Skip to content
Stop Ransomware

The platform

Every layer, one platform — and the proof at the end of it.

Compliance is not demonstrated with products. It is demonstrated with evidence: policies that were actually applied, incidents with a timeline, coverage you can put a number on. This platform is chosen so that evidence is a by-product of running it — not a project you start the month the auditor calls.

Before the project

Where the technical measures usually fall apart.

Fragmented visibility

Endpoint, email, mobile and firewall report into separate consoles. Nobody correlates them, so nobody sees the attack as one story.

Email is still the way in

The native filter stops bulk spam, not targeted phishing or weaponised attachments aimed at your finance team.

Mobile is a blind spot

Phones reach mail, documents and business apps, and in most assessments they are the one layer with no monitoring at all.

Patching by goodwill

No vulnerability inventory and no remediation deadline means the maintenance measure has no evidence behind it.

Response is entirely manual

Isolating a machine depends on someone being available. A 24-hour reporting deadline becomes theoretical.

Nothing to show an auditor

The measures exist in a procedure, but cannot be demonstrated with reports, timelines or logs.

Each of those reads, in an auditor's wording, as a finding against a specific NIS2 measure. They are not operational inconveniences — they are the gaps that get written down.

The architecture

Every layer feeds one platform.

Prevention

Endpoint Behavioural anti-ransomware with rollback of encrypted files, attachment detonation, anti-exploit and credential protection — plus full attack-chain reconstruction per incident.
Email & collaboration Anti-phishing on content, context and communication relationships; attachments and links detonated before delivery, not after; retroactive removal of messages already delivered.
Mobile Application, network and device-level protection on Android and iOS, alongside your MDM — the layer most assessments find completely uncovered.
Browser & data Inspection inside the browser including HTTPS, phishing blocked at the moment of access, and control over what leaves for unauthorised web services.
Vulnerabilities Continuous scanning of operating systems and third-party applications, prioritised by real exploitability, with automated patching inside maintenance windows.

Correlation

One investigation surface Telemetry from every layer normalised into a single timeline, with related events grouped into one case instead of dozens of separate alerts.
Your existing perimeter, kept We do not replace the firewall you already run. Its logs are ingested, so an indicator seen at the perimeter immediately becomes a search across every endpoint.
Retrospective hunting Search history for an indicator you only learned about today — the question every incident eventually asks.

Response & evidence

Automated playbooks A detection becomes an applied action across every layer in seconds: machine isolated, account blocked, the indicator pushed to firewall and email.
Every step recorded Each action is logged with a timestamp, which is what turns a written response procedure into something you can actually demonstrate.
The compliance file Reports, dashboards and exportable timelines — the evidence an auditor and a national authority ask for.

One console

The 24-hour deadline is a reporting problem before it is a security problem.

An early warning has to say something concrete: which system, what impact, which vector, what you did about it. Gathered by hand from four separate consoles, that takes days. With one correlated timeline, the first notification is an export rather than an investigation.

What the 24-hour and 72-hour deadlines actually require →

Live threat-hunting console across correlated events.

Requirement → component → evidence

What each measure actually gets you, on paper.

Letters refer to the risk-management measures in Article 21(2) of Directive (EU) 2022/2555. National transpositions number the same ten measures differently — in Romania they appear as Article 13 of OUG 155/2024.

Measure What covers it What the auditor is handed
(a) Risk analysis and information system security policies XDR/XPR, vulnerability and patch management, external risk monitoring Exposure and risk report, updated periodically, with the history of how it changed
(b) Incident handling XDR/XPR, automated response playbooks, endpoint forensics Complete incident timeline and forensic report, in the shape the authority asks for
(d) Supply chain security Dark-web monitoring and external attack-surface management External exposure report, including leaked credentials and brand impersonation
(e) Security in acquisition, development and maintenance, including vulnerability handling Vulnerability and patch management Vulnerability inventory, remediation deadlines, patch-compliance report per system
(f) Policies to assess the effectiveness of the measures Platform dashboards and periodic reporting A monthly indicator set: threats blocked, mean time to respond, agent coverage
(g) Basic cyber hygiene practices and training Email and collaboration security, browser controls, mobile protection User-behaviour statistics: blocked clicks, attempted access to malicious sites
(i) Human resources security, access control and asset management Endpoint and mobile protection, browser data controls, account remediation Asset inventory with security posture, data-control reports, record of blocked accounts

What this platform does not cover

Cryptography (h), business continuity, backup and crisis management (c), and multi-factor authentication and secured communications (j) are separate chapters of a compliance programme. This platform supports them but does not cover them in full, and we would rather say so than let you find the gap during an audit — see Governance & Compliance and Consulting.

The central argument

The same features, bought four times, behave differently on the day it matters.

Four vendors

  • Four consoles, four alerting models, four support contracts
  • Correlating across layers stays a human job
  • Response is applied by hand, layer by layer
  • Audit evidence is assembled from separate exports, in different formats
  • Every new integration is a project of its own

One platform

  • One console, one policy model, one vendor accountable
  • Endpoint, email, mobile and your existing perimeter correlated automatically
  • An indicator blocked once propagates to every layer
  • A single reporting set, mapped to the NIS2 measures
  • Adding a module does not require an integration project

We lead with Check Point where it fits, and operate identity, endpoint, email, backup and monitoring tooling alongside it. Already standardised on Microsoft Defender, Fortinet, CrowdStrike or another stack? We integrate with and operate the one you already run — the methodology stays the same. A Check Point partner for over three years.

How it is delivered

Technology plus operation, not licences.

A stack nobody operates produces alerts, not compliance. The question an auditor asks is whether someone looked at them, and what they did next.

  1. 01

    Implementation

    Design, installation, policy tuning and cutting the false positives out of the first weeks.

  2. 02

    Continuous operation

    Monitoring, alert triage and policy updates as the infrastructure changes.

  3. 03

    Incident response

    Escalation, isolation, investigation, and help drafting the notification to the authority.

  4. 04

    Compliance reporting

    A periodic set of reports and dashboards, prepared for the security audit.

This is delivered as Threat Prevention & Response. Our role is the managed security service; the legal responsibility stays with your organisation — we deliver the implementation, the operation and the evidence.

Start with what your environment actually needs.

The free Security Checkup measures your current posture against these measures and gives you the gap list in writing.

No obligation. No sales pressure. Just facts about your environment.