Cybersecurity for SMEs
We set up the security a small or mid-sized business needs, from sign-in and email to backups and AI. Then we record what is in place, so you can show it to customers and regulators.
It starts with a conversation, not with code. First we look at what is already there and where the biggest risks are.
What we set up
Access
Every employee gets a password vault and two-step verification on the accounts that support it. Administrators, and employees with access to money or customer data, sign in with a hardware key such as a YubiKey.
- A password vault for every employee, with shared vaults per team
- Two-step verification on email, accounting and other cloud services
- Hardware keys for administrators, with a spare key kept somewhere safe
- Access for leavers closed on their last day
Email and files
We secure the existing email and storage, or move to a service with end-to-end encryption when that fits better. Sensitive files leave the company through a protected link.
- Measures against email forged in your name
- Sharing with a password and an expiry date
- Encrypted email when the content is sensitive
Backups out of reach of ransomware
A backup only helps if an attacker cannot reach it. That is why one copy cannot be changed or deleted from the company's own computers and accounts. And we test that restoring works.
- A copy in a second location that cannot be deleted from the company network
- A restore test, with the result recorded
- Agreements on what comes back first after an attack
A secured AI setup
AI that works with company data is set up on your own servers or in the cloud. The agreements about data are built into the setup itself.
- Models that run in the EU
- No customer data sent to services that train on it
- Access only through a secured network
- A log of what the AI does and retrieves
- Development and production kept apart
Recorded for NIS2, the Dutch Cbw and ISO 27001
What we set up is recorded in SlimCompliance. For each control you can see what is in place and when it was last checked.
- Risks and controls in one place
- Evidence per control, such as the result of a restore test
- In line with the duty of care in the Dutch Cybersecurity Act (Cbw) and with ISO 27001
Why Bitwarden
For password management we usually choose Bitwarden, for these reasons.
- Open source and independently tested
- The source code is public. Bitwarden has its apps and encryption examined every year by external security firms and publishes the reports. On its compliance page Bitwarden lists a SOC 2 Type II report and ISO 27001 certification.
- Data in the EU
- Bitwarden has a separate EU region at bitwarden.eu. The organisation's vault is then stored in the European Union. An account cannot move to another region later, so we make that choice at the start.
- Hardware keys and passkeys
- Two-step verification with a FIDO2 key such as a YubiKey is included in every plan. With a suitable key and browser, a passkey also unlocks the vault without the master password.
- Sharing per team
- Shared passwords live in collections, for example per department. In the admin console an administrator decides who sees what, and the event log shows who did what. With emergency access a trusted colleague can reach a vault if someone is suddenly unavailable.
- Affordable for SMEs
- The Teams plan costs 4 dollars per user per month, billed annually (Bitwarden's price, October 2026).
Proton for email and files
Proton is a Swiss company offering email, calendar, storage and VPN in one business plan. Its services fall under Swiss law. All its apps are open source and externally audited.
- Mail. Email between Proton addresses is end-to-end encrypted. A message to an address outside Proton can be sent with a password, which makes it end-to-end encrypted as well.
- Calendar. The title, description, location and participants of an event are end-to-end encrypted.
- Drive. Files are end-to-end encrypted. Sharing works through a link, with a password and an expiry date.
- VPN. An encrypted connection for people working on public wifi.
- Sign-in. Two-step verification with a hardware key (FIDO2), such as a YubiKey.
When Proton fits
For a small organisation that mainly emails and shares files, handles sensitive data and has few links with other software. Also for a fresh start, when there is no existing email environment to move.
When Microsoft 365 or Google Workspace is the better choice
If the business already runs on Microsoft 365 or Google Workspace, with accounting, planning or a CRM connected to it, switching often costs more than it brings. In that case we set up the existing environment properly: two-step verification for everyone, hardware keys for administrators and sharing outside the organisation only where it is needed.
Where Proton has limits
- Email to an address outside Proton is encrypted in transit. Without a password-protected message, the recipient's email provider can read it.
- The subject line of an email is not end-to-end encrypted.
- Integrations with other software are limited. Outlook and other email clients work through Proton Mail Bridge, an app that runs on the computer itself and requires a paid plan.
- Sharing outside Proton happens through a link. The recipient then opens the file in Proton's environment.
Record and demonstrate with SlimCompliance
SlimCompliance is the compliance platform of Seven Technologies. It holds the risks, the controls and the evidence that they work, such as which accounts have two-step verification and when the last restore test took place.
Since 15 August 2026 the Dutch Cybersecurity Act (Cyberbeveiligingswet) applies, the Dutch implementation of NIS2. If your business falls under it, or a customer asks for ISO 27001, the evidence is ready in SlimCompliance. We work according to ISO 27001 ourselves and record that in SlimCompliance.
Our approach
From advice to management, with one partner
The same rhythm for every project.
Advice
We start with a conversation, not with code. First clarity on what you need and what you do not.
Build
We build and integrate to measure, with technology that fits you. You own your data and your code.
Manage
We stay involved: monitoring, adjusting and growing with your business.
Discuss the security of your business
Half an hour is enough to see where to start.
Call 085 083 5775A 30-minute intake