VIII · Advanced · Security
Advanced cybersecurity consulting
For SMEs that already have basic protection and a plan, and want stronger protection, daily procedures, and a use case.
What we can offer
A firm of 10 to 250 that already closed basic cyber: MFA, monitoring and awareness without a department of 20. A human or an MSSP runs monitoring.
- TO-BE: MFA, VPN/VDI, encryption, active monitoring.
- Awareness plan (acceptable use, simulated phishing).
- Managed-security benchmark for SMEs.
- Phishing campaign and policy review; a human signs.
- ISMS scope and roles. Only after basic.
Who it is for
SMEs that closed the basic service and need MFA, active monitoring, awareness, and a security TO-BE.
Activities
- Pentesting and vulnerability analysis in the real environment.
- Daily procedures and tools for acquisition, configuration, prevention, detection, and response.
- Proactive data protection and response capacity.
- Awareness, security culture, and risk management.
- AI opportunities and a security use case.
Initial diagnosis
- Vulnerability analysis with risk classification and measures to adopt.
Results and deliverables
- Advanced security policy: encryption and cloud, backup, VPN/VDI, MFA.
- Active monitoring of networks, services, and email.
- Awareness plan (acceptable use, materials, phishing simulations).
- Policy review, ISMS scope, ENS categorisation, leadership roles.
- Support to contract managed security (protect, detect, respond).
Use case
- AS-IS and TO-BE diagrams, recommendations, and a service benchmark (live vulnerability management and incident response).
How we deliver
- Security-architecture TO-BE and an operable awareness plan.
- Managed-security vendor benchmark with SME criteria.
- AI drafts the phishing campaign, committee TO-BE, and policy diff; a human or an MSSP runs monitoring.
- Evidence and memo per Annex IV.
Annex IV limits
- Requires a prior Agreement for Cybersecurity (basic).
- Delivery starts after the basic service is finished and justified.
Justification: on-site kickoff, work meetings, on-site close with sign-off, technical memo, and evidence per the call. Delivery window: 3 months from Agreement validation. Rules: Orden TDF/436/2024, de 10 de mayo.