Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Cybersecurity · Managed Security Services

Managed cybersecurity for SMEs: threats stopped before they do damage.

One targeted phishing e-mail can bring an organisation to a standstill for days. Qteco protects your environment at every level, from endpoint to identity, with 24/7 SOC monitoring, EDR on every device, AI-driven e-mail security and people who know what they are doing. No loose tools, but one closed defence.

EDR protection and Microsoft 365 backup are included in every workplace package from around € 89 per workplace per month; SOC monitoring, zero trust and vCISO scale up through the Growth and Scale-up packages. That gives an organisation of 10 to 250 employees enterprise security at SME cost, managed by the team that also knows your IT.

24/7 SOC — continuous monitoring EDR as standard — in every workplace package NIS2-ready — provably compliant Since 2013 — Brainport Eindhoven
Defence in depth

Six layers. One closed defence.

Attackers look for the weakest link. That is why we do not secure one thing very well, but everything well: each layer catches what the previous one misses.

01

Identity & access

MFA on every account, preferably phishing-resistant with passkeys, zero-trust access policy and Conditional Access based on device, location and risk. One stolen password no longer grants access.

02

Endpoints (EDR)

Endpoint Detection & Response on laptops, servers and mobile: blocks malware, recognises suspicious behaviour and automatically isolates infected devices, even when an update has not been installed yet.

03

E-mail & collaboration

AI-driven e-mail security that intercepts phishing, spoofing and malicious attachments, including e-mails that imitate Microsoft or Google. The biggest attack route, closed.

04

Network & connectivity

Managed firewalls, segmented networks (UniFi/Meraki) and secured fixed and mobile connections, up to and including telephony.

05

Data & backup

Immutable 3-2-1 backups on sovereign Dutch infrastructure. Even after a successful attack your data can be restored, ransomware or not.

06

People & awareness

Phishing simulations and training that sticks. Your employees turn from target into first line of defence.

What you get

Security as a service, not as a project.

Not a one-off audit that disappears in a drawer, but continuous protection at fixed, predictable cost. EDR and Microsoft 365 backup are included in every Qteco workplace package.

24/7 SOC monitoring

Our Security Operations Center watches your environment day and night. Suspicious behaviour is assessed and stopped, at 03:00 at night as well, and also when it is a sign-in from another country an hour after a successful login in Eindhoven.

AI detection + human analysisImmediate response & isolation

EDR on every device

Advanced endpoint protection that goes beyond antivirus: behavioural detection, automatic isolation and rollback of damage. On laptops, servers and mobile, standard in every package.

Laptops, servers & mobileIncluded as standard

Zero trust & MFA

Multi-factor authentication enforced on every account, Conditional Access and least-privilege rights throughout the environment, with phishing-resistant passkeys for administrators and finance roles.

No exceptionsMicrosoft Entra ID

AI e-mail security

Smart filtering that also recognises sophisticated phishing, including e-mails that abuse Microsoft or Google services to look trusted, and a report button in Outlook so suspicious mail reaches us in one click.

Anti-phishing & spoofingSafe attachments & links

Awareness & phishing training

Realistic simulations and short, practical training, every quarter. Measurable results: fewer clicks on malicious links, more reports. Also for the board, as NIS2 requires.

Phishing simulationsQuarterly reporting

Incident response & vCISO

A clear response plan before things go wrong, rehearsed annually, and on-demand senior security leadership (vCISO) for policy, risks and compliance. Including the notification deadlines of NIS2 and the GDPR.

Response plan & drillvCISO in Scale-up package
Standalone antivirus or managed security

Is antivirus enough? The difference, in black and white.

A virus scanner recognises known files. Modern attacks use stolen passwords, legitimate tools and intercepted login sessions, and a scanner does not recognise those. Managed security looks at behaviour, across all layers, with people behind it.

Standalone antivirus and a firewall Managed security by Qteco
Detection Known malware based on signatures Behaviour on endpoints, identities and e-mail, with EDR and AI detection
Who is watching Nobody, until an employee notices an alert A SOC that assesses and intervenes 24/7
Stolen password Invisible: the attacker simply logs in MFA and Conditional Access block; abnormal login behaviour is seen
Ransomware Backup often on the same network, so encrypted as well Device automatically isolated, immutable backup untouchable
Evidence for NIS2, insurer or customer A licence, no report Quarterly reporting, logging and a tested incident plan
Cost Low per month, high per incident Fixed fee per workplace, EDR and backup included
Investment

What does managed security cost at Qteco?

At Qteco, security is not a separate service but part of the managed workplace. This is what the security layer of each package contains; the full package contents are on the managed IT page.

Startup

For teams of up to around 20 employees

From € 89 / workplace / month · all-in
  • EDR security on every device
  • MFA and Microsoft 365 backup
  • E-mail security and patching
  • SLA support — response within 4 hours
Request a quote

Scale-up / Enterprise

For organisations with custom requirements

Custom
  • Everything in Growth + vCISO
  • Zero trust + 24/7 SOC
  • Incident plan and NIS2 evidence file
  • Priority within 15 min
Request a quote

All-in indicative prices per managed workplace, including Microsoft 365 licences, management and support; excluding one-off onboarding, hardware and VAT. Standalone security services for organisations with another IT partner are quoted after an intake.

Compliance

NIS2: from obligation to advantage.

Since 15 August 2026 the Dutch Cybersecurity Act makes cybersecurity a board responsibility, with personal liability in case of negligence. The six layers above cover the ten measures of the duty of care; the reports and logging provide the evidence.

01

NIS2 readiness scan

Where do you stand today? Your legal status, sixteen basic measures and an action plan, in two minutes.

02

Risk analysis & improvement plan

Clear measures, in proportion to your size and budget, prioritising what removes the most risk.

03

Demonstrably compliant

Automated evidence for audits, insurers and customers, continuously up to date.

FAQ

Frequently asked questions about managed cybersecurity.

What is the difference between EDR and classic antivirus?

Antivirus recognises known malicious files by their signature. EDR (Endpoint Detection & Response) looks at behaviour: a program that suddenly encrypts files, a PDF reader that starts code, a login that does not add up. EDR isolates the device automatically and can roll back damage. That is why EDR is standard in every Qteco workplace package and antivirus alone no longer is.

What is a managed SOC and does an SME need one?

A SOC (Security Operations Center) is the team plus the tooling that watches your environment 24/7, assesses alerts and intervenes. Managed means you share it with other organisations instead of staffing it yourself. For an SME that is the only feasible way to be watched at night and at weekends; attacks do not wait for office hours. At Qteco, SOC monitoring is part of the Growth and Scale-up packages.

What is the difference between SOC, SIEM and MDR?

A SIEM is the tooling that collects and correlates logs. A SOC is the team that works with it. MDR (Managed Detection & Response) is the service in which an external party performs detection and response for you. Managed cybersecurity by Qteco combines the three: the tooling, the team and the intervention, plus the preventive layers such as MFA, e-mail security and training.

What does managed security cost for a company with 50 employees?

At Qteco, security is part of the managed workplace. For an organisation of 50 employees the Growth package usually fits, from around € 119 per workplace per month all-in, including Microsoft 365 licences, EDR, SOC monitoring, backup, management and support. Expect around 6,000 euros per month for complete IT including security, excluding onboarding, hardware and VAT. Standalone security without management is quoted after an intake.

How fast is action taken in a ransomware incident?

Immediately. The SOC monitors continuously; when suspicious behaviour is detected, an infected device is isolated automatically and the response starts, also outside office hours. In addition your SLA applies: response within 4 hours on Startup, within 1 hour on Growth and priority within 15 minutes on Scale-up. Recovery is done from the immutable backup, which ransomware cannot encrypt.

What happens during the free security check?

The free Microsoft 365 Security Self-Assessment tests your environment on six points: MFA for all users, Conditional Access, a secured link with a local AD, EDR on all devices, immutable backups and security awareness. You see immediately where you stand and receive concrete recommendations. No obligations; just an honest picture.

See also

Security works best in context.

The layers above touch the workplace, the cloud and the law. These pages go deeper.

Background in the news: phishing keeps getting smarter and the lessons of the Odido incident.

Start today

Know where you stand within 2 minutes.

Take the free Microsoft 365 security check, or book a no-obligation call with an engineer right away.