Essential
Baseline protection for small organisations: endpoints, mail and backups in managed hands.
20 to 49 employees
- Endpoint protection and managed patching
- Email security
- Backup and recovery
- Baseline risk assessment
- SOC available as an add-on
One directive, twenty-seven national laws, and what they ask of you.
Five levels, from the basics in order to group-wide defence.
Every required measure, and the service that delivers it.
Detection and response from our European SOC.
Devices, cloud and support, run as one service.
NIS2, DORA and GDPR in one assessment.
Vendor platforms, rolled out and then run.
One named CISO, two days a month.
Direct help, and your report filed on time.
You leave the call with a prioritised list of your gaps and a price indication for closing them. Free and without obligation.
Plan the callWho we are and how we are set up.
Amsterdam, Sofia, Varna and Stara Zagora.
The platforms we implement and operate.
What the work looks like in practice.
The client team in Amsterdam, the engineering in Bulgaria, everything inside the EU. One contract, under Dutch law.
How we deliverSmartCyber
SmartCyber is the service that carries the ten NIS2 areas in practice. The controls underneath every level are the same stack, sized by headcount band, and growing into the next level extends the setup instead of replacing it.
One product
NIS2 does not require new technology. It requires measures, and the measures are services that already exist and already run. That is why moving between levels is a configuration change rather than a migration.
Moving from Protect to Advanced adds the SOC, the SIEM and the response time. Your endpoint agent is not replaced and your policies are not set up again.
Device, server and user counts. The cost therefore tracks the organisation rather than a licence tier you outgrew long ago or will not reach for years.
The reporting a regulator, an insurer or a tender asks for comes out of running the service, not out of a project just before an audit.
One contract, one SLA, one point of contact. The space between two contracts belongs to nobody, which is why we keep it to one.
The levels
The size bands are a starting point, not a rule. A 60-person energy supplier carries more obligation than a 400-person wholesaler, and the intake call is where that gets resolved.
Baseline protection for small organisations: endpoints, mail and backups in managed hands.
20 to 49 employees
Adds monitoring during office hours, so problems surface before your customers see them.
50 to 99 employees
Full round-the-clock SOC, SIEM plus XDR underneath. Where most organisations under NIS2 land.
100 to 499 employees
Built around continuity, with recovery rehearsed and downtime bounded by agreement.
500 to 999 employees
Governance for group structures across several countries, with reporting a board can sign.
1000 employees and above
Pricing follows device, server and user counts and is confirmed in the intake call. We do not publish a per-device figure, because a figure that needs three caveats to be true does not help you.
Side by side
The same table our own team works from. Where a component appears, we operate it. It is not switched on and handed over.
| Capability | Essential | Protect | Advanced | Resilience | Enterprise |
|---|---|---|---|---|---|
| Endpoint protection and managed patching | Included | Included | Included | Included | Included |
| Email security | Included | Included | Included | Included | Included |
| Backup and recovery | Included | Included | Included | Included | Included |
| Baseline risk assessment | Included | Included | Included | Included | Included |
| Managed EDR | Add-on | Included | Included | Included | Included |
| Network security | Not included | Included | Included | Included | Included |
| Identity protection | Not included | Included | Included | Included | Included |
| Security awareness and phishing simulation | Not included | Included | Included | Included | Included |
| SOC coverage | Add-on | Business hours | 24/7 | 24/7 priority | 24/7 co-managed |
| SIEM and XDR | Not included | Not included | Included | Included | Included |
| Critical alerts answered inside 15 minutes, by SLA | Not included | Not included | Included | Included | Included |
| Vulnerability management | Not included | Not included | Included | Included | Included |
| Support with the statutory notifications | Not included | Not included | Included | Included | Included |
| Privileged access management | Not included | Not included | Not included | Included | Included |
| Disaster recovery with tested failover | Not included | Not included | Not included | Included | Included |
| Continuity plan and crisis exercises | Not included | Not included | Not included | Included | Included |
| Supply-chain risk assessment | Not included | Not included | Not included | Included | Included |
| Dedicated analysts and named service lead | Not included | Not included | Not included | Not included | Included |
| Group governance spanning countries and business units | Not included | Not included | Not included | Not included | Included |
| Audit, tender and insurer reporting | Not included | Not included | Not included | Not included | Included |
| Reporting cadence | Annual | Monthly | Quarterly review | Quarterly review | Named lead, monthly |
Add-ons and the one-time onboarding are quoted separately. Where a component shows "Add-on" it is available at that level but is not included in the base price.
What sits underneath
Every level is built from the same components. Which of them are switched on, and how closely they are watched, is what really decides the level.
Managed endpoint protection with a monitored EDR agent, mail filtering and protection against impersonation of directors and suppliers, and patching on a fixed rhythm with exception reporting.
A European SOC watching around the clock, SIEM correlation across endpoint, identity, network and cloud, XDR runbooks, and priority alerts answered inside 15 minutes.
Multi-factor authentication and conditional access, a joiner, mover and leaver process that actually runs, privileged access management, management of accounts with elevated rights, and periodic review against least privilege, meaning no more rights than someone needs.
Immutable backup, a backup that cannot be altered or deleted, restores tested rather than assumed, an agreed RTO and RPO, and failover exercised so the first real test is not the first attempt.
Vulnerability management with agreed remediation windows, hardened baselines, and penetration testing that is scheduled rather than arranged after the fact.
An overview of the state of the measures, per-person training records, incident timelines, and quarterly reporting written for a board rather than for an engineer.
How to choose
Two organisations of the same size can sit two levels apart. These are the questions that really move the answer.
Start at the level your headcount suggests and move up as soon as something changes.
Any one of these is usually enough. With two of them the level underneath will not hold.
Something is already happening
Choosing a package can wait. Containment cannot, and for organisations covered by the Cyberbeveiligingswet the 24-hour deadline is already running.
The intake call answers both. You speak with our CISO directly and get a straight answer, including the components you do not need yet.