Back to Home

Security Protocol & Standards

Our engineering methodology for zero-trust access, defensive network partitioning, and responsible vulnerability management.

In eighteen years of senior IT advisory, Flux Networking has operated on a foundational principle: real security is built through disciplined architecture, not complicated software add-ons. Security that interferes with everyday employee workflows gets bypassed, and software that promises automatic immunity creates false confidence.

This Security Protocol outlines the engineering frameworks, operational safeguards, and defensive standards we apply when designing client networks, as well as the protocols governing our own digital infrastructure.

1. Core Architectural Tenets

Every network environment and cloud migration designed by Flux Networking adheres to three core security principles:

  • Zero Trust Access Control: We operate on the premise that perimeter firewalls alone are insufficient. Every device, laptop, and user account must be continuously authenticated and authorized before gaining access to confidential internal resources, adhering to the CISA Zero Trust Maturity Model guidance (PDF).
  • Defense-in-Depth: We eliminate single points of security failure. If an employee falls victim to a sophisticated phishing lure, strict application whitelisting, network segmentation, and credential vaulting prevent attackers from traversing into database repositories or backup servers.
  • Least Privilege Enforcement: Employees and workstations receive only the minimum access rights required to execute their specific duties. Domain administrator privileges are strictly isolated from day-to-day web browsing and email machines.

2. Framework Alignment & Regulatory Standards

Our cybersecurity hardening and infrastructure assessments directly reference peer-reviewed national standards:

  • NIST Cybersecurity Framework (CSF 2.0): We structure risk assessments around the core functions of the NIST Cybersecurity Framework (PDF): Govern, Identify, Protect, Detect, Respond, and Recover.
  • Identity & Credential Assurance: We configure enterprise directories (Microsoft 365, Google Workspace) to enforce multi-factor authentication (MFA) and eliminate password re-use following the NIST Special Publication 800-63B guidelines (PDF).
  • 3-2-1-1 Backup Resilience: Backups are engineered according to the CISA StopRansomware Guide (PDF): maintaining 3 copies of business data across 2 separate media types, with 1 copy stored in an isolated, immutable cloud repository that ransomware cannot overwrite or delete.
  • Healthcare ePHI Protection: For medical clinics and dental offices, our network segmentation isolates electronic protected health information (ePHI) workstations from guest Wi-Fi and IoT devices, ensuring technical compliance with the HIPAA Security Rule.

3. Scope of Service & Advisory Boundaries

To maintain uncompromising technical quality, Flux Networking enforces clear operational boundaries:

  • Cabling Scope Limitations: Flux Networking specializes in network topology design, managed switch configuration, firewall rule deployment, and commercial Wi-Fi heatmapping. We do not physically pull, terminate, or run cabling drops. We engineer comprehensive structured cabling layout schematics for your licensed low-voltage electrical contractor to install.
  • Trusted Partner Routing: When client engagements require specialized capabilities outside network infrastructure and cyber defense (such as custom web development, complex software engineering, or dedicated 24/7 frontline helpdesk dispatch), we route those requirements directly to vetted external specialist firms to ensure dedicated domain expertise.

4. Website Infrastructure & Digital Transmission Safeguards

We apply the same rigorous defensive hygiene to our own digital footprint that we recommend to our enterprise consulting clients:

  • Transport Encryption: All traffic on fluxnet.us is strictly encrypted using TLS 1.3 with modern cipher suites.
  • Stateless Client Architecture: Our website runs on lightweight, vanilla HTML5, CSS3, and modern ES6 JavaScript. We intentionally avoid heavy third-party tracking scripts, content management system (CMS) plugins, or bloated runtime dependencies that introduce external supply chain vulnerabilities.
  • Secure Form Transmission: Inquiries submitted through our consultation form and assessment wizard are transmitted directly via TLS-encrypted API calls to secure advisor mailboxes. Assessment responses are never stored in public, search-accessible databases.

5. Vulnerability Disclosure & Coordinated Reporting

Flux Networking values the contributions of the cybersecurity community. If you are an independent security researcher and believe you have discovered a potential security vulnerability, configuration flaw, or exposure affecting fluxnet.us, we welcome your disclosure:

Security Contact

Direct Reporting Email: jameshatch@fluxnet.us

Primary Subject Line: [Vulnerability Disclosure] - Description

Direct Office Line: (765) 299-6706

Responsible Reporting Guidelines (Safe Harbor)

We ask that all researchers adhere to ethical disclosure principles:

  • Provide reasonable time for our team to investigate and remediate any confirmed issue before publicly disclosing details.
  • Do not attempt to access, exfiltrate, alter, or destroy client data.
  • Do not execute Denial of Service (DoS/DDoS) attacks or degrade the availability of our systems.
  • Do not utilize automated vulnerability scanners in a manner that floods or degrades production traffic.

Flux Networking will not pursue legal action or initiate law enforcement inquiries against researchers who conduct security evaluations in good faith and comply with these responsible disclosure guidelines. We commit to acknowledging receipt of reported vulnerabilities within 48 hours and prioritizing timely defensive patches.

Ready to Strengthen Your Network Security?

Get a comprehensive, jargon-free security audit for your office network. Discover hidden vulnerabilities before cybercriminals do.

Take 60-Second IT Assessment