Cybersecurity services
Five service lines delivered by one team of 30 specialists in Spain. Most engagements start the same way: by measuring where you actually are. From that diagnosis, we prioritise the work by risk and cost.
Start here: CIS18 Maturity Assessment
Before buying tools or committing to a compliance programme, measure. We assess your organisation against the 18 CIS Controls and deliver a maturity score by domain plus a prioritised roadmap: what to fix first, what can wait, and what you don't need at all. It is the entry point to most of our client relationships and the GAP analysis that feeds any compliance project.
Deliverables: full assessment against the 18 CIS Controls · maturity scoring by domain · prioritised roadmap with quick wins · technical report and executive presentation. Typical timeline: around three weeks from kick-off to the results session.
Assessment
18 CIS Controls
Priorities
- What to fix first
- What can wait
- What you don't need
Roadmap
Prioritised
Not sure where to start?
Three closed questions, no personal data. At the end we suggest which service line to start the conversation with, and why.
Step 1 of 3
We have an incident right now Go straight to incident response, no questions asked.
Choose an option to continue.
Regulatory compliance
- ENS — Esquema Nacional de Seguridad. Spain's public-sector security framework. For private companies it covers the information systems supporting the services or solutions they provide to public bodies for the exercise of their powers, under contract and applicable regulation (Royal Decree 311/2022, Art. 2.3) — not every sale to the public sector. Basic, Medium and High categories, from GAP analysis to declaration or certification.
- NIS2. An EU directive: its obligations reach companies through national transposition law, so concrete obligations are determined by the Spanish legislation in force. On 8 July 2026 the European Commission announced it was referring Spain to the Court of Justice of the EU for failing to complete transposition. Separately, clients subject to NIS2 may pass supply-chain requirements (Art. 21.2.d) on to their suppliers by contract, depending on the supplier's activity and the contract.
- DORA and MiCA. DORA has applied directly since 17 January 2025 to the financial entities in scope, including crypto-asset service providers (CASPs); their ICT suppliers may receive contractual requirements depending on the service they provide. We have prepared Spain's leading crypto exchanges and digital-asset platforms — EurocoinPay, Venga, Mercuryo, CriptoPocket, Criptan and Eurobit — for DORA and MiCA authorisation.
- ISO/IEC 27001. Full implementation support through to certification — we hold it ourselves.
CISO as a Service
A senior security director embedded in your organisation for the days per month you need, with our full team behind them: strategy, governance, compliance evidence, supplier management and board-level reporting — including the oversight NIS2 Article 20 places directly on company directors.
Offensive security
Penetration testing of web applications, APIs and infrastructure; controlled phishing campaigns; WiFi audits; dynamic application security testing; and system hardening against CIS Benchmarks and Spanish CCN-STIC guidance. Methodologies: PTES, OSSTMM, OWASP. Retesting of remediated findings is included as standard in every penetration test — with no expiry date: when your team fixes, we verify it's closed.
We also do what few firms do: hardware and firmware penetration testing on point-of-sale terminals, for platforms processing millions of transactions daily.
Digital forensics and expert witness
Forensic acquisition with documented chain of custody, incident reconstruction, expert reports and courtroom testimony — including counter-expert work. Our forensic work has supported court victories for international industrial groups.
Managed security
Day-to-day security operations: managed endpoint detection and response, email security, vulnerability monitoring, unified console, monthly reporting and an included engineering allowance. Deployed at scale — over 150 sites for a single client.
Incident response
Available year-round: containment, forensic acquisition, analysis, eradication, recovery and reporting. Two models: on-demand activation or a preventive retainer.
A partner responds within one hour, during business hours.