What is IT security in the mid-market, really? Rarely what conference slides show. The attacks that hit mid-sized companies are unspectacular: a phishing mail, a laptop without updates, a VPN access never revoked, a backup that does not come back when it matters. No silver bullet helps against that — operations do: every day, on every device, with evidence.
Our answer has two layers. The operations disciplines sit inside operations itself: patch management, monitoring, inventory and access documentation come with every tier — they are not security products, they are clean work. The protection blocks are added individually: endpoint protection per device, backup per system, zero-trust access per user. We recommend them to practically every customer — but you see what each block costs, and you decide.
Layer 1: What sits inside operations
- Patch management as a security measure — most successful attacks use gaps that had fixes long ago. We close them in fixed cycles, on workplaces, servers and network devices including the firewall. The monthly report is your evidence.
- Access order and user administration — who may reach what from where, defined once and provable at any time; leavers’ access closes the same day.
Layer 2: The protection blocks — each its own guard
Three guards, three attack paths — plus the last line of defence. Each block has its own page explaining what it does, why the old way falls short, and who needs it:
| Block | Guards | Typical attack against it | Billing |
|---|---|---|---|
| Endpoint protection (EDR) | Your devices | Malware, ransomware, abused tools | per device |
| Identity protection (ITDR) | Your user accounts | Account takeover, payment fraud via mail | per account |
| Managed SIEM | The full picture across all logs | Patterns across systems; a duty under NIS-2/audits | per data source |
| Backup with restore tests | Your data — the last line | When something gets through anyway | per system |
| Zero-trust access | The way into the company network | Abused VPN access | per user |
Behind endpoint protection, identity protection and SIEM sits the same 24/7 analyst team — the blocks interlock, but you buy them individually. Our recommended sequence for most environments: endpoint protection and backup first, then identity protection, SIEM when regulation or size demand it.
Evidence instead of assurances
Insurers, auditors and NIS-2 do not ask whether you feel safe; they ask for proof. Our operations produce it as a by-product: patch reports, restore logs, access documentation, inventory.
What we are not
We are not a security operations centre and no substitute for specialised incident response in a major-loss scenario — and we do not claim to be. What we deliver is the layer of protection where most real attacks on the mid-market fail, plus the evidence you need. Where more is required, we say so openly and help you choose.
FAQ
Can we buy the protection blocks without operations? As a permanent arrangement, no. Endpoint protection nobody monitors and a backup nobody tests are snapshots — the value comes from the operations behind them. And the reverse holds: operations without protection blocks is possible, but the offer will state clearly which gap you are leaving open.
Why is endpoint protection not simply included in the price? Because with us you should see what you pay for. One block per device, one line on the invoice — and the freedom to keep an equivalent existing protection instead of paying twice.
Is this enough for NIS-2? Our operations deliver a large share of the technical measures and evidence NIS-2 demands. The organisational duties remain with you; in tier Complete we accompany you quarterly.
What if something gets through anyway? Then what was built beforehand counts: the incident gets detected instead of noticed weeks later, affected devices get isolated, and the tested backup turns a catastrophe into a recovery of known duration.