AI DEFENCEBY ALTARI SYSTEMS
Menu

Security guide / Altari Systems

Quarantine should leave a controlled path to repair.

A restricted device may need enough connectivity to identify itself, receive an update and report evidence. The design challenge is preserving those necessary functions while withholding access that the device has not justified.

Published by Altari Systems · 12 September 2026

Separate identity from an address

IP and MAC observations help describe where a device was seen. They do not by themselves prove that it is the same enrolled device, and they do not establish current health. NAT, address changes, randomisation and spoofing all complicate address-only assumptions.

A stronger decision can combine enrolled certificates, appropriate hardware-backed evidence, device posture and an authenticated session. Context and behaviour then help determine whether the requested access is expected.

Make the restricted state purposeful

Quarantine should define an allowlist of necessary functions: enrolment, authentication, relevant Remedy communication, essential naming/addressing and approved remediation. Those paths need clear destinations, scope and controls of their own.

The restricted device should not retain unnecessary peer, file-share, database, backup or management access. Neither should the operator lose every way to repair it. Retained management and recovery paths deserve explicit design and testing.

Use step-up for the question it can answer

A stronger user authentication can help resolve uncertainty about a session. It cannot remove a malicious process or correct a failed posture check. The access decision still needs evidence about the device and the resource.

A new network location may be normal. Combined identity changes, failed posture and unusual access patterns need a different response. A policy that reacts to a single weak signal risks unnecessary disruption.

Tie readmission to the reason for restriction

Before restoring authority, check what caused the restriction and whether it was addressed. That may require approved remediation, current attestation and an independent observation appropriate to the original condition.

Recertification should specify which state now meets policy. Restoring network access does not establish data recovery or absence of every threat. Any required evidence that remains missing or contradictory must be visible.

Evaluate the actual enforcement path

Remedy Network Trust and integrated quarantine are planned. Existing firewalls, NAC and identity-aware gateways are possible enforcement categories; their mention does not establish a live connector.

A useful pilot names the device class, resources, enforcement points, supported restrictions and release procedure. It should account for alternate network paths and loss of management communication. The goal is a demonstrable bounded outcome.

Questions answered

Talk directly to Altari

Bring the environment.
Start with the right questions.

Discuss a demonstration, current capabilities and a bounded evaluation with Altari Systems.

Request a demonstration