
Knowledge from practice
We write about the subjects we work on every day: backup and recovery, security on the shop floor, POS systems and remote support. No theory, just what we come across on client sites.
Four subjects that keep coming back
Since 2019 we have worked for more than 150 clients, with teams in Amsterdam, Antwerp and Karaman. The questions that reach our desk most often are the ones we write down. That way you can read our approach before you speak to us.
- Backup and recoveryWhat a backup is really worth once you have to restore it, and how to stop ransomware taking your recovery points with it.
- Cybersecurity in retailSecurity on the shop floor differs from security in the office. We describe where the risks sit per location.
- Store IT and POS systemsFrom choosing a POS system to running it across several branches, including the integrations around it.
- Remote supportWhich support models exist, how they compare and what 24/7 cover asks of an organisation in practice.
Guides from our own engineers
Written for the decisions that come across our desk most often: which brand, which platform, what it costs and what to do first. Each one opens with a short answer and ends with the questions clients actually ask.
Outsourcing IT management: what to ask
The questions that make quotes comparable, what to settle before you ask, and where offers diverge without the price showing it.
Read the article →What is a data breach
What counts as a personal data breach and what does not, when the duty to report applies, and why the form mostly asks questions your logs answer.
Read the article →Security awareness: what to measure
Why the click rate is the wrong number to steer an awareness programme by, which number is the right one, and what an exercise should do.
Read the article →Ransomware: how it gets in
What ransomware is, the four routes it almost always takes in, and which controls actually stop it, ranked by how much they do.
Read the article →An ISO 27001 checklist from the IT side
Which ISO 27001 controls sit with your IT supplier and which stay with you. The technical side, written by a company that is certified itself.
Read the article →There is no NIS2 certification
No NIS2 certificate exists. What does exist, what a customer or regulator actually asks you for, and where ISO 27001 helps and where it stops.
Read the article →Managing devices you do not own
Where BYOD actually works, what you can and cannot require on someone’s personal phone, and the middle path between full management and no control at all.
Read the article →Running a one-hour incident tabletop
A practical format for rehearsing an incident with the people who would actually decide, what to put in the scenario, and what to do with the findings.
Read the article →What to log, and how long to keep it
Why default retention is too short to investigate anything, which sources are worth collecting first, and how to decide retention without buying a SIEM.
Read the article →Rolling out MFA without locking people out
The order that avoids a lockout, which accounts break the rollout, and how to move from report-only to enforcement with evidence rather than hope.
Read the article →Answering a supplier security questionnaire
Where the questionnaires come from, which answers actually get checked, and how to build a reusable answer set instead of starting from scratch each time.
Read the article →Offboarding: closing every door on the day someone leaves
Why offboarding fails more often than onboarding, what to close on day one, and how to make the list reusable instead of improvised each time.
Read the article →The first hour after an incident
What to do and above all what not to do in the first sixty minutes of a cyber incident, who to call, which deadlines run, and what has to be ready in advance.
Read the article →Shadow IT: what runs out of your view
Why shadow IT appears, what actually goes wrong, how to map what is running, and why switching it off is rarely the right answer.
Read the article →SPF, DKIM and DMARC: getting mail right
What SPF, DKIM and DMARC each do, why you need all three, and in what order to introduce them without blocking your own mail.
Read the article →Password management and passkeys: the order
Why password rules do not work, what a passkey actually solves, where it stalls in practice and in what order to introduce it.
Read the article →AI in the workplace: what to settle first
Copilot, ChatGPT, Gemini and Claude are already on your desks. What happens to your data, why permissions are the real problem, and what belongs in your policy.
Read the article →Outsourcing system administration: what you hand over and what you keep
When outsourcing system administration is the right move, what you hand over and what you keep, and where the cost sits.
Read the article →Digital sovereignty: what it actually means
What digital sovereignty actually means, why a European data centre is not enough on its own, and which choices there are to make at each layer.
Read the article →Remote support or someone on site: where the line sits
What can and cannot be resolved remotely, the three delivery models, and what a site visit really costs.
Read the article →Zero Trust in practice: where to start
What Zero Trust actually means, why it is not a product you buy, in which order to introduce it, and what it costs an organisation in friction.
Read the article →IT roles: who does what in an IT team
What the titles system administrator, application manager, cloud engineer and data engineer really mean, and which role you actually need.
Read the article →The digital workplace: more than a laptop with Teams
What a digital workplace actually is, the four shapes it comes in and when each fits, why the login is the perimeter now, and what breaks in practice.
Read the article →Windows or Linux: what the choice is really about
What actually differs between Windows Server and Linux: licensing cost, security, management, and who keeps it up at three in the morning.
Read the article →Own servers or cloud: when does the rack stay?
Not everything belongs in the cloud. The four reasons a rack stays, what that means for management and recovery, and how to justify the choice.
Read the article →Key management and encryption: what an audit actually asks
Encrypting is the easy part. This is about where the key sits, who can reach it, and how you show that when a regulator asks.
Read the article →Cloud-managed sites with Meraki: when it fits, and when it does not
When cloud-managed networking like Meraki is the right choice for multiple sites, when it is not, and where the cost and the dependency actually sit.
Read the article →Which IT brands we work with, and when we pick which
Dell, HP, Lenovo, Cisco, Fortinet, Yealink, Veeam, Microsoft and more: what we deliver and manage in the Benelux, and why we pick each one.
Read the article →Business laptops: Dell, HP or Lenovo?
Dell Latitude, HP EliteBook or Lenovo ThinkPad: which fits which user, and what a workplace really costs over three years.
Read the article →Meeting room AV: which kit for which room
Which meeting room hardware fits which room size, why audio decides whether a room works, and how to hand over a finished Teams room.
Read the article →Wi-Fi site survey with Ekahau
A site survey with Ekahau replaces guesswork with a heatmap per floor. What we measure, and when a survey pays for itself.
Read the article →Immutable backup: a copy nobody can delete
Immutable backup with Veeam, Synology and Datto: the 3-2-1-1-0 rule in practice, and why the restore test is the only proof that counts.
Read the article →Firewall and endpoint: building a stack that reports into one place
Firewall, endpoint, identity and edge for a multi-site mid-sized estate, and what NIS2 expects you to be able to show.
Read the article →Azure, AWS or stay where you are?
Which cloud platform fits a mid-sized organisation in the Benelux, what the VMware licensing shift means, and how to keep cloud cost in check.
Read the article →Buy or rent IT hardware?
When renting laptops and meeting room kit is cheaper than buying, when it is not, and what a workplace costs per month all in.
Read the article →NIS2: what you must be able to show
What NIS2 asks of a mid-sized organisation, which evidence an auditor or a customer will ask for, and the order we would put the measures in.
Read the article →Outsourcing your service desk
What an outsourced IT service desk costs per user, which tickets should stay in house, and how to keep quality from dropping in the handover.
Read the article →IT staffing or hiring?
When a seconded IT specialist beats a permanent hire, what an unfilled vacancy costs, and how to keep the knowledge in house.
Read the article →POS systems and branch connectivity
How to keep tills running on the busiest day of the year: network design per branch, and which failures cost money on the spot.
Read the article →Warehouse IT: scanners, Wi-Fi and the WMS
Why a warehouse network fails where an office network does not, how racking and stock change coverage, and what to fix before adding hardware.
Read the article →A Microsoft 365 migration playbook
The order we migrate in, what always takes longer than planned, and the checks that stop a mailbox move from becoming a week of complaints.
Read the article →What 24/7 IT support really means
The difference between on-call and staffed cover, what a night response actually costs, and how to work out whether your organisation needs it at all.
Read the article →Device lifecycle: purchase to certified disposal
What happens to a laptop between the purchase order and the wipe certificate, why staging saves more than it costs, and what an auditor expects at the end.
Read the article →Healthcare IT: shared workstations and uptime
Why a care location needs a different IT design: shared logins, wireless that follows people between rooms, and no maintenance window.
Read the article →SLAs you can actually meet
Response time versus resolution time, priorities that survive a bad week, and what a monthly report needs to be worth reading.
Read the article →Phishing and the human layer
Why awareness training alone does not work, which three controls stop most credential attacks, and what to do in the first hour after somebody clicks.
Read the article →Keeping cloud cost under control
Why a cloud bill creeps up rather than explodes, the five line items that cause most of it, and a monthly routine that takes twenty minutes.
Read the article →Education IT: hundreds logging in at once
Why a school network fails at nine in the morning and not at eleven, and why maintenance never happens during an exam week.
Read the article →Separating OT and IT in manufacturing
How to protect machine control systems that cannot be patched, and where to start with segmentation on a production site.
Read the article →Hospitality IT: guest Wi-Fi and payments
Why guest Wi-Fi should never share a network with the till, how to plan capacity for a full venue, and what to fix before the busy season starts.
Read the article →Cabling and the server rack
The layer nobody looks at until it fails: how many outlets per workplace, when fibre is worth it, and why labelling saves more hours than any tool.
Read the article →Printing and document flows
Printing is boring until it is a security finding. What a multifunctional exposes, and what printing really costs you over a year.
Read the article →What should IT cost per employee?
A realistic monthly figure per employee for a mid-sized organisation in the Benelux, what sits inside it, and which line items are usually missing from a budget.
Read the article →Changing IT supplier without damage
What you are entitled to when a contract ends, the order a transition should run in, and the five things to secure before you give notice.
Read the article →Standardising the Windows workplace
Why eight device variants cost more than the hardware saving, how zero-touch enrolment changes a rollout, and what to standardise first.
Read the article →About this page. All the guides above are published here on itproposal.com. Missing a subject? Let us know at info@itproposal.com and we will pick it up.
From article to approach
Recognise a subject from the articles above? These pages explain how we handle it in practice.
Rather have a conversation than an article
Running into one of these subjects in your own environment? Call +31 85 060 9347 or email info@itproposal.com. We are glad to talk it through with you.
Practical IT knowledge in your inbox
New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.