KMO-portefeuilleAdviesSubsidieKMO

What the KMO-portefeuille gives you: our four advisory modules explained

We are a registered service provider for the KMO-portefeuille. But what can you actually do with it, and is it something for a company of your size? We walk through our four advisory modules, with the value of each for both small and micro businesses.

Brian

Brian

Co-Founder & CEO

3 July 20266 min read
Illustration of four tiles, advisory modules theme

Since June we are a registered service provider for the KMO-portefeuille. The question that came back most often afterwards was: "what can I actually do with it, and is it something for a company of my size?" Fair question. So here we walk through our four advisory modules one by one, in plain language, with the value of each for both small and micro businesses.

To be clear: an advisory engagement is a one-off analysis with a clear report and an action plan, not an ongoing contract. And because it falls under the Advisory pillar of the KMO-portefeuille, you recover a good part of the invoice (up to 45%, depending on your size). You only pay your own share.

And no, "too small for cybersecurity advice" is not a thing. Even a one or two person business today runs on email, accounting and client data. The difference is not whether it is useful, but the scale of the engagement.

The photos below are from our cybersecurity info evening in Boortmeerbeek. There Brian and Ian walked SMEs and non-profits through exactly these themes, from the question "does NIS2 apply to me?" to a concrete plan, in plain language.

Module 1: Cybersecurity Assessment

This answers the question "how secure are we, really?" We do it through conversations and a review of how your organisation handles security. No systems are touched and no technical scans are run. You get a clear overall picture: where you stand, what your biggest risks are, and which steps to take first.

For a small business: with a growing team and increasing reliance on IT, this gives you an objective starting point. It stops you spending budget on the wrong things and helps you set priorities.

For a micro business: even with one or two people you want to know where you are vulnerable. This module tells you, in plain language, which three or four things really matter, without overwhelming you with a long list.

Module 2: Compliance Assessment

This answers "do we actually have to comply with anything?" We look at which regulations or requirements apply to you, think of NIS2, but just as much the requirements clients or insurers impose, and where you do not yet meet them today. You get a clear overview of the gap and the steps to close it.

For a small business: larger clients increasingly send a security questionnaire before they work with you. This module gets you ready for that and can literally save a contract.

For a micro business: you probably do not fall under NIS2, but a client or insurer may still ask for evidence. Here you quickly find out whether that applies to you, without expensive detours or needless panic.

Module 3: Technical Security Audit

This answers "are our systems properly secured?" Where the assessment gives the overall picture, here we look hands-on at your systems, network and website and search for concrete weak spots, such as outdated software or security that is misconfigured. You get a list of what is going wrong and what takes priority, with a summary that makes sense even without an IT background.

For a small business: with several laptops, a server or a web shop, the number of weak spots grows on its own. This check catches problems before an attacker does.

For a micro business: even with few systems you want to be sure your mailbox, website and laptops are not an open door. A focused, smaller audit is often enough here.

Module 4: Incident Response and Crisis Planning

This answers "what do we do if it goes wrong anyway?" Together we build a playbook for the moment something happens, for example ransomware or a hacked mailbox: who does what, who you call, and how you communicate to clients. No tech, just clarity at the moment it counts.

For a small business: with staff and clients depending on you, the difference between half an hour of chaos and a clear plan decides how quickly you are back up and running.

For a micro business: precisely when you have to solve it on your own, a simple plan on paper is worth gold. You do not lose precious hours figuring out what to do.

Which module do you need first?

In practice most owners start with the Cybersecurity Assessment. It gives the overall picture and immediately makes clear which of the other modules are worthwhile for you. If in doubt, start there. A micro business is often served by that single review; a small business regularly combines them, for example an Assessment together with a Technical Audit. Everything is tailored to your situation during a short intake conversation anyway. You will find a full overview on our advisory page.

All four modules fall under the KMO-portefeuille, so you recover a good part of the cost through support from the Flemish government. Just mention it at your intake and we will sort it out together. More about the subsidy itself is at VLAIO.