Security & Performance

Ten services,
one operating concept

Security and speed belong together: what protects your application also decides how quickly it answers. We build both into one concept – from the firewall in front of your systems to delivering your content from the nearest location.

ISO 27001 based on BSI IT-GrundschutzData centres in Germany24/7/365 operation and support

Security

Seven services for protection

Each service stands on its own and combines with the others. What belongs together in your case we work out in conversation.

BaaS & DRaaS

Automatic backup onsite and offsite, immutable backups against ransomware, restarting after an outage.

More

Firewall, WAF & NGF

Protection at network and application level: managed firewall at layer 3/4, web application firewall and next generation firewall.

More

DDoS protection

Incident-based or continuous filtering of overload attacks through external scrubbing centres, including TLS-encrypted traffic.

More

IDS & IPS

Detecting and stopping attacks inside permitted connections – with rule sets that suit your environment.

More

VPN

Encrypted access over IPsec and OpenVPN: for remote work, for linking sites, with MFA and directory integration.

More

SSL certificates

Obtaining, installing and renewing certificates – domain, organisation or extended validated.

More

Security scans

Vulnerability and compliance scans, penetration tests, a report with recommended actions, and a re-test.

More

Performance

Three services for speed and availability

They solve different problems – within one environment, between sites, and in front of the origin system.

Load balancing

Spreading load at layers 4 to 7 within one environment, with keep-alive checks and firewall protection in the same system.

More

Content delivery network

Caching static and dynamic content at distributed locations – shorter load times, less load at the origin.

More

Global server load balancing

Distribution across several sites at DNS level: geo-redundancy, failover and routing by latency, location or system load.

More

Two sides of the same concept

Active and passive protection

Active protection intervenes in the traffic: it permits, filters, blocks and redirects. That includes firewall, WAF and NGF, DDoS defence, IDS and IPS, and encrypted access over VPN.

  • Rule sets we maintain – not set once and left
  • Multi-factor sign-in and directory integration on the VPN
  • Attack detection inside permitted connections
  • Traffic cleaned before it reaches your network

Passive protection does not intervene; it raises the level of protection: it makes transmissions verifiable, uncovers weaknesses, and makes sure data is there again after an incident.

  • SSL certificates, obtained and renewed in good time
  • Vulnerability scans and penetration tests
  • Backup and a restart that has been tested
  • Monitoring around the clock

Three services, three levels

Load balancing, GSLB or CDN – which one when?

Load balancing

One site, one setup. Spreads requests at layers 4 to 7 across several servers and absorbs the failure of a single system.

To load balancing

GSLB

Several sites, DNS level. Absorbs the failure of an entire data centre and directs requests to the right site.

To GSLB

CDN

Caches distributed around the world. Shortens load times and relieves your origin system – it does not spread load inside your setup.

To the CDN

The three do not rule one another out: a load balancer within the site, GSLB between the sites and a CDN in front together make one concept.

Frequently asked questions about Security & Performance

What does "managed" mean with these services?

That we do not merely provide the component but run it: setup, configuration to your specifications, monitoring, maintenance of rule sets and updates, response to faults. You have to look after neither hardware nor software yourself.

Where do the systems run, and who has access?

In our own data centres in Hanover, Wolfsburg and Frankfurt. They are certified to ISO 27001 based on BSI IT-Grundschutz (BSI-IGZ-0552-2023, scope data centres and cloud services). kyberio is in German ownership, subject to German law and not to the CLOUD Act.

Which firewall platform do you use?

The managed firewall is based on OPNsense – virtual or on a dedicated appliance, each with the business subscription and, on request, with the Proofpoint subscription. Web application firewall and next generation firewall run on their own systems in front. Details are under firewall, WAF & NGF.

Do I need load balancing, GSLB or a CDN?

A load balancer spreads requests across several servers within one environment. GSLB works a level above, at DNS level, and distributes between sites – that is how you absorb the failure of an entire data centre. A CDN caches content at distributed locations and shortens load times for your visitors. The three solve different problems and combine well.

Can I book individual services, or only the package?

Individually is possible. A combination is usually the sensible route: a firewall without backup leaves a gap open, and so does a load balancer without attack detection. What belongs together in your case we look at together.

Do you run a SOC?

No. We run protection and monitoring around the clock, but not an operations centre of our own that continuously evaluates security incidents. If you need a SOC or SIEM, we put you in touch with a partner — and provide the infrastructure underneath.

Does this apply to systems that are not hosted with kyberio?

Some services require the systems to run with us, others do not – it depends on how they are connected. Tell us where your systems are today and we will work out in conversation what applies.

What response times do you commit to?

We monitor around the clock, every day of the year. How quickly we intervene and through which escalation stages is set out in your contract — a time we have not committed to is not a time we state here.

Satisfied customers

HornetsecurityIT-PHACONWOLFFAutoDoELAINE technologiesZEDALMAJA.cloudSDV SystemeAucotecPARATFP SignHyperspaceAttinaTutaElectronic Arts

Sovereignty

Paving the way for digital sovereignty

ISO 27001 based on BSI IT-Grundschutz, BSI-IGZ-0552-2023
BSI-IGZ-0552-2023 ISO 27001 based on BSI IT-Grundschutz Scope: all data centers and all cloud services Security concept
  • Owner-managed since 1997

    As an owner-managed operator with our own data centers, we make our decisions independently and are subject exclusively to German / EU law.

  • 100% made in Germany

    Our data center, product development, and customer support are all based in Germany for your digital sovereignty.

  • 24/7 Customer Support

    We are here for you: 24/7/365 customer support, in English and German

Let us find the right solution together

We take the time to understand what you need and to develop solutions that fit. We explain complicated technical matters clearly and precisely as we go. Get in touch with me directly and we will work it out.

  • We will get back to you as soon as we can.
  • No obligation, free of charge.

How we process your details is explained in our privacy notice.