IT security that works day to day and holds when it matters.
From risk analysis through endpoint and network protection to backup, incident plan and security awareness: a security concept that fits your company and also takes account of what cyber insurers, clients and regulatory frameworks require.
Starting point
Cyber attacks have long stopped being a problem only for large companies. In small and mid-sized companies, though, there is often neither the time nor the capacity to review protective measures regularly and develop them further. At the same time cyber insurers, clients and frameworks such as NIS2 increasingly ask for security measures that can be evidenced.
Goal
The aim is an environment that makes attacks harder and is prepared for an incident: secured identities and devices, segmented networks, protected email and dependable backups. Alongside that, clear responsibilities and an incident plan for the case where protective measures are not enough.
Services
-
Risk analysis and security concept
Vulnerability analysis, a review of network, permissions and configurations, and a prioritised action plan as the basis for budget and sequence.
-
Identity and access protection
Multi-factor authentication, Conditional Access, least-privilege permissions, protection for privileged accounts, a password manager.
-
Endpoint protection and MDR
Endpoint protection with detection and response (EDR/XDR), device encryption and, if you want it, managed detection and response with an analyst team around the clock.
-
Network security
Next-generation firewall, segmentation into security zones, secure VPN and zero-trust principles for access from outside.
-
Email security
Protection against phishing, spam and malware, SPF, DKIM and DMARC, encryption and archiving.
-
Vulnerability and patch management
Regular, controlled updates for operating systems, applications and firmware, with monitoring of open vulnerabilities.
-
Backup and disaster recovery
Backup on the 3-2-1 principle including Microsoft 365, encrypted and immutable backups, documented restore tests and defined recovery times.
-
Security awareness
Training and phishing simulations so staff recognise attacks and react correctly.
-
Incident plan and response
Who does what when something happens: contacts, locking accounts, recovery, communication and reporting obligations.
What I work with — and why.
Which components make sense depends on risk, environment and how much protection is needed.
- Sophos Endpoint & MDR
- Endpoint protection with EDR/XDR; MDR adds an analyst team that assesses incidents around the clock and steps in.
- Sophos Firewall
- Next-generation firewall with segmentation, VPN and Synchronized Security with endpoint protection.
- Microsoft Defender & Conditional Access
- Protection for identities, devices and email within Microsoft 365, with access rules by user, device and risk.
- Hornetsecurity
- Email security, backup for Microsoft 365 and security awareness training with phishing simulations.
- Bitdefender
- Endpoint protection as an alternative, depending on the environment and requirements.
- AvePoint
- Backup and governance for Microsoft 365, SharePoint and Teams.
- Proxmox Backup Server
- Backup of virtual servers with verification and targeted restore.
How a project usually runs.
-
01
Analysis
Risk analysis and inventory: what is there, what is active, what is missing?
-
02
Prioritise
An action plan ordered by risk and effort, matched to your budget and to what insurers or clients require.
-
03
Build
A gradual rollout, agreed with your staff, so security works in everyday use.
-
04
Operate
Monitoring, updates, reporting and regular review, because both threats and your environment keep changing.
What clients want to know in advance.
Not finding what you want to know? Ask me directly.
Requirements vary, but multi-factor authentication, verified offline backups, endpoint protection with detection, patch management and an incident plan are generally expected. I document the current state and close the gaps.
Directly, NIS2 mainly affects larger companies in certain sectors. Indirectly it affects many suppliers, because affected clients ask for evidence about the security of their supply chain. I help assess where you stand and produce that evidence.
MFA is the most important first step, but modern phishing techniques get around simple methods. Conditional Access, managed devices, email protection and awareness belong with it, so the measures work together.
Not every one. MDR makes sense when nobody in the company can assess security alerts promptly and an outage would be expensive. I assess that with you based on size, data and risk.
Want to talk through a specific project?
Send me a couple of lines about it, or just call. You reach me directly, no call centre.