Security
Cybersecurity for small and medium companies
Proportionate, sustainable measures: protecting email, endpoints, access and backups, with continuous monitoring and a clear procedure for when something goes wrong.
The starting point
Most incidents in smaller companies do not come from a targeted attack, but from an email, a reused credential or an unpatched system. The sensible response is not buying more tools, but putting the basics in order and watching them.
What we usually find
- Email as the main entry point for fraud and malware.
- Antivirus installed but with nobody reviewing its alerts.
- Administrator credentials shared between several people.
- No defined procedure for the day an incident happens.
Which companies it fits
SMEs and mid-sized companies without an in-house security team that need a defensible level of protection for customers, audits and insurers.
We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.
Request a security assessmentWhat the solution includes
Email protection
Antispam filtering and impersonation controls on the corporate domain.
Endpoint protection
Managed endpoint antivirus, with review of detections and of devices left uncovered.
Access control
Two-factor authentication, review of privileged accounts and clean-up of stale users.
Monitoring and response
Continuous monitoring and, where the service includes it, managed detection and response (SOC/MDR).
How it is deployed
- 1Diagnosis of the current state and of entry points.
- 2Prioritisation of measures by risk and effort.
- 3Deployment of baseline protections.
- 4Short staff training on email and credentials.
- 5Periodic review and policy tuning.
Services involved
Frequently asked questions
- Does this make us GDPR or NIS2 compliant?
- It supports the technical measures, but regulatory compliance includes legal and organisational aspects beyond the technical scope. We do not guarantee compliance.
- Does an SME need a SOC?
- Not always. It makes sense when there is sensitive data, customer requirements or a broad exposure surface.
- What happens if we suffer an incident?
- The agreed procedure is activated: containment, scope analysis, recovery from verified backups and a follow-up report.
- Does it work alongside our current IT provider?
- Yes. The security scope can be contracted on its own and coordinated with whoever manages the rest.
Request a security assessment
We review email, endpoints, access and backups, and prioritise the measures with the greatest real impact.
Request a security assessment