A crystal-clear picture of all your cybersecurity measures

Our independent review examines the current state of your organisation. We map your existing cybersecurity measures, assess whether the baseline measures have been implemented and provide targeted advice on where improvements are needed.

A crystal-clear picture of all your cybersecurity measures

Every organisation needs to defend itself against cyber threats by adequately protecting essential elements such as business processes, data and customer or patient information. A first step in a proactive and mature cybersecurity strategy is to implement baseline measures, as recommended by bodies such as the Dutch National Cyber Security Centre (NCSC). These measures include both technical controls (such as firewalls, antivirus software and encryption) and organisational controls (such as policies, procedures and training). By implementing these baseline measures, an organisation can fend off attacks, increase its resilience to recent digital incidents and establish a strong foundation for further security efforts. Recent incidents have shown that organisations are vulnerable without these measures. Active policy assessment and adjustment are crucial to ensuring compliance and effectively protecting the organisation against new and emerging threats.

The NIS2 Directive

The NIS2 Directive strengthens cybersecurity within the EU. The original NIS Directive protected essential sectors such as energy, transport, finance, healthcare and water supply. The expansion under NIS2 now also brings sectors such as public administration, the chemical industry, food production, digital infrastructure and space within the scope of these regulations. Important digital service providers, such as search engines, cloud services and online marketplaces, are now also subject to these stricter cybersecurity standards. The aim is to strengthen the cybersecurity posture of essential and important entities within the EU.

The Directive specifically emphasises the importance of:

  • Risk management: systematically identifying, evaluating and mitigating cybersecurity risks.
  • Incident handling: establishing processes for an immediate response to security incidents to limit damage and enable rapid recovery.
  • Resilience planning: developing strategies and practices to ensure the continuity of critical services, even during and after significant disruptions, including disaster recovery and business continuity management.
  • Supply chain security: ensuring that every link in the supply chain is adequately protected against cyber threats.

Independent review

Our independent review of the cybersecurity measures currently in place provides a clear overview of the current state of cybersecurity measures within your organisation. We use the CIS (Center for Internet Security) best practices, also known as the CIS Controls. These are a series of actionable security measures designed to help organisations protect themselves against the most common cyber threats. The CIS Controls were developed by a community of IT experts and are based on real attack patterns and effective defensive strategies. They prioritise actions, are widely applicable and are easy to use.

Please note: this review can serve as guidance for matters such as NIS2, but does not constitute legal advice.

This is how we work

We tackle a false sense of security head-on by looking, thinking and acting like a hacker. This allows us to identify precisely those costly threats that could bring you down and that a malicious hacker is looking for.

Every week, the news shows how dangerous it is to believe you are secure when you are not. There is often an underlying issue: responsibilities have not been assigned internally, or not sufficiently; communication has been inadequate; or monitoring has started before the basics are in place.

We look at security from the perspective of your business objectives and ambitions in software development and innovation. A malicious hacker does the same. They want to know where you are vulnerable and where the pot of gold is. We make sure that pot of gold is, and remains, under lock and key.

The review is carried out in 5 phases:

1. Preparation

During the preparation phase, we make sure the relevant staff members are scheduled and fully informed about the process. The first session takes place on site and lasts half a day, followed by a further session via Teams if needed.

2. Interview and assessment

We begin with an in-depth interview with the staff members involved to obtain a good picture of the current state of cybersecurity measures within the organisation. We primarily assess the technical aspects, with a brief review of the organisational aspects, to form a complete picture.

3. Checks and validation

Following the interview, we carry out a brief check of the operation and configuration of the measures wherever possible and applicable. This includes technical validation of the security measures that have been implemented to establish their effectiveness.

4. Analysis and reporting

We analyse the collected data and prepare a detailed report. This report provides a clear picture of the current cybersecurity measures, including partially implemented measures, and identifies opportunities for improvement. The results of our gap analysis enable you to work towards strengthening security and/or drawing up a step-by-step plan to do so.

5. Aftercare: crystal clear

You receive all the results in a clear report with a highly relevant overview. After delivery of the report, we schedule a debrief: we explain everything so that it is crystal clear what you need to do and why. More than once, if necessary!

That is our understanding guarantee.

What do you receive?

  • A clear picture of the current cybersecurity measures
  • Insight into opportunities for improvement and targeted advice on where measures need to be strengthened
  • A gap analysis including priorities
  • A comprehensive briefing

Fixed price

No hassle with complex quotations and complicated retrospective calculations. We work with fixed prices. They do not change if we need to explain things a few extra times. Rather convenient, we think.

Understanding guarantee

Every person responsible for IT or security understands 100% of what is in our report. This prevents issues with interpretation or implementation. We never leave you puzzling over the results.

Highly relevant

You receive reports and advice tailored to your business, your challenges and your current stage of development. Your priorities are handed to you on a plate. Only then can you take the right steps.

We are SECWATCH

For more than 15 years, we have helped medium-sized businesses protect themselves against precisely the right threats. We call these costly threats: risks that could seriously damage your organisation’s continuity and/or reputation.