Defining the need
Which risk is being closed and where the requirement comes from: an insurer's questionnaire for a cyber policy, a client covered by NIS2, a public tender or your own risk analysis.
Many SMEs come to this conversation feeling they have already paid for security: a Microsoft 365 subscription with a long name, an antivirus renewed every year, perhaps a firewall with a web filtering licence. Look inside and half of those features are often unconfigured, left in observe-only mode or applied to a test group nobody ever widened. The problem is not the tool but the gap between purchase and real protection, which rarely has an owner. Apply takes charge of that gap: defining what each tool must achieve, checking whether you already pay for it, trying it on a small group of machines so it does not break a3ERP or the ground-floor printer, and taking it live with blocking enabled and someone who can read its alerts.
The order surprises people: first we write down what needs protecting and to what standard, and only then do we talk about brands and prices.
Which risk is being closed and where the requirement comes from: an insurer's questionnaire for a cyber policy, a client covered by NIS2, a public tender or your own risk analysis.
Plenty of companies hold Microsoft 365 Business Premium and never use the Defender for Business, Intune or Conditional Access features it includes. Others pay for two antivirus products at once. We check before suggesting any purchase.
If you do need to buy, we set two or three options side by side based on your size, your team's skills and three-year cost, not just a discounted first-year price.
The tool goes onto a group of machines from different departments, so clashes with business software, printer drivers and legacy applications nobody dares touch show up early.
Policies, integration with what you already run and distribution through Intune, Group Policy or the vendor console. Nobody has to walk from desk to desk with a USB stick.
Your IT lead learns to read alerts and manage exceptions. If you prefer, we keep the fine-tuning under a support plan.
Each stage has a written exit criterion. We do not move on until the previous stage is stable.
We note what the tool must achieve and how we will measure it: share of devices actually managed, time to handle an alert, number of non-compliant machines.
Five to ten devices for one or two weeks. A conflict is far cheaper to find on ten computers than on two hundred.
Department by department, with a rollback ready and a gradual shift from monitoring to blocking.
Configuration documents, training by video call and an agreed alert procedure, including who responds outside 9:00-18:00.
Before signing an order, ask what will stop happening. “More security” is not a measurable goal; “no unencrypted laptops” or “no account without MFA” is. If a tool cannot be tied to a sentence like that, it is probably not the next thing you need to buy.
Yes. We do not sell any particular brand, and the job is often to finish a rollout that stalled halfway. We need admin access to the console and, if there is a vendor support contract, the contact details to raise tickets on your behalf.
Your company does. Licences are bought in your name, directly from the vendor or through your usual reseller, and consoles sit under admin accounts you control. If you ever stop working with Apply, you remove our access and everything keeps running.
Red.es's Kit Digital programme has a cybersecurity category, but grants go through registered digitalisation agents, and Apply is not one of them. If you receive a grant that way, we can work with the agent on the technical side; we cannot promise you will get it or handle the application.
That is what the rollback at each stage is for. An exception is applied from the console in minutes without touching the device, and afterwards we calmly work out why it clashed. That is also why the switch to blocking never happens on a Friday afternoon or at month-end close.
Tell us what is already installed, which licences you pay for and who is asking for what. We will reply with an initial view of what to switch on and in which order.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.