Cybersecurity
Company security is settled on two fronts that have to agree with each other. The first is written down: policies, registers and answers to the questionnaires your large customers, your insurer and, where it applies, the data protection authority will send you. The second is technical: whatever genuinely stops a booby-trapped email, a ransomware crew or the quiet export of your client list. A document with nothing behind it protects nobody, and protection that was never described cannot be demonstrated on the day of an inspection. We take on both, entirely remotely.
Regulation and requirements
The trigger nearly always comes from outside: a security questionnaire from a major client, the renewal of cyber cover, a request from a public buyer, or the question of whether NIS2 reaches you directly or through the back door, as a supplier to an entity that is in scope. We work along ISO 27001 principles and the guidance published by ANSSI.
GDPR and personal data protection
Where the data about your staff and your clients genuinely sits, who can reach it and what the logs keep about them. The security requirements of the GDPR turn into exact settings in Microsoft 365, in your payroll software and across your file shares.
Security policies and documentation
An information security policy, a risk assessment, what to do when an incident starts and the rules for granting access. These are the papers auditors, public buyers and corporate procurement teams ask to see.
Technical safeguards
Tools are chosen from the risk assessment, not from a vendor catalogue. Protection that is heavier than the risk slows people down, and they end up inventing ways round it; so we take first whatever measurably lowers the risk.
Security tooling deployment
An inventory of what your subscriptions already cover, then a pilot on a handful of machines, then a roll-out carried through to the end. The tool has to protect, not merely appear on an annual invoice.
Infrastructure security
Firewall rules, a network cut into zones, protected remote access instead of a remote desktop published on the internet, and logs gathered in one place.
Application security
Roles in the ERP and the CRM, a dedicated account for every automated link, API keys taken out of configuration files, and dependencies checked before each release.
Data leak prevention (DLP)
Information classification, encrypted laptops and rules in Microsoft Purview that hold back a file of personnel records before it leaves the company.
Database security
Permissions set in the engine itself, a record of who reads which tables, and anonymised datasets for developers instead of a production copy on a laptop.
Web application firewall (WAF)
A filter in front of your shop or client portal that screens out injection attempts, password guessing against the admin area and bots copying your prices.
Access control and endpoint security
A second factor on every account, conditional access in Entra ID, machines looked after through Intune, and rights cut back to what each person truly uses.
VPN and encryption
Encrypted links between your premises and for people on the move, disk encryption on laptops, and a protected way of sending the documents that warrant it.
Vulnerability scanning
Regular examination of your servers, your network and your websites, followed by a ranked list: what gets fixed today, what waits for the next maintenance window.
Monitoring and upkeep
A configuration set once and left alone ages within months: new people arrive, new software appears, attack techniques move on. These services exist to keep protection moving with them.
Where to start
Buying everything at once usually ends with an overspent budget and consoles nobody opens. For an organisation of 10 to 250 people, this is the order we suggest.
Inventory
Which systems and which data you hold, where they live and who holds the keys. Everything else follows from that: which rules apply to you and what deserves the most serious protection.
Risk assessment
A list of the threats that are plausible for your trade and your size. This document prevents pointless purchases, and a risk-led approach is exactly what both the GDPR and NIS2 build on.
The baseline
Policies, a second factor everywhere, patching that happens, endpoint protection and backups whose restore has been tested. That baseline already answers most customer questionnaires and turns away the common attacks.
Targeted tools and watchfulness
We add whatever the risk assessment pointed at, segmentation, application filtering, leak prevention, and then connect monitoring so that an attack is seen arriving rather than discovered afterwards.
A fine is almost never the most expensive part of an incident. Losing a client file costs trust first and sometimes a contract, and ransomware paired with a backup nobody had ever restored can stop a company for weeks. So we begin with whatever limits the damage, not with whatever looks best in a report.
Questions and answers
That depends on your sector, your size and detailed criteria set by the directive and by the national law bringing it in, with exceptions along the way. Many smaller organisations feel the text indirectly, when a customer in scope starts asking about the security of its supply chain. We prepare the technical part of those answers; whether the text reaches you directly is settled with your legal counsel.
Yes. Size excuses nothing once you handle data about employees, patients or clients. A small organisation simply has fewer systems to go through. The seventy-two hour deadline for notifying a breach applies to a five-person practice exactly as it does to a chain of shops.
They are enough to complete a questionnaire, not to stop an attack. A document shields you from the accusation of having no procedure; it does not shield your data. In every recommendation we separate clearly what satisfies a formal requirement from what lowers the risk. Choosing between the two, and at what pace, is yours.
Seldom at the outset. A company with fifteen or so machines already gets a lot from an EDR driven through one console, with well-tuned alerts and somebody reading them. Wider monitoring earns its place when an hour of downtime is expensive, when a contract sets a response time, or when the data you hold is unusually sensitive.
The duration follows the size of the environment and the scope agreed; the timetable is fixed after the opening review and written into the agreement. No visit is needed: conversations happen over video and configuration goes through secure remote access. Where something physical is unavoidable, your team or your installer does it from our instructions.
Related areas
Measure the gap between where you are and what is expected
Tell us what data you handle and what protection is already running. After a remote review we show you where you stand against what your clients and the regulations expect.
Weekdays, 8:00 to 18:00 CET; answers land inside one working day
A call on Teams or Google Meet, whenever writing is not enough
Message received
An answer follows inside one working day. Report an outage that is stopping people working and it moves ahead of everything else.
- Anything unclear gets asked. Where a figure needs detail we do not have, expect an e-mail or an offer of a short call on Teams or Google Meet.
- A proposal follows. What is covered, the figure in euros excluding VAT, and a start date that will hold. Nothing hides beneath an asterisk.
- Then it is your call. The proposal sits in your inbox for as long as you need. Query any line of it, and decide once you are satisfied.