How we approach cybersecurity

An attack on an SME rarely starts with anything dramatic. Usually it's an email, a forgotten laptop or a password that's been in use for years. Follow an ordinary working day and see the layers of protection we put in place for you.

Scroll to follow the day

An ordinary working day

This is a typical SME: a handful of people, their Macs and iPhones, email and files in Microsoft 365, and a network that connects it all.

An attacker sees the same office as a row of doors. We make sure every door is locked, without you having to think about it every day.

All plans From NXT one From NXT step NXT level

The labels show which plan includes each protection. Each higher plan includes everything in the plan below.

An email that looks genuine

What can happen

A member of staff gets a convincing email and enters their password on a fake Microsoft page. Without protection, the attacker can then read that mailbox and send fake invoices to your customers.

What we do

  • Two-step verification and access rules on every account, so a stolen password alone isn't enough. All plans
  • Dark web monitoring that raises the alarm when company data turns up online. From NXT one
  • A password manager for every employee, family licence included. From NXT one
  • Risk-based identity protection that automatically blocks suspicious sign-ins. From NXT step

Someone is emailing as you

What can happen

A fraudster sends emails that appear to come from your company, with different bank details. Your customer pays, and the money is gone.

What we do

  • A domain spoofing monitor that spots misuse of your domain name. From NXT one
  • Advanced protection for your Microsoft 365 environment. From NXT step
  • Extra protection for the cloud apps your team uses. From NXT step

Your devices, always under control

What can happen

A laptop gets left on the train, or a device is infected by an innocent-looking download. Without protection, your company data is there for anyone to pick up.

What we do

  • Central device management, so a lost device can be locked or wiped remotely. All plans
  • Endpoint detection and response (EDR) on every device, spotting and stopping suspicious behaviour. All plans
  • Automatic updates for Microsoft and other software. All plans
  • Settings that follow the CIS baseline, an international security standard. All plans
  • Protection for business apps and the data inside them. From NXT one
  • Management of personal devices staff use for work. From NXT step

Everything encrypted. Now what?

What can happen

Ransomware locks every file, or someone accidentally deletes the customer records folder. Without a proper backup, that means days of downtime, or data you never get back.

What we do

  • A full backup of Microsoft 365. All plans
  • A backup of every device via OneDrive, with version history. All plans
  • A quarterly backup test with a report, so you know restores actually work. From NXT one
  • A full recovery test: once a year in NXT step, twice a year in NXT level. From NXT step
  • Data loss prevention, so sensitive data can't simply leave the business. From NXT step

People are the first line of defence

What can happen

However good the technology, sooner or later someone clicks the wrong link. The difference is a team that knows the warning signs.

What we do

  • Awareness sessions that explain, in plain language, what to watch for. All plans
  • A personal knowledge base with answers to everyday questions. All plans
  • Simulated phishing attacks, so your team can practise safely. From NXT step

Finding weak spots before someone else does

What can happen

An outdated router, an open port or an old account nobody closed. Attackers scan for those automatically and constantly.

What we do

  • Automated monitoring that flags unusual activity in your environment. All plans
  • Full network management, where it's built on equipment from our partners. From NXT one
  • An annual security audit with a vulnerability scan, an in-depth network scan and a check of what's visible from outside. NXT level
  • An annual review of sign-in security on every account. NXT level

Six layers, one system

Security isn't something you buy once. It's a system you look after every day, and that's exactly what we do.

  • An annual security and recovery plan and a technology review to plan ahead together. From NXT step
  • An annual report for the owner on where things stand. NXT level

What if it does go wrong?

No security is a hundred per cent watertight, and anyone who promises otherwise isn't telling you the whole truth. What matters is what happens the moment things go wrong.

That's why we follow a fixed six-step approach. You know in advance what to expect, and you don't have to work out what to do on a bad day.

Security that acts on its own

If something suspicious tries to take hold on a device, the EDR steps in automatically, without waiting for a human. Meanwhile, we get an alert.

Not sure? Report it.

Spotted something odd, like an email that doesn't add up or a screen behaving strangely? Report it through the customer portal or call us on 011 15 46 03.

Better safe than sorry.

First we stop it spreading

We take over. We establish exactly what happened and make sure the problem doesn't spread to other devices, accounts or files.

Back to work as fast as possible

Where needed we restore data from the backup and get devices working again.

You're not on your own

In many cases, a data breach must be reported to the Data Protection Authority within 72 hours. Your insurer will want to know promptly too. We help you with those notifications, so nothing is missed.

Stronger than before

After an incident you get an incident report: what happened, what we did and what we'll change. In a joint review, we discuss how to close the door that was open.

Curious how your business measures up?

Together we look at which layers you already have and where the doors are still open. No obligation, no jargon.