Cybersecurity and compliance
ISO 27001, ENS, NIS2, pentesting, AppSec and a controls and evidence roadmap.
See cybersecurity →Two lines of service for companies that need to comply and protect themselves, or create a website, CRM, application and integration that advances the business with a secure technical foundation.
Cybersecurity protects and demonstrates compliance; Digital development creates and connects the tools with which your business operates.
ISO 27001, ENS, NIS2, pentesting, AppSec and a controls and evidence roadmap.
See cybersecurity →Corporate website, applications, e-commerce, CRM, integrations and custom digital processes.
See digital development →What we say can be verified. Part of the team is certified and we work with tools that real clients use.
Part of the team has the AENOR ISO 27001 Lead Auditor certification.
Meet the team →Penetration tests with agreed scope, technical and executive report, and remediation support.
See pentesting →We work with Odoo CRM and have clients who use it daily.
See CRM →We know the National Security Scheme from the inside: we are in the certification process.
See ENS adaptation →If you are asked for ISO 27001, ENS or NIS2, we start by clarifying what applies, what is missing and what is worth prioritizing.
Scope, risks, SoA, controls, evidence and audit preparation.
See ISO 27001 service →Adaptation plan for Public Administration suppliers and regulated systems.
See ENS service →Governance, risks, incidents, continuity and supply chain.
See NIS2 service →Web, APIs, network and infrastructure testing with technical and executive report.
See pentesting →Web/mobile applications and code review with security by design.
See secure development →Corporate websites, platforms, e-commerce and custom integrations with technical SEO and security by design.
See web development →Training, monitoring, corrective actions and continuous improvement after implementation.
Consult my case →We translate security requirements into decisions, controls and evidence that the team can maintain.
30 minutes to guide scope, urgency and next steps.
Policies, records and evidence intended to be used, not for decoration.
We validate controls with testing, review and practical criteria.
Implementation, audit, maintenance and continuous improvement.
A short process to understand: diagnosis, risks, controls, validation and improvement.
What applies, what is missing and what to prioritize.
Initial reportAssets, threats, impact and treatment.
RoadmapMeasures, those responsible, policies and evidence.
ISMS/planInternal audit, technical review or pentest.
EvidenceMonitoring, training and incidents.
Annual planISO 27001 provides international recognition; ENS is key for the Spanish public sector; NIS2 raises European standards for governance, continuity, incidents and supply chain. If they are designed together, they share controls and evidence.
| Criterion | ISO 27001 | ENS | NIS2 |
|---|---|---|---|
| What is | International standard for information security and ISMS. | Mandatory Spanish framework for the public sector and its ICT suppliers. | European directive to strengthen cybersecurity of critical sectors and supply chains. |
| Who applies | Any company that wants to protect information, sell more trust or access demanding customers. | Public Administrations and private companies that provide services to the AAPP. | Essential or important entities and suppliers that may be affected by contractual requirements. |
| Mandatory | It is not always mandatory, but more and more clients require it as a requirement. | Yes when applied by RD 311/2022 or by public specifications and contracts. | It depends on sector, size, activity and national transposition; It is advisable to analyze applicability as soon as possible. |
| Indicative deadline | 4–9 months depending on size, maturity and internal availability. | 3–8 months depending on Basic, Medium or High category. | 2–6 months for diagnosis, gap plan and first priority controls. |
| Combination | It is advisable to address them in the same roadmap: inventory, risks, controls, evidence, incidents and suppliers can be reused. | ||
We leave only the essentials at home. The rest is worked on in the initial call.
Yes. They share inventory, risk analysis, controls, evidence, incidents, continuity and suppliers.
With an initial diagnosis: we review the sector, clients, tenders, obligations and current maturity.
No. The first 30-minute review is to orient the case and decide if it makes sense to move forward.