Cyber security

Security approached from the identity

A stable and reliable security, identity and access capability is a precondition for continuity today. The question is how you know your solutions will still provide that protection tomorrow — and how you keep both technology and knowledge current.

Why cyber security

Insight before you invest

Metro XS provides supporting services as well as a complete package of scans to test your IT security. That gives your organisation answers to three questions that should precede any investment.

  • Which risks does your organisation actually run?
  • How mature are you in each security domain?
  • Which measures should you take — and to what extent?
What is cyber security today?

The perimeter has become the identity

Driven by digital transformation, cloud and IoT, the digital boundary no longer sits around the network but around the identity and the information object. Who uses which information, when and for what purpose determines which measures are needed.

That is why we distinguish four types of measure: preventive, detective, analytical and responsive. We deliver them coherently, always from both a business and an IT perspective.

Our cyber security services

What we deliver

Security assessment & maturity scan

A structured review of infrastructure, applications, access and processes, with findings by risk, impact and remedy — prioritised.

Cyber defence services

Preventive and detective measures: hardening, segmentation, strong authentication, endpoint protection and configuration monitoring.

Offensive security services

Penetration testing, red teaming and phishing simulations that show what an attacker can actually achieve in your environment.

Monitoring, analysis & response

Logging, detection and a rehearsed incident process. Knowing something is happening is half the work; knowing what to do is the other half.

Cryptography & data protection

Key management, certificates, encryption and data classification — so protection follows the data rather than the network.

Privacy services

GDPR in practice: processing register, DPIAs, retention periods and their translation into technology and authorisations.

ISO & standards services

Guidance towards ISO 27001, NEN 7510 and BIO: from baseline and controls through to audit preparation.

Cloud security

Secure configuration of Microsoft 365, Azure and AWS: identities, networks, key management and continuous configuration control.

NIS2 & supply chain obligations

Translating legal requirements into measures, responsibilities and evidence, including the requirements you must impose on suppliers.

Security products

Proven products, honestly advised

We supply and implement security products for access protection, multi-factor authentication, privileged access, monitoring and data protection. Because we are not tied to a single vendor, we choose based on your situation: size, existing landscape, operational capacity and budget.

Every proposal comes with the reasoning: why this product, which alternative was considered and what the licence and operating costs are over three years.

  • Selection based on a weighted set of requirements
  • Proof of concept in your own environment before you sign
  • Implementation with knowledge transfer to your administrators
  • Transparent view of licence and operating costs
  • Exit scenario discussed up front, not discovered afterwards

Start with a baseline

In three weeks you will know where your biggest risks are and what it costs to reduce them.

Plan a security assessment