Skip to content

535 040 361511 275 531

Book an IT review

IT security built in layers, not sold on fear

We won't tell you someone is attacked every eleven seconds. We'll tell you which layers of protection make sense at your scale, what they cost and what none of them can guarantee.

A server room aisle with racks on both sides

When it's worth tackling

You don't need to wait for an incident. These situations are reason enough.

If you recognise two or three of these signs, a free IT review will show you where to start.

  • Staff sign in to business email with just a password, no second factor.
  • A backup exists, but nobody has ever checked whether data can be restored from it.
  • Former employees may still have active accounts or access to files.
  • The same admin passwords are used in several places.
  • There's no device list, so nobody can say how many devices have up-to-date protection.
  • The business processes personal data or client data covered by an NDA.
  • An insurer or business partner has started asking about security in a questionnaire.

The layers we implement as part of this service.

  1. 1

    Two-factor authentication

    Rolling out a second factor for email, files and admin accounts. One of the cheapest changes, and it closes the most common route to account takeover.

  2. 2

    Tidy accounts and permissions

    Reviewing accounts, removing unused ones, limiting admin rights and separating admin accounts from everyday accounts.

  3. 3

    Workstation and server protection

    Deploying and maintaining endpoint protection in a central console, with policies suited to each workstation type. Base tier or detection and response, depending on the risk.

  4. 4

    Email security

    Sender domain authentication with SPF, DKIM and DMARC, attachment filtering and rules against messages impersonating management. Email is still the most common way in.

  5. 5

    Updates as a process

    Security-critical updates are applied as a priority and logged. Outdated software is one of the most common attack routes, even where antivirus is running.

  6. 6

    Backup as the last line of defence

    Three copies on two types of media, one of them off-site, plus restore testing. It's the only layer that saves you after a successful ransomware attack.

  7. 7

    Network segmentation

    Separating the networks for guests, staff, production equipment and servers. This limits how far an attacker can get after compromising one device.

  8. 8

    Incident reporting procedure

    One page: what staff should do, who to notify, what not to do and who decides to disconnect a device from the network. Tested, not just written.

What you get in writing.

  • Prioritised risk register

    A list of identified risks ranked by impact and cost to fix, clearly marking what we haven't checked.

  • Security policy configuration

    Endpoint protection policies, email rules and authentication settings, documented so another engineer could reproduce them.

  • Incident reporting procedure

    A one-page sheet to put up near workstations, plus an extended version for the decision-maker with the order of actions and a contact list.

  • Backup restore test report

    A document confirming that a backup was restored, exactly what was restored and how long it took. A date and a signature, not an assurance.

Who is responsible for what.

Security isn't a service you can buy in full and then stop thinking about. Part of the responsibility stays with you, and we'd rather say so up front.

On the NexaIT side

  • deploying and maintaining the agreed protection layers and policies in the central console
  • monitoring security alerts using the available tools, within your package's support window
  • security-critical updates within the agreed scope
  • technical support during an incident, including isolating devices and restoring data from backup
  • regular configuration reviews and a protection status report
  • backup restore testing in line with your package

On your side

  • deciding which layers to implement and the licence budget
  • approving two-factor authentication and communicating it to staff
  • training staff to report suspicious messages
  • telling us promptly when someone leaves, so their accounts can be blocked
  • decisions on reporting an incident to the supervisory authority or to clients
  • physical security of premises and storage media
  • managing contracts with suppliers who have access to your systems

What this service doesn't include.

Clear scope boundaries are part of a good contract. We talk about them before you sign, not when the first invoice arrives.

For penetration tests, compliance audits and digital forensics, we help you find the right specialist and join the technical discussion. But we don't pretend to do everything.

  • a guarantee that no incident will happen. No provider can honestly promise that
  • penetration testing and compliance audits by a certification body
  • legal representation and notifications to the supervisory authority, which are the data controller's decision and obligation
  • post-incident digital forensics, a separate laboratory specialism
  • recovering data from physically damaged media
  • negotiating with attackers. We don't hold such talks and don't recommend paying a ransom
  • endpoint protection licences, billed separately per device
  • monitoring outside the support window in the START IT and BUSINESS IT packages

When it's a good fit, and when it isn't

It makes sense if

  • The business processes data whose loss or leak would have real consequences.
  • You want to start with what reduces risk most, not with the most expensive tool.
  • You need to answer a security questionnaire from a business partner or insurer.
  • Security is meant to be maintained, not implemented once and forgotten.

We don't recommend it if

  • You're after a compliance certificate. That's a job for a certification body, not an IT provider.
  • You expect a guarantee that nothing will happen. We won't give one.
  • An incident is already under way and you need digital forensics. Your first call should be to a specialist incident response team.
  • The business isn't ready for two-factor authentication. Without it, the other layers are worth far less.

What affects the price

  1. the number of devices and servers to protect, because licences are billed per device
  2. the protection tier: base or detection and response
  3. the number of add-on modules, such as disk encryption or email security
  4. the starting point: no two-factor authentication and untidy accounts mean more work at the start
  5. the number of sites and whether the network needs physical segmentation
  6. whether you need a disaster recovery plan, not just a backup
  7. whether reporting is required for a business partner or insurer
View packages and rates

Questions before you decide.

Is antivirus included in the managed IT price?

No. It's charged per device, from PLN 19 net per month for base protection and from PLN 29 for detection and response. Keeping these separate is deliberate: you pay for the devices we actually protect, and our support price can be compared with other providers' offers.

Where would you start in a business with 15 workstations?

With two-factor authentication for email and admin accounts, a review of former employees' accounts and a backup restore test. Those three cost little and close the most common ways in. Endpoint protection and network segmentation come next, not first.

What do you do when an incident happens?

We isolate infected devices from the network, secure what can be secured, assess the scope and start restoring data from backup. At the same time we inform the decision-maker, because some decisions, including notifying the supervisory authority, are yours as the data controller. We don't negotiate with attackers.

Is this enough for GDPR compliance?

It covers the technical side, and only that. Compliance also includes records, data processing agreements, legal bases and procedures, which are the data controller's responsibility, often with a lawyer's help. We say so plainly rather than selling technical safeguards as compliance.

From our projects, without client names.

All case studies

Related

Free · 60 minutes online · no obligation

An IT review, not a sales call.

  1. You talk to an engineerOnline, by video call. Not with a salesperson. We don't install or change anything.
  2. We check 8 areasBackups, access, network, email, server, licences, protection and KSeF readiness.
  3. You get a scorecardThree priorities on one page, emailed after the meeting. Yours to use however you like.

We don't use a contact form. We answer the phone and reply to emails.