Mubiz Cybersecurity
Audit, integrate, maintain and support: we reduce your company’s exposure with proven tools, without superfluous subscriptions.
Services
One row per service: what we do, with which tools, what you receive and how success is measured.
Audit and advise
Identify your current strengths and weaknesses, then decide what to fix first.
Approach
- Interviews with management and IT leads
- Inventory of assets, access rights and backups
- Attack-surface and Active Directory scans
- Review of policies and practices
- Prioritised debrief to management
Tools
- SwissCyberCheck (attack surface: DNS, certificates, ports, applications)
- OpenVAS / Greenbone (vulnerabilities)
- PingCastle (Active Directory)
- Nmap
- ISO 27001 self-assessment grid
Deliverables
- Audit report with risk map
- Initial risk register
- Priced and prioritised action plan (90 days, 12 months)
- Debrief in a management meeting
Success indicators
- Exposure score before and after
- Number of open critical vulnerabilities
- Share of backups actually tested
- Time to fix critical findings
Integrate
Deploy the services that improve your protection and productivity, without superfluous subscriptions.
Approach
- Choice of building blocks based on the audit
- Mock-up on a pilot scope
- Progressive deployment, service by service
- Team training and documentation
Tools
- Wazuh (SIEM and XDR)
- Vaultwarden / Bitwarden (password vault)
- Authelia (multi-factor authentication, SSO)
- OPNsense (firewall, WireGuard VPN, IDS/IPS)
- Rspamd / Mailcow (e-mail filtering)
- Restic / UrBackup (encrypted backups)
- Zabbix (monitoring)
Deliverables
- Services installed on your premises or on Swiss hosting, containerised
- Operating and recovery procedures
- Accounts, rights and logs configured
- Training of users and administrators
Success indicators
- Multi-factor authentication on 100% of privileged accounts
- Encrypted backups with a successful monthly restore test
- SIEM alerts qualified and handled
- Deployment schedule met
Maintain
Keep the security level over time: nothing degrades silently.
Approach
- Update and patch calendar
- Continuous monitoring and monthly alert review
- Recurring vulnerability scans
- Quarterly restore test
- Monthly report
Tools
- Zabbix (monitoring)
- Wazuh (detection)
- OpenVAS (recurring scans)
- Automatic patching and CIS Level 2 hardening
- Restic / UrBackup (backups)
Deliverables
- Monthly report: vulnerabilities, incidents, backups, availability
- Change log
- Patch plan
- Documented restore tests
Success indicators
- Critical patches applied within 7 days
- Service availability
- Successful restore rate
- Number of incidents and time to resolution
Support and CISO-as-a-Service
A part-time security officer who owns governance and talks to your management.
Approach
- Defined days per month, monthly security committee
- Roadmap and trade-offs
- Relations with providers, insurers and auditors
- Incident management
- Awareness campaigns
Tools
- Risk register
- Internal policies and standards (writing)
- Indicator dashboard
- Internal phishing campaigns and training
- Requests for proposals and benchmarks by domain
Deliverables
- Up-to-date policies and standards
- Maintained risk register
- Quarterly reporting to management
- Incident response plan
- Specifications and offer evaluations
Success indicators
- Major risks handled according to plan
- Decreasing click rate on phishing campaigns
- Compliance requirements covered (ISO 27001 self-assessment)
- Incident response time
Catalogue by domain
The services Mubiz delivers today, with its current resources and skills.
Compliance
- General and domain-specific policies
- Internal standards
- Internal audit and internal control system (ICS)
- ISO 27001 self-assessment
CISO assistant
- Benchmark by domain
- Request for proposal writing
- Offer evaluation and decision support
- Implementation project management
Operational security
- SIEM (build and run)
- PAM
- XDR
- Password vault
- Code management
- IDS/IPS
- Vulnerability scanning
- Backup and restore
- Code scanning
Security awareness
- Internal phishing campaigns
- Training
Architecture
- Project architecture reviews
Secure infrastructure
- CIS Level 2 hardening
- Automatic OS patching
Attack surface
- Attack surface scanning: DNS, certificates, ports, applications
IAM
- Active Directory scan (PingCastle)
- AD recertification
Risk management
- Risk register design
- Risk treatment: assessment, mitigation
- Periodic reviews
Partnerships
Mubiz Cybersecurity relies on tools and communities we publish or run.
SwissCyberCheck
Attack-surface scan of a company (DNS, certificates, ports, applications) with a clear report and a one-year lock on passed checks.
swisscybercheck.ch
ContreAttHack
The cyberdefence handbook for the frugal CTO: 21 chapters, 70 free solutions with their integration recipe.
contreatthack.comNeverHackedAgain
Community and resources to never get hacked again: good practices, incident feedback, mutual help between managers.
Afterwork CyberSec Lausanne
Monthly meetups of cybersecurity professionals in French-speaking Switzerland, open to all, run with Mubiz.
cyberseclausanne.chWhere to start?
A short audit gives an accurate picture of your exposure and of the first measures to take. Let’s talk.
Request an audit