Cybersecurity

Know where you stand, what to fix first and how to show it: security assessment, a prioritised plan and compliance.

What it is

An organisation’s security is not measured by the tools it has bought, but by what would happen if someone got in tomorrow where they should not. We help you understand where you stand, what to fix first and how to show it to clients, auditors or authorities.

We work on your side: we review what is there, prioritise with judgement and, when changes have to be made, coordinate them with your team or your IT provider.

What we do

  • Security assessment A review of architecture, configuration, access and what is exposed to the internet, with vulnerability analysis and technical tests agreed in writing.
  • Security plan Actions ranked by risk and effort, with owners and deadlines, so the budget goes first to what matters most.
  • Compliance The GDPR, NIS2, Spain’s Esquema Nacional de Seguridad (ENS) or the security requirements a client or a tender imposes, turned into concrete measures.
  • Supplier security What to ask of whoever hosts your data or builds your applications, how to check it and which clauses to put in the contract.
  • Incident readiness Who decides, who is told and what happens in the first hours, written down before it is needed.
  • Pre-launch review An independent look at an application or an integration before it goes live.

What you receive

  • A clear report on where you stand, with the risks in order of priority.
  • A realistic action plan that separates what configuration and procedures can fix from what needs investment.
  • If there are technical tests, a report with each finding, its severity and how to fix it.
  • Support during implementation, if you need it.

Frequently asked questions

Do you carry out penetration tests?

Yes, as part of a security assessment and always with scope, dates and authorisation in writing. We do not run tests that could interrupt a service without your explicit authorisation.

Do you certify compliance with any standard?

No. Certifications are issued by independent, accredited bodies. Our job is to make sure your organisation reaches that audit prepared, or knows what it is missing.

Does NIS2 apply to us?

It depends on your sector and size. As of October 2026, Spain has not finished transposing the directive, but it is worth knowing now whether you will fall within its scope and what it will require, because risk management and incident reporting cannot be improvised.

Facing a technology decision?

Tell us what is at stake: an investment, a vendor, an artificial intelligence project or a security or access problem. The first conversation is free.