When you need this service
Most incidents do not begin with a sophisticated attack but with a neglected security baseline. Typical signs include:
- Accounts and access rights are scattered, with no overview of who can access what.
- Multi-factor authentication is used inconsistently or not at all.
- Former employees’ accounts and access rights are still active.
- Employees have not been trained to recognise phishing and other common attacks.
- A client, partner or regulation such as NIS2 asks about security, but there is no concrete answer.
- There is no plan defining who does what and who must be notified during an incident.
What the service includes
Cybersecurity baseline audit
A focused assessment that establishes an honest baseline across accounts, access, devices, backups, websites and working practices. The result is a prioritised action plan.
Access and risk review
Who has which rights, what is excessive and what is missing — including risk analysis and upgrade plans for outdated systems.
Implementation of practical controls
Multi-factor authentication, password management, backups and other baseline practices configured so that people actually continue using them.
Employee training
Short, practical sessions that teach employees to recognise phishing and common scams — people are the first target in most attacks.
Ongoing security monitoring
After the initial work, I keep an eye on the environment through reviews, updates and ongoing advice so the baseline does not quietly deteriorate.
How the engagement works
I begin with an audit of the real situation — not only the paperwork, but actual accounts and systems. I then create a prioritised plan: what must be fixed now, what comes next and what can wait. Implementation is gradual, with a clear explanation of why each change matters. If useful, the engagement continues with monitoring and regular training. I also support progress towards NIS2 and ISO 27001.
Outcome: an information-security baseline that is genuinely in use — documented access, trained employees and a clear incident plan.
Frequently asked questions
Does an audit mean a large and expensive project?
No. A baseline audit is a focused engagement designed to establish an honest starting point and a prioritised plan. Most findings can usually be resolved through disciplined housekeeping rather than major investment.
What is the difference between NIS2 and ISO 27001?
NIS2 is a European Union directive requiring certain sectors and sizes of organisation to manage cybersecurity. ISO/IEC 27001 is an international information-security management standard. Certification is voluntary, but clients and partners increasingly expect its principles. I help determine which requirements apply and to what extent.
Our company is small. Would anyone really attack us?
Most attacks are automated and do not choose targets by size. They scan everything that is publicly reachable and weakly protected. Small companies are often easier targets precisely because the basics have not been organised.
Let’s start with a short conversation
Describe in a few sentences what your company needs help with. I will reply personally, and together we can assess whether and how I can help.