Diensten

Services

DienstenServices

Elf managed services, één vaste IT-professional, één standaard. Elke dienst hieronder volgt dezelfde discipline: bepalen wat het je bedrijf moet opleveren, de specifieke maatregelen implementeren die daarvoor zorgen, en alles documenteren. Dit is geen brochure: dit is precies wat ik uitrol en monitor, en waar ik achter sta.

Eleven managed services, one dedicated IT professional, one standard. Every service below follows the same discipline: define the business outcome, implement the specific controls that deliver it, and document everything. This is not a brochure: it is precisely what I deploy, monitor, and stand behind.

NetwerkgatewayNetworking Gateway

Een perimeter die segmenteert, beschermt en automatisch omschakelt, geen plastic providerrouter.

A perimeter that segments, protects, and fails over, not a plastic ISP router.

Je gateway is het ene punt waar elke dreiging, elke thuiswerker en elke byte aan bedrijfsverkeer samenkomt, en bij de meeste bedrijven is dat de standaardbox van de provider met het standaardwachtwoord. Ik vervang die door een next-generation firewall die is geconfigureerd voor jouw werkelijke verkeer: gesegmenteerde interne netwerken, versleutelde externe toegang en een tweede WAN-pad voor als de primaire lijn uitvalt. Eén goed gebouwde gateway neemt een hele categorie bedrijfsrisico weg.

Your gateway is the single point where every threat, every remote worker, and every byte of business traffic converges, and in most companies it is the ISP's default box with the default password. I replace that with a next-generation firewall configured for your actual traffic: segmented internal networks, encrypted remote access, and a second WAN path for when the primary line drops. One well-built edge removes an entire category of business risk.

Wat ik lever

What I deliver

  • NGFW-implementatie met geoblocking en DNS-filtering afgestemd op jouw verkeersprofiel, nooit op leveranciersstandaarden, en desgewenst ook flowinspectie
  • NGFW deployment with geo-blocking and DNS filtering tuned to your traffic profile, never left on vendor defaults, and flow inspection if you want it too
  • VLAN-segmentatie die servers, werkplekken, VoIP, gasten en IoT scheidt, met gedocumenteerde firewallregels tussen VLAN's
  • VLAN segmentation separating servers, workstations, VoIP, guest, and IoT, with documented inter-VLAN firewall rules
  • WireGuard- of IPsec-VPN (IKEv2) voor thuiswerkers en site-to-site-verbindingen, zonder RDP dat open naar buiten staat en zonder port-forwarding-sluiproutes
  • WireGuard or IPsec (IKEv2) VPN for remote workers and site-to-site links, with no exposed RDP and no port-forwarding shortcuts
  • Dual-WAN-failover met automatische healthchecks, zodat een kapotte lijn bandbreedte kost in plaats van de bedrijfsvoering stil te leggen
  • Dual-WAN failover with automatic health checks, so a cut line degrades bandwidth instead of stopping the business
  • Firewallregels onder wijzigingsbeheer, met geplande reviews en geversioneerde configuratieback-ups
  • Change-controlled firewall rulebase with scheduled reviews and versioned configuration backups
  • NGFW
  • Flowinspectie (optioneel)
  • Flow inspection (optional)
  • WireGuard/IPsec-VPN
  • WireGuard/IPsec VPN
  • Dual-WAN failover

Netwerkgateway bespreken voor jouw bedrijfDiscuss Networking Gateway for your business

WiFi-oplossingenWiFi Solutions

Een draadloos netwerk waar je medewerkers nooit over nadenken, en gasten geen misbruik van kunnen maken.

Wireless your staff never think about, and guests cannot abuse.

Bovenop de netwerkgateway lever ik ook WiFi. Dode plekken in de dekking en wegvallende videogesprekken zijn een dagelijkse aanslag op de productiviteit, en een plat draadloos netwerk met een gedeeld wachtwoord is een open deur naar alles wat erachter zit. Ik ontwerp zakelijke WiFi rond gemeten dekking en geauthenticeerde toegang: WPA3-Enterprise met 802.1X/RADIUS voor medewerkers, VLAN-geïsoleerde gasten- en IoT-netwerken, en centraal beheerde accesspoints. Het resultaat is een draadloos netwerk dat presteert als bekabeling en identiteit afdwingt als een deur op slot.

On top of the Networking Gateway, I offer WiFi as well. Dead zones and dropped video calls are a daily productivity tax, and a flat, shared-password wireless network is an open door into everything behind it. I design business-grade WiFi around measured coverage and authenticated access: WPA3-Enterprise with 802.1X/RADIUS for staff, VLAN-isolated guest and IoT networks, and centrally managed access points. The result is wireless that performs like cabling and enforces identity like a locked door.

Wat ik lever

What I deliver

  • RF-sitesurvey met kanaal- en zendvermogenplanning voordat er hardware wordt besteld: dekking wordt ontworpen, niet aangenomen
  • RF site survey with channel and transmit-power planning before any hardware is ordered: coverage is designed, not assumed
  • WPA3-Enterprise met 802.1X/RADIUS-authenticatie gekoppeld aan je directory, zodat een vertrekkende medewerker de WiFi-toegang verliest zodra het account wordt uitgeschakeld
  • WPA3-Enterprise with 802.1X/RADIUS authentication tied to your directory, so a departing employee loses WiFi access the moment their account is disabled
  • Gescheiden, VLAN-gesegmenteerde SSID's voor bedrijfs-, gasten- en IoT-verkeer, met client-isolatie afgedwongen op het gastennetwerk
  • Separate VLAN-segmented SSIDs for corporate, guest, and IoT traffic, with client isolation enforced on the guest network
  • Centraal beheerde accesspoints met automatische firmware-updates, healthmonitoring en alerting
  • Centrally managed access points with automatic firmware updates, health monitoring, and alerting
  • WPA3-Enterprise
  • 802.1X/RADIUS
  • VLAN-segmentatie
  • VLAN segmentation
  • Centraal beheerde AP's
  • Centrally managed APs

WiFi-oplossingen bespreken voor jouw bedrijfDiscuss WiFi Solutions for your business

Werkplekbeheer & IntuneWorkstation Management & Intune

Elke werkplek gepatcht, gemonitord en vervangbaar, en een nieuwe laptop vóór de lunch compliant.

Every workstation patched, monitored, and replaceable, and a new laptop compliant by lunchtime.

Trage, ongepatchte, ongedocumenteerde werkplekken kosten je medewerkers ongemerkt tijd en houden de deur open voor aanvallers, en apparaten met de hand configureren schaalt niet verder dan een handvol machines. Ik beheer elke werkplek via Microsoft Intune, waar de staat van een apparaat een kwestie van beleid is: Windows Autopilot richt nieuwe hardware zero-touch in, patching van besturingssysteem en applicaties loopt volgens een gefaseerd ringschema, en compliancebeleid bepaalt via Conditional Access de toegang tot bedrijfsdata. Elk apparaat kan in uren in plaats van dagen worden gereset of vervangen, en problemen komen als melding bij mij binnen voordat ze als klacht bij jou binnenkomen.

Slow, unpatched, undocumented workstations quietly cost your people time and hold the door open for attackers, and configuring devices by hand does not scale past a handful of machines. I manage every workstation through Microsoft Intune, where device state is a matter of policy: Windows Autopilot provisions new hardware zero-touch, operating system and application patching runs on a staged ring schedule, and compliance policies gate access to company data through Conditional Access. Any device can be reset or replaced in hours instead of days, and problems surface as alerts to me before they surface as complaints to you.

Wat ik lever

What I deliver

  • Elke werkplek ingeschreven in Intune, met apparaatstatus en compliance centraal gemonitord en problemen gesignaleerd voordat gebruikers ze merken
  • Every workstation enrolled in Intune, with device health and compliance monitored centrally and problems flagged before users notice them
  • Zero-touch-onboarding met Windows Autopilot: een ingerichte laptop gaat rechtstreeks naar de nieuwe collega en configureert zichzelf volgens jouw baseline
  • Windows Autopilot zero-touch onboarding: a set-up laptop ships straight to the new hire and configures itself to your baseline
  • Geautomatiseerde patching van Windows en applicaties van derden volgens een getest ringschema, met compliancerapportage
  • Automated Windows and third-party application patching on a tested ring schedule, with compliance reporting
  • Compliancebeleid gekoppeld aan Conditional Access, zodat alleen versleutelde, gepatchte, gezonde apparaten bij bedrijfsdata komen
  • Device compliance policies tied to Conditional Access, so only encrypted, patched, healthy devices reach company data
  • Gestandaardiseerde builds en beheerde applicatie-uitrol: beveiligingsbaselines, afgedwongen schijfversleuteling en dezelfde apps en instellingen op elke machine
  • Standardized builds and managed application deployment: security baselines, enforced disk encryption, and the same apps and settings on every machine
  • Volledige hardware- en software-inventaris met garantie- en levenscyclusregistratie, als basis voor een voorspelbaar vervangingsbudget
  • Complete hardware and software asset inventory with warranty and lifecycle tracking, feeding a predictable replacement budget
  • Microsoft Intune
  • Windows Autopilot
  • Patchbeheer
  • Patch management
  • Conditional Access

Werkplekbeheer & Intune bespreken voor jouw bedrijfDiscuss Workstation Management & Intune for your business

EndpointbeveiligingEndpoint Security Solutions

Ga ervan uit dat er op de phishingmail wordt geklikt, en zorg dat het nergens toe leidt.

Assume the phishing email gets clicked, and make sure it goes nowhere.

Antivirus die alleen virussen herkent die al bekend zijn, is geen beveiligingsstrategie in het ransomwaretijdperk. Ik beveilig elk endpoint in lagen: EDR die kwaadaardig gedrag detecteert en isoleert, attack-surface-reductionregels die de technieken blokkeren waar phishingpayloads op leunen, en het verwijderen van permanente lokale beheerdersrechten. Het doel is simpel: één verkeerde klik op één machine moet één verkeerde klik op één machine blijven.

Antivirus that only recognizes viruses it already knows is not a security strategy in the ransomware era. I harden every endpoint in layers: EDR that detects and isolates malicious behavior, attack surface reduction rules that block the techniques phishing payloads depend on, and the removal of standing local admin rights. The objective is simple: one bad click on one machine must stay one bad click on one machine.

Wat ik lever

What I deliver

  • EDR (Microsoft Defender for Business-klasse) met gedragsdetectie, geautomatiseerd onderzoek en apparaatisolatie met één klik
  • EDR (Microsoft Defender for Business class) with behavioral detection, automated investigation, and one-click device isolation
  • Attack-surface-reductionregels (ASR) die misbruik van Office-macro's, LSASS-credentialdiefstal en scriptgebaseerde aanvalsketens blokkeren
  • Attack surface reduction (ASR) rules blocking Office macro abuse, LSASS credential theft, and script-based attack chains
  • Permanente lokale beheerdersrechten verwijderd; waar lokale admin nodig is, regelt Windows LAPS de wachtwoorden: een dienst die elk apparaat een uniek wachtwoord geeft en dat automatisch regelmatig wijzigt
  • Standing local admin rights removed; where local admin is required, Windows LAPS manages the passwords: a service that gives every device a unique password and changes it automatically on a schedule
  • Een uitgeschreven incidentresponsrunbook: isolatie, credentialreset en herstelstappen, afgesproken voordat je ze ooit nodig hebt
  • A written incident response runbook: isolation, credential reset, and recovery steps agreed before you ever need them
  • EDR
  • Incidentrespons
  • Incident response
  • ASR-regels
  • ASR rules
  • LAPS / least privilege

Endpointbeveiliging bespreken voor jouw bedrijfDiscuss Endpoint Security Solutions for your business

Office 365-beheerManaged Office 365

De tenant waar je bedrijf op draait: beveiligd, onder controle en echt beheerd.

The tenant your business runs on: hardened, governed, and actually managed.

Bij de meeste Microsoft 365-tenants is één gestolen wachtwoord genoeg voor business email compromise, omdat ze nog op standaardinstellingen draaien. Ik beheer die van jou als de kritieke infrastructuur die het is: MFA afgedwongen via Conditional Access, mailauthenticatie dichtgezet met SPF, DKIM en DMARC, extern delen bewust ingericht in plaats van per ongeluk, en licenties teruggebracht tot wat je mensen echt gebruiken. Je tenant is niet langer een onbewaakt risico, maar een beheerd bedrijfsmiddel.

Most Microsoft 365 tenants are one stolen password away from business email compromise, because they still run on defaults. I manage yours as the critical infrastructure it is: MFA enforced through Conditional Access, mail authentication locked down with SPF, DKIM, and DMARC, sharing governed instead of accidental, and licensing trimmed to what your people actually use. Your tenant stops being an unattended risk and becomes a managed asset.

Wat ik lever

What I deliver

  • Beveiligingsbaseline voor de tenant: afgedwongen MFA, Conditional Access-beleid dat legacy-authenticatie en riskante aanmeldingen blokkeert, en gescheiden beheerdersaccounts
  • Tenant security baseline: enforced MFA, Conditional Access policies that block legacy authentication and risky sign-ins, and separated admin accounts
  • SPF, DKIM en DMARC geconfigureerd en volledig afgedwongen, zodat je domein moeilijk te spoofen is bij pogingen tot factuurfraude
  • SPF, DKIM, and DMARC configured and moved to enforcement, making your domain hard to spoof in payment-fraud attempts
  • Anti-phishing-, Safe Links- en Safe Attachments-beleid (Exchange Online Protection / Defender for Office 365) scherper afgesteld dan de standaard
  • Anti-phishing, Safe Links, and Safe Attachments policies (Exchange Online Protection / Defender for Office 365) tuned beyond defaults
  • Grip op extern delen voor SharePoint, OneDrive en Teams, zodat bestanden de tenant bewust verlaten, niet per ongeluk
  • External-sharing governance for SharePoint, OneDrive, and Teams, so files leave the tenant deliberately, not accidentally
  • Microsoft Secure Score-tracking, zodat je beveiligingsniveau meetbaar blijft
  • Microsoft Secure Score tracking, keeping your security posture measurable
  • Conditional Access
  • MFA
  • SPF/DKIM/DMARC
  • Defender for Office 365

Office 365-beheer bespreken voor jouw bedrijfDiscuss Managed Office 365 for your business

Zakelijke telefonieManaged Telephony

Bereikbaar op je vaste bedrijfsnummer, overal: op kantoor, thuis en onderweg.

Reachable on your main business number anywhere: in the office, at home, and on the road.

Zakelijke bereikbaarheid strandt vaak op een verouderde telefooncentrale of op losse mobiele nummers waar niemand meer grip op heeft. Ik lever en beheer zakelijke telefonie op basis van 3CX: één telefooncentrale voor het hele bedrijf, met apps voor desktop en mobiel, zodat iedereen belt en bereikbaar is op het vaste bedrijfsnummer. En omdat ik ook het netwerk beheer, krijgt spraakverkeer voorrang op een eigen VLAN, zodat gesprekken helder blijven, ook als het netwerk het druk heeft.

Business reachability often founders on an aging phone system or a scatter of mobile numbers no one keeps track of. I deliver and manage business telephony built on 3CX: one phone system for the whole company, with desktop and mobile apps, so everyone calls and can be reached on the main business number. And because I also manage the network, voice traffic gets priority on its own VLAN, keeping calls clear even when the network is busy.

Wat ik lever

What I deliver

  • 3CX-implementatie en volledig beheer: installatie, updates, back-ups van de configuratie en monitoring van de centrale
  • 3CX deployment and full management: installation, updates, configuration backups, and monitoring of the phone system
  • Je huidige vaste nummers gaan mee (nummerbehoud), met SIP-trunks van een provider die past bij je belvolume
  • Your existing numbers move with you (number porting), with SIP trunks from a provider that fits your call volume
  • Apps voor desktop en mobiel, plus vaste toestellen waar dat handig is, allemaal op hetzelfde bedrijfsnummer
  • Desktop and mobile apps, plus desk phones where they make sense, all on the same business number
  • Keuzemenu's, wachtrijen, routering op openingstijden en voicemail naar e-mail, ingericht rond hoe jouw bedrijf bereikbaar wil zijn
  • Call menus, queues, business-hours routing, and voicemail-to-email, built around how your company wants to be reached
  • Spraakverkeer op een eigen VLAN met QoS-voorrang, zodat de gesprekskwaliteit niet afhangt van wat het netwerk verder doet
  • Voice traffic on its own VLAN with QoS priority, so call quality does not depend on whatever else the network is doing
  • 3CX
  • Nummerbehoud
  • Number porting
  • SIP-trunks
  • QoS / VLAN

Zakelijke telefonie bespreken voor jouw bedrijfDiscuss Managed Telephony for your business

CamerabeveiligingCamera & Surveillance

Scherp beeld wanneer het ertoe doet, alleen zichtbaar voor wie het mag zien.

Sharp footage when it matters, visible only to the people who should see it.

Een camerasysteem is zo betrouwbaar als het netwerk waarop het draait, en zo veilig als de manier waarop je erbij kunt. Goedkope cloudcamera's sturen je beelden naar servers waar je geen zicht op hebt, en een recorder die open aan het internet hangt is een klassiek beginpunt voor een inbraak, digitaal én fysiek. Ik ontwerp en beheer camerabeveiliging als volwaardig onderdeel van je netwerk: PoE-camera's op een eigen, afgeschermd VLAN, opslag in eigen huis en beveiligde toegang op afstand via VPN in plaats van port-forwarding.

A camera system is only as reliable as the network it runs on, and only as secure as the way you reach it. Cheap cloud cameras send your footage to servers you have no view of, and a recorder exposed to the internet is a classic entry point for a break-in, digital and physical alike. I design and manage camera surveillance as a first-class part of your network: PoE cameras on their own shielded VLAN, storage on your own premises, and secure remote access over VPN instead of port forwarding.

Wat ik lever

What I deliver

  • Een cameraplan op basis van een rondgang door je pand: posities, kijkhoeken en resolutie afgestemd op wat je werkelijk wilt vastleggen, zoals ingangen, kassa of magazijn
  • A camera plan based on a walkthrough of your premises: positions, viewing angles, and resolution matched to what you actually need to capture, such as entrances, tills, or warehouse
  • PoE IP-camera's op een eigen, geïsoleerd VLAN, zodat een camera nooit een opstapje naar je bedrijfsdata kan worden
  • PoE IP cameras on their own isolated VLAN, so a camera can never become a stepping stone into your business data
  • Opslag op een lokale recorder (NVR) met een instelbare bewaartermijn, zodat de beelden in eigen huis blijven en er geen cloudabonnement nodig is
  • Storage on a local recorder (NVR) with a configurable retention period, keeping footage in-house with no cloud subscription required
  • Ingericht volgens de AVG: een passende bewaartermijn, beelden alleen toegankelijk voor bevoegde personen en een duidelijke melding van cameratoezicht
  • Set up in line with the GDPR: an appropriate retention period, footage accessible only to authorized people, and clear notice that cameras are in use
  • Live meekijken en terugkijken op kantoor of veilig op afstand via de VPN, zonder open poorten naar buiten
  • Live viewing and playback in the office or securely from anywhere over the VPN, with no ports opened to the outside
  • Monitoring op uitval: een camera die offline gaat of een schijf die volloopt is een melding bij mij, geen ontdekking achteraf
  • Failure monitoring: a camera going offline or a disk filling up becomes an alert to me, not a discovery after the fact
  • PoE
  • NVR
  • Eigen VLAN
  • Dedicated VLAN
  • Toegang via VPN
  • VPN access
  • AVG
  • GDPR

Camerabeveiliging bespreken voor jouw bedrijfDiscuss Camera & Surveillance for your business

Linux-serverbeheer & patchingLinux Server Management & Patching

Servers die stil hun werk doen: gepatcht, gemonitord en gedocumenteerd.

Servers that quietly do their job: patched, monitored, and documented.

Bijna elk bedrijf heeft er wel één: een Linux-server die ooit voor een applicatie, website of database is neergezet en sindsdien vooral met rust wordt gelaten. Zo'n server doet het, tot hij het niet meer doet, en tegen die tijd weet niemand meer precies hoe hij in elkaar zit. Ik neem dat beheer uit handen: updates en security-patches volgens een vast schema, hardening volgens een gedocumenteerde baseline, monitoring met meldingen, en documentatie waarmee elke server te herbouwen is in plaats van onaantastbaar te worden.

Almost every company has one: a Linux server that was once set up for an application, website, or database and has mostly been left alone since. A server like that works, until it does not, and by then nobody remembers exactly how it fits together. I take that burden off your hands: updates and security patches on a fixed schedule, hardening against a documented baseline, monitoring with alerts, and documentation that makes every server rebuildable instead of untouchable.

Wat ik lever

What I deliver

  • Beheer van Debian-, Ubuntu- en andere Linux-servers, on-premises of in de cloud, volgens één vaste werkwijze
  • Management of Debian, Ubuntu, and other Linux servers, on-premises or in the cloud, under one consistent discipline
  • Security-patches en updates volgens een vast, getest schema, met onderhoudsvensters die je vooraf kent en een terugvalplan per update
  • Security patches and updates on a fixed, tested schedule, with maintenance windows you know in advance and a rollback plan for every update
  • Hardening volgens een gedocumenteerde baseline: SSH met sleutels in plaats van wachtwoorden, een firewall die alleen doorlaat wat nodig is, en minimale rechten voor elke service
  • Hardening against a documented baseline: key-based SSH instead of passwords, a firewall that only allows what is needed, and least privilege for every service
  • Monitoring en alerting op schijfruimte, geheugen, services en certificaatverloop, zodat ik problemen zie voordat jij ze merkt
  • Monitoring and alerting on disk space, memory, services, and certificate expiry, so I see problems before you notice them
  • Volledige documentatie per server: wat erop draait, waarom, en hoe hij wordt herbouwd, aangevuld met back-ups en geteste restores via de back-updienst hieronder
  • Full documentation per server: what runs on it, why, and how it gets rebuilt, complemented by backups and tested restores through the backup service below
  • Debian / Ubuntu
  • Patchbeheer
  • Patch management
  • Hardening
  • Monitoring

Linux-serverbeheer bespreken voor jouw bedrijfDiscuss Linux Server Management for your business

Back-upoplossingenBackup Solutions

Een back-up is een belofte. Een geteste restore is een feit.

A backup is a promise. A tested restore is a fact.

De vraag die ertoe doet is niet "hebben jullie back-ups", maar "hoeveel data kun je je veroorloven te verliezen, en hoe lang kun je je veroorloven stil te liggen". Ik bouw back-ups die precies die vraag beantwoorden: een 3-2-1-architectuur met onveranderlijke kopieën die ransomware niet kan versleutelen, dekking voor de Microsoft 365-data die Microsoft niet voor je back-upt, en hersteltests met resultaten die je kunt nalezen. Herstel wordt een gedocumenteerde procedure, geen gok op de slechtste dag voor je bedrijf.

The question that matters is not "do you have backups", it is "how much data can you afford to lose, and how long can you afford to be down." I engineer backups to answer exactly that: a 3-2-1 architecture with immutable copies that ransomware cannot encrypt, coverage for the Microsoft 365 data Microsoft does not back up for you, and restore tests with results you can read. Recovery becomes a documented procedure, not a gamble taken on the worst day for your business.

Wat ik lever

What I deliver

  • 3-2-1-back-uparchitectuur (drie kopieën, twee soorten media, één externe locatie) ontworpen rond jouw afgesproken RPO en RTO, niet rond een leveranciersstandaard
  • 3-2-1 backup architecture (three copies, two media types, one off-site) designed around your agreed RPO and RTO, not a vendor default
  • Onveranderlijke, logisch air-gapped back-upkopieën die zelfs een aanvaller met beheerderswachtwoorden niet kan versleutelen of verwijderen
  • Immutable, logically air-gapped backup copies that even an attacker holding admin credentials cannot encrypt or delete
  • Microsoft 365-back-up voor Exchange Online, SharePoint, OneDrive en Teams, verder dan de standaardretentie van Microsoft
  • Microsoft 365 backup covering Exchange Online, SharePoint, OneDrive, and Teams, beyond Microsoft's native retention
  • Hersteltests, op bestandsniveau en van volledige systemen, met gedocumenteerde, geklokte resultaten
  • Restore tests, file-level and full-system, with documented, timed results
  • Versleuteling tijdens overdracht en in rust, met bewaakte back-upjobs en melding op dezelfde dag bij elke fout
  • Encryption in transit and at rest, with monitored backup jobs and same-day alerting on any failure
  • 3-2-1-architectuur
  • 3-2-1 architecture
  • Onveranderlijke kopieën
  • Immutable copies
  • RPO/RTO
  • Microsoft 365-back-up
  • Microsoft 365 backup

Back-upoplossingen bespreken voor jouw bedrijfDiscuss Backup Solutions for your business

Soevereine cloudSovereign Cloud

Samenwerken in een cloud die op eigen hardware draait: je data blijft van jou.

Collaboration in a cloud that runs on your own hardware: your data stays yours.

Wil je precies weten waar je gegevens staan en wie erbij kan, en dat zelf in de hand houden? Dan bouw ik een soevereine cloud op basis van Nextcloud: dezelfde software die ook binnen delen van de Duitse overheid wordt gebruikt. Die draait op hardware die ik zelf samenstel en beheer: bij jou op locatie, of in een Europees datacenter. Documenten, agenda's, videogesprekken en chat draaien op dat ene systeem; ik houd het gepatcht en bewaakt, en jij bepaalt wie toegang heeft en hoe lang gegevens bewaard blijven. Zo wordt digitale soevereiniteit iets concreets in plaats van een term uit een folder.

Would you rather know exactly where your data sits and who can reach it, and keep that in your own hands? Then I build you a sovereign cloud based on Nextcloud: the same software used inside parts of the German government. It runs on hardware I assemble and manage myself: at your own location, or in a European data centre. Documents, calendars, video calls, and chat run on that one system; I keep it patched and watched, and you decide who has access and how long data is kept. That turns digital sovereignty into something concrete instead of a word in a brochure.

Wat ik lever

What I deliver

  • Ontwerp en bouw van de privécloud: ik stel de hardware samen, richt Nextcloud in en plaats het bij jou op locatie of in een Europees datacenter, waar ik het voor je beheer
  • Design and build of the private cloud: I assemble the hardware, set up Nextcloud, and place it at your own location or in a European data centre, where I manage it for you
  • Eén werkomgeving voor documenten en bestanden, gedeelde agenda's, videogesprekken en chat, met mappen die je gecontroleerd deelt met klanten, leveranciers of je accountant
  • One workspace for documents and files, shared calendars, video calls, and chat, with folders you share with clients, suppliers, or your accountant in a controlled way
  • Een eigen account per medewerker met MFA, rechten per map of team, en toegang die stopt zodra het account wordt uitgeschakeld: je kunt aanwijzen wie bij welke gegevens kan, wat helpt bij je verantwoording onder de AVG
  • A separate account per employee with MFA, permissions per folder or team, and access that ends the moment the account is disabled: you can show who can reach which data, which helps with your own GDPR accountability
  • Beheer door mij: updates van platform en besturingssysteem volgens een vast schema, hardening volgens een vaste baseline die ik vastleg en documenteer, en monitoring die een probleem als melding bij mij neerlegt voordat het als klacht bij jou binnenkomt
  • Managed by me: platform and operating system updates on a fixed schedule, hardening to a fixed baseline that I set and document, and monitoring that turns a problem into an alert to me before it becomes a complaint to you
  • Back-ups volgens dezelfde discipline als de back-updienst hierboven: 3-2-1, onveranderlijke kopieën en geteste restores, afgestemd op de RPO en RTO die we afspreken
  • Backups under the same discipline as the backup service above: 3-2-1, immutable copies, and tested restores, matched to the RPO and RTO we agree
  • Nextcloud
  • Open source
  • Eigen hardware
  • Your own hardware
  • Op locatie
  • On-premises
  • EU-hosting
  • EU hosting
  • MFA

Soevereine cloud bespreken voor jouw bedrijfDiscuss Sovereign Cloud for your business

MaatwerkCustom work

Ik help ook graag bij andere IT-gerelateerde vraagstukken.

I am glad to help with other IT-related questions too.

Misschien is het een combinatie van een paar diensten hierboven, misschien iets heel anders. Leg het voor, dan breng ik in kaart wat er nodig is en stel ik een aanpak voor die bij je situatie past. Past het niet bij wat ik doe, dan zeg ik dat ook.

Maybe it is a combination of a few of the services above, maybe something else entirely. Put it to me and I will map out what is needed and propose an approach that fits your situation. If it is not a fit for what I do, I will say so.

Wat ik lever

What I deliver

  • Een inventarisatie vooraf: wat het vraagstuk precies is, wat het raakt, en wat een oplossing moet doen
  • An assessment up front: what the question actually is, what it touches, and what a solution has to do
  • Een voorstel met een afgebakende scope in gewone taal, zodat vooraf duidelijk is wat er wel en niet in zit
  • A proposal with a defined scope in plain language, so it is clear up front what is and is not included
  • De uitvoering en de overdracht, gedocumenteerd en daarna mee te nemen in het beheer of over te dragen aan je eigen team
  • The work and the handover, documented and afterwards folded into management or handed over to your own team
  • Inventarisatie
  • Assessment
  • Afgebakende scope
  • Defined scope
  • Eén aanspreekpunt
  • One point of contact
  • Documentatie
  • Documentation

Maatwerk bespreken voor jouw bedrijfDiscuss custom work for your business

Elke samenwerking begint met een inventarisatie.

Every engagement starts with an assessment.

Ik beoordeel wat je hebt, leg in gewone taal uit wat er op het spel staat, en stel een vaste scope voor met concrete maatregelen en de bijbehorende kosten. Geen verplichtingen, geen jargon, geen druk.

I review what you have, explain what is at risk in plain language, and propose a fixed scope with named controls and named costs. No obligation, no jargon, no pressure.

Neem contact opGet in Touch