Cybersecurity for SMEs

"ESET research puts the cost of a security incident in the Netherlands at an average of 270,000 euro, some fifty thousand above the global average."

Why are SMEs an attractive target?

Plenty of business owners assume they are too small to be interesting. Attackers see it differently: they are not looking for the biggest prize, but for the easiest way in. In smaller companies that door is open more often, because nobody is watching security specifically. Cybersecurity for SMEs does not start with more tools, it starts with knowing what happens in your environment.

Limited time, budget and knowledge

You have a business to run. Security is added on top of everything that already has to happen, and it drifts to the bottom of the list. That is not negligence, that is arithmetic with the hours you have.

Rarely an in-house IT security team

Your IT is taken care of, by an internal administrator or an external partner. But management is not the same as security: one keeps systems running, the other watches for people getting in unnoticed. That second role is almost never filled in a smaller company.

The complexity of modern attacks

Attackers increasingly use valid credentials instead of malware. No antivirus alert goes off, because technically someone simply logs in. Without monitoring that recognises the behaviour, you find out only once the damage is done.

Prevention, detection and response

What does good cybersecurity look like for a smaller business?

Good cybersecurity is not a product you switch on and forget. It is three things that catch what the others miss: prevent what can be prevented, see what gets through anyway, and act fast when it counts. Take one away and the other two are worth less.

Prevention: getting the basics right

Multi-factor authentication on every account, updates that actually get rolled out, safe password management and a properly configured Microsoft 365 environment. This is the unglamorous part of cybersecurity, and also the part that stops most attacks. We map what you already have before recommending anything.

Detection: monitoring that knows what to look for

Prevention does not stop everything, so you want to see what gets through. We monitor your workstations, servers, accounts and Microsoft 365 environment around the clock for signals that do not add up. A suspicious login from another country at three in the morning becomes an alert at the time, not a discovery weeks later.

Response: acting fast when an incident hits

An alert is only worth something if someone acts on it. When a threat is confirmed we isolate the affected device or account, so the attacker gets no further while you are still on the phone. With MDR Premium we respond to cyber threats within ten minutes.

What do you get out of it?

You do not buy security for the technology, but for what it gives you: less chance of downtime, proof that you are in control, and one less thing to think about in the evening. Below is what changes, point by point.

Less risk of business downtime

An attack takes your systems down. You find out in the morning when you start up, and by then the encryption finished long ago. Recovery takes days to weeks, with your business largely at a standstill.

The attack stands out at the first suspicious step, not the last. The affected device comes off the network straight away and the rest of your business carries on.

Meeting the demands of clients, regulators and insurers

Every tender, audit or insurance application sends you searching again. You do not know exactly what is being monitored, so you cannot demonstrate it either.

You get monthly reports setting out what was seen and what was done. That is exactly the evidence clients, insurers and regulators ask for.

Peace of mind without your own security team

Outside office hours nobody is watching. Holidays, weekends and public holidays are precisely when attackers try, because the odds of anyone noticing are low.

Someone is always watching, including when you are not. You only need to know one thing: who to call. The rest is arranged.

How do you know it is time to invest?

Not every company needs round-the-clock monitoring tomorrow. But there are three situations where waiting costs more than starting. Recognise one of them and a scan is the logical first step.

You handle sensitive client data

Personnel files, medical records, financial administration or client designs. In a data breach your own losses are not the only problem: there is also your reporting duty and the trust of the people whose data you held.

You fall under NIS2

NIS2 is the European directive on digital resilience, implemented in the Netherlands as the Cybersecurity Act. It applies from 15 August 2026 and directly affects more than 8,000 organisations. If it does not cover you, it still reaches you through clients who do fall under it and who will start setting requirements for their suppliers.

You have had an incident before

A company that has been hit once gets targeted again more often. Working access is resold, and an environment that was open once often still is somewhere.

Managed Detection & Response packages

Two packages with a clear difference in response speed and depth. MDR Essentials suits organisations that want the basics properly covered. MDR Premium adds full incident response, faster response times and monthly reporting.

MDR Essentials

Workstation and server security

External attack surface insight
Vulnerability scan on workstations and servers
Network insight
Detection of malware, ransomware and more
Vulnerability scan for website(s) and domains
Insight into misconfigurations on workstations and servers
Insight into Microsoft 365 and Azure misconfigurations
Automatic remediation of vulnerabilities

User security

Detecting stolen credentials, session hijacking, email or account takeover, and more
Insight into risky employee and administrator accounts
Monitoring of user behavior
Dark web monitoring of business accounts

Incident Response

Integration with existing Microsoft environment
Incident Response support
Limited scope, with post-calculation applicable
Response time to cyber threats
Best effort
Automatic response to cyber threats
Limited
Threat Intelligence
Extensive detection of security incidents (200+ additional detections)
Monthly security reporting

Most popular

MDR Premium

Workstation and server security

Insight into external attack surface
Vulnerability scan on workstations and servers
Network insight
Detection of malware, ransomware, and more
Vulnerability scan for website(s) and domains
Insight into misconfigurations on workstations and servers
Insight into Microsoft 365 and Azure misconfigurations
Automatic vulnerability resolution

User security

Detection of stolen credentials, session hijacking, email or account takeover, and more
Insight into risky employee and administrator accounts
User behavior monitoring
Dark web monitoring of company accounts

Incident Response

Integration with existing Microsoft environment
Incident Response support
Included, additional charges may apply
Cyber threat response speed
In less than 10 minutes
Automatic response to cyber threats
Full
Threat Intelligence
Extensive detection of security incidents (200+ additional detections)
Monthly security reporting

Start at the beginning

Request your free cybersecurity scan

You only know what to fix once you know what is going wrong. The free cybersecurity scan maps your workstations, accounts and Microsoft 365 environment and shows where the biggest risks are. There is no commitment and you keep the findings.

laptop screen with a cybersecurity scan running checking all settings

Frequently asked questions about cybersecurity for SMEs

Why does cybersecurity matter for small businesses too?

+

What does cybersecurity cost for a small or medium-sized business?

+

Which cybersecurity measures matter most for smaller businesses?

+

Can I outsource cybersecurity completely?

+

Does this approach make me NIS2 compliant?

+

Can I outsource cybersecurity if I already have an IT provider?

+