Security approached from the identity
A stable and reliable security, identity and access capability is a precondition for continuity today. The question is how you know your solutions will still provide that protection tomorrow — and how you keep both technology and knowledge current.
Insight before you invest
Metro XS provides supporting services as well as a complete package of scans to test your IT security. That gives your organisation answers to three questions that should precede any investment.
- Which risks does your organisation actually run?
- How mature are you in each security domain?
- Which measures should you take — and to what extent?
The perimeter has become the identity
Driven by digital transformation, cloud and IoT, the digital boundary no longer sits around the network but around the identity and the information object. Who uses which information, when and for what purpose determines which measures are needed.
That is why we distinguish four types of measure: preventive, detective, analytical and responsive. We deliver them coherently, always from both a business and an IT perspective.
What we deliver
Security assessment & maturity scan
A structured review of infrastructure, applications, access and processes, with findings by risk, impact and remedy — prioritised.
Cyber defence services
Preventive and detective measures: hardening, segmentation, strong authentication, endpoint protection and configuration monitoring.
Offensive security services
Penetration testing, red teaming and phishing simulations that show what an attacker can actually achieve in your environment.
Monitoring, analysis & response
Logging, detection and a rehearsed incident process. Knowing something is happening is half the work; knowing what to do is the other half.
Cryptography & data protection
Key management, certificates, encryption and data classification — so protection follows the data rather than the network.
Privacy services
GDPR in practice: processing register, DPIAs, retention periods and their translation into technology and authorisations.
ISO & standards services
Guidance towards ISO 27001, NEN 7510 and BIO: from baseline and controls through to audit preparation.
Cloud security
Secure configuration of Microsoft 365, Azure and AWS: identities, networks, key management and continuous configuration control.
NIS2 & supply chain obligations
Translating legal requirements into measures, responsibilities and evidence, including the requirements you must impose on suppliers.
Proven products, honestly advised
We supply and implement security products for access protection, multi-factor authentication, privileged access, monitoring and data protection. Because we are not tied to a single vendor, we choose based on your situation: size, existing landscape, operational capacity and budget.
Every proposal comes with the reasoning: why this product, which alternative was considered and what the licence and operating costs are over three years.
- Selection based on a weighted set of requirements
- Proof of concept in your own environment before you sign
- Implementation with knowledge transfer to your administrators
- Transparent view of licence and operating costs
- Exit scenario discussed up front, not discovered afterwards
Start with a baseline
In three weeks you will know where your biggest risks are and what it costs to reduce them.
Plan a security assessment