Infrastructure / Security and Identity / Barracuda
There are two entry points to monitor, and they aren't located in the same place.
Barracuda: networking, email, backup, and remote access.A company that has installed a firewall often believes it has addressed the issue. But a firewall cannot see what’s coming into a mailbox, and an email service cannot see what’s passing through the connection. These are two separate entry points, and Barracuda is one of the few providers to cover both with a single management interface.
Three Reasons Why a Company Thinks It's Covered
None of the three is a mistake caused by inattention. They are sound lines of reasoning that do not follow through to the end.
The firewall predates external hosting
It was designed when the servers and data were located in the building. Since then, the files have been stored Microsoft 365 and employees are working from home: most of the traffic no longer passes through the equipment that was designed to handle it.
The equipment monitors a path that no one uses anymore.
Message filtering is considered to be set up
Microsoft 365 It effectively filters out a large portion of unwanted messages. The ones that still get through are messages that contain neither attachments nor dangerous links: a request for a wire transfer signed by an executive, written correctly, and appearing within the context of a genuine conversation.
The most expensive message is the one that seems completely normal.
No one has ever restored from the backup
A backup runs every night, and no one pays attention to it. The question isn't whether it's running, but how long it would take to get the company up and running again from that backup on a Tuesday morning, without the original server.
A backup that has never been restored is just a plan.
The two entrances, and what's watching over them
They do not follow the same path, use the same signals, or employ the same tools. Treating one does not treat the other, and this is the most common source of confusion.
What Passes Through the Connection
Everything that comes in and goes out through the network: the websites visited, the services used, connections established from outside the network to your servers, and traffic between your various sites.
- Incoming connections to your servers
- Traffic between headquarters and branch offices
- Remote Access for Employees
- Websites and services accessed from your computers
Barracuda CloudGen Firewall. A network firewall with built-in site-to-site connectivity that can be managed from a single console across multiple locations.
What Happens in Inboxes
Messages received by your employees. This is traffic that does not pass through any network equipment, because the message arrives directly at a service hosted by Microsoft.
- Messages that impersonate a manager or a vendor
- Payment Requests to a Modified Account
- Malicious Links and Attachments
- Accounts of employees whose passwords have been compromised
Barracuda Email Protection. Message filtering, detection of phishing attempts, cleaning of messages that have already been delivered, and employee awareness training.
Preventing a document from being sent is another challenge
Monitoring incoming data says nothing about what leaves the company: a customer file saved on a personal device, a confidential document forwarded to a private email address, or a conversation with an unmanaged assistant. This is addressed in * Microsoft 365*, along with other tools, and we devote an entire page to it.
Prevent data from leavingSix categories, and you take only what you need
Barracuda is not a single, indivisible package: each of these components can be purchased and operated separately. The benefit of combining them becomes apparent when the IT team is small, because they are then consolidated into a single console—BarracudaONE—which is included at no additional cost.
CloudGen Firewall
The firewall installed at your premises, with built-in site-to-site connectivity. It connects the headquarters, branch offices, and externally hosted servers, and automatically determines the best path for each type of traffic.
SecureEdge and SecureEdge Access
The same functionality provided as a hosted service rather than as hardware: filtering, site-to-site connectivity, and application access. SecureEdge Access provides access to a specific application rather than the entire network.
Email Protection
Inbound filtering, detection of messages impersonating a known individual, and removal of messages already delivered when a campaign is identified. Three plans, two of which include backup Microsoft 365 and employee awareness training.
The Application Firewall
Sold under the name Barracuda Application Protection, either as hardware or as a service. This is what monitors your websites and interfaces exposed to the internet—the entry point that’s least often discussed, yet is worth a project all on its own.
Barracuda Backup
Backing up your servers and data Microsoft 365, with a copy stored off-site. What matters most is the recovery time, and that’s what we focus on.
Managed XDR
A monitoring center that monitors reports of all of the above, day and night, and issues alerts. For a two-person team, this replaces an on-call schedule that would be impossible to maintain.
How We Do It
There are four steps, and the first one is the one that can scale back the project. It takes place before the quote is prepared, because some of what you're looking for may already be covered by your current licenses.
What Your Licenses Already Cover
We identify the licenses Microsoft 365 currently in place and what they actually include in terms of message filtering, then we compare that to what is enabled in your organization. The two almost never match.
Sometimes the conclusion is to activate a service you're already paying for rather than buying something else. We'll let you know.
A Record of Your Incoming Accesses
Who is connecting from outside the network, to what, and using what equipment. Service provider access points, production machines that can be accessed remotely, and connections between sites are recorded one by one.
Seamless Commissioning
The new equipment is installed and tested in monitoring mode before it goes live. Message filtering is initially set to reporting mode so that we can assess how many messages it might incorrectly flag.
If a filter blocks a legitimate message, it is disabled within a month, and the company then finds itself under less scrutiny than before.
The recommissioning test
We perform a full restore using replacement hardware and measure how long it takes. That’s the only way to know how reliable a backup is.
What You Need to Know Before Making a Decision
Four questions that come up in every project, along with our answers— even when they don’t go our way.
Should we add a filter before Microsoft 365 ?
Not always. Depending on your licenses, some fraud detection capabilities are already included, and many companies have simply never enabled them. We look into that first.
Adding this feature is justified when you need something that Microsoft doesn't provide: automatic removal of messages you've already read, measured employee engagement, or shared administration with the rest of the organization.
Is the name "NG Firewall" still in use?
It was replaced by the Barracuda CloudGen Firewall in 2017. It's part of the same product family, just under a different name.
Another name is changing, and it’s best to know about it before renewing: CloudGen Access is being replaced by SecureEdge Access, and Barracuda has published a procedure for migration. If you’re using either of these, we’ll take a look at the version you have installed and determine how long it will continue to receive updates.
Why choose Barracuda over another provider?
Because it covers both the network and email systems under a single management structure—something few providers do—and because it can be operated by a team of just two people.
We also install other types of equipment. Our expertise in both areas allows us to advise you on your specific needs rather than on what we know how to sell—and you can ask us for references in both areas.
Who manages all of this afterward?
Security systems require ongoing maintenance: updates, certifications, filter adjustments, and monitoring alerts. Without this maintenance, they become outdated and eventually become a hindrance without providing any protection.
Your teams can handle this, and we'll train them. We can also manage the operations, with availability schedules specified in the contract.
The questions that come with it
A company's security is never determined by a single factor. Here are the three factors that most often come up at the same time.
Prevent data from leaving
The classification of sensitive documents and what prevents a file from being sent to a private address or an unmanaged service.
ComputersManage computers and mobile devices
An unupdated computer remains a point of entry, regardless of the equipment placed in front of it. This is the ongoing challenge that always accompanies it.
The FarmMaking sure all of this lasts over time
Monitoring, updates, reviewing alerts, and written availability schedules. What happens to a facility when no one is looking after it.
Let's start with what you're already paying.
Before making a purchase recommendation, we identify what your licenses Microsoft 365 cover and what is not activated. You will receive a written response— even when the advice is “activate what you already have.”
Three offices in French-speaking Switzerland: Renens, Sion , and Châtel-Saint-Denis. What we offer is the opportunity to meet the engineers who will do the work.
Restore it for good, once and for all
Restore a server from a backup onto replacement hardware and time the process. That’s the only number that matters when it happens, and it’s the one almost no one knows.
We measure it together with you.

