Skip to content
Okena Systems

Service

Cybersecurity for smaller businesses

A small company does not get attacked for what it is, it gets attacked because it was open. Almost everything starts with an email, an account without a second factor, or a machine with no protection. Security for a twenty-person business is not about buying an expensive product: it is about closing, in the right order, the doors people actually come in through.

The problem

How they get in

Ordered by how often it happens, not by how dramatic it sounds:

  • An email impersonating a supplier and changing a bank account number
  • A reused password that turns up in somebody else's breach
  • Mailbox access with no second factor, from anywhere in the world
  • An attachment or link opened by someone in a hurry
  • A machine without current protection that encrypts whatever it can reach on the network
  • A service published to the internet that nobody remembered was published
  • A former employee whose access was never removed

Scope

What is in, and what is not.

What we put in place

  • Email protection: anti-phishing, anti-spam and control over domain impersonation
  • Endpoint protection with EDR, not just traditional antivirus
  • A perimeter firewall that is configured and reviewed, not installed and forgotten
  • Continuous monitoring, with alerts that somebody actually reads
  • Second factor and a review of accounts and identities
  • Security audits and penetration testing
  • Verified backups: the last line, and the one that decides whether an attack is a scare or a closure
  • GDPR compliance work as it affects the systems

Things worth saying plainly

  • We apply security and privacy good practice adapted to each client's environment
  • Nobody can promise they won't get in. What can be done is cut the probability a long way and, above all, be able to recover
  • Security is not bought, it is maintained: a tool installed and never reviewed gives a false sense of cover
  • We do not issue certifications or conformity marks: we prepare the technical ground, and certification is granted by an accredited body. We are not certified against any standard
  • The human link needs habits, and no product fixes that

How it works

The order it gets done in

The order matters more than the tooling: some measures cost very little and prevent a great deal, and those go first.

  1. See what is exposed

    Which services are published, which accounts exist, who is an administrator of what, and which machines are out of support. Something nobody remembered almost always turns up.

  2. Close the cheap and effective things

    Second factor on email, legacy protocols blocked, access removed for people who have left, and confirmation that backups exist and restore. This is the part that removes the most risk for the least money.

  3. Deploy protection

    EDR on the machines, email filtering, and a firewall configured around how the company actually works. With alerts that reach somebody who acts on them.

  4. Maintain and verify

    Regular reviews, restore tests and an audit when due. Without this part, everything above expires.

Who it is for

Who it is for

  • Companies holding other people's data

    Law firms, clinics and accountancy practices. An incident here is not just a technical problem: it is a notifiable breach.

  • Companies that invoice from a system

    If the business stops when the system stops, the ability to recover is worth more than any product.

  • Companies that have already had a warning

    An attempted email fraud, a leaked password, a machine behaving oddly. That is the moment measures get approved without debate.

Service area

Scope

Most of this service is remote: email, identity, endpoint protection and monitoring. It can be delivered to companies anywhere in Spain.

The on-site part is the firewall, the physical network review and work on specific machines, within the usual Baix Llobregat and Barcelona area.

See the service area across Baix Llobregat and Barcelona

Questions

Frequently asked questions.

We're small. Would anyone really attack us?
Email fraud and ransomware do not pick targets by size: they look for what is open, automatically. Being small is not protection — it usually means fewer measures.
Does this make us GDPR compliant?
It covers the technical side of the security measures, which matters but is not all of it: the GDPR also brings documentation and governance obligations. If you need full compliance, you also need specialist legal advice.
Do you do penetration testing?
Yes, with the scope and the authorisation in writing before we start. A test without written permission is not a test, it is something else.

Start by finding out what is open

The initial review is free and usually enough to see the two or three things worth closing this week.

Talk to a technician