% less onboarding effort. Reusable runbooks, standardised deployment patterns and handover documentation that cut go-live time and reduced escalations.
  • 25% faster delivery. Terraform and Ansible automation for repeatable validation and deployment environments.
  • Partner programme for 30+ resellers. Curriculum, demo scripts, objection handling and success criteria, built and delivered as a repeatable enablement motion.

Figures reflect results achieved in roles at Akamai / Guardicore and Secret Double Octopus. Customer names available under NDA where permitted.

S-Shield brand banner: Shlomo (Eyal) Salman, cybersecurity solutions engineer specialising in Zero Trust, IAM, multicloud and micro-segmentation across EMEA.
Illustrated portrait of Shlomo (Eyal) Salman.
Shlomo (Eyal) Salman, Barcelona

Shlomo (Eyal) Salman

Founder & Principal Security Consultant

Shlomo has spent over twenty years in enterprise security and infrastructure, starting in systems and Active Directory work at Check Point and Hewlett Packard, then moving through telco infrastructure, professional services and security vendor pre-sales.

Most recently he was a Solutions Engineer and Security Architect at Akamai Technologies and Guardicore, leading Zero Trust, microsegmentation and breach detection engagements for Fortune 500 customers across EMEA. Before that he led the pre-sales team at Secret Double Octopus, working on enterprise passwordless authentication and identity security.

He works comfortably at both ends of a project: whiteboarding dependency maps with an infrastructure team in the morning, and explaining the risk trade-offs to a board in the afternoon. He holds an LLB, which turns out to be more useful in security than expected — contracts, compliance obligations and regulatory scope come up constantly.

Based in Barcelona, working across EMEA. LinkedIn profile

Tell us what's stalled, and we'll tell you whether we can help.

The first conversation is a technical one, not a sales call. If the work isn't a fit, we'll say so.

Directshlomo@sshield.net
General enquiriesinfo@sshield.net
Based in

Barcelona, Spain — EMEA coverage