Subscribe to GEN
Login to GEN
A secure environment is not an office with a lock on the door and antivirus on the desktops. It is a physically and logically closed space in which the default answer to "can data leave here?" is no, and every exception is deliberate, documented and technically enforced. Most organisations describe themselves as secure whilst running the same laptops, the same public cloud services and the same consumer messaging apps as everybody else. A genuinely secure environment starts from the opposite position: nothing is permitted until there is a reason for it.
GEN designs, builds and operates secure environments for clients whose work genuinely cannot tolerate leakage: financial institutions, defence and aerospace suppliers, legal and forensic practices, research organisations and businesses handling material whose disclosure would end a contract or a company. We also work inside them ourselves. Our own operational sites are run to the same standard, which is why we are able to describe the friction honestly rather than sell an idealised version of it.
The model rests on four principles, applied together. Applied separately they achieve very little.
Logical controls are irrelevant if somebody can walk into the room. Physical protection is layered, so that no single failure grants access to the working area.
The single most effective exfiltration device ever built is the modern smartphone. It has a camera, a microphone, encrypted storage, an independent radio path to the outside world and a screen its owner is entitled to look at. No amount of network engineering compensates for allowing one into a secure area.
The policy is unpopular for roughly a fortnight, after which it becomes unremarkable. It is also the control that clients ask about first, because it is the one they can see working.
Every user is issued a hardware security token, and it is mandatory. No workstation, system or internal application can be logged into without one. There is no password only route, no fallback, no temporary exception and no emergency bypass, because a bypass that exists is a bypass that will be used.
The point of the arrangement is that the credential and the person are only ever brought together inside the secure environment, under supervision. A token held on site cannot be stolen from a bag on a train, cannot be used from a home network and cannot be quietly borrowed at the weekend. It is an authentication control and a physical custody control at the same time, which is what makes it worth the administrative effort.
The network is built so that the ordinary failure modes are not available. There is no browsing, no consumer cloud, no file sharing service and no general route to the Internet from a workstation.
Every system in the environment runs Linux: servers, workstations, firewalls, hypervisors, telephony and appliances. There is no Microsoft software anywhere in the estate. No Windows, no Active Directory, no Exchange, no Microsoft 365, no Teams, no OneDrive, no Entra.
Microsoft is a threat in its very name. No other vendor has a comparable record: decades of critical vulnerabilities, a monthly patch cycle that has run for a quarter of a century without ever arriving at a secure product, and an architecture so porous that the fixes themselves routinely introduce the next set of holes. It has been described as trying to patch a fishing net with sugar cubes, and the description is fair. The problem is not that Microsoft is careless with individual bugs, it is that the underlying design is inherently weak, and no amount of patching changes what is underneath.
Then there is single sign-on, sold as convenience and delivered as a single point of catastrophic failure. The proposition is that one identity should unlock the mail, the files, the finance system, the customer records and the administrative console. When that identity is taken, and it is taken constantly, the attacker inherits the entire company in one step. There is no containment, no segmentation and nothing left to fall back on. Companies have lost their livelihoods to exactly this, and the architecture worked precisely as designed while it happened. A secure environment does the opposite: identity is compartmented, access is granted per system, and no single credential opens everything.
The platform is also built around telemetry, cloud identity and cloud storage, behaviours that are increasingly difficult to switch off and increasingly re-enabled by updates. A platform whose default posture is to send data to its vendor cannot be reconciled with an environment whose defining property is that data does not leave. Add a monoculture that attracts the overwhelming majority of commodity malware, licensing that assumes cloud identity, and update mechanisms that change behaviour without consent, and the case closes itself.
Linux gives us the properties the environment requires: source that can be inspected, builds we control, machines that do nothing we have not asked for, no dependency on a vendor's cloud for identity or licensing, and long-term stability without forced change. Systems are deployed from hardened, standardised images, run without local administrative rights for users, and are rebuilt rather than repaired.
Users do not install software. There is no application store, no download, no "just this once". The environment carries a deliberately small catalogue of applications, each one assessed, packaged, version-pinned and allow-listed by name and by cryptographic signature.
Communication is the hardest part to get right, because every convenient option is also an exfiltration route. The environment therefore provides a small number of internal channels and nothing else.
Communication with the outside world happens deliberately, through defined and monitored gateways operated at the boundary, by named people, under a documented process. It is not something an individual workstation can do on a whim. Further detail on the transport layer is set out in GENuinely Secure Communications.
A closed environment still has to receive client material and deliver work product. The difference is that it happens through one known route rather than dozens of unknown ones.
Technology addresses the outsider. Process addresses the insider, who is a far more realistic threat and, in the great majority of incidents, is not malicious but simply looking for an easier way to do their job.
Controls that are not observed are assumptions. Everything of consequence is logged inside the environment, correlated, and reviewed by people who know what normal looks like.
Almost every organisation that suffers a serious data loss had a security policy, a firewall and an antivirus subscription. What it did not have was a closed environment. Data left through a channel nobody had thought to enumerate: a personal cloud account used to work at home, a messaging app used because the approved route was slow, a photograph of a screen, a memory stick in a coat pocket.
Convenience is the attack surface. Every tool that makes information easier to move makes it easier to move out. The modern working environment has been built, deliberately and profitably, to maximise that ease, and the organisations that supply those tools are not the ones who carry the consequences when material escapes.
Not every organisation needs every element of this. A closed WireGuard mesh, biometric airlocks and searching people on their way out are proportionate to some businesses and absurd for others, and we would say so rather than sell it. But the principles apply to everybody: know what you hold, know every route by which it could leave, close the ones you do not need, and watch the ones you do. Every organisation can adopt those, and should, as far as its circumstances practically allow.
What does not work is the half-way house. You are either security aware or you are not. There is no partial position, because security is decided by the weakest route left open, not by the strongest one you have closed. An organisation with a hardened network and an open USB port has an open USB port. One with a strict device policy that quietly tolerates a manager using a personal cloud account has no device policy. Controls that are applied when convenient are not controls, they are preferences, and an attacker only has to find the day they were inconvenient. The decision to take security seriously is binary. What follows from it, how far you go and what you spend, is where proportion belongs.
A secure environment costs something real. It is slower to work in, it constrains how people communicate, and it removes tools they are used to at home. We say so plainly rather than pretending otherwise. What it buys is a defensible position: an environment where you can state, and demonstrate with evidence, exactly what routes existed for a piece of information to leave, and account for every one of them. Very few organisations can do that. The ones who genuinely need to are the ones we build these environments for.
Section 5 of the GEN Framework Agreement sets out our confidentiality and data protection obligations, including the extended scope of confidentiality and the protection of personnel. The controls described here are how those obligations are met in practice rather than on paper. Where a client requires work to be carried out within a secure environment, that requirement is recorded in the Site Record under Section 2.6 and applies to every engagement on that site.
We do not present this as compliance with a certification scheme. The general purpose schemes an organisation is usually asked about are a long way below the standard described on this page, and passing one says very little about whether data can actually leave a building. Where a client carries genuine sector obligations, whether regulatory, contractual or imposed by their own customers, the environment is designed to those specific requirements, which are almost always stricter and considerably more concrete than any general standard.
A secure environment can be a single room, a floor, a building or a distributed estate joined by a private mesh. The scope follows the material being protected and the obligations attached to it, not the size of the organisation. We begin with an assessment of what actually needs protecting, what routes currently exist for it to leave, and what the business can realistically live with, then design and build accordingly.
If your organisation handles material where a leak would be terminal, contact our team to discuss the design, construction and operation of a genuinely secure environment.