Security is built into a system before any code is written or servers are bought: you decide which data to protect, who gets access and how, what to encrypt, which events to log, and where data and backups will live. These decisions are recorded in a network diagram, an access matrix and written procedures. They can be added to a running system later, but it takes longer and costs more: data has to be moved and people have to change their habits.
Key takeaways
Security by design is an approach where protection requirements go into the technical specification alongside features. The architect answers not only "how will this work" but also "what happens if a password is stolen or a server fails".
Protection added after the fact turns into a set of patches. Each one closes a single scenario and often leaves new workarounds behind: a port opened "temporarily", a shared admin account, a copy of the database on a developer's laptop.
What is easier to do at the design stage:
The project starts with a data inventory and classification: you cannot protect what you do not know exists. List your systems, databases, file storage and every channel through which data leaves the company: email, messengers, contractors, cloud services.
Each type of data is then assigned a class. The class sets the requirements for access, encryption and storage location.
| Data class | Examples | What it requires |
|---|---|---|
| Public | Price list, service descriptions, job openings | Protection from tampering: only designated people can edit |
| Internal | Procedures, plans, work correspondence | Employees only, sign-in with two-factor authentication |
| Confidential | Customer base, contracts, finance, employee data | Role-based access, encryption, activity log, tested backups |
| Biometric and genetic | Fingerprints and face templates in an access control system | All of the above, plus storage in Uzbekistan and registration of the database in the state register |
The next step is a threat model: who could cause harm (an outside attacker, an employee, a contractor), through which entry point, and what the business would lose. We covered how to assess likelihood and impact and set priorities in our article on information security risks, and the typical causes of leaks in the piece on personal data leaks.
Tip Start with a one-page table: system, what data it holds, who owns it, who has access, where backups are kept. That table alone shows the main risks and the first steps.
Every employee and every service gets exactly the access needed for the job. This is the principle of least privilege: a sales manager does not need the accounting database, and a public website does not need HR files.
Companies with remote staff and cloud services benefit from the zero trust model. NIST SP 800-207 describes it this way: a device or account is not trusted simply because it sits on the internal network. Every request to a resource is checked: who the user is, which device they are on, and whether they are allowed to perform this particular action.
For a small company, a VPN with two-factor authentication remains a workable option. When there are many employees, contractors and services, access to individual applications through a zero trust gateway (ZTNA) is easier to control than letting a person into the whole network at once.
Segmentation limits the damage: an attack that starts in one zone does not spread across the whole company. A flat network is one where accounting, the warehouse, guest Wi-Fi and servers share a single segment, so one infected laptop can see everything.
A typical layout for an office of 30–50 people looks like this.
| Segment | What is inside | Who has access | Rules between segments |
|---|---|---|---|
| Servers | Databases, CRM, accounting system, file storage | Administrators; employees only to their own applications | Only the ports of required applications are open, everything else is closed |
| Workstations | Employee desktops and laptops | Employees | To servers through approved applications, between departments only when needed |
| DMZ | Website, mail gateway, VPN gateway | External users, to public services | Into the internal network only specific requests, for example from the website to an API |
| Guest Wi-Fi | Guests' phones, personal devices | Everyone | Internet only, internal network closed |
| Devices | Printers, cameras, access controllers | Administrators | Connection to the management server only |
The boundaries between segments are enforced by a firewall with explicit rules: whatever is not allowed is denied. In the cloud, virtual networks and security groups play the same role.
The perimeter is every point where your infrastructure touches the outside world: internet links, remote access, public services and email. The design records why each of these points is open and who is responsible for it.
SPF, DKIM and DMARC are DNS records that receiving mail servers use to tell your emails from forgeries. Since 1 February 2024, Gmail has required SPF or DKIM from all senders, and SPF, DKIM and DMARC together from anyone sending more than 5,000 messages a day. Without these records, company emails land in spam more often and fraudsters find it easier to send mail in your name.
Data is encrypted in three states: in transit, at rest and in backups. Then intercepted traffic, a stolen disk or an exported archive is useless without the key.
Backups are built into the design through two parameters: RPO, how much data the business can afford to lose, for example the last hour of records, and RTO, how quickly the system must be back in operation. They determine backup frequency, storage location and server redundancy. We described the 3-2-1 rule, protecting backups from ransomware and the steps to take after a failure in our article on recovering IT systems after failures.
Important A backup that has never been restored is not yet protection. Build scheduled test restores into the design and measure how long they take.
Logs record the events that let you spot an attack and reconstruct an incident. OWASP guidance for applications names this minimum:
Passwords, access tokens, keys, payment card data and unnecessary personal data are never written to logs, otherwise the log itself becomes a source of leaks. Records are shipped to a separate server where administrators of production systems cannot delete them, and clocks on all servers are synchronised, otherwise events from different systems cannot be linked into one chain.
The minimum log retention period in CIS Controls v8.1 is 90 days (safeguard 8.10). Industry rules and partner contracts may require longer, so the retention period is set in the design for each system. The design also decides who reviews the logs and responds to alerts: your own team or an external monitoring service.
The storage location is chosen based on the law, performance and who will be responsible for the infrastructure. Since 27 March 2026, Article 27-1 of the Law "On Personal Data" No. ZRU-547, as amended by Law ZRU-1125 of 26 March 2026, requires three categories to be stored in Uzbekistan: biometric data, genetic data and data of telecom operators' users. Databases containing this data are registered in the State Register of Personal Data Bases (Article 20).
Other personal data may be stored and processed abroad if one of the conditions in part three of Article 27-1 is met: the country is recognised as providing adequate protection, the operator follows standard contractual clauses or binding corporate rules, or it complies with international standards from an approved list.
For the design, this means biometric data from an access control system stays in the country, while the location for a CRM or website is chosen on speed, price and ease of support. A comparison of your own server, a cloud in Uzbekistan and a foreign cloud, the list of countries and latency measurements are in our article on choosing a cloud or server in Uzbekistan.
A security project ends with documents that allow the system to be built, verified and handed over to another team. The work goes in this order:
At the end you have a network diagram, an access matrix, backup and incident response procedures, and a prioritised list of measures. These documents are needed both for implementation and when you have to show your level of protection to a partner or a bank.
At Syntra Systems we start with an information security audit, from $1,200: we map what needs protecting, check servers, networks, email, websites and workstations, review access rights and personal data handling, and deliver a report with priorities. If the system is already running, the audit shows where to start the rework.
Then we build data and access protection, from $4,000: roles and two-factor authentication, encryption, protection of email from spoofing, backups with tested restores, firewall and VPN, incident procedures and staff training. The full scope is on our cybersecurity for business page.
Let’s discuss your project
Tell us what you need, and we will estimate the timeline and cost and suggest a solution.
Yes. It starts with an audit: what is already in place, where critical data lives and which weaknesses are most dangerous. Measures are then introduced step by step, usually beginning with access rights and backups, without stopping the business.
No. They do not protect against a stolen password, excessive employee permissions or an infected device inside a flat network. Protection works when access control, segmentation, encryption, logging and backups are built together.
With a list of systems and data, two-factor authentication for email and cloud services, a separate backup with a tested restore, and revoking access for former employees. None of these steps requires a large investment.
Preferably. If logs sit on the same server, an attacker with admin rights will erase their tracks. A small company can use a separate virtual machine or cloud log storage with restricted access.
A data center protects against physical access, but not against a database exported with a stolen password, a permissions mistake on storage or a lost backup. Encryption makes such data useless without the key.
A flat network is when accounting, the warehouse, guest Wi-Fi and the servers all sit in the same segment, so one infected laptop can see everything in it. The network is split into zones, and a firewall guards the boundaries between them with one rule: anything not explicitly allowed is denied.
The price depends on the number of systems, employees and sites. At Syntra Systems an information security audit starts from $1,200, data and access protection from $4,000, and security event monitoring from $800 per month.