VII · Basic · Security
Basic cybersecurity consulting
Cybersecurity plan for SMEs without basic protection or without a plan fit to their activity, basic ISMS documentation (ISO 27001 and medium-high ENS), and a use case.
What we can offer
What to protect first in a firm of 10 to 250: an AS-IS leadership can read and a plan a small team can apply. We do not sell you a SOC you will not run.
- Vulnerability analysis: inventory, tests, prioritised list.
- AS-IS diagram and a leadership report.
- Protection plan (users, mail, backups, patching).
- Policies and pentest summary in committee language; a human signs.
- Continuity and GDPR inventory. Basic ISMS for the next level.
Who it is for
SMEs that need to know what to protect, a response plan, and minimum ISMS docs — not a SOC they will not run.
Activities
- Risk posture and critical assets/data.
- Business continuity after incidents.
- Breach and attack response plan.
- Short/medium-term cybersecurity strategy.
- Data-protection and security compliance.
- Basic ISMS documentation (ISO 27001 and medium-high ENS) for a core service.
- Use case and AI opportunities in security.
Initial diagnosis
- Vulnerability analysis: inventory, asset audit, pentesting, findings, and vulnerable devices/services.
Results and deliverables
- Protection plan: users/passwords, mail/servers/endpoints, anti-ransomware backups, patching.
- Continuity plan: incidents, vulnerabilities, response, and recovery.
- GDPR measures: processing-activity register and inventory.
Use case
- Vulnerability analysis with test results and recommendations.
- AS-IS information-system diagram and pentest report (method, findings, impact).
How we deliver
- Pentest and AS-IS that leadership can read, not only IT.
- A security policy a small team can actually apply.
- AI drafts policies, the pentest summary, and awareness copy; a human signs. Not a SOC.
- Basic ISMS docs ready for the advanced or certification service.
Justification: on-site kickoff, work meetings, on-site close with sign-off, technical memo, and evidence per the call. Delivery window: 3 months from Agreement validation. Rules: Orden TDF/436/2024, de 10 de mayo.