Skip to content

Cybersecurity for SMEs

Cybersecurity that fits a growing business

You do not need to be a large organisation to get your security properly sorted. We put the measures that matter most for your business in order, carry them out and keep them up to date. You know where you stand, and you can show it to customers and partners.

Where to start

Solid security without a security department

In most SMEs, IT sits with a handful of people who also have their own jobs to do. Security easily slips down the list, not because it is unimportant, but because nobody is quite sure where to begin. That is where we come in. We first look at what is in place, agree with you what will make the biggest difference and work through it step by step: from updates and endpoint protection to a network divided into logical segments. Whatever is done gets documented. Your security grows with your business, at a pace that suits you.

  • A clear picture of where you stand, in order of what matters
  • Updates, endpoint protection and segmentation that are kept up to date
  • Colleagues who know what to do when something odd lands in their inbox
  • A file you can use to answer questions from customers, supply chain partners and auditors
A screen full of system log lines, photographed up close.

At a glance

Who it is for
SMEs with or without their own IT person, up to organisations with several hundred employees.
Two routes
Start with an audit, or hand your security over to us on an ongoing basis straight away.
Certified ourselves
Infodatek Group is ISO 27001 and NEN 7510 certified, so we work to the same standards we help you with.

The basics

The measures that give SMEs the most value

Good Cybersecurity rarely starts with anything complicated. The biggest gains come from measures that have proven themselves for years, as long as someone keeps them up consistently. Keeping them up is what really counts in practice, and that is exactly the work we take off your hands.

  • Multi-factor sign-in for email, Microsoft 365 and remote access
  • Patch management: updates for devices, servers and network on a fixed schedule
  • Endpoint protection on laptops, PCs and servers, managed centrally
  • A segmented network, so guests, printers and the office stay out of each other's way
  • Backups with an offline copy, and restore tests that show it works
  • Clear agreements on who can access what

Two routes

An audit first, or ongoing security from day one

If you would like to know how things stand first, start with a security audit. We review your network, devices, servers, cloud environment and access rights, and we also look at the agreements around them. You receive a report with a summary for management at the front and the detail for your administrator at the back. The report is yours, even if your IT is managed by another provider.

If you choose Cybersecurity as a managed service, we keep your security up to date as the technology moves on. An audit is simply included. Would you rather have another party carry out that review? We are happy to cooperate.

People and technology

Cybersecurity is also about habits

Technology catches a great deal, but your colleagues make the difference. Someone who spots an unusual payment request and knows where to report it makes your business stronger. With security awareness, online with phishing tests or in a small classroom group, that becomes a habit rather than a one-off lesson.

If you want someone watching outside office hours as well, that is possible. A SOC assesses the signals from your devices, servers, network and Microsoft 365 day and night, and steps in when something is not right. Your security stays in good hands at weekends too.

Demonstrable

Answer customer questions and NIS2 with confidence

More and more SMEs receive a security questionnaire from a large customer or a supply chain partner. Sometimes because that customer falls under NIS2 itself, sometimes because it is part of a tender. With an up-to-date file, the answers are at hand instead of having to be worked out again each time.

If your business falls under NIS2 itself, or you are working towards ISO 27001 or NEN 7510, we guide you with Smart Compliance from baseline assessment to audit. Everything you do for your security counts towards it directly.

Who it is for

Cybersecurity for every kind of SME

The basics are the same everywhere, the emphasis differs. A few situations we come across often.

Professional services

Consultancies, accountancy practices and estate agents handle confidential client data in Microsoft 365. Here the focus is on secure accounts, well-configured sharing permissions and staff who recognise a strange request.

Manufacturing and engineering

Alongside the office there are machines and controllers that last for years. We separate the production network from the office and set up targeted remote access for suppliers, so maintenance and security go hand in hand.

Suppliers to large customers

If you supply a business that falls under NIS2, requirements reach you through the contract. We help you answer those questionnaires with a file that shows what you have in place.

Healthcare and social care

If you work with patient or client data, NEN 7510 applies to you. Because we are certified to that standard ourselves, we know the requirements from practice and set up your security accordingly.

Growing businesses without an IT person

Going from ten to forty employees, IT often grows along without anyone noticing. We bring order to accounts, permissions and devices, so your security becomes as professional as the rest of your business.

Frequently asked questions

Frequently asked questions about Cybersecurity for SMEs

Is Cybersecurity not mainly something for large companies?

No. In SMEs especially, a few well-configured measures go a long way: multi-factor sign-in, updates on a fixed schedule, endpoint protection, a segmented network and a backup you can actually restore. We scale the approach to your business, so you do not get a programme built for a multinational, but a plan that fits twenty or eighty colleagues.

Where do we start if we do not know how things stand?

With a security audit. We agree beforehand what we will look at, carry out most of the work remotely and deliver a report in order of urgency, with the cost of resolving each point. After that, the choice is yours: tackle the points yourself, hand them to us or discuss them internally first. There is no commitment.

Do we have to switch from our current IT partner?

Not necessarily. We also carry out audits when your IT is managed by another party, and you are free to share the report with whoever you like, including your current provider. If you then want to move your security or all of your IT management to us, that is possible. But the audit stands on its own and commits you to nothing.

Will this mean a lot of work for our staff?

Most of it they will not notice. We schedule updates and checks for times that affect you least, and much of the work happens remotely. What they will notice is multi-factor sign-in and the occasional short training session or practice email. That takes little time and makes them more confident in their day-to-day work.

What if we want IT management and security in one agreement?

Then Digital Care Managed Operations is the place to be: management and security of your IT for a fixed price per employee per month, in the Start, Plus, Pro and Elite editions. Day and night monitoring can be added, and it comes as standard in Elite. You can also take Cybersecurity on its own, as a managed service or as an audit.

Wondering what Infodatek can do for you?

A thirty-minute call with one of our specialists. Your environment, your questions. An honest conversation.

An Infodatek Group colleague picking up the handset of a desk phone.