Knowledge Hub · Security

Where should we start with FirstNet if we have several cybersecurity gaps?

Security · Answered by FirstNet Technology Services

Short answer

Start with the risk that is costing you most today, whether that is phishing, an ageing firewall or VPN pain. FirstNet runs a discovery session, proposes the first service, then expands into adjacent layers once the first one is proving its value.

In detail

A typical sequence looks like this:

  • Discovery: FirstNet reviews your current tools, users, sites, recent incidents and compliance drivers
  • Risk assessment, where needed: identify vulnerabilities across users, systems and connectivity, assess likelihood and business impact, check alignment to regulatory requirements and define a prioritised remediation roadmap
  • First service: for example Mimecast for phishing, Firewall as a Service for an ageing firewall, or Netskope or Cloudflare Zero Trust to replace a VPN
  • Expansion: add adjacent layers such as Sophos MDR, DMARC enforcement or a web application firewall on the same FirstNet contract

Some services let you test or measure before you commit. Netskope offers a structured Proof of Value, and a monitoring-only DMARC record shows who is sending email as your domain before any enforcement.

This approach avoids a disruptive rip-and-replace and puts budget where the risk is highest first.

Source: FirstNet Security service page →

Didn’t answer your question?

Call