Skip to content
Van Oosten Advies B.V.

Managed IT

Security that keeps watch at night too

Small businesses are not smaller targets, just easier ones. A stolen password, a convincing phishing email, an invoice with a different bank account number: most attacks do not start with advanced technology, but with an account that was not properly protected.

Security is in every package, in increasing layers. Essential puts MFA on every account. Complete adds a fixed security baseline and 24/7 monitoring of your Microsoft 365 accounts. Premium also watches the laptops day and night, and trains your staff. The monitoring is done by the Huntress security operations centre: people who watch and step in, even when I am not around.

Why this matters

Insurers, customers and legislation increasingly ask for demonstrable security, from small businesses too.

  • You are not sure whether everyone uses MFA.
  • An employee once clicked a wrong link, and nobody knows what happened next.
  • Your cyber insurer or a large customer asks about your security measures.
  • You work with sensitive data: patients, clients, financial or legal files.
  • You fall under NIS2, or supply an organisation that does.

The layers

Each layer catches what the previous one misses.

  • MFA on every account, so a stolen password on its own is not enough. In every package.
  • A fixed security baseline: conditional access, Defender for Business and secure default settings, monitored for deviations. From Complete upwards.
  • 24/7 monitoring of Microsoft 365 accounts for suspicious sign-ins, forwarding rules and stolen sessions (Huntress ITDR). From Complete upwards.
  • 24/7 laptop monitoring by a security operations centre that isolates an infected laptop immediately (Huntress EDR). In Premium.
  • Security awareness training with short lessons and phishing simulations, so your staff recognise a suspicious email. In Premium.
  • A quarterly security report and an annual IT plan. In Premium.

What you get

Security that is demonstrably switched on, and people who respond when something happens.

  • On a suspicious sign-in or an infected laptop the security operations centre steps in, day and night: blocking the account or isolating the laptop.
  • After an incident a report on what happened and which recovery steps are needed, which I then carry out.
  • An overview of your measures that you can show to an insurer or a customer.
  • Staff who know what to look out for.

What it is not

  • Not a guarantee that nothing will ever happen. Nobody can honestly promise that; what I can promise is that an attack is spotted and contained quickly.
  • Not a certification programme such as ISO 27001. I help you get the technical measures in order, but certification is a separate project.
  • Not a penetration test. For a formal security test I refer you to a specialist firm.
  • Not an extra virus scanner next to Defender. A second scanner makes management more complicated and security no better.

Frequently asked questions

What is a security operations centre?

A team of security analysts who review alerts day and night. Software flags a suspicious sign-in; an analyst judges whether it is real and steps in. For a small business, setting up such a team yourself is unaffordable. Through Huntress it is part of Complete (for accounts) and Premium (for laptops too).

Isn't Defender enough?

Defender for Business, which is part of Business Premium, is a good foundation and is switched on in Complete and Premium as well. But software does not respond to what falls just outside its rules, and at night nobody looks at the alerts. That is what the 24/7 monitoring is for.

Does this help with NIS2?

It covers a large part of the technical measures: MFA, device management, backup, monitoring and training. NIS2 also asks for policy, a risk analysis and reporting procedures; I help with those at the hourly rate. For sectors with stricter requirements there are additional Defender and Purview licences.

What happens if something does go wrong?

The security operations centre isolates the laptop or blocks the account and sends a report with recovery steps. I carry those out, restore files from the backup where needed and keep you informed. In Premium there is also an emergency line outside office hours.

How secure is your business today?

Tell me briefly how your accounts and laptops are secured today, as far as you know. In a first conversation you will hear where the biggest risks are.