Service
Cybersecurity for smaller businesses
A small company does not get attacked for what it is, it gets attacked because it was open. Almost everything starts with an email, an account without a second factor, or a machine with no protection. Security for a twenty-person business is not about buying an expensive product: it is about closing, in the right order, the doors people actually come in through.
The problem
How they get in
Ordered by how often it happens, not by how dramatic it sounds:
- An email impersonating a supplier and changing a bank account number
- A reused password that turns up in somebody else's breach
- Mailbox access with no second factor, from anywhere in the world
- An attachment or link opened by someone in a hurry
- A machine without current protection that encrypts whatever it can reach on the network
- A service published to the internet that nobody remembered was published
- A former employee whose access was never removed
Scope
What is in, and what is not.
What we put in place
- Email protection: anti-phishing, anti-spam and control over domain impersonation
- Endpoint protection with EDR, not just traditional antivirus
- A perimeter firewall that is configured and reviewed, not installed and forgotten
- Continuous monitoring, with alerts that somebody actually reads
- Second factor and a review of accounts and identities
- Security audits and penetration testing
- Verified backups: the last line, and the one that decides whether an attack is a scare or a closure
- GDPR compliance work as it affects the systems
Things worth saying plainly
- We apply security and privacy good practice adapted to each client's environment
- Nobody can promise they won't get in. What can be done is cut the probability a long way and, above all, be able to recover
- Security is not bought, it is maintained: a tool installed and never reviewed gives a false sense of cover
- We do not issue certifications or conformity marks: we prepare the technical ground, and certification is granted by an accredited body. We are not certified against any standard
- The human link needs habits, and no product fixes that
How it works
The order it gets done in
The order matters more than the tooling: some measures cost very little and prevent a great deal, and those go first.
See what is exposed
Which services are published, which accounts exist, who is an administrator of what, and which machines are out of support. Something nobody remembered almost always turns up.
Close the cheap and effective things
Second factor on email, legacy protocols blocked, access removed for people who have left, and confirmation that backups exist and restore. This is the part that removes the most risk for the least money.
Deploy protection
EDR on the machines, email filtering, and a firewall configured around how the company actually works. With alerts that reach somebody who acts on them.
Maintain and verify
Regular reviews, restore tests and an audit when due. Without this part, everything above expires.
Who it is for
Who it is for
Companies holding other people's data
Law firms, clinics and accountancy practices. An incident here is not just a technical problem: it is a notifiable breach.
Companies that invoice from a system
If the business stops when the system stops, the ability to recover is worth more than any product.
Companies that have already had a warning
An attempted email fraud, a leaked password, a machine behaving oddly. That is the moment measures get approved without debate.
Service area
Scope
Most of this service is remote: email, identity, endpoint protection and monitoring. It can be delivered to companies anywhere in Spain.
The on-site part is the firewall, the physical network review and work on specific machines, within the usual Baix Llobregat and Barcelona area.
Questions
Frequently asked questions.
- We're small. Would anyone really attack us?
- Email fraud and ransomware do not pick targets by size: they look for what is open, automatically. Being small is not protection — it usually means fewer measures.
- Does this make us GDPR compliant?
- It covers the technical side of the security measures, which matters but is not all of it: the GDPR also brings documentation and governance obligations. If you need full compliance, you also need specialist legal advice.
- Do you do penetration testing?
- Yes, with the scope and the authorisation in writing before we start. A test without written permission is not a test, it is something else.
Start by finding out what is open
The initial review is free and usually enough to see the two or three things worth closing this week.
Talk to a technicianYou may also need
Related services.
- BackupBackups verified by restoring them: machines, servers, Microsoft 365 and a recovery plan.
- IT maintenanceA fixed monthly fee: support included, preventive reviews and a grip on what you have.
- Networks & Wi-FiCabled network, Wi-Fi and VPN: working across the whole floor, and from outside.
Would you rather talk it through? Call 622 317 788. You get the same person who will do the work.