subscription service
IT security
Most break-ins come down to missing updates, no MFA and no monitoring - not an advanced attack. So we start by reducing exposure, not by buying a tool.
Order matters
A conversation about security usually starts with tools, and it should start with exposure. Incident statistics in small and mid-sized companies don’t show advanced attacks - they show unpatched services exposed to the internet.
Four things close off most real routes in, and none of them require buying a system:
- up-to-date router and firewall firmware
- two-factor authentication everywhere there’s a login
- remote desktop port not directly reachable from the internet
- offline backup, verified by a test restore
Only once that’s done does monitoring have something to watch.
What the service covers
- risk analysis following good practice, for GDPR or NIS2
- environment consultation on reducing exposure to the internet
- rollout of good practices matched to the identified risk
- monitoring tools - Wazuh, Suricata
- security policy preparation and regular reviews
- incident handling with reporting that meets GDPR and NIS2 deadlines
Accountability, not just technique
During an incident the question isn’t “who attacked”, but “were adequate preventive measures in place”. NIS2 fines reach €10 million or 2% of global turnover, and running software without security updates is hard to defend as an adequate measure.
That’s why we document what we do - risk analyses and reviews are evidence, not just an activity.
Risk analysis: what comes out of it
Not a document for a drawer. The result is a list of specific items ranked by the cost of fixing them against the cost of leaving them. It usually turns out a few items at the top of the list are free or nearly free, and nobody has done them yet regardless.
The analysis covers a systems and data inventory, a review of what’s exposed to the internet, an assessment of permissions, and a check of whether incident procedures exist. Without an inventory you can’t assess risk - you don’t know what could leak.
What we don’t sell
We don’t run penetration tests on our own if the basics aren’t in place. A test would show the same thing as a review, just at a higher price. We also don’t deploy SIEM in a company where nobody will read the alerts - a tool generating notifications nobody opens is a cost, not a safeguard.
The order is always the same: first reduce exposure, then procedures and backups, monitoring last. Reversing that order is the most common way to spend a security budget without raising the level of security.
After an incident
If one has already happened, we hold ourselves to the same standard we teach clients to require from vendors: a post-breach analysis report with the entry vector, a list of systems accessible to the attacker, an assessment of what data may have leaked, and a remediation plan with dates and responsible people. Without those four things, a report to the supervisory authority is guesswork.
Who this works for
Companies covered by NIS2, or processing personal data at a scale that makes GDPR a real risk. And subcontractors to organizations in defense, energy or government - there the bar is higher, because an attacker comes in through the weaker link in the supply chain.
Frequently asked questions about security
Does NIS2 apply to my company?
Possibly, if you operate in manufacturing, transport, digital services or waste management. The directive extended obligations to a much wider group of organizations than before, and responsibility for the state of cybersecurity sits with the board. A risk analysis is the first step to establishing what covers you.
Where do you start?
With a review of what’s exposed to the internet, and with the basics: firmware currency, two-factor authentication, log monitoring, and checking whether the backup can actually be restored. We add SIEM-type tools only once those basics are done - otherwise you’re paying to detect attacks that could have been prevented.
How much time does a company have to report an incident?
Under NIS2 obligations it’s 24 hours for an initial report and 72 hours for a full one. For a personal data breach, 72 hours to the supervisory authority. Without an inventory and logs you can’t establish what leaked in that time - and that’s the practical reason to have them.
Do you deploy specific tools?
Yes: Wazuh for security monitoring and Suricata for network traffic detection. We match them to the identified risk level, not the other way round - not every company needs full SIEM, and every company needs an up-to-date router.