IT-Local team
IT Local team

Which security level suits your organisation?

How far should and do you want to go in securing your IT environment? We are happy to help you make that choice and can set up security at three security levels: Essential, Plus and Elite. We do this by means of a matching, balanced package of services.

Our security levels and packages

Essential

With Essential, you choose a basic level of security: the minimum measures for any business to work safely from the cloud.

Our Essential package includes - as the name suggests - everything essential for the security of your IT environment, from two-factor authentication and backup to firewall and virus scanner; we will relieve you of all your worries through professional management.

Plus

Want a comprehensive set of security measures that tackles most risks for small and medium-sized businesses? Then security level Plus is the best choice.

Our Plus package offers you some interesting additions compared to the Essential package. You choose smart, future-proof security that not only protects, but also prevents attacks. Including better protection of mobile devices and stronger authentication against phishing. We also help you meet compliance requirements with data labelling.

Elite

If you are a high-risk organisation because you work with a lot of sensitive data, for example, the Elite security level is the right option.

With the Elite package, you choose the most comprehensive level of security. With this package, we actively anticipate internal and external threats. Through continuous monitoring and automatic response, we ensure that your IT environment remains guarded day and night.

Security according to the Zero Trust principle

In designing the levels and packages, we have assumed security according to the Zero Trust principle in which you secure all employees, devices and applications, wherever they are and without hindering your company's productivity. Zero Trust aligns with modern working from the cloud, where everyone wants to be accessible anywhere on any device

What exactly is in the packages?

Check the table below for an overview of all services per package. This way, you can easily compare the packages.

We have divided our services into the five pillars of Zero Trust:

  • Identity: who is trying to gain access?
  • Devices: what is trying to gain access?
  • Network: where does communication take place?
  • Applications: which application or service is being accessed?
  • Data: which data is accessed?

Below the table you will find a brief description of the services.

Happy workplace - save on licences and hardware

Want to know more?

In a no-obligation discussion, we will be happy to advise which package is right for you.

Call me for an appointment

Services

Security package

Essential

Security package

Plus

Security package

Elite*

Identity

Setting up and managing a tenant-baseline

Clean-up: 1x per year

Clean-up: once every six months

clean-up: 1x per quarter

Geoblocking for management accounts

Login with MFA

Biometric login on devices
Longer retention Entra ID logs

1 year

1 year

Phishing-resistant login with passkeys
Detection of high-risk logins

Devices

Device security
Data encryption on devices
Additional protection of company data in mobile use
Vulnerability management on devices

Network

Firewall with monitoring
Network segmentation

Applications

App approval at tenant and local level
Risk management for cloud applications

Data

E-mail security (spam, malware and phishing)

Setting up and checking DNS records for e-mail

including reporting

including reporting

Backup for data, mailboxes and SharePoint
Data classification and labelling
Risk management for internal threats

Overarching

Automatic incident response: XDR
Optional
Optional
Options
Cyber Security Assessment Tool-scan (CSAT)
Optional
Optional

Optional

Security awareness programme

Optional

Optional

Optional

Password management tool
Optional
Optional

Optional

MFA for servers

Optional

Optional

Optional

Cloud-based Wi-Fi authentication

Optional
Optional

Optional

Price per user per month

On request

On request

On request

* For the Elite package, you will need the add-on Microsoft Defender Suite for Business Premium in addition to your Microsoft 365 Business Premium licence.

More about our services

Below is a brief description of each service:

Setting up and managing a tenant baseline

setting up a security baseline for your Microsoft 365 environment, we ensure that your tenant meets our and Microsoft's recommended standards for security and management. We monitor this security baseline policy, detect deviations from the baseline policy and remediate these deviations (automatically). In addition, we like to keep your tenant clean. That is why we periodically clean up old accounts and test accounts. We do this on the basis of predefined policies. We also update applications within Intune and check the current rights within SharePoint. Within the Essential package, we do this once a year. With Plus, we clean up once every six months and with Elite we do this once every quarter

Geoblocking for management accounts

Administrator accounts are always a wanted target for attackers. Through geoblocking, we ensure that you can only log into the tenant with management accounts from pre-approved countries.

Login with MFA

strong password is no longer enough. Around 7,000 password attacks are carried out every minute worldwide. With multifactor authentication (MFA), you add an extra layer of security: in addition to the password, an employee has to give additional approval or enter an additional code via an app. So cracking a password is no longer enough to break in. And if someone makes an attempt... we see it and take action. We are also there for you in case of any login problems. Via Self Service Password Reset (SSPR), your employees can reset their passwords themselves

Biometric login on devices

With Windows Hello, your employees don't log in with their password, but biometrically (via facial recognition, fingerprint or PIN). This is easier and more secure than password + MFA - you only use MFA the first time. We can only activate Windows Hello if your environment is fully in Microsoft Azure AD (Microsoft Entra ID).
IT management - Andy

Longer retention Entra ID logs

For an audit or a security incident, logging is crucial to be able to search further back in time. By default, logs in Microsoft Entra are only stored for one month. With Plus and Elite, we integrate the logs from your tenant with Log Analytics so that they are stored for a year.

Phishing-resistant login with passkeys

is a major risk for organisations, especially among users with access to sensitive systems. Passkeys offer a stronger, phishing-proof form of authentication without passwords. They are tied to the Microsoft Authenticator app on your phone and non-transferable, making misuse virtually impossible. Passkey login is available in the Plus or Elite package. We can enable this method for your entire organisation or only for specific departments within the organisation (e.g. the finance department).

Detection of high-risk logins

Not every login is what it seems. Microsoft Entra ID Protection acts as a digital security agent that continuously detects suspicious login attempts, such as an employee suddenly trying to log in from another continent or a device behaving strangely. By detecting risky logins automatically, we can intervene quickly before damage occurs. For example, in the form of additional authentication, blocking access or informing the user. Microsoft Entra ID Protection is available in Elite.

Image

Device security

Viruses, spam, phishing mail and malware... you don't need that. Using Microsoft Defender for Endpoint, including advanced Endpoint Detection and Response(EDR)functionality and ongoing monitoring from our Management Department, we make sure your IT environment stays safe. We scan and isolate all possible threats on devices, tell you what to do in the event of a threat and assist where necessary.

Data encryption on devices

We encrypt all data on Windows devices with Microsoft BitLocker. This prevents data from being read by unauthorised persons. Our management system enforces encryption at workstations and keeps track of the status of the encryption. We carefully store the recovery keys in case they are needed.

Additional protection of company data in mobile use

Mobile devices such as smartphones and tablets are increasingly used for business communication and access to company data. This data also ends up on the device itself. In the Plus and Elite package, we offer you extra protection of your business data when used on the move. With Microsoft Intune, we can ensure that this sensitive information remains protected. You can choose to manage phones completely via Intune Mobile Device Management (MDM), for example in the case of company phones. Only managing company data in apps via Intune Mobile Application Management (MAM), for example for private phones, is also possible. In doing so, we combine security for your organisation with privacy for your employees.

Vulnerability management on devices

Vulnerabilities in software and configurations are often the entry point for attackers. Within the Elite package, we use Defender Vulnerability Management to continuously monitor devices for risks, e.g. missing updates and weak settings. This proactive approach helps to identify vulnerabilities early and take targeted action so that we close security holes before they are exploited.
Bart Boer

Firewall with monitoring

With a firewall, your corporate network is protected 24/7 from outside abuse. Our next generation firewall from Fortigate meticulously filters internet traffic - even before it enters your network or computers. And offers you additional benefits such as managing multiple internet connections and establishing a secure connection to your corporate network. Of course, we provide support, the latest firmware updates and security licences.

Network segmentation

With network segmentation, we separate the guest network from the production network. This prevents guests from accessing your company info. Both segments function independently, are thoroughly isolated via VLAN technology and have a strong Wi-Fi password.

App approval at tenant and local level

We set up an app approval process for you. This process prevents you from simply installing apps manually on the tenant or locally. We check every app you want to install beforehand.
IT Local-SharePoint training

Risk management for cloud applications

Cloud applications such as Microsoft 365, Salesforce or Dropbox often contain sensitive business information. With Microsoft Defender for Cloud Apps, part of our Elite package, we gain insight into the use of these apps, detect risky behaviour and can automatically intervene in suspicious activity. This is how we ensure that data in the cloud is well protected, without limiting the flexibility of modern working.

E-mail security (spam, malware and phishing)

Thousands of phishing and spam emails are sent every day, often with the aim of tricking employees or invading systems. With Microsoft Defender for Office 365, we filter email traffic even in the cloud, before it reaches your organisation. This way, we reduce the chances of harmful messages getting in at all. And if phishing emails are less likely to reach your employees, there is automatically less chance that someone will accidentally click on a link... If something does slip through, we will offer you immediate help. We also actively investigate spam.

Setting up and checking DNS records for e-mail

For proper delivery of all your e-mail, we set up the Domain Name System (DNS) records (SPF, DMARC, DKIM) for you. Even if they are not managed by you. We check the records periodically and update them if necessary. Having the right DNS settings not only ensures that your e-mail arrives, but also prevents malicious attacks such as spoofing.

Backup for data, mailboxes and SharePoint

With our backup solution, you are always assured that your valuable data (mailboxes, SharePoint sites and OneDrives) in Microsoft 365 are safely stored in our data centre. And that you can quickly access it again in case of data loss. We secure your data on a daily basis and continuously check and test the backup process. Our backup solution works on the basis of so-called Binary level object storage(Blob), which is ideal for large amounts of unstructured data. The backup cannot be deleted or modified until the retention time has expired. Thus, you protect the data against various dangers, such as cyber attacks and human error.

Data classification and labelling

With Microsoft Purview, we can automatically recognise and label sensitive company data, both in Microsoft 365 and beyond. Think of documents containing customer data or financial information. By classifying this data, we can apply targeted security measures such as encryption or access restrictions. With this, we help you meet compliance requirements. This service is part of the Plus and Elite packages.

Risk management for internal threats

A cyber threat does not always come from outside. Sometimes risk arises precisely within the organisation, think of data breaches or deliberate actions by employees. With Insider Risk Management, part of the Elite package, we gain insight into risky behaviour, such as sharing sensitive files or using personal cloud storage. This allows us to take timely action and protect company data from internal threats.

Automatic incident response: XDR

In a security incident, every second counts. With eXtended Detection and Response (XDR), suspicious activities are automatically detected and analysed across multiple systems. Together with our renowned partner, we continuously monitor suspicious signals and perform automated actions, such as isolating a device or terminating active sessions. This way, we limit the impact of an attack even before it can spread. XDR comes as standard in the Elite package and is an option with the other packages.

CSAT scan

Our Cyber Security Assessment Tool (CSAT) gives you quick and good insight into how your IT environment is doing in terms of security. After a thorough technical scan and going through an extensive questionnaire, you will receive a clear report. It shows you exactly where the vulnerabilities are in your company. And you can use the action points to work with us to make your IT environment more secure.

Security awareness programme

With our security awareness programme, you train your employees' security awareness. We do this by periodically and unannounced sending fake phishing emails to test how alert your employees are, via short learning moments and online training sessions. Clear dashboards and reporting and evaluation moments offer you insight into how your organisation is doing. Within the programme, you can choose between a standard or a customised programme.

Password management tool

Welcome123, Hetty1983, Apeldoorn2024... weak passwords and login credentials of your employees make your company vulnerable to hackers. Keeper is a convenient and secure tool to protect, manage and even share all passwords and other login data. We are happy to implement this for you.

MFA for servers

Are you working with your own servers within a hybrid or on-premises environment? Then the Microsoft MFA solution is not ideal and we additionally recommend DUO's MFA solution.

Cloud-based Wi-Fi authentication

Access to corporate Wi-Fi should not only be fast, but also secure. With our RADIUS-as-a-Service solution, we provide reliable and scalable authentication, without local infrastructure. Your employees log in securely and only authorised devices are granted access. This solution is ideal for organisations looking to modernise and centrally manage access to their Wi-Fi.

Three steps to the right security level

In three steps, we ensure that you and your organisation get to the right security level. And then stay there:

1. Determine the most appropriate security level
We will gladly help you choose the most appropriate security level and package for your organisation. Call us for an appointment or use the form below.

2. Setting up the desired security level
Have you made your choice? Then we will start working for you. We will set up security for you and thus bring your organisation to the desired security level. We charge a fixed amount for this.

3. Stay at the set security level
Once we have set everything up for you, we make sure your security remains at the set level. We do this by constantly monitoring your IT environment and intervening where necessary. You pay an amount per user per month for this. Because you pay for actual use, you never pay too much, you keep a grip on your costs and avoid high investments as your business grows.

security baseline

Minimum requirements for your security

Due to the sharp increase in cyber threats, we are stepping up IT security for our customers in our services. We want every customer to be at least at our basic level of security (Essential) from now on. 

    Image