Need to prove what happened?
An incident, a dismissal, a data leak or open litigation in Spain. We acquire the evidence without altering it, analyse it with a reproducible method and sign an expert report that survives cross-examination. We report in English for your legal and executive teams, and appear before the Spanish court. Party-appointed or court-appointed.
If the incident is live, do not power anything off or rebuild it. Isolate the affected machines from the network and call us before touching the systems: every hour that passes destroys volatile evidence.
Six questions, twenty-two services
Pick the one that looks like your situation. We will tell you what you need, and also what you do not.
We don’t protect servers
We protect your continuity, your contracts, your customers and your reputation. An incident is never paid for in servers: it is paid for in the four things the business runs on, and rarely does only one of them go. That is what we work to prevent.
01 Continuity
A ransomware encryption stops operations for anywhere between three days and three weeks. What decides the length is not the antivirus: it is whether backups were isolated from the domain and whether anyone had ever tested restoring them.Disaster recovery →
02 Contracts
Without ENS conformity you cannot sign with the Spanish public sector. Without evidence of risk management, your financial client will not renew under DORA. Compliance stopped being paperwork: it is the entry requirement to the tender.Regulatory compliance →
03 Customers
GDPR gives you 72 hours to notify a breach, and your customers find out. What decides whether they stay is not that nothing happened: it is that you can state exactly what happened, who it affected and what you closed.Incident response →
04 Reputation
A breach tells its own story. Between «they got in and we do not know what they took» and an expert report with a closed timeline and scope lies the distance between a headline and a press note.Digital forensics →
Offence, defence and compliance from the same team. The people who attack you in the Red Team are the ones who answer the incident and sign the expert report. No subcontracting, no handovers between vendors.
Ongoing consulting, without growing your headcount
THE LATEST ARTICLES FROM OUR BLOG
Information Security Plan for SMEs: How to Design It in 5 Phases
1. Introduction The Information security plan is the most important …
Cybersecurity Training for Businesses: From Awareness to Drills
1. Introduction Cybersecurity training for businesses is the investment with …
Cloud Security Audit: AWS, Azure and Google Cloud Under Control
1. Introduction Cloud security auditing has become a necessity for …
Ransomware Incident Response: What to Do and What Not to Do
1. Introduction Ransomware incident response is one of the most …
THEY TRUST US








