Neoxis IT
Home Blog About Us Contact
RO EN FR
Contact Us
🔍
A security audit is a full assessment of the company's security posture: vulnerability scanning (network, servers, applications), review of access policies, firewall configuration analysis, verification of backup and disaster recovery, assessment of staff awareness (simulated phishing tests), and a GDPR and NIS2 compliance review. The result: a detailed report with prioritised risks and a remediation plan.
A multi-layered strategy: Prevention: 3-2-1 backup with an offline copy, enterprise antivirus with AI, advanced email filtering, rigorous patch management. Protection: network segmentation, principle of least privilege, MFA on every critical account. Detection: monitoring of suspicious behaviour, automatic alerting. Recovery: a tested disaster recovery plan, immutable backups.
GDPR (the General Data Protection Regulation) requires any company that processes the personal data of EU citizens to follow strict rules: explicit consent, the right to erasure, breach notification within 72 hours, and a mandatory DPO in certain cases. Non-compliance can lead to fines of up to 4% of annual turnover. Neoxis provides GDPR advice and implementation.
An incident response plan includes: identification (how we detect incidents), containment (how we limit the impact), eradication (how we remove the threat), recovery (how we restore services), lessons learned (how we prevent a recurrence). It also includes an escalation matrix, emergency contacts and communication templates.
Modern endpoint protection includes: next-generation antivirus with behaviour-based detection (not just signatures), EDR (Endpoint Detection & Response) for advanced threats, device management (security policies, disk encryption, application control), web filtering (blocking malicious sites). All of it managed centrally with real-time alerting.
NIS2 (Network and Information Security Directive 2) is the EU directive that broadens cybersecurity requirements. It applies to companies in essential sectors (energy, healthcare, transport, banking) and important sectors (manufacturing, food, digital). The requirements: risk assessment, security measures, incident reporting within 24 hours, supply chain security. Neoxis helps with NIS2 assessment and implementation.
The best practices we apply: WPA3 or WPA2-Enterprise with RADIUS authentication, segmentation (a separate network for guests and IoT), separate SSIDs (staff versus visitors), rogue AP detection, a captive portal for guests with terms of use, and full activity logging. We recommend enterprise-grade equipment (Ubiquiti, Cisco Meraki, Fortinet).
MFA (Multi-Factor Authentication) adds a further layer of security on top of the password: an authenticator app (Microsoft Authenticator, Google Authenticator), SMS, or a hardware key (YubiKey). It stops 99.9% of attacks based on compromised credentials. It is mandatory for: email, VPN, remote access, administration panels and privileged accounts.
A combination of technology and training: Technology: advanced email filtering (anti-spam, AI-based anti-phishing), sandboxing for attachments, URL rewriting. Training: regular awareness sessions, phishing simulations (we send test emails and measure who clicks), clear policies for reporting suspicious emails. Incidents typically drop by 70-90% after six months of the programme.
A pentest (penetration test) simulates a real cyberattack in order to find vulnerabilities. The types: external (from the internet), internal (from the company network), web (web applications), social (phishing, physical access). Recommended frequency: once a year, or after major infrastructure changes. The cost depends on the type of test and the size of the perimeter being tested — we prepare a tailored quote once we have defined the objective and what exactly goes into the test.
Securing remote access: VPN (IPSec or SSL) with MFA authentication, Zero Trust (continuous verification of identity and device), secured RDP (never exposed directly to the internet), device compliance (checks for up-to-date antivirus and a patched OS), session management (automatic timeout, logging). More about VPN.
We work to: ISO 27001 (information security management), CIS Controls (18 prioritised controls), the NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover), GDPR (personal data protection) and NIS2 (security of networks and information systems). We apply these standards in a way that fits each client's size and industry.

Didn't find your answer?

Contact us and we'll respond as soon as possible.

Contact Us