Services & commercial offers

Six complementary building blocks from intent to operational compliance — including AI and agents. Indicative prices excl. VAT, Belgium, excluding travel outside the agreed region.

01 — Pillar

NIS2 transition

For essential and important entities, and suppliers exposed via the supply chain: we turn the obligation into a manageable programme — gap, governance, measures and evidence.

NIS2 transition — shield and compliance network

NIS2 Flash diagnostic

2 to 3 weeks

4 900 € HT
  • Applicability workshop & critical-services mapping
  • Targeted gap analysis (governance, risk, incident, supply chain)
  • Maturity score + top 10 actions
  • Executive readout (45–60 min)
Request this offer

Compliance retainer

Quarterly follow-up

1 850 € excl. VAT / month
  • Evidence & indicators review
  • Audit / inspection preparation
  • NIS2 measures watch & Belgian good practices
  • Ad hoc support (8 h / month included)
Discuss the retainer
02 — Framework

ISO 27001 — pragmatic ISMS

An information security management system sized to you: useful day-to-day, ready for certification if you choose.

ISO 27001 — ISMS and controls

ISMS scoping

Scope & risks

7 500 € HT
  • Scope and context definition
  • Risk analysis (SME-adapted method)
  • Statement of Applicability (SoA) v1
  • 6–12 month implementation plan
Request a scoping

Certification support

Through stage 1/2 audit

On quote depending on scope
  • Operational policies and procedures
  • Registers, KPIs, management review
  • Dry-run internal audit + remediation plan
  • Coordination with the certification body
Get a quote
03 — Put to the test

PenTest & penetration testing

Tests that speak business: exploitability, impact, prioritised fixes, and retest included on standard packs.

Penetration testing — attack-surface analysis

External / surface audit

Light black-box

3 800 € HT
  • Controlled recon & scan
  • Targeted manual tests
  • Executive + technical report
  • 60-min readout
Schedule

Targeted scenario / light red team

On a business objective

On quote
  • Attack hypothesis validated with you
  • Realistic intrusion chain
  • Focus on detection & response
  • Deliverable for leadership + SOC/IT
Describe a scenario
04 — Resilience

DR / BCP exercises

A plan that was never exercised is only an intention. We run useful, measurable exercises that fit your NIS2 / ISO evidence pack.

DR/BCP exercises — operational resilience

Leadership & IT tabletop

Facilitated half-day

2 900 € HT
  • Ransomware / critical outage scenario
  • Facilitation & observations
  • Gap report & action plan
Book a tabletop

Technical recovery exercise

On live or mirrored environment

From 5 500 € HT
  • RTO/RPO objectives tested
  • Runbook & timing
  • Structured lessons learned
  • BCP/DRP plan update
Request a quote
05 — Equipment

IT hardware specialised in security

Advice, supply and commissioning of equipment for Belgian SMEs and mid-market. No window-dressing partnerships: we recommend realistic building blocks for your risk, team and budget — then we deliver and configure.

IT security hardware
Scope

What we supply

  • Next-gen firewall / UTM
  • Endpoint protection (EPP/EDR)
  • Tokens and MFA / SSO solutions
  • Hardened network appliances (VPN, segmentation, filtering)
  • Logging / SME-fit light SIEM
  • Immutable backups / backup appliances
Offer

SME Security pack

Baseline shield for 20–150 seats: firewall, endpoints, MFA, hardening and related NIS2 evidence documentation.

On quote — typically €3,500–12,000 excl. VAT hardware + integration depending on volume.

Request a quote
Method

How it works

  • Needs & constraints scoping (no jargon)
  • Short comparison (2–3 options) with TCO
  • Order, configuration, tests
  • Skills transfer + evidence

Commercial transparency

XpandIT stays independent: hardware is a means, not an end. No brand is promoted here without a public partnership listed on the former site; vendor choices are made case by case and stated in your quote.

06 — Artificial intelligence

AI & AI agents integration in organisations

For Belgian SMEs and mid-market firms that want AI tools and agents in business processes — concretely, securely and with governance. Human accountability, data and NIS2 alignment included, without useless jargon.

AI and agents integration

AI opportunity scoping

2 to 3 weeks

From 3 900 € HT
  • Mapping of processes suited to AI / agents
  • Value · risk · data maturity matrix
  • Shortlist of realistic tools or agents for your context
  • 90-day roadmap + indicative budget
  • Executive readout (45–60 min)
Request a scoping

Agent governance & security

Responsible framework

4 500 € HT
  • SME-fit AI / agents usage policy
  • Data classification & accountabilities
  • Risk / NIS2 / supply-chain alignment
  • Auditability checklist and related evidence
Governance framework

Team training

Half-day to 2 days

From 1 800 € HT
  • Workshops for leadership, business and IT (adapted levels)
  • Practical cases: limits, control, useful prompting
  • Internal good practices and adoption criteria
  • Handover kit for your internal trainers
Schedule training

Link to NIS2 and research

AI is not a gadget: it touches data, decisions and accountability. We connect agent projects to your cyber posture — and, where useful, to the governance frames discussed in our research.

Need a combined quote?

NIS2 + hardware, ISO + PenTest, or AI + governance: we build a single proposal without duplicates.

Talk to an expert