Free trial

How Suitable took its security to the next level

Dutch menswear retailer Suitable combines 28 physical stores with a successful e-commerce operation across some 15 countries. Its security was already in good shape, but Suitable wanted to go further: not to assume things were fine, but to have them tested by an independent expert. That proactive attitude (daring to look critically at your own environment before anything goes wrong) made Suitable an ideal candidate for the CYSSME programme, in which the company was paired with mentor Lupasafe.

Sector / industry
Fashion retail, e-commerce
Company size
Around 200 employees, 28 stores
Key question
Independent verification and security taken to a higher level

A strong foundation as the starting point

Suitable did not start from zero, quite the opposite. MFA was enforced on user accounts, endpoint protection was rolled out with central monitoring, backups ran on the e-commerce platform, external vulnerability scans ran regularly and DDoS protection was in place. For a retailer of this size, a strong starting position. Pieter-Jan Schutte, responsible for e-commerce and IT, now wanted that foundation independently verified and further professionalised: from good measures to demonstrable and structured policy.

We had a lot in good order, but I did not want to just think it, I wanted to see it in black and white. An external eye that looks critically at what we do only makes you better.

Pieter-Jan Schutte, e-commerce and IT

Two angles: people and technology

Suitable approached the project broadly and thoughtfully, along two tracks at once: people and technology. Denise, customer service manager, took the human side. Her team handles a high volume of messages from unknown senders every day and is notably sharp about it: common phishing tricks are recognised with ease. Denise wanted to lift that level company-wide: to measure how the office and the stores score and bring everyone up to the same standard. Pieter-Jan took the technical side: cloud, network, devices and email. The Lupasafe platform was set up fully live during the kick-off itself, a pace that shows how decisively Suitable operates.

Verification that pays off immediately

The independent review confirmed the broad picture: Suitable’s foundations are sound. As with almost every SME, it also surfaced refinements, in the cloud configuration, on the network and in a few account settings. What sets Suitable apart is the speed of response: the most important items were picked up and resolved the same day. Remaining items were each given an owner and a clear instruction.

Just as valuable: items that did not need immediate fixing were not brushed aside but consciously weighed. Suitable started a risk register in which trade-offs are recorded explicitly, including review dates. Exactly the approach you see in mature organisations: not everything has to happen now, but everything has a decision.

Alert in practice

During the project, customer service proved its worth as a first line of defence. When a sophisticated, genuine phishing attempt reached the team (one that standard virus scanners did not catch), it was quickly spotted and reported. IT and Lupasafe acted at once: systems were checked, precautions were taken and the lesson was turned into a practical working agreement for the whole team. A textbook example of reporting, fast action and learning coming together.

The human firewall, measured

The first phishing simulation ran company-wide (office and stores) with a realistic scenario in Suitable’s own house style. Anyone who clicked received a short micro-training straight away rather than a reprimand, and alongside the click rate, the reporting rate was tracked as the key metric. That positive, non-punitive approach fits Suitable’s culture and demonstrably works.

My team already recognises a lot, but I wanted it measured company-wide. Now we have figures instead of a feeling, and you can see people getting genuinely sharper.

Denise, customer service manager

The effect was quickly visible: employees report and forward noticeably more suspicious emails than before. Alertness is growing throughout the organisation.

Results

  • Independent confirmation that Suitable’s security foundations are sound.
  • Improvement points in cloud, network and account settings addressed quickly, the most important ones the same day.
  • A complete and factual view of the M365 environment, the network and the devices, from a single place.
  • Measurably higher alertness among employees and rising reporting behaviour.
  • A risk register started with conscious trade-offs and review dates, from a feeling to structured risk management.
  • A customer service team that proved itself in practice as a strong first line of defence.

The way forward

Suitable keeps building on this foundation. On the agenda are an information security policy on paper with an annual risk session (in which new developments such as AI in customer service are also consciously weighed), phishing simulations as a fixed quarterly process with targeted scenarios per audience, and, via the CYSSME partners, an exploration of continuous security monitoring. This is how a strong foundation grows step by step into a demonstrable and future-proof security programme.

Security is never finished. But we now know exactly where we stand, and we work from facts and a clear plan. That brings peace of mind, for us and for our customers.

Pieter-Jan Schutte

About Suitable

Suitable is a Dutch menswear brand and retailer, with 28 physical stores across the Netherlands and an e-commerce platform serving customers in around 15 countries. Visit suitableshop.nl.

CYSSME partners involved

Lupasafe.

CYSSME (Cyber Security for Micro, Small and Medium sized Enterprises), info@cyssme.eu, +32 16 79 85 85, www.cyssme.eu. This project is funded by the European Union’s Digital Europe programme under Grant Agreement 101128101, and is supported by the European Cybersecurity Competence Centre.