NIS2 checkContact

SmartCyber

SmartCyber: your security in five levels

SmartCyber is the service that carries the ten NIS2 areas in practice. The controls underneath every level are the same stack, sized by headcount band, and growing into the next level extends the setup instead of replacing it.

One product

One platform, five levels

NIS2 does not require new technology. It requires measures, and the measures are services that already exist and already run. That is why moving between levels is a configuration change rather than a migration.

10 / 10Article 21(2) areas covered from one platform, by one team, on one contract.

Every step builds on the last

Moving from Protect to Advanced adds the SOC, the SIEM and the response time. Your endpoint agent is not replaced and your policies are not set up again.

The price follows what you have

Device, server and user counts. The cost therefore tracks the organisation rather than a licence tier you outgrew long ago or will not reach for years.

Evidence is a by-product

The reporting a regulator, an insurer or a tender asks for comes out of running the service, not out of a project just before an audit.

One accountable party

One contract, one SLA, one point of contact. The space between two contracts belongs to nobody, which is why we keep it to one.

The levels

Five levels, matched to your size and your obligation

The size bands are a starting point, not a rule. A 60-person energy supplier carries more obligation than a 400-person wholesaler, and the intake call is where that gets resolved.

Level 1

Essential

Baseline protection for small organisations: endpoints, mail and backups in managed hands.

20 to 49 employees

  • Endpoint protection and managed patching
  • Email security
  • Backup and recovery
  • Baseline risk assessment
  • SOC available as an add-on
Talk about this level
Level 2

Protect

Adds monitoring during office hours, so problems surface before your customers see them.

50 to 99 employees

  • The Essential base, carried over
  • Managed EDR
  • Network security
  • Identity protection
  • Business-hours SOC with monthly reporting
Talk about this level
Level 4

Resilience

Built around continuity, with recovery rehearsed and downtime bounded by agreement.

500 to 999 employees

  • The Advanced base, carried over
  • Priority SOC
  • Identity and privileged access management
  • Recovery with failover that gets rehearsed
  • A continuity plan, exercised against real scenarios
  • Supplier risk, assessed and documented
Talk about this level
Level 5

Enterprise

Governance for group structures across several countries, with reporting a board can sign.

1000 employees and above

  • The Resilience base, carried over
  • Co-managed SOC with dedicated analysts
  • Named service lead and custom integrations
  • CISO-as-a-service across entities
  • Group governance spanning countries and business units
  • Reporting fit for audits, tenders and insurers
Talk about this level

Pricing follows device, server and user counts and is confirmed in the intake call. We do not publish a per-device figure, because a figure that needs three caveats to be true does not help you.

Side by side

What changes between the levels

The same table our own team works from. Where a component appears, we operate it. It is not switched on and handed over.

SmartCyber capabilities per level
CapabilityEssentialProtectAdvancedResilienceEnterprise
Endpoint protection and managed patchingIncludedIncludedIncludedIncludedIncluded
Email securityIncludedIncludedIncludedIncludedIncluded
Backup and recoveryIncludedIncludedIncludedIncludedIncluded
Baseline risk assessmentIncludedIncludedIncludedIncludedIncluded
Managed EDRAdd-onIncludedIncludedIncludedIncluded
Network securityNot includedIncludedIncludedIncludedIncluded
Identity protectionNot includedIncludedIncludedIncludedIncluded
Security awareness and phishing simulationNot includedIncludedIncludedIncludedIncluded
SOC coverageAdd-onBusiness hours24/724/7 priority24/7 co-managed
SIEM and XDRNot includedNot includedIncludedIncludedIncluded
Critical alerts answered inside 15 minutes, by SLANot includedNot includedIncludedIncludedIncluded
Vulnerability managementNot includedNot includedIncludedIncludedIncluded
Support with the statutory notificationsNot includedNot includedIncludedIncludedIncluded
Privileged access managementNot includedNot includedNot includedIncludedIncluded
Disaster recovery with tested failoverNot includedNot includedNot includedIncludedIncluded
Continuity plan and crisis exercisesNot includedNot includedNot includedIncludedIncluded
Supply-chain risk assessmentNot includedNot includedNot includedIncludedIncluded
Dedicated analysts and named service leadNot includedNot includedNot includedNot includedIncluded
Group governance spanning countries and business unitsNot includedNot includedNot includedNot includedIncluded
Audit, tender and insurer reportingNot includedNot includedNot includedNot includedIncluded
Reporting cadenceAnnualMonthlyQuarterly reviewQuarterly reviewNamed lead, monthly

Add-ons and the one-time onboarding are quoted separately. Where a component shows "Add-on" it is available at that level but is not included in the base price.

What sits underneath

The measures per level

Every level is built from the same components. Which of them are switched on, and how closely they are watched, is what really decides the level.

Endpoints and email

Managed endpoint protection with a monitored EDR agent, mail filtering and protection against impersonation of directors and suppliers, and patching on a fixed rhythm with exception reporting.

Detection and response

A European SOC watching around the clock, SIEM correlation across endpoint, identity, network and cloud, XDR runbooks, and priority alerts answered inside 15 minutes.

Identity and access

Multi-factor authentication and conditional access, a joiner, mover and leaver process that actually runs, privileged access management, management of accounts with elevated rights, and periodic review against least privilege, meaning no more rights than someone needs.

Continuity

Immutable backup, a backup that cannot be altered or deleted, restores tested rather than assumed, an agreed RTO and RPO, and failover exercised so the first real test is not the first attempt.

Exposure

Vulnerability management with agreed remediation windows, hardened baselines, and penetration testing that is scheduled rather than arranged after the fact.

Evidence

An overview of the state of the measures, per-person training records, incident timelines, and quarterly reporting written for a board rather than for an engineer.

How to choose

Your obligation matters more than your headcount

Two organisations of the same size can sit two levels apart. These are the questions that really move the answer.

Signs the size band is enough
  • One country, one entity, one regulator
  • Not in an Annex I sector, and no customer is asking for evidence yet
  • Downtime is inconvenient rather than existential
  • No personal data beyond employees and normal commercial contacts

Start at the level your headcount suggests and move up as soon as something changes.

Signs you need a level higher
  • You are in an Annex I sector, whatever your headcount
  • A tender or a large customer has already sent you a security questionnaire
  • An hour of downtime has a number attached to it that people can quote
  • You operate in more than one member state, so more than one regulator
  • Your insurer has started asking specific questions at renewal

Any one of these is usually enough. With two of them the level underneath will not hold.

Something is already happening

If something is happening right now, start there

Choosing a package can wait. Containment cannot, and for organisations covered by the Cyberbeveiligingswet the 24-hour deadline is already running.

Which level fits, and what would it cost?

The intake call answers both. You speak with our CISO directly and get a straight answer, including the components you do not need yet.

Cyber Incident