Cybersecurity covers the technical and organizational measures that protect a company's systems, networks and data from unauthorized access, ransomware and data leaks.
What is usually included
- A risk and vulnerability assessment
- Multi-factor authentication, endpoint and email protection
- Employee training to recognize phishing
- An incident response plan and Law 25 compliance
Frequently asked questions
Are small businesses really targeted?
Yes. Attackers often go after small and medium-sized businesses because they are usually less protected than large organizations.
Where should we start to improve our cybersecurity?
Turn on multi-factor authentication, make sure you have tested, isolated backups, and train your staff. A risk assessment then helps prioritize the rest.
What does Law 25 require after an incident?
Law 25 requires businesses to keep a register of confidentiality incidents and to notify the Commission d'accès à l'information and the people affected when an incident poses a risk of serious harm.