SSHepherd®

Enterprise Solutions · Zero Trust Network Access

Be Invisible.
Be Invincible.

SSHepherd® completely removes the open, listening ports for SSH, RDP, and applications — while still maintaining the full access and functionality of those services for authorised users.

Zero Open Ports Zero Trust Architecture Immutable Audit Trail BNM RMiT 2025 Aligned NIST SP 800-207 ISO 27001
The Problem

Traditional Security Leaves You Exposed

VPNs and Firewalls are a necessary piece of your perimeter security — but this is not enough. Protecting your resources inside the perimeter is a vital piece of your defence.

Open ports will always be the primary attack vector for threat actors. Even with firewalls, ports often remain open for operational needs, increasing the attack surface and making them prime targets for ransomware, DDoS attacks, and unauthorised remote access.

Preventing unauthorised access to your critical systems, auditing activity during remote access sessions, mitigating the risk of data loss, and good cyber hygiene are key to most security compliance guidelines like NIST, CIS, CERT, and all others.

  • Persistent Open Ports

    Even with firewalls, ports often remain open for operational needs, increasing your attack surface.

  • Inefficient Access Controls

    Existing solutions struggle to dynamically manage access without causing disruptions to operations.

  • Compliance Auditing Complexity

    Organisations must adhere to strict compliance regulations — NIST, ISO 27001, GDPR — while ensuring smooth IT operations.

  • Lateral Movement Risk

    Once inside, attackers move laterally across your network. Traditional tools have no built-in mechanism to stop this.

How It Works

Inverse Coupling Architecture

SSHepherd utilises a proprietary WebSocket tunnel between the Client and Agent in the absence of open ports. The tunnel is TLS-encrypted and appears as standard outbound web traffic from the Agent machine.

01

Deploy the Agent

Install the lightweight Shepherd Agent on any protected server, VM, or IoT device. Extremely lightweight — CPU under 1%, RAM 128–512 MB — with no changes to your existing network or security stack.

02

Ports Close. Assets Go Dark.

SSH (port 22) and RDP (port 3389) are instantly closed and cloaked. Your servers become a “dead box” — invisible to port scans, brute-force attempts, and reconnaissance. The attack surface no longer exists.

03

Authorised Access via Secure Tunnel

The C3 Server acts as the central policy engine and identity broker. Authorised users connect via the Shepherd Client through an encrypted outbound-only TLS tunnel — full SSH and RDP functionality, zero open inbound ports.

Core Capabilities

Everything You Need to Secure Privileged Access

SSHepherd consolidates Zero Trust Network Access, Privileged Access Management, and session monitoring into a single, lightweight platform.

Control Access

Only authorised users and applications can see SSH, RDP, or application services. Enforces zero-trust posture for on-premise and cloud assets.

Real-Time Live View

Gives security staff live oversight of all active SSH and RDP sessions — who is connected, from where, and what they are doing in real time.

Terminate Sessions

Built-in kill switches allow immediate manual or automated session termination via SIEM — removing ingress/egress points for lateral movement instantly.

Archive for Audit

Full video playback of RDP sessions and text replay of SSH sessions. Logs stored centrally on the C3 database — tamper-proof, not on the local agent.

Full Auditing

Comprehensive logs — who, when, from where, what they did — streamed to your SIEM for real-time threat identification and forensic investigations.

Prevents Lateral Movement

By removing the exposed attack surface and enforcing just-in-time connections, SSHepherd eliminates the pathways attackers use to move inside your network.

On-Premise & Cloud

Works uniformly across on-premise data centres, AWS, Azure, GCP, and hybrid environments. Consistent control without changing your existing infrastructure.

Easy Deployment

Lightweight agent. Supports Windows, Linux, Kubernetes. Compatible with Ansible, Chef, and Puppet. No changes to existing network or security stack required.

How We Compare

SSHepherd® vs. Other Solutions

Most ZTNA and security tools reduce exposure — SSHepherd eliminates it entirely. Servers appear as a “dead box” to every attacker.

Capability SSHepherd® Firewalls / VPN EDR / NDR Zscaler ZPA Teleport
Removes open / listening ports✓ Yes✗ No✗ No✗ No✗ No
Zero Trust Access Control✓ YesLimitedLimited✓ Yes✓ Yes
Real-time session monitoring✓ YesLimited✓ Yes✗ NoPartial
Session recording (video / text replay)✓ Yes✗ NoLimited✗ NoPartial
Real-time kill switch✓ Yes✗ NoLimited✗ No✗ No
Outbound-only connectivity✓ Yes✗ No✗ No✓ Yes✓ Yes
Seamless user experience✓ Yes✗ NoModerateModerateModerate
Compliance & forensics audit trail✓ YesLimitedLimitedLimitedPartial
Compliance & Regulatory Alignment

Built for Regulated Industries

SSHepherd directly addresses control objectives across major cybersecurity frameworks and Malaysian regulatory mandates.

NIST SP 800-53 / 800-207

NIST Zero Trust Architecture

Implements stringent access control policies aligned with NIST SP 800-53 and the Zero Trust Architecture standard NIST SP 800-207.

ISO/IEC 27001

Information Security Management

Supports risk assessment, access control documentation, and compliance reporting required under ISO 27001 Annex A controls.

GDPR / CCPA / PDPA

Data Privacy Regulations

Ensures secure handling of personally identifiable information through encrypted access channels and immutable audit trails.

FIPS 140-2

Cryptographic Standards

All data in transit encrypted using TLS 1.2/1.3 tunnels. Cryptographic modules capable of FIPS 140-2 compliance. Supports MFA, SAML 2.0, and OIDC.

BNM RMiT 2025

Bank Negara Malaysia RMiT

Directly addresses BNM’s revised Risk Management in Technology policy (effective November 2025) — attack surface reduction, privileged access control, and continuous monitoring.

CTRAG

Cloud Technology Risk Assessment

Aligns with CTRAG (BNM Appendix 10) requirements for zero-trust principles, secure configuration, and audit log enablement in cloud and hybrid environments.

Quantum Readiness

Defence Through Attack Surface Elimination

Nation-state actors are currently using a “Harvest Now, Decrypt Later” (HNDL) strategy — scanning for open management ports (TCP 22, TCP 3389) and siphoning encrypted data today to decrypt retroactively when quantum computers mature.

1

Step 1: Invisibility — Immediate Action

Before spending on Post-Quantum Cryptography (PQC), stop the bleeding. Deploying SSHepherd immediately eliminates the attack surface — adversaries cannot scan, find, or harvest from ports that do not exist.

2

Step 2: Transition — Medium Term

Because SSHepherd protects legacy infrastructure by hiding it, your organisation buys crucial time. No need to panic-upgrade every legacy server, because those servers are no longer exposed.

3

Step 3: PQC Integration — Long Term

As NIST finalises PQC standards, SSHepherd’s TLS tunnels can be upgraded to quantum-resistant algorithms — securing the entire brokered connection without touching the underlying cloaked servers.

“A quantum computer cannot crack a connection it cannot find.

SSHepherd removes the door entirely. It does not matter how powerful the adversary’s quantum computer is if there is no network port to aim it at. SSHepherd secures your infrastructure today, satisfies BNM RMiT mandates, and buys the time needed to execute your long-term quantum strategy.

Use Cases

Built for Every Sector

Enterprise IT Security

Protects internal corporate networks from port-based attacks and provides centralised, auditable privileged access management.

Financial Services & Banking

Ensures secure remote access for banking infrastructure. Directly supports BNM RMiT 2025 and CTRAG compliance for Malaysian financial institutions.

Healthcare & Medical Devices

Prevents unauthorised access to IoT medical equipment and healthcare servers — protecting sensitive patient data at the network level.

Government & Defence

Secures classified networks and critical infrastructure. The “dead box” architecture ensures assets are invisible even to adversaries inside the perimeter.

Cloud & Data Centres

Enables a “Secure by Default” posture for cloud-hosted workloads across AWS, Azure, GCP, and on-premise data centres.

Component Architecture

Three Components. One Unified Platform.

The SSHepherd ecosystem is composed of three discrete components working together to deliver complete privileged access control.

Component 1

C3 Server — Command & Control

  • Central policy engine and identity broker
  • On-premise, private cloud (AWS/Azure/GCP), or hybrid
  • Supports 10,000+ Shepherd Agents per cluster
  • 500+ concurrent active sessions per standard node
  • Active-Active clustering behind standard load balancers
  • Recommended: 8 vCPU, 32 GB RAM, 1 TB SSD, 10 Gbps NIC
Component 2

Shepherd Agent — Protected Endpoint

  • Installed on any protected server, VM, or IoT device
  • Windows Server 2012 R2 through 2025, Windows 10/11 Enterprise
  • RHEL 7/8/9, CentOS 7, Ubuntu 18.04–24.04, Debian 10, Amazon Linux
  • Kubernetes (GKE, EKS, AKS, OpenShift) — DaemonSet deployment
  • CPU: <1% idle · RAM: 128–512 MB · Disk: 200–500 MB
  • No open inbound ports required — all inbound blocked
Component 3

Shepherd Client — User Interface

  • Application used by authorised administrators to connect
  • Supports Windows 10/11, macOS 11+, Linux (Ubuntu/Fedora)
  • Minimal hardware — runs on standard corporate laptops
  • MFA, SAML 2.0 (Microsoft Entra ID / Azure AD), OIDC (Okta, Ping)
  • All traffic outbound only — TCP 443 TLS to C3 Server

Ready to Make Your Infrastructure Invisible?

Our team can arrange a Proof of Concept (PoC) to demonstrate how SSHepherd can make your critical infrastructure invisible to attackers and showcase its superior auditing capabilities in your environment.