For small businesses and professional practices

Security and compliance, sized for small businesses.

We help you protect your systems and get in line with GDPR, NIS2 and the Cyber Resilience Act, without big-firm consulting and with a clear path.

A path in clear phasesWritten proposal before we startOnline payment upfront
What we do

Four areas, one path

We start with an assessment and step in only where needed.

Cybersecurity

Protecting systems and data

We secure workstations, network, email and accounts, lowering the likelihood of attacks and downtime.

  • Review of updates, antivirus and configurations
  • Secure access: passwords, two-factor authentication, permissions
  • Tested backups and a recovery plan
  • Basic training against phishing and scams
Learn more

GDPR

Personal data protection

We support the technical and organisational side of protecting the data of customers, employees and suppliers.

  • Mapping of processing activities and records
  • Technical and organisational security measures
  • Procedures for data subject requests and data breaches
  • Coordination with your legal adviser or DPO, if you have one
Learn more

NIS2

NIS2 Directive · Italian Legislative Decree 138/2024

NIS2 mainly concerns medium and large organisations in specific sectors, but it also reaches their suppliers. We check with you whether and how it applies.

  • Scope check: are you in scope or a supplier to a company in scope?
  • Gap analysis against the required security measures
  • Management of risks, suppliers and incidents
  • Procedures and documents to answer customers in scope
Learn more

Cyber Resilience Act

CRA · EU Regulation 2024/2847

It concerns anyone who makes, imports or distributes products with digital elements (software, connected devices). Reporting duties for vulnerabilities and incidents apply from 11 September 2026; full application from 11 December 2027.

  • Check whether your product falls under the regulation
  • Security requirements from the design stage
  • Vulnerability and update management
  • Technical documentation and readiness for reporting
Learn more

We are technical consultants: we do not issue certifications and we do not replace a lawyer or a DPO. For legal matters we work alongside the professional you trust.

Does it apply to me?

Four questions to know where to start

A quick orientation, not legal advice.

Do you have at least 50 employees, or turnover or a balance sheet total above 10 million euro?
Do you work in sectors such as energy, transport, health, water, digital infrastructure, ICT services, manufacturing or food and chemicals production?
Are you a supplier to companies in these sectors?
Do you make or sell software or devices with digital components?
Where to start

Initial assessment

A defined first step, at a fixed price, to understand where you stand and what is really needed.

Initial assessment

from €290one-off, remote
  • About 60 minutes talking through your business
  • Review of workstations, network, email, backups and suppliers
  • Check of what applies to you among GDPR, NIS2 and CRA
  • Written report with priorities, timing and indicative costs
How we work

From assessment to upkeep

  1. 01

    Initial assessment

    Interview and analysis: systems, data, suppliers and the obligations that apply to you.

  2. 02

    Action plan

    A document with priorities, timing and costs. You decide what to do and when.

  3. 03

    Work and documents

    We put the technical measures in place and prepare procedures and records.

  4. 04

    Upkeep

    Periodic checks and updates as rules and systems change.

Request an assessment

Tell us about your business

Tell us your sector, number of workstations and what worries you. We reply with a written proposal, with price and timing, before any work begins.

Prefer to write to us directly?

Frequently asked questions

Does NIS2 apply to my small business?

It depends. In general the directive applies to medium and large organisations in the listed sectors (energy, transport, health, digital infrastructure, manufacturing and others), with some exceptions. Even if you are not in scope, you may supply a company that is, and receive security requirements from them. We check this together in the initial assessment.

Do you issue certifications or compliance statements?

No. We help you understand what is needed, put the technical measures in place and prepare the documentation. Certifications and legal opinions are for accredited bodies and professionals.

Does the Cyber Resilience Act apply if I don't make hardware?

The regulation covers products with digital elements, so it includes software that is sold or distributed, not only hardware. It does not cover simply using software and devices you bought. We check your case.

How much does it cost and how do I pay?

After a first conversation we send a written proposal with price and timing. We start once payment is made online, before any work begins.

Do you work remotely?

Yes, most of the work is done remotely, with you connected when we work on your systems.

Which program do you need to connect to our systems?

Before the session we tell you which connection tool to use. You start and end the session, and we stay connected only for as long as needed.