Segmentation and Zero Trust, taken all the way to production.
A boutique security consultancy for enterprises across EMEA. We design the architecture, build the policy, run the rollout, and stay until it holds.
What we do
Five practices, deliberately narrow. Each runs from discovery through to a working, documented, supportable deployment — not a slide deck and an invoice.
Segmentation & Zero Trust
Our deepest practice. Dependency discovery, application mapping, policy design, ring-fencing, phased enforcement, migration off legacy controls, and optimisation of environments that stalled partway through.
Identity & access security
IAM and identity security architecture, Active Directory and Entra ID, single sign-on, MFA and passwordless rollouts, least-privilege design, and the machine and service identities most programmes forget about.
Cloud & infrastructure security
Security architecture and posture reviews across AWS, Azure and GCP, hybrid estates, network security, and secure cloud migration — including the unglamorous work of making segmentation and identity behave consistently on both sides of the boundary.
Security architecture & advisory
Architecture assessments, Zero Trust strategy, target-state design and roadmaps, HLD and LLD documentation, and technical advisory for security leadership who need a defensible plan rather than a maturity score.
Vendor & channel services
Delivery and pre-sales capacity for vendors, distributors and integrators without enough local hands. Technical discovery, PoC and PoV execution, implementation, partner enablement, curriculum and demo assets, and RFI/RFP technical tracks.
The Guardicore practice
Most segmentation projects don't fail on the technology. They stall at the point where someone has to decide what a business-critical application is genuinely allowed to talk to — and nobody wants to be the person who breaks production.
Built from the inside
Between 2021 and 2024, our founder led enterprise Zero Trust and microsegmentation engagements at Akamai Technologies and Guardicore, working with Fortune 500 customers across Europe and Israel. That included directing more than ten migration programmes valued above one million euros, standardising deployment patterns and runbooks across regions, and building the partner enablement programme used by over thirty resellers and integrators.
Where we help
New deployments that need to reach enforcement rather than stopping at visibility. Existing estates where policy has drifted or coverage plateaued. Migrations off legacy internal firewalls and VLAN-based controls. And incident-driven work, where containment has to happen first and the architecture follows.
How we work
Map before you block. Enforce in stages with a rollback path at every step. Document the policy so the customer's own team can own it after we leave. Every engagement ends with runbooks and an enabled internal team, because a segmentation deployment only one consultant understands is a liability.
Track record
Selected outcomes from two decades of enterprise engagements, in-house at security vendors and independently.
- Ransomware containment, global enterprise. Identified lateral movement through segmentation analytics during a live incident, supported isolation and full containment; the customer subsequently standardised on the platform across more than 4,000 additional licences.
- Ten-plus Fortune 500 migrations. Directed enterprise moves to Zero Trust microsegmentation, each valued above one million euros, across European and Israeli estates.
- 40% higher technical win rate. Structured discovery, customer-specific validation plans and executive readouts, applied consistently across a PoC and PoV portfolio.
- 30% less onboarding effort. Reusable runbooks, standardised deployment patterns and handover documentation that cut go-live time and reduced escalations.
- 25% faster delivery. Terraform and Ansible automation for repeatable validation and deployment environments.
- Partner programme for 30+ resellers. Curriculum, demo scripts, objection handling and success criteria, built and delivered as a repeatable enablement motion.
Figures reflect results achieved in roles at Akamai / Guardicore and Secret Double Octopus. Customer names available under NDA where permitted.

Shlomo (Eyal) Salman
Founder & Principal Security Consultant
Shlomo has spent over twenty years in enterprise security and infrastructure, starting in systems and Active Directory work at Check Point and Hewlett Packard, then moving through telco infrastructure, professional services and security vendor pre-sales.
Most recently he was a Solutions Engineer and Security Architect at Akamai Technologies and Guardicore, leading Zero Trust, microsegmentation and breach detection engagements for Fortune 500 customers across EMEA. Before that he led the pre-sales team at Secret Double Octopus, working on enterprise passwordless authentication and identity security.
He works comfortably at both ends of a project: whiteboarding dependency maps with an infrastructure team in the morning, and explaining the risk trade-offs to a board in the afternoon. He holds an LLB, which turns out to be more useful in security than expected — contracts, compliance obligations and regulatory scope come up constantly.
Based in Barcelona, working across EMEA. LinkedIn profile
Tell us what's stalled, and we'll tell you whether we can help.
The first conversation is a technical one, not a sales call. If the work isn't a fit, we'll say so.