A network is a set of decisions, not a box of hardware.
CyberCrest designs network security Christchurch organisations can actually verify: segmented topologies on Ubiquiti UniFi, firewall policy written against the site rather than inherited from a default template, wireless planned from a physical survey, and every zone, address range and rule documented in a pack handed over at completion. Fast where it needs to be. Contained everywhere else.
Your ISP router is not a firewall.
The unit the provider supplied performs routing and network address translation. It is not a security appliance and was never designed to be one. Meanwhile every public IP address in New Zealand is scanned continuously by automated infrastructure looking for exposed management interfaces, forgotten port forwards and devices running firmware from three years ago.
A UniFi Cloud Gateway places a genuine next-generation firewall in that path: inspecting traffic in real time, matching it against current threat intelligence, and dropping what does not belong before it reaches a single device on the internal network. Rules are written per zone with a stated reason, then reviewed — because a firewall policy nobody has read in two years is a document, not a control.
- InspectionEvery packet examined in real time against stateful policy, not simply forwarded.
- IDS / IPSTraffic matched against a continuously updated signature database; intrusion attempts blocked rather than logged for later.
- Threat intelligenceKnown malicious hosts, botnets and command-and-control infrastructure denied at the edge.
- DNS filteringMalicious and phishing domains blocked network-wide, including on devices that cannot run endpoint software: cameras, printers, terminals, building services.
- Encrypted accessWireGuard tunnels replace port forwarding entirely. No inbound management port is exposed to the internet, on any site we specify.
- LoggingPolicy decisions logged so an incident can be reconstructed instead of guessed at.
A flat network is a single blast radius.
On most small and medium networks every device shares one broadcast domain. The unpatched terminal, the smart display, the visitor's laptop, the camera recorder and the file server are all neighbours. Compromise any one of them and the rest are reachable without crossing a single control.
We divide the network into zones — staff, payments, surveillance, building services and IoT, guest — with traffic between them denied by default and every exception written explicitly as a rule with a documented reason. The policy matrix is a deliverable, not an internal working note: a plain statement of exactly what may talk to what, which somebody can audit in a year without reverse-engineering a live configuration.
Three points that matter in practice. The surveillance segment carries no outbound internet route, so a camera cannot be recruited into a botnet and a recorder cannot quietly phone home. Payment devices sit in their own zone, which is the baseline expectation under PCI DSS. Guest traffic reaches the internet and nothing else, including no client-to-client visibility.
Segmentation costs nothing additional in hardware. It is a design decision, made once, at the only point in a project where it is inexpensive to make.
Discuss your site →Coverage is designed, not guessed.
Most wireless complaints are not hardware problems. They are the result of access points mounted wherever there happened to be a power outlet, all broadcasting at full transmit power on overlapping channels, competing with each other and with every neighbouring network in the building.
We survey the building first. Construction materials, existing interference, floor plate, ceiling height, where people actually work and what they are actually running. In Christchurch that matters more than most cities: the post-earthquake building stock is heavy on steel framing, concrete shear walls and foil-backed insulation, all of which attenuate 5 GHz and 6 GHz far more aggressively than the plasterboard-and-timber assumptions built into most vendor coverage calculators.
From the survey we model access point placement, channel allocation, band steering and transmit power before specifying any hardware. Coverage overlaps deliberately at around −67 dBm at the cell edge so devices roam cleanly instead of clinging to a distant access point at 6 Mbps and dragging the cell down with them.
- SurveyPhysical site walk, spectrum scan and client density assessment before any design work begins.
- PlacementModelled overlap for clean roaming across floors, stairwells, outdoor areas and between buildings.
- ChannelsNon-overlapping allocation with transmit power tuned to the cell edge rather than left at maximum.
- StandardsWiFi 6 and WiFi 7 with WPA3 throughout, and 802.1X where the environment warrants per-user authentication.
- BackhaulEvery access point hardwired to PoE switching. No daisy-chained mesh extenders holding up a business.
- ValidationPost-installation survey confirming the delivered coverage matches the design, handed over as a report.
The parts that stay in the walls for a decade.
Cabling, switching and power are the least glamorous decisions on any project and the most expensive to revisit. They get specified properly the first time.
Structured cabling
Cat6 and Cat6A to AS/NZS 3080, terminated to patch panels, certified with a tester and handed over with the results. Runs planned around the building rather than around the obstacles somebody found on the day.
PoE switching
UniFi PoE switches power access points, cameras, door readers and phones over a single cable, with per-port VLAN policy, power budgeting, per-port monitoring and remote restart. A camera that has locked up gets power-cycled from a browser, not from a ladder.
Cloud gateways
Routing, next-generation firewall, intrusion prevention and VPN in one appliance, managed from a single interface across every site an organisation operates.
Racks & power
Enclosures sized with expansion headroom, metered PDUs, labelled patching, a documented port map, and seismic restraint to NZS 4219 where the installation requires it. The next engineer to open the cabinet should be able to read it without a phone call.
Failover & UPS
Automatic WAN failover with LTE cutover, and battery backup sized to hold the critical load for a stated runtime rather than an optimistic one.
VPN & multi-site
WireGuard for staff working off site, and site-to-site tunnels joining offices, warehouses, yards and remote premises into one managed network with one policy set.
The deliverable is a document set, not just a working light.
Most organisations cannot produce a current diagram of their own infrastructure. That is not negligence — it is what happens when the installer's remit ended at the mounting bracket and nothing was written down.
Every CyberCrest project completes with an as-built pack. It is the same format on every site, and it belongs to the client.
- Logical topologyZones, routes, trust boundaries and inter-zone policy.
- Physical topologyRack elevation, device locations, cable routes and patch schedule.
- Addressing planSubnets, VLAN identifiers, reservations, DHCP scopes and static assignments.
- Port scheduleEvery switch port, what is on it, which VLAN it carries and what power budget it draws.
- Firewall policy statementEach rule in plain language with the reason it exists.
- Wireless design recordAccess point positions, channels, transmit power and the post-installation validation survey.
- CredentialsHanded over under a defined process, held by the client, not retained as leverage.
- Change logMaintained from commissioning onward where a managed agreement is in place.
From assessment to handover.
Every engagement opens with a conversation at no cost. From there the assessment is scoped work with a defined deliverable, because a design worth acting on takes more than a walk-around.
Consultation
A short conversation about the site, the problem and the constraints — enough for us both to judge whether there's a fit.
Assessment
Survey of current state, coverage and exposure. Findings presented in person, with a fixed-scope proposal to follow.
Design & delivery
Documented architecture, then configuration, hardening and commissioning. Cabling and electrical works are carried out by licensed partner trades under our specification and sign-off.
Operation
Handover with the full as-built pack, then monitoring and change control under a managed agreement where required.
Network security Christchurch, Canterbury and beyond.
CyberCrest works across Christchurch city, the Selwyn and Waimakariri districts and wider Canterbury, with national coverage by scope and two client sites under support in London.
- Christchurch Central
- Riccarton
- Addington
- Papanui
- Hornby
- Halswell
- Sydenham
- Woolston
- Sumner
- New Brighton
- Belfast
- Wigram
- Rolleston
- Lincoln
- Prebbleton
- West Melton
- Rangiora
- Kaiapoi
- Woodend
- Selwyn District
- Waimakariri District
- Ashburton
- Timaru
- Wider South Island
- London, United Kingdom
Find out what's actually on your network.
Most organisations don't have a current diagram of their own infrastructure. Start with a conversation about the site — if there's a fit, an assessment will tell you exactly what's there and what it's exposed to.