Something usually sets it off. A major client sends a security questionnaire, UODO writes after a reported incident, or management wonders if NIS2 reaches the company directly or via an essential entity it supplies. We build on ISO 27001 principles and on recommendations from CERT Polska.
First we establish where employee and client records are held, which people have access and what leaves a trace. The GDPR security requirements then turn into concrete configuration across Microsoft 365, payroll software and network folders.
A top-level security policy, a risk register, a plan for handling incidents and rules on who gets which rights. Auditors, public contracting authorities and purchasing departments of big customers tend to ask for exactly these.
We pick tools according to your risk analysis rather than a vendor price list. Controls that go too far slow people down, and people who are slowed down look for workarounds, so we focus on what cuts real risk.
We start by checking what your current subscriptions already cover, test on a few computers and then finish the remote rollout, so the product ends up defending you rather than merely being paid for.
A tidy firewall policy, separate zones inside the network, a safe way in for remote staff instead of RDP open to the world, and one central store for server logs.
Roles in your ERP and CRM, dedicated accounts for integrations, API keys moved out of config files and a dependency check before each release goes live.
Labels for sensitive files, laptops with encrypted disks and Purview policies able to stop a message full of PESEL numbers on its way out.
Rights enforced at the database level, a record of which tables each person reads, and pseudonymised copies handed to developers and testers.
Screens traffic reaching your web shop or customer portal, turning away SQL injection, brute-force attempts on the admin login and bots scraping prices for comparison sites.
Multi-factor sign-in for all users, Entra ID policies that judge each login in context, Intune-managed laptops and rights cut back to the tasks people really perform.
Secure tunnels linking branch offices and home workers, disk encryption on every laptop and protected mail whenever the content is confidential.
Scheduled checks of your servers, network devices and sites against known vulnerabilities, followed by a clear ranking: fix this now, schedule that for the next service window.
Settings configured once and never revisited age quickly as people join, systems change and attackers adopt new tricks. The services below stop your defences drifting out of date.
Purchasing the whole catalogue in one go tends to exhaust the budget and leave products unmanaged. For companies employing 10 to 250 people, we suggest this order.
A list of your systems and information, their locations and everyone holding access. It shows which laws are relevant and where protection must be tightest.
Next we document the dangers that plausibly affect a business of your kind and scale. It prevents wasted spending, and both the GDPR and the cybersecurity act are built on a risk-based approach.
Written rules, multi-factor sign-in, timely updates, EDR and backups proven by a restore test. Together they satisfy most client questionnaires and defeat common attacks.
Then come the measures the risk register calls for, perhaps DLP, a WAF or network zoning, along with continuous monitoring that helps spot intrusions earlier.
Penalties imposed by UODO seldom make up the largest bill after an incident. Losing a client database erodes trust and contracts, while ransomware combined with never-tested backups may stop operations for weeks. So our priority is limiting harm, rather than producing reports that simply look reassuring.
It depends on your sector, your size and the detailed criteria of the directive and Poland's national cybersecurity system act, which include exceptions. Smaller companies often feel the rules indirectly, when regulated clients start asking about supplier security. We help prepare the technical side of those answers, while whether the act applies to you is a question for your lawyer.
It does. Headcount changes nothing once you process information about staff, patients or clients; there are just fewer systems to go through. A five-person bookkeeping office faces the same 72-hour deadline for reporting a breach to UODO as a national retailer.
Paper will get you through a questionnaire, but it will not halt an intruder. It answers the accusation of missing procedures, not the loss of information. In our recommendations formal compliance items and real risk reduction are listed separately, leaving the choice of scope and pace with you.
A security operations centre is staffed by people who follow alerts without pause and intervene at the first suspicious sign, weekends and nights included. With a dozen or so PCs, EDR plus a single dashboard and carefully set notifications is often sufficient. Continuous monitoring earns its cost when every hour offline hurts, or when NIS2 duties and client contracts demand a rapid reaction.
It depends on the size of the environment and the scope of work. We set the timeline after the initial review and put it in the contract. No visits are required: we meet over Teams or Google Meet and configure everything through secure remote connections.
Describe the information you handle and the safeguards already running. After a remote review we will show how your current setup compares with what regulators and clients will expect.
Your enquiry has reached us
You will hear back within one working day, and if you have reported an outage that is holding up work, it goes to the front of the queue.
No match for that name. Try a different spelling or pick a bigger town nearby - all our support is delivered online, so your choice has no effect on the service.