Area 09 · Security

Information security

The largest section of our catalogue. We cover both sides: the paperwork an inspector studies and the technical measures that actually stop an intruder. Separately they do not work: documents without security tools will not protect the data, and tools without documents will not survive an inspection.

16
services in this area
10 days
the personal data document set
24/7
incident monitoring
Register
the selected security tools

Protection by technical means

The tools are chosen from your threat list rather than by buying the most expensive option. Excess only gets in the staff's way and never pays for itself.

The right order

Grabbing everything at once is costly and usually fruitless. The sequence that works looks different.

01

We look at what is there

What data exists, which systems hold it and who can see it. From that follow its classification and the protection requirements.

02

We write the threat model

We write down exactly which dangers we are defending against in your case. That document cuts out unnecessary purchases and saves money.

03

Documents and basic protection

A set of documents, a permission procedure, patching and antivirus. It answers most of an inspector's questions and stops the common attacks.

04

Security tools and monitoring

We roll out the solutions from the threat list and start event monitoring so an incident does not go unnoticed.

A fine for mishandling data is by no means the worst of the consequences. A customer database that leaks damages your name more than any enforcement notice, and after a ransomware attack with unusable backups an organisation stands still for weeks.

Questions and answers

It does. Headcount is irrelevant: if you hold employee records and customer contacts, the obligations arise in full. A small organisation has less work to do, but the set of documents stays the same.

To pass an inspection on paper it is sometimes genuinely enough, but that defends against a fine rather than against data loss. We always separate the two: this satisfies the requirements, and this actually reduces the risk - and we leave the decision to you.

It depends on the system's classification and on whether your clients include public bodies. In some cases certification is mandatory, in others any solid product will do. This is established during the survey, before anything is bought.

This means a shift of specialists watching what happens without a break and stepping in on suspicious activity. For a small organisation, antivirus with a central console and properly configured alerts is enough. Continuous monitoring pays off where downtime is measured in money per hour.

For a typical company the documents come together in about ten working days after the survey. The technical measures depend on the infrastructure and take from one to three months.

Let us see whether you are ready for an inspection

Расскажите, какие сведения обрабатываете и что уже предпринято. Проведём обследование и покажем разрыв между нынешним положением и требуемым.