Technical protection

Tools are chosen from your risk assessment, not from the top of a price list. Excess security frustrates colleagues and never earns its keep.

Security solution deployment

We pick products that suit your size, trial them in a pilot and finish the configuration remotely, so they protect you rather than merely appear on an invoice.

Infrastructure protection

Firewall rules, a network split into zones, secure remote access and central collection of logs from servers and network devices.

Application security

Reviews of code and third-party libraries, role-based permissions and hardened integrations before a new release reaches production.

Data loss prevention

Labelling of sensitive data, disk encryption and Microsoft Purview rules that stop CPR numbers and customer lists from leaving the organisation.

Database security

Permissions set inside the database itself, a record of who reads what, and masking of personal data in test and development copies.

Web application firewall (WAF)

A filter in front of your shop and customer portal that turns away SQL injection, password-guessing runs and bots scraping your prices.

Access control and endpoint protection

MFA on every account, conditional access in Entra ID, device management through Intune and privileges trimmed to what each person really needs.

VPN and encryption

Encrypted tunnels between sites and for people working from home, plus encryption of laptops and of emails carrying sensitive content.

Vulnerability scanning

Scheduled scans of servers, networks and websites for published weaknesses, with a clear ranking of what gets patched today and what can wait for the next maintenance window.

The order that works

Tackling everything at once is costly and rarely pays off. This sequence does.

01

Asset overview

Which systems and data you hold, where they sit and who can reach them. That settles which rules apply and what deserves the strongest protection.

02

Risk assessment

We record the threats that are realistic for your business. The document saves you from needless purchases and is itself a NIS2 requirement.

03

Baseline and policies

Policies, MFA, patching, EDR and backup. Together they answer most questions from customers and regulators and block the everyday attacks.

04

Advanced tools and SOC

We roll out whatever the risk assessment calls for and switch on event monitoring, so no intrusion slips by unseen.

A fine from Datatilsynet is seldom the worst outcome. A leaked customer database hurts your reputation far more than any reprimand, and ransomware paired with a backup that fails can bring a company to a standstill for weeks.

Frequently asked questions

Directly in scope are, broadly, medium and large organisations in the sectors the law lists, such as energy, transport, healthcare, manufacturing and digital services. Many smaller firms are drawn in indirectly because their customers must impose requirements on suppliers. We help you establish your position and anticipate what customers will ask.

Yes. Headcount is irrelevant once you process information about staff or customers. A small firm has fewer systems to review, yet the duties are identical, including reporting a breach to Datatilsynet within 72 hours.

It may be enough to answer a questionnaire, but it guards you against a reprimand rather than against losing data. We always separate what satisfies a requirement from what genuinely lowers risk, and leave the decision with you.

A SOC is a team of analysts who follow events constantly and step in when activity looks suspicious. For a smaller firm, EDR with a central console and well-chosen alerts is often sufficient. Continuous monitoring pays off when an hour offline is expensive or when NIS2 demands a fast response.

Documentation for a typical business is finished three to four weeks after the review. Technical measures depend on your environment and usually take one to three months. Everything runs remotely, so there is no need to clear diaries for meetings on site.

See how far you are from NIS2 and GDPR

Tell us which data you handle and what is already in place. We review your environment remotely and show the gap between where you are and where you need to be.

Coverage
All of Denmark, delivered remotely

This site uses only essential cookies: they keep pages working and store your chosen town. Read more in our privacy policy.