IT protection & hardening Cyber attack protection: secure your IT before you pay the price

We secure your information system against the main cyberattack scenarios by combining technical protections, access management, monitoring, team awareness, incident response procedures and recovery measures. The goal: reduce your exposure, detect abnormal behaviour faster and limit the impact of an incident.

This matters because a serious cyber strategy is not only about preventing an attack. NIST CSF 2.0 structures risk management around six functions: Govern, Identify, Protect, Detect, Respond and Recover.

Technical + organisational approach
Solutions deployed in 4 to 8 weeks
Team awareness included

What you get

After protection deployment

360° hardening — technical, organisational and human — with a prioritised roadmap and procedures ready to respond to any incident.

6 pillars of hardening
30/60/90 prioritised roadmap
360° technical + human + organisation

€27,000: average cost of a cyberattack for a French SME (CESIN 2024)

How do you protect a business from cyberattacks?

Effective protection relies on several complementary layers. No firewall, antivirus or isolated tool is enough on its own: you need to know your assets, restrict access, keep systems up to date, detect suspicious events, know how to respond and have a recovery capability.

ANSSI presents its IT hygiene measures as a minimum security baseline, covering access, updates, backups, networks and awareness.

Know your exposure

Assets, users, software, accessible services.

Protect access

MFA, privileges, administrator accounts.

Protect equipment

Workstations, servers, applications, networks.

Detect

Logs, alerts, monitoring.

Respond

Procedures and responsibilities in case of incident.

Recover

Backups, DRP and continuity.

Solutions deployed in 4 to 8 weeks Technical + human + organisational approach 24/7 incident response (optional)

+100 businesses protected

MFA / EDR / Backup technical baseline

4.9/5 client satisfaction

The 6 pillars of your cyber attack protection

Six operational pillars, deployed together: reduce exposure, secure identities, protect systems, detect, respond and recover.

Attack surface reduction

  • exposed services
  • obsolete systems
  • misconfigurations
  • unnecessary access
  • dormant accounts
  • priority patches

See the cybersecurity audit.

Identity & access security

  • MFA
  • administrator accounts
  • least privilege principle
  • joiner / leaver management
  • access rights review

ANSSI issues specific recommendations on multifactor authentication and passwords; CISA also strongly recommends MFA, particularly against ransomware scenarios.

Workstation, server & network protection

  • firewall
  • EDR / endpoint protection
  • segmentation
  • hardening
  • updates
  • configurations

Detection & supervision

  • tool
  • surveillance
  • hours
  • handling
  • escalation
  • SLA

ANSSI treats security supervision as a device to organise and operate (processes, roles, detection, event handling) — not as a tool that is simply installed. It is not a SOC by default.

Incident response

  • roles
  • procedure
  • qualification
  • isolation
  • communication
  • escalation
  • return to normal

Backup & recovery

  • protected backups
  • restore tests
  • BCP/DRP according to scope
  • recovery scenarios

CISA specifically recommends offline/encrypted backups and regular testing in its ransomware prevention measures.

Is your business sufficiently protected?

Your protection level

Protection 50 / 100
Exposure Moderate
Priorities 4
  • Identities40 %
  • Workstations & servers60 %
  • Backups70 %
  • Detection30 %
  • Response40 %
  • Human60 %

Priority protections

  • roll out MFA across sensitive access
  • set up security monitoring
  • formalise incident response
  • test restore procedures

Recommended pack

Strengthened protection

Get my hardening plan

Indicative diagnostic, not a technical audit. The real deliverable is a 30 / 60 / 90-day roadmap, prioritised after the security audit.

Antivirus and firewall: why that is no longer enough to secure an IT system

An antivirus and a firewall remain useful. They only cover part of the information system, though: the network and, in part, the workstations. An attack often comes from elsewhere: an account, an untested backup, an untreated alert or a human error.

That is not necessarily sufficient. Several layers come into play, and each has a distinct role.

Firewall

Network control.

Endpoint protection / EDR

Workstations and servers.

MFA

Identities.

Backups

Recovery.

Supervision

Detection.

Procedures

Response.

Training

Human factor.

Cybersecurity rests on an architecture of complementary protections, not on buying a single piece of software.

How do you protect your business against phishing?

Phishing is one of the most frequent attack vectors. Protection combines identities, email, awareness and a reporting reflex — not a single isolated tool.

MFA

Limit the impact of a compromised password.

Email filtering & protection

Reduce phishing messages reaching inboxes.

Awareness

Recognise suspicious requests.

Reporting procedure

What does the employee do when in doubt?

How do you reduce the risk and impact of ransomware?

Ransomware is not handled with a single tool. You need to reduce entry points, detect earlier, contain the incident, restore data and resume operations.

CISA ransomware recommendations cover MFA, updates, protected backups and recovery procedures in particular.

  1. Prevent

    Patches + access + MFA

  2. Detect

    Monitoring

  3. Contain

    Incident procedure

  4. Restore

    Backups

  5. Recover

    DRP

The protections we can deploy in your IT

We do not deploy a fixed catalogue of eight mandatory products. Depending on your IT, uses and priorities, we put in place all or part of these protections.

Identities

  • MFA
  • account hardening
  • privilege review

Endpoints

  • antivirus/EDR according to context
  • security policies
  • updates

Network

  • firewall
  • segmentation
  • remote access
  • VPN

Cloud

  • access
  • configurations
  • accounts
  • logs

Email

  • protection
  • rules
  • awareness

Backups

  • architecture
  • isolation
  • restore

Supervision

  • tool
  • hours
  • handling
  • escalation
  • SLA

Incidents

  • procedure
  • escalation
  • roles
  • recovery

Technical solutions stay fitted to your environment

We do not build your cybersecurity around a mandated tool. We start from your infrastructure, your risks and the solutions already in place, to decide what to keep, complement, replace or configure better.

Keep

What already protects you properly — no replacement for the sake of a catalogue.

Complement

The real gaps: MFA, backups, supervision, procedures — where the IT system is exposed.

Replace

Only what is unfit, too exposed, or impossible to harden as it stands.

Configure better

The tool is already there: the settings, rights and operating model often are not.

Any vendor licences, cloud subscriptions or supervision services are identified separately in the proposal.

What does a better-protected IT system look like?

The engagement shows up in day-to-day IT operations: controlled access, readable alerts, tested backups and identified owners.

Before

  • accounts without MFA
  • rights never reviewed
  • untested backups
  • scattered alerts
  • nobody knows what to do in case of attack
  • tools installed without steering

After

  • sensitive access hardened
  • privileges under control
  • tested backups
  • centralised alerts
  • incident procedure
  • identified owners
  • steered security roadmap

How do we secure your business?

A clear sequence, adapted to your IT: diagnose, prioritise, deploy, verify, document, train, then keep the setup evolving.

  1. Diagnostic

    Understand the environment.

  2. Risk prioritisation

    Do not treat everything at the same level.

  3. Target architecture

    Define suitable protections.

  4. Deployment

    Install/configure the measures.

  5. Tests

    Verify they work.

  6. Documentation

    Procedures and responsibilities.

  7. Training

    Teams concerned.

  8. Supervision

    Tool, hours, handling, escalation, SLA.

  9. Continuous improvement

    Reassessment and evolution.

Your security roadmap

This is not a generic list of best practices: it is a 30 / 60 / 90-day plan, prioritised from your security audit. NIST CSF 2.0 is built around a full cycle — from governance through to recovery after an incident. That is the thread we follow to protect the business, without deploying everything at once.

0–30 days

Urgent

  • remediate critical vulnerabilities found in the audit;
  • enable MFA on high-impact access;
  • address exposed accounts (admin, VPN, RDP, cloud);
  • verify, isolate and test backups;
  • harden access: who gets in, from where, with which rights.

30–60 days

Structure

  • segment the network and limit lateral movement;
  • formalise procedures (incident, restore, access);
  • configure the detection tool (EDR, logs, alerts);
  • write useful policies: passwords, rights, suppliers.

60–90 days

Sustain

  • train teams (phishing, reflexes, incident roles);
  • test: restore, incident exercise, targeted campaign;
  • define supervision: hours, handling, escalation, SLA;
  • control: access reviews, suppliers, backups;
  • improve: a monthly loop, not a one-off project.

Without an audit, the plan stays theoretical. With the audit, each 30 / 60 / 90-day stage maps to a real gap in your environment — not a product catalogue.

Want this deliverable on your scope? The security audit finds the gaps; this roadmap says in which order to fix them so the business can withstand a cyber attack.

Who should secure their IT against cyberattacks?

Not only after an incident. Any organisation whose operations, data or access depend on IT needs concrete protection — including when the audit or pentest has already listed the gaps.

SMEs without a cybersecurity officer

You have no CISO or dedicated team — we become your cybersecurity partner and deploy protection suited to your size and budget.

Organisations holding sensitive or critical data

Health, finance, HR, intellectual property, customer data — these assets justify stronger protection (access, encryption, backups, monitoring), not just antivirus.

E-commerce, SaaS & online services

Your business relies on systems connected 24/7 — protection against DDoS attacks, injections and account compromise is critical.

Businesses highly dependent on their IT

If a few hours of downtime stop production, billing or customer service, securing the information system is no longer an IT project: it is business continuity.

Organisations hit by phishing, fraud or ransomware

We close the exploited gaps, harden access, isolate backups and put procedures in place to prevent a repeat — not just “clean up” the incident.

Organisations after an audit or pentest

You already have the list of vulnerabilities: we take on the remediation phase. The security audit and penetration test find the gaps; this page is the plan to fix them.

From finding the gaps to fixing them

A report without remediation leaves vulnerabilities open. This page is the step where we fix them — after understanding, testing and prioritising, before monitoring and re-checking.

  1. Cybersecurity auditunderstand
  2. Pentestchallenge
  3. Remediation planprioritise
  4. Cyber protectionfix
  5. Supervisionoperate
  6. Re-checkverify

Already have the list of gaps? We take on the remediation phase: fix, monitor, then verify — not re-read the report.

How much does cyber attack protection cost?

Cost depends on your IT size, desired protection level and scope to cover. Well-deployed protection costs on average 10× less than an incident.

Essential hardening

€2,500 – 4,900 excl. VAT

Simple environment / SME

  • Access hardening
  • Baseline protection configuration
  • Backup plan
  • Prioritised hardening actions
  • Team awareness
Request a quote

Complete protection & supervision

€9,900 – 18,000 excl. VAT+

Architecture, scoped supervision and continuity

  • Strengthened architecture
  • Extended deployment
  • Detection tool configured
  • Defined hours and event handling
  • Escalation and SLA
  • Procedures, continuity, support
Request a quote

Indicative pricing excl. VAT — Complianz fees, excluding third-party licences and tools. A tailored quote is provided within 24 hours. What determines the cost?

Installing an alerting tool is not a SOC. Supervision in this pack is a scoped setup: tool, surveillance, hours, event handling, escalation and SLA. A SOC (dedicated team, on-call cover, continuous alert handling) is only offered if it is actually stood up, on quote.

What determines the cost of cyber attack protection?

The ranges (€2,500 – 18,000 excl. VAT) are Complianz fees. They do not tell you whether an EDR, firewall or vendor SOC is included: those licences and subscriptions are a separate line, unless the quote says otherwise in so many words.

Complianz fees

Included in the prices shown.

  • scoping and protection architecture
  • configuring access, MFA, backups, procedures
  • deploying and setting up the tools you retain
  • training, support, scoped supervision

Third-party licences and tools

Not included, unless the quote says otherwise.

  • EDR, antivirus and firewall licences
  • cloud, backup and secure-email subscriptions
  • vendor SOC or third-party 24/7 on-call cover
  • network hardware and licence renewals

The €5,500 excl. VAT strengthened-protection figure is a fee. It does not, by default, include the EDR licence, the firewall or a SOC. Those costs are shown separately and, where possible, contracted in the client’s name.

Number of users

Number of workstations

Servers

Sites

Cloud infrastructure

Network architecture

Current protection level

Tools already in place

MFA already in place or not

Supervision required

Backups

Availability requirements

Level of support needed

Any software licences

Your questions about cyber attack protection

Our experts respond within 24 hours to all your questions about securing your IT.

Contact us
How do you protect a business from a cyberattack?

By combining reduced exposure, access hardening (MFA), workstation and server protection, detection, incident response and recovery — not a single tool. NIST CSF 2.0 structures this from governance through to recovery. See how to protect the business →

What are the main protections against cyberattacks?

Useful protections are MFA, access hardening, EDR or suitable endpoint protection, isolated and tested backups, scoped supervision, incident procedures and staff awareness. This is not a catalogue of eight mandatory products: we keep, complement, replace or configure according to the IT system. See the protections we can deploy →

How do you protect an SME against cyberattacks?

An SME starts with the urgent: critical vulnerabilities, MFA, exposed accounts, backups, access. Then it structures (segmentation, procedures, monitoring) and sustains (training, tests, control). A 24/7 SOC is not the starting point. See the 30 / 60 / 90-day roadmap →

Is antivirus enough to protect a business?

No. Antivirus helps against known threats, but it does not replace MFA, tested backups, an incident procedure or supervision. Information-system protection rests on complementary layers, not one piece of software. See antivirus, firewall and complementary layers →

What is the difference between antivirus and EDR?

Antivirus relies mainly on known signatures. EDR (Endpoint Detection and Response) watches behaviour on workstations and servers to detect and block attacks, including unknown ones. EDR is not mandatory for every SME, but it becomes relevant when data, remote access or exposure justify it. See protection layers →

What is MFA for?

MFA (multi-factor authentication) adds a second factor to a password. A credential stolen through phishing or a leak is no longer enough to get in. ANSSI and CISA strongly recommend it, especially against ransomware scenarios and for admin, VPN, email and cloud accounts.

How do you protect against phishing?

Phishing is treated at several levels: MFA, email protection, filtering rules, staff awareness and a procedure if a link has been clicked. An awareness campaign does not replace access hardening. See phishing protection →

How do you protect against ransomware?

You need to reduce entry points, detect earlier, contain the incident, restore and resume operations. CISA ransomware guidance covers MFA, updates, protected backups and recovery procedures in particular. See how to limit ransomware impact →

What should you do after a cyberattack?

Isolate affected machines, do not pay a ransom, call in an expert, report to ANSSI and the CNIL if personal data is involved, then activate recovery. If the IT system is still compromised, incident response or an investigation may be needed before a simple hardening project.

Should you keep offline backups?

Yes, especially for ransomware. CISA in particular recommends maintaining offline or encrypted backups and regularly testing that they can be restored. A backup reachable from the same network as production can be encrypted or deleted by the attacker.

What is a SOC?

A SOC (Security Operations Center) is a team and a setup: detection, alert handling, roles, hours, escalation and SLA. It is not a monitoring tool that has been installed. ANSSI treats security supervision as a device to operate, not as a product.

Does an SME need a SOC?

Not systematically: the level of supervision must be proportionate to the risks, exposure, obligations and capabilities of the organisation. Many SMEs first need a scoped tool, defined hours, event handling, escalation and an SLA — a SOC is only offered if it is actually stood up. See what supervision covers in our packs →

What is the difference between cyber protection and a cybersecurity audit?

The audit finds the gaps in the IT system. Cyber protection fixes them and deploys the measures: it is the deploy step in the journey. Without remediation, the report leaves the holes open. See the path from finding gaps to fixing them →

What is the difference between a pentest and cyber protection?

A pentest tests whether flaws can actually be exploited, in an authorised scope. Cyber protection prioritises and remediates, then hardens the IT system. The two follow each other: test, then remediate, then optionally re-check with a retest. See penetration testing →

How much does it cost to secure an IT system?

Complianz fees range, as a guide, from €2,500 to €18,000 excl. VAT depending on scope. EDR licences, firewall, cloud subscriptions or a vendor SOC are a separate line, unless the quote says otherwise. Cost depends in particular on users, workstations, servers, cloud and current protection level. See pricing and cost factors →

Can you secure an infrastructure that is already compromised?

Yes, but not as a simple hardening project if the attacker is still inside. Incident response or an investigation may be needed first: contain, eradicate, then only rebuild and harden. Hardening an IT system that is still compromised can leave the access open.

Can you take over remediation from an audit done by another firm?

Yes. If you already have the list of vulnerabilities, we take on the remediation phase: prioritise, fix, monitor, then re-check. A scoping exercise checks the perimeter, how old the report is and what has already been treated. Have my vulnerabilities fixed →

Ready to secure your business before the next attack?

Our experts deploy protection suited to your IT in 4 to 8 weeks. First conversation free, confidential, no commitment.

Secure my business
First conversation free Deployment in 4 to 8 weeks No commitment
Innovation hub