Cybersecurity and GDPR for small businesses

Small companies also need protection against fraudulent messages, compromised accounts and data loss. We start by reviewing the current setup and choosing measures suited to your work and equipment.

What I do for your company's security

A review of the current setup, identification of the biggest risks and implementation of baseline measures to reduce them: safer sign ins, updates, backups and clear access rules.

  • Multi factor sign in (MFA) on all key systems
  • Protection against phishing and fraudulent email
  • Encrypted backups with automatic restore testing
  • Ransomware protection
  • Proper password management (a password manager for the team)
  • GDPR review: which data, where, who has access, how it is protected
  • An incident response plan (what you do when it happens)

GDPR for small businesses

GDPR is not just a privacy policy on a website. It is how your company handles the personal data of clients, employees and suppliers.

For most small companies it comes down to a few concrete measures: a written record of processing activities, contracts with processors (for example accounting software providers), secure backups and a clear procedure in the event of a breach.

Frequently asked questions

  • Are we really a target? We are a small company. Yes. Automated attacks (ransomware, phishing) do not target a specific company, they target weak protection. Being smaller means less protection, not less interest.
  • How much does baseline security cost? Baseline protection for a company with 10 employees: EUR 200 to 400 one off plus EUR 30 to 80 per month for tool licences (password manager, MFA, backups).
  • Do you carry out security reviews? Yes. An annual security review with a report and recommendations is included in the larger IT support packages.