All laptop endpoints are configured with firewalls enabled. All production services are managed and protected by Security Groups within AWS. By default the behaviour is to deny-all and permit of exception (as required).