
Cybersecurity that can handle NIS2
Detect, contain, recover and demonstrate. We build and staff the security programme of mid-market organisations, with 24/7 monitoring and evidence an auditor accepts.
A firewall plus antivirus no longer covers it
Most mid-sized organisations have built their security up in layers: a firewall from 2019, virus scanners on the laptops, a backup that runs but is rarely restored. On paper it adds up. In practice, the answer to the question that really matters is missing: how do you notice that someone is inside, and what happens in the hour after that?
ITproposal sets up security as a programme instead of a collection of separate products. We combine detection on your workstations and servers, a security team that watches day and night, and documentation you can hand to an auditor or insurer without panic.
We are not a hyperscale consultancy and not a one-person shop. You get a fixed point of contact in the Benelux, with our own shift behind the scenes covering the night and weekend hours.
- One party for security and management You do not have to mediate between your security vendor and your managed services provider when something goes wrong.
- Kiwa NEN 4400-1 certified The way we deploy personnel has been audited, which saves work in your own supplier assessment.
- Built on what you already use Microsoft 365, Azure, AWS and VMware. We do not add an extra stack where your existing licences can already do the job.
- Experience in retail, healthcare and logistics Sectors with peak loads, till and scanning processes and little room for downtime.
Six building blocks of a complete security programme
You can start with everything at once, or with the parts where your risk is greatest. Each block can be purchased separately and fits within the same reporting and the same point of contact.
Visibility on every device
EDR software on laptops, workstations and servers, rolled out centrally and actively monitored instead of passively installed.
Eyes on your environment, at night too
Analysts from our security team assess alerts every day of the year. A suspicious alert is picked up straight away, not on the next working day.
Ready for the Cybersecurity Act
A baseline assessment against the NIS2 measures, implementation of what is missing and a file you can hand to an auditor.
Access under control
Rolling out multi-factor authentication, shielding administrator accounts and checking periodically who can reach what, so that rights move with role changes.
Immutable backup and recovery
Backups that can no longer be changed or deleted, with periodic restore tests and a recorded recovery time per system.
Training that sticks
Phishing simulations and short, targeted training sessions. Participation and results are tracked, so that you can demonstrate progress.
What NIS2 and DORA ask of your organisation
The Dutch Cybersecurity Act, the implementation of the European NIS2 directive, shifts liability explicitly to board level. Even if you do not fall within the scope yourself, the requirements still reach you through your clients and contracts. Demonstrability therefore becomes just as important as the measure itself.
- Risk management that is documented A current overview of your risks, the measures you have chosen and the residual risk you knowingly accept.
- Mandatory incident reporting An early warning and a full report to the regulator within the deadlines the law prescribes, with roles assigned in advance.
- Continuity and recovery Backup, crisis management and a recovery plan that has been tested rather than only described.
- Supply chain security Agreements with suppliers about their security, and visibility of the risk they bring into your organisation.
- Access and authentication Multi-factor authentication, rights management and periodic checks on who can still reach what.
- Accountability at board level Directors supervise the measures and must be able to show that they have been trained on them.
- DORA for the financial chain If you supply banks or insurers, further requirements apply on testing digital resilience and registering your ICT outsourcing.
- Evidence an auditor accepts Reports, logs and test records that substantiate both the measure and the way it works.
Who is watching when your office is closed
Alerts from your workstations, servers, firewalls and Microsoft 365 come together in one place. Our analysts do not see separate alarms there, but the pattern behind them: a sign-in from an unknown location, followed by an account that suddenly moves through folders it never visits.
That work does not stop when your working day stops. At the end of the day the team hands over to the evening shift, so that someone is watching the screens at night and at weekends as well, with the same agreements and the same file.
- One view of your entire environment Workstations, network, identities and cloud in the same timeline, so that connections become visible instead of separate alerts.
- Noise removed before you see it Known false alerts are filtered out; what remains has been assessed by an analyst before you get a call.
- Handover without loss of information Every shift change runs through the same ticket and the same context, across time zones too.
- You can read back what happened What stood out, what was done and what it meant, recorded and usable when dealing with your auditor or insurer.
How we work during an incident
A cyber incident disrupts every organisation. The difference is not whether it happens, but how quickly and how well coordinated the response is. This is the order we follow.
Detection & triage
An alert from the detection software arrives at our security team. The analyst determines whether it is real, classifies the severity and starts the first containment.
Containment
We take affected devices off the network, secure the traces for investigation and inform your board as soon as the severity calls for it.
Clean-up & recovery
The threat is removed, systems are restored from immutable backup and we validate integrity before everything goes live again.
Evaluation & reporting
Analysis of the underlying cause, adjustment of the measures and the reports to the regulator within the deadlines the law prescribes.
Security rarely stands on its own
These services connect most often to a security programme.
Where do you stand today?
Book a thirty-minute conversation with no obligation. We go through your current security position, name the gaps we see and set out what is needed to be demonstrably in order in time.