← Back to the overview
VLAIO · Packages
START
A thorough baseline assessment and a concrete action plan to start working on.
- Duration
- 2 to 3 weeks
- Excl. VAT
- €9,500
- Net cost after 50% subsidy
- €4,750
Who it's for
SMEs that want to know where they stand on cybersecurity and need a grounded plan to take targeted steps — without committing to large investments upfront.
What's included
- Kickoff workshop with management and IT lead
- Inventory of assets, suppliers and critical processes
- External vulnerability scan of your public infrastructure
- Light phishing simulation to test the human side
- Review of existing policies and backup setup
- In-depth interviews with key staff
- Risk analysis based on CIS Controls v8 and NIS2
What you get
- Detailed audit report (50+ pages)
- Prioritised action plan with impact and effort estimates
- Two-page executive summary for management
- Live readout session with room for questions
How it runs
- 01Week 1 — Kickoff & information gathering
- 02Week 1-2 — Technical scans and interviews
- 03Week 2 — Analysis and reporting
- 04Week 3 — Readout with management and delivery
Effort breakdown
| Phase | Task | Days |
|---|---|---|
| Start | Administration | 1 |
| Preparation | 1 | |
| Analysis | Technical analysis | 3 |
| Governance analysis | 3 | |
| Roadmap | Summary of observations | 1 |
| Quick Wins (QWA) & SLM Roadmap | 1 | |
| Presentation | 1 | |
| TOTAL | 11 | |
Packages
MEDIUM
Everything in START, plus guidance to actually fix the most important findings.
PLUS
End-to-end program from analysis to executed improvements — including tooling and training.
Extension #1 — Red Team
A realistic attack simulation by external ethical hackers — see how far an attacker would actually get.
Extension #2 — Extra guidance
Additional budget for implementation, follow-up, or audit and certification preparation.