We close the most common entry points in your business: calmly, traceably, without jargon and without fear selling. From someone who learned security at enterprise level.
Baseline protection is not a major project and no reason to panic. It is three stations we walk together, understandable and at your pace. They apply to every business, whether with a shop floor, an office or a workshop, and equally to pure online trade: the entry points are the same.
No blame, simply reality in most small businesses: accounts and access grew over the years and nobody had time to clean up. That is exactly where the most common entry pointsare, not in Hollywood hacking scenes.
We look at them together, in your language: what is open, what matters, what can wait.
The same three lines, only closed: two-factor sign-in for your most important accounts, secured email, so your messages actually reach the inbox and are far harder to spoof in your name, and a properly configured Office 365.
You do not get a checklist, you understand at every step what it does and why it comes first.
Technology is half the job, the other half is the people on the phone and in the office. A short training in plain language makes sure security lands in everyday work instead of disappearing into a binder. We also tell you in plain language which handful of measures actually matter for a business your size (the basics, done right): as orientation, not as a checklist.
The most important settings are set correctly once, the day-to-day administration of your IT stays with you: we are deliberately not a replacement for a managed IT provider. We do not audit, we do not certify and we do not guarantee completeness. What we do promise: the most common entry points are closed, and you understand your own protection.
The path does not end at a list, it ends at a business that understands its own protection.
Baseline protection for a small business does not need enterprise tools, it needs someone who knows both worlds: security and an owner’s working day.
Knows from over ten years of running businesses himself that there is no time for IT projects between the day-to-day work and the end of the day. So we translate every measure into plain language and into steps that work alongside the daily business.
Comes from enterprise-level IT security and therefore knows which handful of measures really count in a small business. Solid baseline protection instead of security theater, explained without jargon.
Deliberately labeled as examples: they show the approach, not a specific client.
A store with grown-over IT: shared passwords, one email account for everything, Office 365 exactly as it shipped. We clean up together, in a clear order: first the accounts, then the email, then Office 365. In the end the owner understands his own protection for the first time.
A team that works with orders, supplier emails and customer data every day should recognize the typical tricks without having to cram jargon. The awareness training meets everyone at the register, not in the server room. Security becomes an everyday routine instead of a special topic.
Number of accounts, email setup, team size: that determines the scope. Which is why the flat rate comes after the intro call, up front and binding, instead of a number pulled out of thin air.
We look at your business together and say openly what is worth doing and what can wait.
Optional, for anyone who wants to know precisely: a prioritized analysis of where things get stuck and in which order they are worth fixing. Credited when you hire us.
MFA, secured email, hardened Office 365 and team training, scaled to your business.
For small businesses baseline protection comes first: secure sign-in with two factors (MFA), protected email (SPF, DKIM, DMARC), a properly configured Office 365 and understandable training for the team. That is exactly what we set up. We do not certify or attest, we close the gaps that are actually exploited.
The scope depends on your business: number of accounts, email setup, Office 365 environment, team size. That is why we name the flat rate after a free intro call, up front and binding. Anyone who wants more detail starts with the Deep-Dive Check for $430, which is credited when you hire us.
No, and we say so openly: an audit or a certificate is explicitly not part of what we deliver. We close the most common entry points, explain every step and tell you honestly where our limits are. If you need a formal attestation, you need a specialized auditor, and we will tell you that instead of selling you something else.
No, and we say that openly on purpose: we set the most important security settings of your Office 365 correctly once, the day-to-day administration stays with you. For the website and the AI assistant we offer long-term support; for your internal IT we are not a replacement for a managed IT provider.
The same way we recommend you do. Everything we run for clients, meaning website, contact form, fonts and scripts, sits on servers in Germany, with no tracking and nothing loaded from third-party servers. For the baseline protection itself we work in your accounts, not ours: we set things up properly once and hand them over, and your data stays with you throughout. Security and data protection are the same subject from two sides, so we treat them that way.
A conversation between equals, free and without obligation: we look at your business together and say openly what is worth doing and what can wait. Honest, concrete, no fear selling.
Book an intro call →