← Kit Consulting

VII · Basic · Security

Basic cybersecurity consulting

Cybersecurity plan for SMEs without basic protection or without a plan fit to their activity, basic ISMS documentation (ISO 27001 and medium-high ENS), and a use case.

Category
Servicio de Asesoramiento en Ciberseguridad (Básico)
Type
Basic
Price
€6,000 (VAT excluded). Annex IV / Acelera Pyme aid amount: €6,000 in segments A, B and C.
Segments
SMEs from 10 to under 250 employees (voucher A €12,000 · B €18,000 · C €24,000).
Coverage
Nationwide Spain · Any productive sector
Advisor
Pedro Armando Manfredi · Kit Digital IA · Barcelona
URL
https://kit-digital-ia.com/kit-consulting/ciberseguridad-basico

What we can offer

What to protect first in a firm of 10 to 250: an AS-IS leadership can read and a plan a small team can apply. We do not sell you a SOC you will not run.

  • Vulnerability analysis: inventory, tests, prioritised list.
  • AS-IS diagram and a leadership report.
  • Protection plan (users, mail, backups, patching).
  • Policies and pentest summary in committee language; a human signs.
  • Continuity and GDPR inventory. Basic ISMS for the next level.

Who it is for

SMEs that need to know what to protect, a response plan, and minimum ISMS docs — not a SOC they will not run.

Activities

  • Risk posture and critical assets/data.
  • Business continuity after incidents.
  • Breach and attack response plan.
  • Short/medium-term cybersecurity strategy.
  • Data-protection and security compliance.
  • Basic ISMS documentation (ISO 27001 and medium-high ENS) for a core service.
  • Use case and AI opportunities in security.

Initial diagnosis

  • Vulnerability analysis: inventory, asset audit, pentesting, findings, and vulnerable devices/services.

Results and deliverables

  • Protection plan: users/passwords, mail/servers/endpoints, anti-ransomware backups, patching.
  • Continuity plan: incidents, vulnerabilities, response, and recovery.
  • GDPR measures: processing-activity register and inventory.

Use case

  • Vulnerability analysis with test results and recommendations.
  • AS-IS information-system diagram and pentest report (method, findings, impact).

How we deliver

  • Pentest and AS-IS that leadership can read, not only IT.
  • A security policy a small team can actually apply.
  • AI drafts policies, the pentest summary, and awareness copy; a human signs. Not a SOC.
  • Basic ISMS docs ready for the advanced or certification service.

Justification: on-site kickoff, work meetings, on-site close with sign-off, technical memo, and evidence per the call. Delivery window: 3 months from Agreement validation. Rules: Orden TDF/436/2024, de 10 de mayo.

Free assessment

Contact