Consulting · IT security
The damage is rarely spectacular.
In small businesses the most common incident is not a movie-style attack but a hijacked mailbox or a backup that stopped running months ago. We record where you are actually exposed and settle what happens in an emergency.
Why the usual security debate misses small businesses
Security consulting often starts with technology that will never matter to a business of fifteen people. What causes damage in practice is unglamorous: a password used in three places at once, an account never revoked after someone left, a backup that runs but has never been restored.
The second gap is the emergency itself. Almost every business has some kind of backup. Hardly any can say how long a restore takes, who performs it, and how long the business can work without the systems. That is what decides whether an incident is an annoyance or an existential problem.
The third gap is organisational: who notices that something happened, and who does that person call? Without a defined procedure, hours disappear into the question of who is responsible.
So this engagement records both: the technical state and the emergency procedure. The result is a list sorted by likelihood and damage, not by technical elegance.
For most businesses the most effective measures are the unglamorous ones: a second factor on the important accounts, a tested restore path, a current overview of accounts. That is what the report says, even if it sounds less impressive.
What happens during the consulting days
- Survey of systems and accounts
- Which systems are in use, who has access to what, where accounts depend on individuals, which accounts stayed active after someone left.
- Check backups and restore
- Not only whether a backup runs, but where it goes, how old the latest state is, and whether a restore has ever been tested. An untested backup is an assumption.
- Assess risks rather than list them
- Every gap is rated by likelihood and potential damage, related to your business. A theoretical risk with no bearing on how you work does not belong on the list.
- Design the incident procedure
- Who notices an incident, who do they call, what gets disconnected first, how long does a restore take, and how does the business keep working meanwhile.
How the engagement runs
- Initial call, free of charge, about 30 minutes We set the scope and check whether there is a specific trigger, such as a customer requirement or a past incident.
- Day 1: on-site survey Systems, accounts, backups, ways of working. Plus conversations with the people who would have to act in an emergency.
- Analysis between the on-site days Risk assessment, draft incident procedure, prioritisation of measures. This time is not billed as a consulting day.
- Day 2: walkthrough We go through risks and measures together and decide what you implement yourselves and where outside help is needed.
- Report and handover Survey, rated risk list, incident procedure and prioritised measures with implementation guidance.
What you hold at the end
- Rated risk list
- Sorted by likelihood and damage, each with cause and recommended countermeasure.
- Incident procedure on one page
- Who does what in which order, with phone numbers. Deliberately short, because nobody reads a manual during an incident.
- Assessment of the backup situation
- What is backed up, what is not, how old the latest state is, and how long a restore realistically takes.
- Prioritised list of measures
- With effort, cost range and a note on what your own team can handle.
What is not part of this engagement
- No penetration test
- We do not actively attack your systems. That is a separate service with its own engagement and its own legal safeguards.
- No implementation
- Setting up multi-factor authentication, backups or endpoint protection are separate services with their own quote.
- No certification
- The report is not evidence under ISO 27001 or a comparable standard and does not replace an audit.
- No forensic investigation
- An ongoing or past incident needs forensic analysis, which is a different thing from this survey.
Effort and price
Usually two consulting days
A single-site business with a manageable system landscape is surveyed and analysed in two days. Multiple sites or a grown server landscape add a third day. 1,250 euro per consulting day of eight hours, plus VAT, travel and, where required, accommodation.
1,250 euro per consulting day of 8 hours, plus VAT, travel and, where required, accommodation.
What that means in figures
| Consulting days | Fee, net |
|---|---|
| 1 | 1,250 euro |
| 2 | 2,500 euro |
| 3 | 3,750 euro |
| 4 | 5,000 euro |
| 5 | 6,250 euro |
1,250 euro per consulting day of 8 hours, plus VAT, travel and, where required, accommodation.
IT security: Frequently asked
What does the IT security survey cost?
1,250 euro per consulting day of eight hours, plus VAT, travel and accommodation where required. Two days is typical, so 2,500 euro net.
Is this a penetration test?
No. We do not attack anything, we record the state and assess risks. A penetration test is a separate service and only makes sense once the fundamentals are in place.
We do have a backup. Is that not enough?
A backup without a tested restore path is an assumption. We check where it goes, how old the latest state is and how long a restore realistically takes. That is where it most often fails in an emergency.
Do we get evidence for customers or insurers?
You get a structured report with rated risks and measures. That is not a certificate and not an ISO 27001 audit. Formal evidence requires an accredited body.
What if we have an incident right now?
Then this engagement is the wrong instrument. An ongoing incident needs immediate containment and possibly forensic analysis. Call us and we will tell you honestly what comes first.
What do the recommended measures usually cost?
The most effective ones are usually cheap: a second factor on important accounts, a password manager, a tested restore path, an account overview. The report gives a cost range per measure so you know what you are talking about before requesting quotes.
Talk it through first
A 30-minute call clarifies whether an engagement is the right instrument. If it is not, we say so there.
Last reviewed: