Skip to main content

Security

Cybersecurity for small and medium companies

Proportionate, sustainable measures: protecting email, endpoints, access and backups, with continuous monitoring and a clear procedure for when something goes wrong.

The starting point

Most incidents in smaller companies do not come from a targeted attack, but from an email, a reused credential or an unpatched system. The sensible response is not buying more tools, but putting the basics in order and watching them.

What we usually find

  • Email as the main entry point for fraud and malware.
  • Antivirus installed but with nobody reviewing its alerts.
  • Administrator credentials shared between several people.
  • No defined procedure for the day an incident happens.

Which companies it fits

SMEs and mid-sized companies without an in-house security team that need a defensible level of protection for customers, audits and insurers.

We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.

Request a security assessment

What the solution includes

  • Email protection

    Antispam filtering and impersonation controls on the corporate domain.

  • Endpoint protection

    Managed endpoint antivirus, with review of detections and of devices left uncovered.

  • Access control

    Two-factor authentication, review of privileged accounts and clean-up of stale users.

  • Monitoring and response

    Continuous monitoring and, where the service includes it, managed detection and response (SOC/MDR).

How it is deployed

  1. 1Diagnosis of the current state and of entry points.
  2. 2Prioritisation of measures by risk and effort.
  3. 3Deployment of baseline protections.
  4. 4Short staff training on email and credentials.
  5. 5Periodic review and policy tuning.

Frequently asked questions

Does this make us GDPR or NIS2 compliant?
It supports the technical measures, but regulatory compliance includes legal and organisational aspects beyond the technical scope. We do not guarantee compliance.
Does an SME need a SOC?
Not always. It makes sense when there is sensitive data, customer requirements or a broad exposure surface.
What happens if we suffer an incident?
The agreed procedure is activated: containment, scope analysis, recovery from verified backups and a follow-up report.
Does it work alongside our current IT provider?
Yes. The security scope can be contracted on its own and coordinated with whoever manages the rest.

Request a security assessment

We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.

Request a security assessment