Six questions, twenty-one services
Pick the one that looks like your situation. We will tell you what you need, and also what you do not.
3 servicesI need to comply with a regulationNIS2, DORA, GDPR, ISO 27001 and PCI-DSS. We tell you what applies to you, what is missing and by when it has to be closed.View services →8 servicesI want to know if they can get inWe attack you the way a real adversary would, with an agreed scope. Pentest, Red Team, applications, WiFi, RFID and phishing.View services →3 servicesI need to detect and respondNIS2 gives you 24 hours to notify. We build the detection capability and the response plan.View services →2 servicesIt already happened to meIncident in progress or open litigation. What happened, how they got in and what they took, with court-admissible evidence.View services →2 servicesI want to build on secure groundAWS, Azure and industrial environments. We design and harden from the start instead of patching afterwards.View services →3 servicesI want to use AI without exposing my dataLanguage models and RAG on your own infrastructure. Your documentation never leaves your network, and never trains anyone else.View services →
Looking for training for your team? See our cybersecurity courses.
Ongoing consulting, without growing your headcount
Who runs your auditWe do not subcontract. The team that audits is the team that signs the report.These are the certifications behind every report we deliver.
Offensive security and Red TeamOSCPCRTOCRTO IIeWPTXeCPPT (100/100)API Penetration TestingHack The Box Pro LabsMaldev Academy
Digital forensics and incident responseeCDFPIncident Forensic Analysis (INCIBE)Court-admissible expert reports
Governance, risk and complianceCISSPISO 27001 Lead AuditorCCSP (ISMS Forum)CDPP (ISMS Forum)Spanish ENS and Risk Analysis (CCN)PMP (PMI)
Industrial and OTCCI Black Level ProfessionalOT Industrial CybersecurityUniversity Postgraduate Course
IntelligenceCyber Intelligence and OSINT (CCN)
Top 1 %on the CCN-CERT Atenea platform
1st placeWeb Hacking · CCN-CERT STIC Conference 2025
WinnersNavaja Negra 2025
Part of our team holds Personnel Security Clearance, a requirement for handling classified information in public administration and defence projects.
THE LATEST ARTICLES FROM OUR BLOG
In our blog we discuss tools, operations, vulnerabilities, etc.
Aug 25, 2026
Linux Server Hardening: Essential Security Checklist
1. Introduction Linux server hardening remains the task with the …
Aug 24, 2026
Applied Cryptography and PKI: Encryption, Signatures and Key Management
1. Introduction Applied cryptography and PKI is the discipline behind …
Aug 23, 2026
Zero Trust Architecture: Enterprise Implementation Guide
1. Introduction Zero Trust architecture has moved from analyst hype …
Aug 22, 2026
Lateral Movement and Persistence: The Decisive Red Team Phase
1. Introduction Lateral movement and persistence Red Team operations mark …
THEY TRUST US







