Request a quote
Emergency SectorsCareers About us Blog Get in touch
NLNederlandsENEnglishESEspañolFRFrançaisTRTürkçe
Close-up of two monitors showing log lines and coloured terminal output

Cybersecurity that can handle NIS2

Detect, contain, recover and demonstrate. We build and staff the security programme of SMEs and enterprise organisations, with 24/7 monitoring and evidence an auditor accepts.

Starting point

A firewall plus antivirus no longer covers it

Most mid-sized organisations have built their security up in layers: a firewall from 2019, virus scanners on the laptops, a backup that runs but is rarely restored. On paper it adds up. In practice, the answer to the question that really matters is missing: how do you notice that someone is inside, and what happens in the hour after that?

ITproposal sets up security as a programme instead of a collection of separate products. We combine detection on your workstations and servers, a security team that watches day and night, and documentation you can hand to an auditor or insurer without panic.

We are not a hyperscale consultancy and not a one-person shop. You get a fixed point of contact in the Benelux, with our own shift behind the scenes covering the night and weekend hours.

  • One party for security and management You do not have to mediate between your security vendor and your managed services provider when something goes wrong.
  • Kiwa NEN 4400-1 certified The way we deploy personnel has been audited, which saves work in your own supplier assessment.
  • Built on what you already use Microsoft 365, Azure, AWS and VMware. We do not add an extra stack where your existing licences can already do the job.
  • Experience in retail, healthcare and logistics Sectors with peak loads, till and scanning processes and little room for downtime.
SME

Cybersecurity for SMEs

A small or mid-sized business faces the same attacks as a corporation, without the headcount to absorb them. There is no security officer, the systems administrator does security on the side, and nobody is watching between six in the evening and eight in the morning, the window in which most ransomware actually detonates.

So for an SME we do not start with a two-year programme. We start with the measures that remove the most risk per euro spent: multi-factor authentication on everything reachable from outside, detection on the workstations, and a backup someone has actually tested restoring. Only once those stand do we look further.

Cybersecurity advice for SMEs, as we practise it, means hearing what you do not need. A one-day baseline assessment shows where you stand, which three things come first and what they buy you. You can act on the outcome yourself or leave it with us; we are not the party that sells you a full management contract for a problem a setting would have fixed.

  • Start with one block, not six You take what matters now and expand when it suits, within the same reporting and the same point of contact.
  • On what you already pay for In many SME environments half of the security you need already sits in the Microsoft 365 licence, unused. We switch that on first.
  • No security team of your own required We cover the night and weekend hours, so you do not have to free up or hire anyone for them.
  • Predictable instead of project-based A fixed monthly rhythm with fixed reporting, so security does not become a fresh investment decision every time.
  • NIS2 reaches you indirectly too If you fall outside the scope yourself, the requirements still arrive through your larger customers. What that means in practice is on the NIS2 page.
Enterprise

Cybersecurity for enterprise organisations

In larger organisations the problem is rarely that too little is in place. It is that too much is, from too many vendors, in too many places. Four sites each with their own firewall rules, a SIEM understood by one person, and an acquisition whose domain still runs separately; that is where the gaps appear, not in the absence of a product.

We come in as an addition rather than a replacement. If you have your own CISO and security team, we take over the hours your people cannot sustain: the night, the weekend, the first triage. If a SIEM or XDR is already running, we plug into it instead of standing a second one beside it. And if what is missing is mainly hands, they come through IT staffing and work inside your processes and your change management.

Scale also makes the burden of proof heavier. Multiple countries means multiple regulators, and if you supply the financial chain, DORA adds requirements on testing your resilience and registering your outsourcing. How recovery fits into that sits under data and business continuity.

  • Multiple sites, one picture Locations, countries and subsidiaries in the same timeline, so an attack starting in two places at once is seen as one incident.
  • Alongside your own team We top up the hours and the roles you cannot cover, rather than replacing what you have built.
  • Plugging into what runs Your existing SIEM, XDR or ticketing system stays leading; we deliver the analysis inside it and not next to it.
  • Acquisitions and stray domains Mapping and merging environments that were never tidied up after an acquisition, with the risks that sit there named explicitly.
  • Regulators in several countries One file that serves the NIS2 reporting duty and, for the financial chain, the DORA requirements at the same time.
What you get

Six building blocks of a complete security programme

You can start with everything at once, or with the parts where your risk is greatest. Each block can be purchased separately and fits within the same reporting and the same point of contact.

Detection

Visibility on every device

EDR software on laptops, workstations and servers, rolled out centrally and actively monitored instead of passively installed.

Monitoring

Eyes on your environment, at night too

Analysts from our security team assess alerts every day of the year. A suspicious alert is picked up straight away, not on the next working day.

Compliance

Ready for the Cybersecurity Act

A baseline assessment against the NIS2 measures, implementation of what is missing and a file you can hand to an auditor.

Continuity

Immutable backup and recovery

Backups that can no longer be changed or deleted, with periodic restore tests and a recorded recovery time per system.

People

Training that sticks

Phishing simulations and short, targeted training sessions. Participation and results are tracked, so that you can demonstrate progress.

Compliance

What NIS2 and DORA ask of your organisation

The Dutch Cybersecurity Act, the implementation of the European NIS2 directive, shifts liability explicitly to board level. Even if you do not fall within the scope yourself, the requirements still reach you through your clients and contracts. Demonstrability therefore becomes just as important as the measure itself.

  • Risk management that is documented A current overview of your risks, the measures you have chosen and the residual risk you knowingly accept.
  • Mandatory incident reporting An early warning and a full report to the regulator within the deadlines the law prescribes, with roles assigned in advance.
  • Continuity and recovery Backup, crisis management and a recovery plan that has been tested rather than only described.
  • Supply chain security Agreements with suppliers about their security, and visibility of the risk they bring into your organisation.
  • Access and authentication Multi-factor authentication, rights management and periodic checks on who can still reach what.
  • Accountability at board level Directors supervise the measures and must be able to show that they have been trained on them.
  • DORA for the financial chain If you supply banks or insurers, further requirements apply on testing digital resilience and registering your ICT outsourcing.
  • Evidence an auditor accepts Reports, logs and test records that substantiate both the measure and the way it works.
Security team

Who is watching when your office is closed

Alerts from your workstations, servers, firewalls and Microsoft 365 come together in one place. Our analysts do not see separate alarms there, but the pattern behind them: a sign-in from an unknown location, followed by an account that suddenly moves through folders it never visits.

That work does not stop when your working day stops. At the end of the day the team hands over to the evening shift, so that someone is watching the screens at night and at weekends as well, with the same agreements and the same file.

  • One view of your entire environment Workstations, network, identities and cloud in the same timeline, so that connections become visible instead of separate alerts.
  • Noise removed before you see it Known false alerts are filtered out; what remains has been assessed by an analyst before you get a call.
  • Handover without loss of information Every shift change runs through the same ticket and the same context, across time zones too.
  • You can read back what happened What stood out, what was done and what it meant, recorded and usable when dealing with your auditor or insurer.
Analyst wearing a headset in front of a wall of monitoring screens in a darkened room
Approach

How we work during an incident

A cyber incident disrupts every organisation. The difference is not whether it happens, but how quickly and how well coordinated the response is. This is the order we follow.

Detection & triage

An alert from the detection software arrives at our security team. The analyst determines whether it is real, classifies the severity and starts the first containment.

Containment

We take affected devices off the network, secure the traces for investigation and inform your board as soon as the severity calls for it.

Clean-up & recovery

The threat is removed, systems are restored from immutable backup and we validate integrity before everything goes live again.

Evaluation & reporting

Analysis of the underlying cause, adjustment of the measures and the reports to the regulator within the deadlines the law prescribes.

Related services

Security rarely stands on its own

These services connect most often to a security programme.

We work with
Palo Alto Networks Fortinet Trend Micro Bitdefender Okta Thales Cloudflare
Frequently asked

Questions we get about this

The ones that come up most, answered briefly.

We already have a firewall and antivirus. Is that not enough?

That has not covered it for some time. A complete programme has six building blocks: detection on every device, 24/7 monitoring, immutable backups, access management, awareness among your people, and recording what you do in a way you can show. A firewall is one of those, and it sees nothing of what happens inside.

What does NIS2 mean for us in practice?

That you have to be able to show what you have arranged, not just that you arranged it. Think of a current overview of your systems, recorded procedures for incidents, and evidence that backups have been tested. We set it up so the evidence comes out of the management work itself, rather than being assembled afterwards.

Who is watching when our office is closed?

Our monitoring runs 24/7, with people on shift rather than on call. During an incident we follow a fixed model: isolate, establish what was hit, restore from an immutable backup, and only then reopen. You hear from us before you notice it yourself.

Can we start small?

Yes. The six building blocks can be taken separately, and in practice it often starts with detection and immutable backups, because those prevent the most damage. We say what is then still uncovered, so you make a deliberate choice rather than buying false comfort.

Is a penetration test included, or is that separate?

Separate, deliberately. A pen test is a snapshot and management is a standing arrangement; putting both in one price makes both unclear. We run it or have it run, and the resulting report goes into the management cycle: every finding gets an owner and a date, and at the next test you can see what happened to the previous list.

How do we know whether our people recognise phishing?

By measuring it instead of hoping. We send simulated phishing mail and track who clicks, who reports it and how fast. That percentage is the number that matters, because a report within five minutes is the difference between an incident and a morning of clean-up. Anyone who clicks gets an explanation, not a reprimand; a culture where people hide a mistake is more dangerous than the mistake.

Do we have to replace what we already have?

Usually not. We start by looking at what is there and what it actually does, because in practice there is often more installed than anyone realises and less configured than everyone assumes. A firewall that is well chosen but half set up is worth more finished than replaced. Anything that genuinely has to go we name with the reason attached, so the decision stays yours.

Brands

The brands above, one page each

What the brand makes, which lines we supply and what we do around it.

What we are audited on ourselves

Our own certifications

ITproposal is certified for ISO 9001 (quality), ISO/IEC 27001 (information security), ISO 14001 (environment) and Kiwa NEN 4400-1 (labour hire and secondment). That says something about how we work and how we have our own processes assessed; it is not a certification you inherit from us.

Where do you stand today?

Book a thirty-minute conversation with no obligation. We go through your current security position, name the gaps we see and set out what is needed to be demonstrably in order in time.

Practical IT knowledge in your inbox

New guides on management, security and the workplace, written by the people doing the work. No sales talk, and you can unsubscribe in one click.

We use your address for the newsletter only. See our privacy policy.

Request a quote Call