KIDANVerse

Zurich

KIDANVerse

Lausanne

A refreshed experience is in progress. A few pages may be temporarily limited.

TOC

End-to-end security operations monitoring.

On-demand Consulting

Expert guidance for strategic technology decisions.

As a Service (Managed)

Enterprise services supporting critical IT infrastructure.

Implementation

Seamless enterprise technology solution deployment.

Training

Empower teams with expert-led technology programs.

Assessment and Audit

Gain complete visibility into your technology infrastructur

Solutions

Tailored IT solutions for operational excellence.

Procurement and Licensing

Expert on-demand consultation for technology procurement

Support

Dedicated IT support for seamless operations.

Most visited page

Expert guidance for strategic technology
decisions.

About Us

Learn more about KIDAN’s vision, values, and expertise.

Security Operations
Center (SOC)

Proactive security operations to
protect data asset

Infrastructure Operations Center (IOC)

Intelligent operations control for
agile IT systems

Network Operations
Center (NOC)

Ensuring smooth network operations
and uptime 24/7

About us

Expert guidance for strategic technology
decisions.

Contact Us

Learn more about KIDAN’s vision, values, and expertise.

Our Partners

Meet KIDAN’s partners working together to deliver technology solutions, support, and growth for businesses.
Strategic Vendor Partners
Collaborating with global leaders for advanced IT solutions
200 +
Technical Managed Solutions
Delivering specialized tools to address complex IT challenges
110 +
Enterprise clients across industry sectors
trust KIDAN’s strategic partnerships and solutions to drive technology success.
1250 +

ManageEngine

IAM

Access Manager Plus

ADManager Plus

ADSelfService Plus

Access Manager Plus

Key Manager Plus

Identity 360

PAM360

Password Manager Pro

Recovery Manager Plus

IAM

UEM

Security

Networks

Cloud

MSP

Help Desk

IT Analytics

ColorTokens

Cloudflare

SentinelOne

Microsoft

Horizon3

Zoho

Xink

Sangfor

390+

Strategic Vendor Partners

115+

Technical Managed Solutions

1'300+

Enterprise clients across industry sectors

Security Operations Center (SOC)

Infrastructure Operations Center (IOC)

Network Operations Center (NOC)

Help Desk and Service Desk

Trusted ColorTokens Partner in Switzerland

Colortokens Microsegmentation
That Keeps You Breach Ready

We architect and deliver true Zero Trust microsegmentation. Contain threats, secure any workload, and eliminate lateral movement with the definitive Swiss authority on the Colortokens platform. Strengthen your critical environments with micro-segmentation, network visibility, and Zero Trust security.

Powering and Protecting Switzerland Core Industries

Breaches Are Increasing Every Year
Despite Spending More and More

Spend​


(US$ Billion)

0
0
0
0
0
0
0
0
0
0

2014

2015

2016

2017

2018

2019

2020

2021

2022

2023

Breaches are publicly disclosed every year
3980 +

Breaches are inexpensive for the bad actor…​

Initial access​
$ 0
Avg. breakout time​
0 Minutes

but very expensive for the business.​

Avg. cost of breach​
$ 2 M
Mean time to remediate​
0 Days

A Single Breach Shouldn't Become a Catastrophe

icon Ransomware Propagation

In an unsegmented network, ransomware spreads like wildfire. Without granular microsegmentation, a compromised endpoint can easily infect your most critical servers, leading to total operational shutdown.

Traditional security creates compliance gaps with limited visibility and weak controls, making it difficult to track access, enforce policies, and maintain consistent audit readiness.

Expanding across hybrid environments increases security gaps, reduces visibility, and complicates policy enforcement, leaving organizations exposed to risks across workloads, applications, and users.

Our Outcome-Driven MicroSegmentation Blueprints

Simplify Security in a Complex Hybrid Cloud

We build a unified segmentation policy that is independent of the underlying network. This ensures consistent, centrally managed security for your workloads, whether they are on-premises or in the cloud. 

Apply the same security logic across VMs, containers, bare metal, on-prem, and public clouds.

Automatically group and secure workloads based on attributes (e.g., tags, labels, roles), no static IP dependencies.

Deep traffic insights across environments help simplify policy creation and threat detection.

Stop Ransomware in Its Tracks

We use Colortokens to create impenetrable micro-perimeters around critical assets. If an attacker breaches the perimeter, they are trapped and cannot move laterally, neutralizing the threat. 

Prevents malware from moving laterally across workloads or segments. 

Only explicitly allowed communication is permitted ransomware can’t “guess” its way across the network. 

Rapid detection and isolation of infected segments minimize impact and recovery time. 

Pass Audits Without Panic

We leverage the platform’s visualization and policy tools to create and enforce software-defined boundaries. This generates clear, audit-ready reports that prove compliance and reduce audit preparation time by weeks.

Limit communication to what’s strictly necessary, a key compliance pillar.

Demonstrate control over traffic flows and access paths, useful for audits.

Create compliance-aligned policies once and apply them consistently across all environments.

Average breach cost

globally (2024)
$ 4.51
Of breaches involve

lateral movement
60 %
How fast an attacker

moves laterally
25 Min
Average time to

breach detection
90 Days

The Uncomfortable Truth

Stop planning to prevent the breach. Start planning to survive it.

No security stack is impenetrable. Attackers need one successful phishing email, one misconfigured endpoint, one stolen credential. Your team must stop every attempt, every time. That asymmetry is irreversible. The CISOs who sleep at night are not the ones who believe their perimeter holds — they are the ones who have built systems that contain the damage the moment it gets through. The question is no longer can we stop them? It is: when they get in, how far can they go?

Your Security Stack Has a Missing Layer

Most organizations believe they are protected because they have invested in the right tools. They are right that those tools matter. They are wrong that they are sufficient. Each tool in your stack covers a specific layer — and there is a critical layer none of them cover.

Firewall / NGFW

Perimeter defense

Controls traffic entering and leaving your network. Entirely blind to communication happening between systems already inside.
❌  Can’t stop internal lateral movement

SIEM / SOC

Detection & monitoring

Aggregates logs, generates alerts, enables investigation. Detection takes ~95 days on average. By then, the damage is done.
❌ Detects — does not contain

EDR / XDR

Endpoint protection

Identifies malicious behavior on endpoints and can isolate a device. But it cannot block traffic between other systems in real time.
⚡ Partial — endpoint only, not network-level

Microsegmentation

The missing layer

Draws invisible walls inside your network. Every workload, server, and device can only communicate with what it is explicitly authorized to reach. Attackers get in — and go nowhere.
✔️ Actively contains breach blast radius

Strategic Perspective

Most companies aren't looking at this yet.
That's exactly the opportunity.

The majority of enterprises today believe their EDR and firewall are enough. They will learn otherwise — the question is whether they learn it from a report or from a breach. Organizations that deploy microsegmentation now are not just safer — they are more compliant, more insurable, and ahead of regulatory pressure that is already building. Waiting for an incident to justify the investment is the most expensive decision a CISO can make.

The ColorTokens Xshield Platform

Don't just prevent.


Contain. Survive. Continue.

ColorTokens Xshield is an enterprise microsegmentation platform that draws granular security boundaries inside your network — at the workload, endpoint, and device level. An attacker who gets in finds themselves trapped in a single segment, unable to reach your critical systems, your data, or the rest of your infrastructure. The breach happens. The business doesn’t collapse.

Stop the Spread of Ransomware in Seconds

Xshield provides the visibility and granular microsegmentation needed to contain breaches at the source, preventing lateral movement and protecting your most critical assets.

Without Xshield

✗ Full operational shutdown. $4.88M+ recovery cost.

VS

With Xshield Active

✓ Breach contained. Business continues. Recovery: hours.

Why ColorTokens — Not Another Vendor

Recognized as a Leader in the 2024 Forrester Wave™ for Microsegmentation, ColorTokens simplifies breach containment with an agentless, AI-powered approach that delivers enforcement in weeks, not years.

★ Forrester Wave™ LeaderMicrosegmentation · Q3 2024

No new agents

Competitors require deploying proprietary agents on every host. Xshield uses your existing EDR — saving weeks of rollout time.

AI-assisted policy, not manual configuration

Other vendors require IT and security teams to define every policy. Xshield's AI proposes them — you approve.

Covers everything

Servers, endpoints, cloud, containers, OT/IoT, legacy systems — in one console. Competitors cover some. Xshield covers all

60–90 days to enforcement

vs. months or years with legacy segmentation approaches. Fastest time-to-value in the market.

Overall Rating​
3 /5
Product Capabilities​
4 /5
Customer Experience
4 /5
sensors installed
0 K+
servers protected​
0 K+
35+ Patents​
2 Years

Don’t let hackers finish what they start.

Xshield visualizes your environment, assesses risk, and secures all workloads and endpoints by placing a micro-perimeter around each for strong protection.

Protect Your Crown Jewels with ColorTokens Xshield

Every organization has crown jewels: critical applications, servers, and data. ColorTokens Xshield protects them using real-time visibility, microsegmentation, threat containment, simple policy enforcement, and continuous compliance ensuring only authorized access while blocking malware, ransomware, and lateral movement.

The KIDAN Advantage
Your End-to-End Swiss Partner

Exclusive Swiss Authority & Access

As the sole official distributor (VAD) and most certified partner (VAR) for Colortokens in Switzerland, we provide an extensive level of service.

✅ local, bilingual engineers

✅ Access to top-tier vendor support

✅ Swiss data laws (FADP) Compliance

✅ optimized commercial termss

Your success is guaranteed by our unique position in the
market.

Strategic Zero Trust Architecture

We don’t just deploy agents; we architect breach containment.

✅Starts with your business risk, not just technology

✅ Comprehensive Zero Trust strategy tailored to your environment

✅ Seamless integration with your SIEM and SOAR platforms

✅ Measurable reduction in attack surface and organizational risk

Built to strengthen your entire security posture from the inside out.

Full Lifecycle Integration & Consumption

We are not transactional resellers; we are a lifecycle
partner.

✅ Consume resilient security on your terms

✅ Engage us for fixed-scope On-Demand Projects

✅ Transition to a fully managed As a Service subscription

✅ Augment your team with 24/7 protection from our
Technology Operations Center (TOC)
We adapt to your operational model.

Key Outcomes

Empower your security teams with the data-driven insights and automated controls needed to drastically reduce your attack surface and ensure business continuity in the face of a breach.

50–80%

Breach Impact Reduction

Measurable reduction in blast radius and operational damage within 60–90 days of deployment.

50–80%

Full Environment Visibility

Every asset, every traffic flow, every dependency mapped — in under one hour, with no disruption.

90%

MITRE ATT&CK Coverage

90% of lateral movement attack techniques addressed. Updated automatically every 24 hours.

0 Min

Agent Maintenance

Xshield rides on your existing EDR — no new agents to qualify, deploy, or maintain. Zero added overhead.

<0.1%

Business Disruption Risk

30-day simulation before any enforcement. Policy changes tested in real time. Outage likelihood below 0.1%.

Day 1

Compliance Readiness

Supports GDPR, DORA, NIS2, PCI-DSS, nDSG. Enforced segmentation reduces audit scope from day one.

Free Breach Readiness Assessment

Delivered in 48 hours · No commitment · No disruption

Asset & Posture Visibility

Full inventory of your attack surface, blast radius, and breach impact metrics across all environments.

Lateral Movement Analysis

Which MITRE ATT&CK techniques could be used against your environment today, and how far they could go.

Roadmap & Recommendations

A prioritized, actionable plan showing measurable security improvements through Zero Trust microsegmentation.

Already using CrowdStrike, SentinelOne or Microsoft Defender? You are minutes away from starting. colortokens.com/breach-readiness-assessment

The risk is universal.

The stakes differ by industry.

From SWIFT infrastructure in banking to life-saving systems in healthcare, we provide the granular visibility and control required to meet stringent industry regulations and prevent systemic failure.

Banking & Financial Services

Where a breach becomes a systemic event

Banks run interconnected core systems — payment platforms, trading engines, client portals — all communicating internally. A single compromised endpoint can reach SWIFT infrastructure, core banking, and client data if lateral movement is not blocked. Beyond the financial loss, the regulatory and reputational consequence is existential.

FINMA

DORA

PCI-DSS

NDSG

NIS2

DORA (EU) requires financial entities to demonstrate operational resilience and breach containment capability

FINMA expects documented network segmentation as part of ICT risk management

Isolate payment systems, trading environments, and client data — even if one is compromised

Zero Trust microsegmentation directly satisfies key requirements across DORA, FINMA circular 2023/1

Healthcare & Life Sciences

Where a breach stops patient care

Hospital networks connect clinical systems (LIS, PACS, infusion pumps, connected devices) with administrative and external systems on the same infrastructure. Ransomware that reaches a PACS server or a ward’s infusion pump network is not a data problem — it is a patient safety crisis. Healthcare is the most targeted sector globally for ransomware attacks.

nDSG (CH)

GDPR

LRV

HIN

ISO 27001

Isolate medical devices, clinical systems, and patient data from administrative networks

Agentless coverage for IoMT — Xshield protects legacy medical devices that cannot run agents

nDSG and GDPR demand strict controls on patient data — microsegmentation enforces them architecturally

When ransomware hits: clinical operations continue in unaffected segments

Manufacturing & Critical Infrastructure

Where a breach stops the physical world

Modern manufacturing environments connect IT and OT on the same network — ERP systems, SCADA, PLCs, and industrial controls. An attacker moving from the IT environment into OT can halt production lines, damage equipment, or in critical infrastructure, create safety incidents. Legacy OT devices cannot run security agents — making traditional protection impossible without microsegmentation.
 

NIS2

IEC 62443

nDSG

ISO 27001

Agentless Gatekeeper protects PLCs, SCADA, and legacy OT that cannot support endpoint agents

NIS2 mandates network segmentation for operators of essential services — microsegmentation is the direct answer

Enforce strict IT/OT separation: a breach in the corporate network cannot reach the production floor

IEC 62443 zone and conduit model implemented through Xshield policy enforcement

Public Sector & Government

Where a breach compromises public trust

Government agencies hold some of the most sensitive data that exists — citizen records, infrastructure schematics, law enforcement data, national security information. Public sector environments are chronically under-resourced for security while being high-value targets for state-sponsored attackers. A lateral movement attack in a government network can persist undetected for months.
 

NIS2

nDSG

NCSC Guidelines

ISO 27001

Segment sensitive citizen data, critical infrastructure controls, and administrative systems — architecturally, not by policy alone

NIS2 requires essential service operators to implement network segmentation and access control

Switzerland's NCSC recommends Zero Trust principles for federal and cantonal ICT environments

State-sponsored lateral movement is the primary attack vector — microsegmentation is the primary mitigation

ColorTokens is Rated a Leader in the Forrester Wave™: Microsegmentation Solutions, Q3 2024

KIDAN Blueprint

Reference Architecture:
A Blueprint for RansomwareContainment with Microsegmentation

Case study

How a Swiss Pharmaceutical Firm Secured its Hybrid Cloud with KIDAN and Colortokens

On-Demand Webinar 

Beyond Firewalls: A CISO’s Guide to
Practical Zero Trust

For Our Partners: Become a Certified Colortokens Reseller

As the exclusive Swiss distributor for Colortokens, we are actively building a network of elite IT partners. We provide the training, technical pre-sales support, and commercial framework necessary to empower you to deliver world-class microsegmentation solutions to your clients. Partner with the source.

Trusted by Leading Organizations

Request Your
Free Customized Demo

MM slash DD slash YYYY
Time
:
Untitled(Required)

By clicking 'Submit', you agree to processing of personal data according to the Privacy Policy.

Your Questions Answered by the Experts

What is microsegmentation and how does it differ from network-based controls like VLANs and firewalls?

Think of it as the difference between a castle wall and a dedicated bodyguard for every important person inside. Traditional firewalls and VLANs are like castle walls they are strong at the perimeter but offer little protection once someone is inside. Microsegmentation provides a dedicated bodyguard for each individual application (workload). It uses the workload’s identity, not its network address, to enforce policy. This means if one server is compromised, it is immediately isolated and cannot communicate with others, stopping lateral movement and containing the breach.

This is a critical design consideration. The Colortokens agent is a lightweight, kernel-level component engineered for high performance. For the vast majority of enterprise workloads, the performance impact is minimal to negligible, typically consuming less than 1-2% of CPU. A core part of our blueprint is to establish a performance baseline during the initial ‘visibility-only’ phase to ensure that when policies are enforced, there is no adverse impact on your business applications.

This is central to our methodology and the platform’s design.

Every KIDAN engagement follows a zero-disruption rollout plan:

  1. Visibility Phase: We deploy agents in a non-enforcement mode to simply observe and map 100% of your traffic flows. There is no impact.
  2. Simulation Phase: We use this map to build and model policies. You can see the exact impact of a proposed rule before it is ever enforced.
  3. Phased Enforcement: We begin enforcement on the least critical applications, validate the outcome, and progressively expand the policy across your environment in controlled stages. This methodology guarantees a secure, seamless transition without any operational disruption.

Microsegmentation is not defined by employee count, but by the level of operational risk and IT complexity. In reality, we cover and recommend microsegmentation by use case but realistically would advise it from companies above 50 employees, on average. It delivers the highest strategic value to organizations that have: a hybrid environment (on-premise and cloud), strict compliance requirements (FINMA, PCI, ISO), high-value intellectual property to protect, or a low tolerance for downtime caused by a breach. If a single security incident could cause significant financial or reputational damage, you are the right size for a microsegmentation strategy. Our scoping call is designed to determine if this strategic value aligns with your specific operational reality.

Quick details before your demo

Almost there – a few quick details first.

Thank you for applying to the KAI Builder Program by KIDAN.

Your application is now under review. Our team will carefully evaluate your use case, commitment level, and strategic fit. If shortlisted, you will hear from us within 5 business days to schedule your Discovery Call.

We look forward to potentially building the future of AI together.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details For Pricing

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.

Quick details before your demo

Almost there – a few quick details first.