Skip to main content

Security

Cybersecurity for small and medium companies

Proportionate, sustainable measures: protecting email, endpoints, access and backups, with continuous monitoring and a clear procedure for when something goes wrong.

The starting point

Most incidents in smaller companies do not come from a targeted attack, but from an email, a reused credential or an unpatched system. The sensible response is not buying more tools, but putting the basics in order and watching them.

What we usually find

  • Email as the main entry point for fraud and malware.
  • Antivirus installed but with nobody reviewing its alerts.
  • Administrator credentials shared between several people.
  • No defined procedure for the day an incident happens.

Which companies it fits

SMEs and mid-sized companies without an in-house security team that need a defensible level of protection for customers, audits and insurers.

We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.

Request a security assessment

What the solution includes

  • Email protection

    Antispam filtering and impersonation controls on the corporate domain.

  • Endpoint protection

    Managed endpoint antivirus, with review of detections and of devices left uncovered.

  • Access control

    Two-factor authentication, review of privileged accounts and clean-up of stale users.

  • Monitoring and response

    Continuous monitoring and, where the service includes it, managed detection and response (SOC/MDR).

How it is deployed

  1. 1Diagnosis of the current state and of entry points.
  2. 2Prioritisation of measures by risk and effort.
  3. 3Deployment of baseline protections.
  4. 4Short staff training on email and credentials.
  5. 5Periodic review and policy tuning.

Real-world scenarios

A fraudulent email impersonating a supplier

The most repeated case is not a sophisticated attack: it is an email imitating a known supplier and asking for a change of bank account. The defence combines mail filtering, visible marking of external messages, multi-factor authentication on mailboxes and an internal rule that bank detail changes are verified through a channel other than email.

One infected machine on a flat network

In many SMEs every device shares one network: workstations, servers, printers, cameras and machinery. If one machine is compromised, it reaches the rest unimpeded. Network segmentation and access control limit the blast radius and turn a serious incident into a contained one.

What is covered and what is not

Seintec deploys and operates the technical measures: mail protection, multi-factor authentication, managed antivirus, patching, segmentation, backups and alert review, with periodic status reports. Legal advice on data protection is outside scope and remains with the company's law firm or consultant, as does drafting internal policies, which management must approve. Seintec supplies the technical documentation those policies rely on and joins review meetings when the compliance owner asks for it.

What is at stake if it is left unaddressed

  • Unpatched software

    Operating systems and applications past end of support account for most of the vulnerabilities exploited at scale.

  • Excessive permissions

    Users running with administrator rights turn any human mistake into an organisation-wide problem.

  • No user awareness

    The highest-return measure is still that people can recognise an attempted fraud and know who to tell without fear of blame.

Frequently asked questions

Does this make us GDPR or NIS2 compliant?
It supports the technical measures, but regulatory compliance includes legal and organisational aspects beyond the technical scope. We do not guarantee compliance.
Does an SME need a SOC?
Not always. It makes sense when there is sensitive data, customer requirements or a broad exposure surface.
What happens if we suffer an incident?
The agreed procedure is activated: containment, scope analysis, recovery from verified backups and a follow-up report.
Does it work alongside our current IT provider?
Yes. The security scope can be contracted on its own and coordinated with whoever manages the rest.
Where should a company starting from scratch begin?
With the basics, in this order: an inventory of devices and access, multi-factor authentication on mail and remote access, managed antivirus with central visibility, verified backups and up-to-date patching. Those five points cover most real incidents before any more advanced measure is considered.
Is a standard antivirus not enough?
An unmanaged antivirus detects things, but nobody sees the alerts or checks which machines are unprotected or unpatched. The difference with a managed service lies in the central console, the periodic review and the response when something is detected, not in the product installed on each device.
What legal obligations apply to an SME?
Processing personal data requires proportionate technical and organisational measures, a record of processing activities and the ability to notify a breach within the deadline. Seintec implements the technical measures and documents what has been deployed; legal advice remains with the firm or consultant handling compliance.
How often is the security posture reviewed?
Alerts are handled continuously within the managed service, and the overall position is reviewed with the company at the agreed intervals. That review covers unpatched machines, accounts without multi-factor authentication, backup results and incidents in the period, each with a concrete action and a date.
What should staff do when they suspect a fraudulent email?
Stop, avoid clicking or replying, and report it through an internal channel agreed in advance. The important part is that reporting carries no blame, because hesitation is what turns a caught attempt into a successful one. Where the message concerns a payment or a change of bank details, verification goes through a known telephone number rather than any contact detail supplied in the message itself.

Request a security assessment

We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.

Request a security assessment