Skip to content

Cybersecurity

CSIRT and CSIPT under one retainer.

One number for incidents, one team keeping your risk small in the first place. No separate SOC vendor, no detached pen-test outfit, no insurance policy that aligns with nothing. One retainer, two teams, fixed people who know your setup.

CSIRT, your incident response team

24/7 reachable for cyber incidents. A number that gets answered, a runbook we set up together for your organisation, and a team that takes over: detection, containment, eradication, recovery, forensics. Coordination with police, NCSC, the Dutch DPA and your insurer when needed. Each quarter we drill the runbook in a tabletop exercise with your internal team, so you do not learn to improvise the day it matters.

CSIPT, your incident prevention team

Continuous prevention so the CSIRT has as little work as possible. Hardening of endpoints, servers and cloud tenants. Patch management with measurable cycle time. Vulnerability scans and threat hunting on your logs. Awareness and phishing training for your internal team, not an annual simulation but an ongoing programme. Periodic pen test, in-house or via a fixed partner. Vendor risk inventory reviewed yearly, because your risk also lives in your supply chain.

NIS2 and compliance

For essential and important entities, organised response plus prevention is a legal requirement. This retainer covers it in practice: documented plan, trained roles, audit trail, notification route to CSIRT-NL and your supervisor. Not sure if you fall under NIS2? Run the NIS2 quickscan first.

Know where you stand first

Before we talk retainer, run the incident-readiness scan first. Ten questions, you get a tier score immediately, a per-cluster gap list and the three things that need attention first. No sales pitch, just an honest starting point.

Pricing

fromOn requestbased on scope and SLA

Fixed monthly fee, scope based on organisation size, sector and required SLA. No ticket fees, no extra charge for incident hours inside the retainer. Pen tests and audits outside scope are billed separately at the Development day rate.

Ready to put your response route in order?

One intro call, then a readiness scan with a real person, then a proposal with scope and SLA tailored to you. No sales pitch, no months-long process.