Endpoint
Configuring and maintaining protection on workstations and servers, checking agent health and responding to detections.
CYBERSECURITY
Practical protection of devices, accounts, mail and data — matched to the size of the company and to real threats. The goal is to reduce risk without making everyday work harder for your team.
Ask about an auditA single tool does not create security. The order an attacker has to break through does.
Configuring and maintaining protection on workstations and servers, checking agent health and responding to detections.
Order in accounts, roles and permissions, plus multi-factor authentication where it genuinely matters.
Reducing phishing and domain spoofing: SPF, DKIM, DMARC and rules that do not block people from working.
Access rules, backups and DLP policies that limit uncontrolled movement of information out of the company.
Collecting signals from the infrastructure and reacting to anomalies instead of waiting for a user to notice.
Short, comprehensible rules employees can actually follow — an unenforceable policy protects nobody.
Scope depends on what the company actually has to lose. These are the things I start with, because they make the largest difference at the lowest cost.
Most companies already own security tools. The problem is rarely what is missing — more often it is what was half-deployed and left that way.
Everyone works on accounts with local administrator rights.
It was easier during workstation rollout and nobody reversed it afterwards.
I remove the rights and leave a controlled elevation path for tasks that genuinely need it. This single change has the largest effect on what happens after somebody opens the wrong attachment.
Antivirus is everywhere, but the console shows agents silent for months.
Nobody opens the console while nothing appears to be wrong.
I check coverage, get the agents reporting again and set an alert on coverage dropping. A workstation whose agent does not report is, in practice, an unprotected workstation.
A purchased tool runs in monitor-only mode.
It was switched on “to try it out” so nothing would be blocked, and stayed that way.
I review the detections from monitor mode, agree exceptions for what the work genuinely requires, and only then switch it to blocking.
Administrative passwords circulate in messages and spreadsheets.
There is no password manager and access has to be handed over immediately.
I introduce a password manager with access control and rotate everything that previously travelled in plain text. A password sent once is a password burned.
Software that no longer receives patches is still running in the environment.
It works, so nobody touched it — and sometimes a single device or program with no newer version keeps it alive.
I establish what is still supported by its vendor and what merely runs. Whatever cannot be replaced right away gets isolated from the rest of the network, with a dated replacement plan — rather than waiting for the moment somebody else makes that decision for us.
The company pays for cloud services nobody has ever put on one list.
They were bought by different people at different times, and subscriptions renew themselves.
I write down what is subscribed to, who administers it, what data goes there and whether sign-in is protected by MFA. It usually produces the same result: a few services to switch off and a few accounts that outlived an employee.
Nobody knows what to do in the first hour after an incident.
No plan was written, because “nothing ever happens here”.
I write a short procedure: who to notify, what to disconnect from the network and what not to delete. One page somebody will read under pressure — not a thirty-page document.
A policy you cannot enforce is worse than no policy at all, because it creates the illusion of control. So an audit starts from the actual state, not from a product catalogue.
Most incidents do not come from missing tools but from unfinished configuration: an agent that stopped reporting, an account nobody disabled, an exception added "temporarily" two years ago, an alert going to a mailbox nobody opens.
More often than not, the largest security improvement comes from finishing what you already own — not from another licence.
The questions that come up most often about this service.
In a small company that is almost never the first step. Before we talk about tools it is worth closing the things that cost nothing: administrator rights, MFA, backups held off the server, disabling accounts when people leave. Only once that is done does another product start to change anything.
No. A review mostly means looking at configuration and talking to people, not switching systems off. Changes that could interrupt something are planned separately and rolled out in stages, in windows agreed with you.
No. Technical security is one element, but compliance also covers documentation, lawful bases and contracts with processors. I can put the technical layer in order and describe what was done — I do not issue legal assessments, because I am not a lawyer.
Rights, MFA and backups. Those three require no purchase and account for most of the difference between an incident that is annoying and one that stops the company for a week.
I can help secure the environment, cut off access and rebuild systems from backup. Full post-breach forensics is work for a specialist team, and with a serious incident I will say so plainly rather than learn on your case.
No specification required. A few sentences about your company and what currently does not work is enough to start.
Go to contact