IT security for small businesses

    Work safely without it eating your day

    Attackers do not only go after big companies. It usually starts with an e-mail, an old password or a backup that does not work. Together with you we find the weak spots and fix them, in plain language.

    Where it goes wrong

    Five weak spots we keep seeing

    • The same password in several places
    • No two-step verification on e-mail and bookkeeping
    • Backups that have never been restored
    • Laptops and phones that are behind on updates
    • A phishing e-mail that looks just like the real thing

    The good news is that you can fix most of these in an afternoon. We help you do it.

    Home office

    Your office is only as safe as the cheapest gadget on your Wi-Fi

    Picture this: your son downloads a free cheat for his game. It contains malware that collects passwords, and the gaming PC is on the same Wi-Fi as your work laptop and the NAS with your books. Or the cheap camera by the front door hasn't had an update in years. At home there's no IT department to say: let's put that somewhere else.

    • A guest network for visitors and smart devices
    • A network of its own (a VLAN) for your work and your NAS
    • A router with updates and a strong admin password
    • Working remotely through a VPN, without open ports

    Before and after

    One big network, or four small ones

    This is what a home office usually looks like, and this is how we set it up.

    Now Everything on one Wi-Fi: one infected device can reach all the others.

    Your router

    • Your work laptop
    • NAS with your backups
    • Printer and scanner
    • Your business phone
    • The kids' tablet
    • Your son's gaming PC
    • Your partner's laptop
    • A visitor's phone
    • Smart doorbell
    • Smart TV
    • Smart thermostat
    Better Separate networks: everyone has the internet, but work stays out of reach.

    Your router

    • Work

      • Your work laptop
      • NAS with your backups
      • Printer and scanner
      • Your business phone
    • Family

      • The kids' tablet
      • Your son's gaming PC
      • Your partner's laptop
    • Guests

      • A visitor's phone
    • Smart devices

      • Smart doorbell
      • Smart TV
      • Smart thermostat

    What we do for you

    Peace of mind, step by step

    Security check

    We go through your devices, accounts, Wi-Fi, backups and website. You get a short list of what needs doing now and what can wait.

    Phishing training

    A practical session with real examples, so your team recognises that one wrong link.

    Accounts and passwords

    A password manager, two-step verification or passkeys. We set it up properly together.

    Backups that work

    Following the 3-2-1 rule, encrypted, and we test that restoring really works.

    Safe remote working

    A VPN or a secure tunnel to your own server, without opening ports on your router.

    Website and server

    Updates, security headers, backups and a check for known vulnerabilities.

    Approach

    Check, fix, train, repeat

    1. Check - Together we look at where things stand. No finger-pointing.
    2. Plan - A short list, in order of importance. You decide what we do.
    3. Fix - We fix it, or we do it together so you learn how.
    4. Train - Your team knows what to look out for. The best firewall sits between your ears.
    5. Repeat - After a while we look again, because attackers do not stand still either.

    It really happened

    How it went wrong for others

    Real cases in brief, with the link to the full story. Want to read and practise more? Head to Stay safe.

    • 2026

      A fake IT colleague calls customer service

      Customer service staff at a large Dutch telecoms provider, and millions of customers

      Cost: Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.

      What happened

    • 2017

      The backup was on the same server

      A small Dutch bookkeeping office

      Cost: Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.

      What happened

    • 2022

      A media server on a home PC opened the company vault

      A senior engineer at a company that makes a password manager

      Cost: A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.

      What happened

    Questions

    Common questions about security

    There are only two of us. Is this for us?

    All the more so. Small businesses have no IT department watching over them, and a check takes little of your time.

    Do we need to buy lots of things?

    Usually not. The gains are mostly in settings and habits, not in new equipment.

    Can we simply book an hour of help?

    Yes. In the shop you can book network and security by the hour. After your order we contact you to arrange a time.

    Do we get a thick report?

    No. You get a short, clear list of what needs to happen and why.

    Something has already gone wrong. Can you help?

    Yes. Send us a message as soon as you can: we normally reply within one working day and then look straight away at what is needed. In the meantime, first aid after a hack helps.

    Press play

    Curious how safe you are now?

    Book a security check, or take the ten-question self-test in the Lab first.

    Real story - 2026

    A fake IT colleague calls customer service

    Customer service staff at a large Dutch telecoms provider, and millions of customers

    What happened
    In early February 2026 a man speaking good Dutch phoned customer service. He posed as a colleague from the IT department: a problem needed fixing, and for that the employee had to log in to an internal system. On a fake login page the employee entered a username, a password and a verification code. The data of millions of customers was then downloaded in a short time. Later, fraudsters called customers about 'compensation' for the breach and asked them for a text code.
    Why it worked
    A colleague from IT, a problem that needs fixing now, and English IT jargon sprinkled through the Dutch. The extra security step was bypassed because the employee handed over the code. According to NOS, access was also set up too broadly and no alarm went off during the large download. The company only learned of the theft when the criminals got in touch themselves.
    What it cost
    Data from 6.2 million customer accounts, including IBANs and ID document numbers. The company refused to pay a ransom and the data was published.
    What would have stopped it
    Real IT never asks you to log in through a link they give you on the phone, and never asks for your code. Hang up and call the service desk back on the internal number. As a customer: your provider doesn't call about compensation, and you never pass on a text code.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2017

    The backup was on the same server

    A small Dutch bookkeeping office

    What happened
    On 12 February 2017 hackers got into the network and encrypted every file on the server, including the backup files. They got in through a remote-working connection that was open to the internet, combined with a weak password. The office paid the ransom and got its files back. A court case with the IT supplier followed.
    Why it worked
    The only backup lived on the same machine as the data, so the ransomware simply took it too. A second disk to take home now and then had been suggested back in 2010. And at the office's request, the passwords had been made simpler.
    What it cost
    Three bitcoin in ransom (2,890.83 euros), one week without any work and another with hardly any. The total claim was over 42,000 euros; the court split the blame.
    What would have stopped it
    A backup on the same machine isn't a backup. Use two disks in rotation, one of them always unplugged and off site. And never leave remote access open to the internet without two-step verification.

    The full story (opens the original source):

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.

    Real story - 2022

    A media server on a home PC opened the company vault

    A senior engineer at a company that makes a password manager

    What happened
    The engineer's personal computer at home ran a media server for films and series, for private use. The security update for a known flaw had been available since May 2020 but was never installed. Through that flaw an attacker put a keylogger on the computer. It captured the master password when the engineer logged in to the company vault, which let the attacker copy a backup containing customer data.
    Why it worked
    A hobby server on the same PC as the work, about 75 versions behind. The personal and work vaults were linked with the same master password.
    What it cost
    A backup of all customer vault data was copied. The UK privacy regulator imposed a fine of 1.2 million pounds.
    What would have stopped it
    Work on a work device. Hobby servers, gaming PCs and smart devices belong on a separate network, not on the computer you work on. Update everything that can be reached from the internet, and keep work and personal passwords apart.

    Summary by 3D-eVo in our own words, checked against the sources on 3 October 2026. The source is in charge of its own story.