Skip to content
Cybersecurity

Attackers do not pick large companies. They pick open doors.

We protect your accounts, devices and mailbox in a way that fits an SME, and teach your team to recognise a suspicious email. If something does happen, everyone knows the next step.

Padlock on a laptop keyboard
MFA for everyone
Including the managing director and admin accounts.
Devices protected
Endpoint protection on every laptop and server.
An alert team
Short training and phishing simulations that stick.
An incident plan
Who calls whom, and what happens first.

What cybersecurity means for an SME

Cybersecurity is not a product you buy once, but a set of agreements and settings that together raise the bar. For an SME it is mostly about getting the basics right: who can sign in where, which devices are protected, and what happens when someone does click a link.

In practice: we set up MFA and conditional access in Microsoft Entra ID, protect laptops and servers with endpoint protection, filter your mail for phishing and malware, train your team with short sessions and simulations, and write a response plan with you that fits on one page.

Why this matters for your business

SMEs are an easy target

Most attacks are automated. They look for weak passwords and missing MFA, whatever the size of your business.

An incident hits more than your IT

Downtime, delayed invoicing, messages to clients and questions from your insurer. The real damage is outside the server cabinet.

Clients and insurers ask about it

More and more often you have to show that MFA, backups and an incident plan are in order. It helps when that is on paper.

If something does happen

What happens when someone clicks the wrong link

A colleague enters a password on a fake login page, or a laptop starts behaving oddly. This is how it goes from that moment on.

The response plan sets out in advance who decides on your side and whom we notify. That way no time is lost in the moment.

  1. 1
    Automatic

    The first door stays shut

    Without a second factor, the sign-in is refused. A device behaving like ransomware is isolated from the network by the endpoint protection straight away.

  2. 2
    Alert

    We see it, you do not have to look

    The alert goes to our service desk and is assessed straight away during office hours. Outside those hours you reach us on the emergency line.

  3. 3
    Contain

    We establish what is affected

    Which accounts, devices and data are involved. Passwords are reset, sessions revoked and suspicious mailbox rules removed.

  4. 4
    Recover

    Back to work, from a clean base

    Devices are cleaned or reinstalled and, where needed, we restore data from a tested backup.

  5. 5
    Afterwards

    A report, and a better baseline

    You get a short written report of what happened and what we changed. Useful for your insurer, your clients and your team's next training.

What we monitor for your security

Continuously monitored
At the centre
Your business

Every layer around your business is configured, documented and monitored by us.

Identity & sign-in

Entra ID, MFA, conditional access, admin accounts.

Laptops & servers

Endpoint protection, encryption and updates.

Mail

Filtering for phishing, malware and spoofed senders.

Network & firewall

Managed firewall, segmentation, secure remote access.

People

Awareness training and phishing simulations.

Incidents

Response plan, follow-up and report afterwards.
Presentation for a team on a large screen

Security starts with your team

A short awareness session at the office often does more than yet another tool. We show real examples of phishing and explain what to do when in doubt.

The security baseline

What we check first at every SME

Twelve points that together cover most of the risk. How many are in order at your business today?

Identity

  • MFA on all accounts, including admin accounts
  • No shared accounts for daily work
  • Admin rights separate from the everyday account

Devices

  • Endpoint protection on every laptop and server
  • Encrypted drives on laptops
  • Updates rolled out within a fixed period

Mail

  • SPF, DKIM and DMARC set up correctly
  • Links and attachments checked before they reach the inbox

Recovery

  • A backup that is separate from the network
  • A restore test in the past year

People and agreements

  • An awareness training in the past year
  • A response plan on paper, with contact persons

These points align with the basic measures of the CyberFundamentals framework of the Centre for Cybersecurity Belgium (CCB). Whether NIS2 applies to your business is explained on the CCB website. We help with the technical measures and do not give legal advice.

Have your security baseline checked
For the technically minded

How it is set up

The details below are for IT managers and technical decision-makers. If that is not you, feel free to skip this.

Not sure what you are covered for today?

Three questions, two minutes, and a first picture of where your IT stands today.

Start the IT check

Questions we get

That depends on your sector, your size and your role as a supplier to businesses that do fall under it. The Centre for Cybersecurity Belgium (CCB) publishes the official information. We help you with the technical measures, but do not give legal advice.

Also of interest
View all solutions

Let us look at where your doors are open today.

A short baseline check of your accounts, devices and mail, and an honest answer on what needs doing first.