IT security
Accounts, backup and incidents — under control
Practical security for companies where Microsoft 365, cloud tools, devices and business systems have become important, but where ownership, access and recovery are not clear enough.
The first step is a scoped security review at a fixed price. You get a clear current-state picture, a prioritised action plan and an approach you can carry out without creating more admin than value.
Get a clear security map and action plan.
IT security is really about peace of mind
For small companies, security is rarely about advanced enterprise software. It is about the right people reaching the right things, information you can trust and a way forward when something breaks.
When those parts are in place the result is concrete: fewer interruptions, fewer unnecessary errors and less everyday stress.
The right access
The right people should reach the right systems, with the right permissions and without old accounts lingering for no reason.
Information you can trust
It should be clear who did what, important changes should be traceable, and data should not change or disappear without control.
Availability when you need it
Backup, recovery and update routines should be good enough for the business to keep running even when something goes wrong.
Common problems we see in small businesses
Risk rarely comes from one big failure. It is several small gaps in accounts, routines, updates and backup that together make the business more vulnerable than it needs to be.
Phishing via email
A credible email is often enough for someone to click wrong. When email is the way in, both protection and routines need to work.
Accounts without enough protection
When important accounts lack multi-factor and clear admin rules, a leaked password becomes a bigger problem than it needs to be.
Updates that slip through the cracks
Old computers, routers and servers live on without a clear patch flow. That creates unnecessary risk and harder troubleshooting.
Backup that exists but is untested
Many companies have copies but no practical recovery routine. Then you do not know how long an outage will actually last.
Access that has grown uncontrolled
When staff change roles or leave, access often stays behind. That makes the environment harder to oversee and secure.
Our first delivery: security review + action plan
We start with what gives the most effect per hour invested. The security review is a clear entry point for companies that want to know where they stand before deciding the next step.
The result is an easy-to-read report with priorities. What should you do first? What can wait? What gives the most effect in the short term?
This is what we review
- Logins and account protection, focused on multi-factor, admin accounts and access levels.
- Email protection and phishing routines in Microsoft 365 and other central tools.
- Devices, updates and standardisation of computers, networks and important services.
- Backup, recovery and readiness to get back up quickly after an outage.
- Access, ownership and practical routines when staff start, change role or leave.
How it works
The work follows the same logic as the rest of Webverkstan: first understand the situation, then scope the right actions, then deliver in a way that can be maintained.
Mapping
We go through your environment, your most important systems and how you work day to day. The goal is to see where the gaps actually are.
Security map
You get a clear current-state picture of accounts, devices, backup, access and dependencies that affect risk and recovery.
Action plan
We prioritise what to do first, what can wait, and what effect each action gives — in less friction and less risk.
Security uplift
When you want to carry out the plan we take the next step and set a security baseline you can live with day to day. The focus is on the actions that most clearly reduce risk and disruption.
Typical actions
- Enable and clean up multi-factor for important accounts.
- Clean up and document access and admin accounts.
- Get the patch flow, standardisation and device lifecycle in order.
- Verify backup and run at least one recovery test.
- Set a simple incident routine for the first steps when something happens.
Ongoing security
Security loses effect when it is done only once. For the clients who want to continue, we can follow up the baseline, keep the routines in order and help when the business changes.
The baseline stays alive
We follow up that accounts, devices and core settings do not slide back into old habits.
Routines for change
Onboarding, offboarding and changed roles become part of how you work instead of manual special cases.
Continuous improvement
When the business grows or changes systems we help you adjust the baseline without creating a heavy side project.
Results you notice day to day
When accounts, updates and recovery become clearer, both the incidents and the time it takes to recover when something goes wrong go down.
Case
Restaurant chain avoids downtime
We took over operations and standardised the environment for eight restaurants. The result was zero unplanned downtime over six months and a clearer foundation for both support and security.
Read the caseFewer small incidents that steal time from the business.
A shorter way back when something does go wrong.
Clearer ownership of accounts, backup and access.
Who is this for?
Companies without their own IT or security function that still depend on everyday systems working.
Businesses with Microsoft 365, cloud services and several business-critical systems that need a clear security floor.
Companies that want to get risks, routines and priorities in order without launching a large compliance project.
Extra relevant when
- You have had an incident or a close call with phishing, hijacked accounts or missed backup.
- You are growing, hiring or opening more locations and need better control before the environment gets more complex.
- Customers or vendors start asking clearer questions about security, access and readiness.
Common questions
Here we answer the most common questions about what is included, how much time it takes internally and how security work fits with everyday operations.
The most important thing is a clear current-state picture. Once you know which accounts, devices, backup flows and access actually exist, it becomes possible to prioritise the right actions in the right order.
MFA means that login requires more than just a password. It makes a leaked or guessed password go much less far, and it is often one of the fastest actions for better account protection.
If you handle personal data, there needs to be order in access, ownership and how you act if something happens. We help you get routines and a technical baseline in order, but the legal assessment always starts from your business.
For certain businesses and supply chains, the requirements on incident handling, documentation and ownership can be higher. If you are covered, or face customer requirements in the area, we help you get the baseline in order so you stand more firmly day to day.
You need to set aside time for mapping and decisions, but we drive the work, carry out the actions and document. The goal is for you to get control without it becoming an extra full-time project internally.
Book a security review
Tell us briefly about your environment and we will get back with an approach, next steps and a fixed price for the review.
Book a security review