Cybersecurity for SMEs

IT security in Cologne – protection that holds when it matters

Firewall, endpoint protection, verified backups and an emergency plan that has actually been tested. We set up IT security so that it does not get in the way day to day and still works in an emergency. We look after the IT security of small and medium-sized businesses in Cologne and the surrounding area – from the firewall and verified backups to the emergency plan. When something happens, we can reach you quickly from our base in Köln-Bilderstöckchen.

Free security check Backup based on the 3-2-1 rule NIS2 preparation Emergency plan included

The situation

Attackers don't go for the big. They go for the reachable.

The most common misconception among SMEs is: “We’re too small to be of interest.” The exact opposite is true. Modern attacks are automated. They scan the internet for open access points, outdated systems and weak passwords – without checking how big the company behind them is. If you are reachable, you will be attacked.

The damage rarely comes from the encryption itself, but from what follows: days without your ERP system, without email, without access to customer data. On top of that come reporting obligations under the GDPR, questions from your cyber insurer and customers who want to know whether their data has been affected.

So we approach it from the other side: not “How do we keep everyone out?” but “What happens if someone does get in – and how quickly can we get back to work?”

Illustration: a shield made up of several security layers – firewall, endpoint protection and permissions – next to a 3-2-1 backup concept.
Protection does not come from a single product but from layers – and from backups that can actually be restored.
  • Layered protection instead of a single firewall that everything depends on
  • Backups that are tested – a backup that has never been restored is not a backup
  • Offline and immutable copies that ransomware cannot encrypt along with everything else
  • Staff awareness training, because most incidents start with an email
  • Documented emergency plan with responsibilities, sequence and contacts
  • Evidence you can show for the GDPR, your cyber insurer and your auditors

Services in detail

Our IT security services

Security is not a product you buy once. We combine technical measures, ongoing monitoring and organisational rules into a concept that fits the size of your business.

Firewall & network security

WatchGuard and Sophos firewalls with intrusion prevention, content filtering and VPN. Network segmentation, so that one infected computer does not take the whole company down with it.

Endpoint protection & EDR

Modern protection on every workstation and server – based not only on signatures but on behaviour. Suspicious encryption activity is stopped before it spreads.

Backup & data protection

A backup concept based on the 3-2-1 rule with Veeam, Acronis or Synology: three copies, two media, one off-site. With regular test restores instead of blind trust.

Disaster Recovery

A recovery plan that has been rehearsed, with defined targets for recovery time and maximum data loss. We know beforehand how long it will take – not only when disaster strikes.

Email security

Spam and phishing filters, attachment scanning, SPF, DKIM and DMARC setup. So that forged senders can no longer send invoices to your customers in your name.

Awareness & access rights

Training for your staff using realistic examples, multi-factor authentication, password management and a permissions concept based on the principle of least privilege.

Ransomware

Ransomware protection: the question is not if, but for how long you are down

A ransomware attack costs small and medium-sized businesses several days of downtime on average. What determines how long is not the technology but the preparation. These six points decide whether you are back at work the next morning or lose a week.

  • A backup the attacker cannot reach. Today's ransomware deliberately looks for backups and encrypts them too. We work with immutable backups and a copy outside the network – reachable for recovery, out of reach for the attack.
  • Multi-factor sign-in wherever there is access from outside. The most common way in is not a hacking attack but a stolen password. With a second factor, it is of no use to the attacker.
  • Separate permissions. Anyone who works with administrator rights day to day hands them to the malware when an attack happens. We separate everyday accounts from admin accounts.
  • Detection, not just defence. Modern attacks move through the network unnoticed for days before they strike. Endpoint detection reports suspicious behaviour before anything is encrypted.
  • A rehearsed emergency plan. Who gets called when, what gets disconnected first, who talks to customers and the authorities. A plan in a binder does not help – it has to have been run through at least once.
  • A recovery that has been timed. “We have backups” is not an answer. The answer is: after how long is each system running again? We work out that figure with you and put it in writing.

NIS2

NIS2: what small and medium-sized businesses can expect

The EU NIS2 Directive considerably widens the range of companies with cybersecurity obligations. Many businesses are not directly covered – but have the requirements passed on to them by their clients. Three questions clarify where you stand.

Are we directly covered?

What counts is sector and size. Covered sectors include energy, transport, health, water, digital infrastructure, IT services, postal services, waste, chemicals, food and manufacturing – in each case from 50 employees or €10 million annual turnover.

  • Check your sector
  • Check headcount and turnover
  • Put the result in writing

Does it affect us through the supply chain?

This is the more common case. Companies that are covered must take their suppliers' security into account and pass the requirements on by contract. If you work for such a client as a supplier, service provider or trades business, you will receive questionnaires and contract clauses.

  • Review client contracts
  • Be ready to answer questionnaires
  • Prepare your evidence

What exactly needs to be done?

Requirements include risk management, incident handling with reporting channels, emergency and backup concepts, supply chain security, access control with multi-factor sign-in, and training. Management is personally liable for implementation.

  • Take stock
  • Prioritise the gaps
  • Build up documentation

To be honest: most of what NIS2 requires is good IT practice – verified backups, multi-factor sign-in, up-to-date systems, controlled access, an emergency plan. If you already do all that, the main task is to document what you do. That, not the technology, is where SMEs most often fall short.

In one conversation, we tell you whether NIS2 applies to you and, if so, which three things to tackle first. No scaremongering, and without turning it into a project you don't need.

How we work

From security check to reliable protection

We don't start by selling technology but with an honest assessment of where you stand.

  1. Security check

    We check the firewall, backups, endpoint protection, permissions, patch level and external attack surface. You receive a clear report with prioritised findings.

  2. Prioritise risks

    Not everything has to be fixed at once. We rank by likelihood and potential damage and tell you plainly what needs doing this week and what can wait until later this year.

  3. Implement

    Set up technical measures, rebuild backups, clean up permissions, write the emergency plan. In agreed time windows, without interrupting your business.

  4. Monitor & rehearse

    Ongoing monitoring, monthly backup tests, regular patch level reviews – and an emergency plan that is rehearsed at least once a year.

Our audit tool

What we audit with: Security Audit Pro

We don't carry out the security check with a checklist in our heads but with our own software. Security Audit Pro reads out the Windows environment – clients and servers, Active Directory, Exchange, updates, Defender, network and backup – and assigns every finding to a risk level, a module, a check and an object. We built the tool ourselves; it is now in its sixteenth version.

The benefit is repeatability. Two audits of the same network reach the same result – even if six months lie between them and a different colleague carries them out. What you get at the end is not a collection of observations but a list sorted by urgency, with technical evidence and a recommendation for each item.

The audit is read-only: nothing is changed, and nothing is installed that stays behind afterwards. See all views of the tool at a glance.

Findings list from Security Audit Pro: a table with columns for risk, module, check, object, finding and recommendation; the rows are sorted by risk level, with the findings rated critical at the top.
This is what the result looks like: every finding with its risk level, affected system and recommendation. All details in the image are sample data.

Why INFONET

Security that suits SMEs

Enterprise solutions fail in SMEs not because of the technology but because nobody is there to run them. We build what you can actually sustain day to day.

  • Appropriate, not maximal. We don't recommend a solution that overwhelms your team or breaks your budget. Security that gets in the way gets bypassed – and is then worthless.
  • Backups that are verified. We regularly carry out test restores. The most common damage is caused not by missing backups but by backups that do not work when they are needed.
  • Preparation for NIS2. Even if you are not directly covered, many clients pass the requirements down the supply chain. We clarify what is relevant to you and make sure you can provide evidence.
  • Clear responsibilities in an emergency. An incident is not the moment to start working out who calls whom. The emergency plan is fixed in advance – on paper too, in case the systems are down.
3-2-1
backup rule as standard
24/7
monitoring of critical systems
100%
of backups tested regularly
30+
years of experience

Free IT security check
In around 60 minutes, we check the key points of your security posture and tell you where your three biggest risks lie. On site or remote, free of charge and without obligation.

Frequently asked questions

Questions about IT security

We have antivirus software and a firewall. Isn't that enough?

Both are necessary, but not sufficient on their own. A conventional virus scanner recognises what is already known; modern attacks deliberately use new or legitimate tools. What also matters: verified backups outside the network, multi-factor authentication, up-to-date systems, a permissions concept and security-aware staff. These are exactly the points we check in the security check.

What is the 3-2-1 backup rule?

Three copies of your data, stored on two different types of media, with one copy off-site. In addition, we use immutable backups that cannot be deleted or encrypted even with stolen admin rights. That is the most effective single protection against ransomware.

Does NIS2 apply to us?

The NIS2 Directive directly covers mainly larger companies in certain sectors. Many smaller businesses are affected indirectly, however, because clients pass the requirements down their supply chain by contract. We look at your specific situation and implement the measures in a way you can demonstrate to clients and auditors.

How quickly can we get back to work after a ransomware attack?

That depends almost entirely on preparation, not on the attack. With verified, immutable backups and a documented sequence, we usually get the core systems back within one working day and the complete environment within a few days. Without that preparation, we are talking about one to two weeks – and about which data is lost for good.

That is why we work out this time with you in advance rather than finding it out in an emergency.

Do we have to implement NIS2 even though we only have 30 employees?

With 30 employees you are, as a rule, not directly covered – the threshold is 50 employees or €10 million annual turnover in one of the sectors listed. It can still affect you indirectly: companies that are covered share responsibility for the security of their supply chain and pass the requirements on to their service providers and suppliers.

So if you work for a hospital, an energy supplier or a larger industrial company, the questionnaires will come. We check this with you in one conversation and put the result in writing – which in itself is an answer you can show your client.

What if we have already been attacked?

Call us. What matters then is the right order: isolate the affected systems rather than restarting them straight away, secure the evidence, contain the damage and only then restore in a controlled way. In parallel, reporting obligations under the GDPR and towards your cyber insurer need to be checked. We guide you through this process and take care of the technical side.

How often should backups be tested?

We check critical systems every month with a test restore, and at least once a year we run through a complete recovery. That is the only way to know your actual recovery time. A backup that has never been restored is an assumption – not protection.

Do you also train our staff?

Yes. The vast majority of successful attacks begin with an email that someone opened. We run practical awareness sessions using real examples from your industry – short, easy to follow and without finger-wagging. On request, we add simulated phishing campaigns to measure the effect.

What does a firewall cost?

With a firewall you pay for two things, and the second is regularly forgotten: the device and the licence for the security features. Without a valid licence, a firewall keeps working but no longer receives new signatures or security updates – it then becomes a risk itself.

The price depends on throughput, number of users and the features you need. A business with fifteen workstations and one line needs a different device from one with two sites and thirty home workers connecting via VPN.

Make sure every quote includes: the device, the licence for the planned term, setup, rule set maintenance and manufacturer support for replacement if the device fails.

What does ransomware protection actually mean?

Not a single product but a chain. Antivirus alone is not enough, because modern ransomware attacks don't arrive as a known file but through stolen credentials and vulnerabilities that nobody knows about yet.

What actually protects you: separate permissions, so that a compromised account cannot work its way through the entire organisation. Two-factor sign-in. Prompt updates. Detection of unusual behaviour rather than just known malware. And a backup that cannot be deleted from the affected system.

That last point decides the outcome of an emergency. Everything before it reduces the likelihood – the immutable backup determines whether you are back at work in two days or in two weeks.

What does a security incident cost?

The ransom is rarely the biggest item. More expensive are the downtime, the recovery, the reporting obligations towards authorities and customers, legal support and the loss of trust among clients.

Work out what a day without working IT costs your business – wages, lost orders, contractual penalties. That figure is the honest yardstick for what prevention may be worth.

Related services

Clients

Who trusts us

Whether for a one-off assignment or a long-standing partnership: when precision and reliability matter in IT, well-known names from retail, aviation, industry, medical technology, logistics and the events sector rely on our expertise. A selection from our client list:

  • REWE

  • Lufthansa Systems

  • RTL

  • Circus Roncalli

  • Fluke

  • Tektronix

  • Ewals Cargo Care

  • emeis Fachklinik Bensberg

  • pfm medical

  • Guett-Dern

  • Hans Jungblut

  • Intercom

  • Von Borries & Partner

  • TUNA FOOD

  • Morawitzky

Free initial consultation

Do you know how long you could keep working without IT?

Most companies only find out when disaster strikes. We find out beforehand – in a free security check.

+49 221 984300-0Switchboard and support hotline

[email protected]Reply within 4 hours on working days

Robert-Perthel-Straße 7250739 Köln – Bilderstöckchen

Mon–Fri 9 am–6 pmEmergency support outside these hours by arrangement