1. Home
  2. Services
Service catalogue · 2026 edition

Cybersecurity services.

One flagship service, twelve services in three families and two platforms of our own.

Penetration testing as a service, offensive security, intelligence and response, and protection of the cloud and the digital workplace. Each service has a code to reference it in proposals and programmes.

Service catalogue · 2026 edition

Twelve services in three families, with the same method and the same platforms.

Engagements with a scope, a schedule and a final report, designed to answer a specific question. Each service has a code to reference it in proposals and programmes, and any of them can be delivered as PTaaS.

Offensive security

We think and act as a real attacker would, with clear rules of engagement and controlled exploitation. The goal is not a list of vulnerabilities but knowing what could really happen in your organisation and what needs fixing first.

OF-01OF-02OF-03OF-04OF-05OF-06
OF-01Manual validation

External penetration testing

What an attacker would see, and achieve, from the Internet.

We simulate real attacks from outside the organisation: networks, web applications, APIs and Internet-facing servers. We identify firewall weaknesses, misconfigurations and exploitable vulnerabilities, and validate every finding by hand with reproducible evidence and specific recommendations.

  • DeliveryRemote
  • ApproachBlack box or grey box
  • FrameworkOWASP WSTG, PTES
  • RecommendedAnnual
See the service page

What's included

  • Reconnaissance and mapping of the exposed surface
  • Vulnerability analysis with manual validation
  • Controlled exploitation, with no denial of service
  • Review of web applications and APIs (OWASP Top 10)
  • Remediation plan prioritised by risk

Deliverables

  • Executive report
  • Technical report
  • Results presentation session
  • Retest of findings
Black, grey or white boxThe approach determines how much information the team receives before starting. Black box: no prior information, like an external attacker starting from zero. Grey box: with credentials or partial information, to go further and assess the risk posed by a legitimate user. White box: full access to code, architecture and configuration, for maximum coverage of critical systems. We recommend grey box for most web and internal pentests: more depth in less time.
OF-02Manual validation

Internal penetration testing

What happens once the attacker is already inside.

Simulates an attack from inside the corporate network: a compromised laptop, a malicious employee or an unmanaged device. We assess servers, workstations, network devices, Active Directory and permissions, plus segmentation and privilege control, to minimise the risk of lateral movement. Delivered entirely remotely, with our probe or a machine provided by the organisation.

  • Delivery100% remote, with probe
  • FrameworkPTES, MITRE ATT&CK
  • RecommendedAnnual
See the service page

What's included

  • Enumeration of the internal network and Active Directory
  • Privilege escalation and controlled lateral movement
  • Review of segmentation and access control policies
  • Analysis of workstations, servers and network devices
  • Recommendations to strengthen internal security

Deliverables

  • Executive report
  • Technical report
  • Results presentation session
  • Retest of findings
OF-03Manual review of critical flows

Source code review

Vulnerabilities caught before they reach production.

Security review of application and service source code, combining automated analysis with manual review of the critical parts: authentication, session management, input handling, cryptography and access control. We detect embedded secrets, vulnerable dependencies and insecure patterns, with fix examples for the development team.

  • DeliveryRemote
  • ScopeWeb, backend and mobile
  • FrameworkOWASP ASVS, CWE Top 25
  • RecommendedBefore each major release
See the service page

What's included

  • Static analysis of the code and its dependencies
  • Detection of embedded secrets, keys and credentials
  • Manual review of the critical flows
  • A fix recommendation per finding, with examples

Deliverables

  • Technical report with findings by file and line
  • Session with the development team
  • Retest of the fixed version
OF-04Controlled simulation

Man-in-the-middle simulation

Can someone listen to, or alter, your company's communications?

Man-in-the-middle attacks remain one of the most common threats on corporate networks. We run controlled simulations to assess how vulnerable your communications are: Wi-Fi security, authentication protocols and data encryption. The report includes concrete solutions such as VPNs, digital certificates and stronger policies.

  • DeliveryOn-site or remote with probe
  • FrameworkPTES, vendor best practices
  • RecommendedAnnual or after network changes
See the service page

What's included

  • Audit of corporate and guest Wi-Fi networks
  • Traffic interception and service spoofing tests
  • Review of authentication and encryption protocols
  • Mitigation measures: VPN, certificates and policies

Deliverables

  • Technical report
  • Mitigation guide
  • Results presentation session
OF-05Training included

Phishing simulation

The human factor, measured and trained.

We design simulated phishing campaigns that replicate the techniques real cybercriminals use, and measure open, click and credential-submission rates by department. Then we provide training to improve the security culture and prevent real incidents.

  • DeliveryRemote
  • OptionalVishing and smishing
  • RecommendedQuarterly or every six months
See the service page

What's included

  • Scenarios tailored to the company
  • Campaigns by email and messaging
  • Metrics by department: opens, clicks and credentials
  • Follow-up awareness training

Deliverables

  • Results report with metrics
  • Awareness session
  • Training material
OF-06Continuous service in TORO

Continuous attack surface discovery

Your exposure changes every week. We keep watch.

A pentest is a photograph; the attack surface is a film. This recurring service periodically identifies every exposed resource of the organisation (domains, subdomains, IP addresses, services, certificates and applications), both those the organisation knows about and those discovered during reconnaissance. Every new asset or relevant change is analysed and reported, and the full picture can be checked at any time in TORO.

  • DeliveryContinuous service
  • PlatformTORO
  • FrequencyWeekly or monthly
  • ComplementsOF-01
See the service page

What's included

  • Inventory of exposed assets and shadow IT
  • Detection of new domains, services and ports
  • Monitoring of certificates, technologies and vulnerable versions
  • Alerts on changes and critical exposures

Deliverables

  • Attack surface dashboard in TORO
  • Alerts on changes
  • Periodic exposure report
A cycle that never stopsEach iteration discovers the exposed assets, analyses the changes since the previous one, reports what matters (a new subdomain, an open port, an expired certificate) and verifies that what was reported has been dealt with. The inventory, with its history, is the starting point for the next external pentest.

Intelligence and response

When something has already happened, or may be happening, what matters is understanding it rigorously: what happened, how, what the impact is and how to stop it happening again. We work with traceable evidence and, when required, with legal validity.

IR-01IR-02IR-03IR-04
IR-01Legal validity

Digital forensics

What happened, how, and with what impact, with evidence that holds up.

Thorough investigations to identify the origin, nature and impact of an attack: recovery of deleted data, analysis of system logs and extraction of digital evidence with legal validity. We determine whether there was unauthorised access, data theft or tampering with systems, and deliver recommendations to strengthen security.

  • DeliveryRemote or on-site
  • ScopeServers, workstations, mobile devices and cloud
  • AvailabilityOn demand
See the service page

What's included

  • Evidence acquisition with chain of custody
  • Analysis of disks, memory, logs and artefacts
  • Reconstruction of the incident timeline
  • Recovery of deleted information

Deliverables

  • Forensic expert report
  • Incident timeline
  • Hardening recommendations
While you contact us
  • Do not switch off or restart the affected machine
  • Do not format, reinstall or run clean-up tools on it
  • Restrict access to the bare minimum
  • Write down who did what, and when
IR-02DARKFORGE forensic module

Email and phishing forensics

Every suspicious email, analysed down to the last header.

We analyse in depth the suspicious or fraudulent emails received by the organisation: full headers, SPF, DKIM and DMARC authentication, the domains, IP addresses and servers involved, links and attachments. We also check your own domain's posture against spoofing and deliver a report that is useful both for decision-making and for documenting the incident to third parties.

  • DeliveryRemote
  • PlatformDARKFORGE
  • ComplementsIR-04 and CL-02
See the service page

What's included

  • Header analysis and SPF, DKIM and DMARC verification
  • Investigation of the domains, IPs and servers involved
  • Analysis of malicious links and attachments
  • Anti-spoofing audit of your own domain

Deliverables

  • Forensic report in PDF or Word
  • Indicators of compromise
  • Recommendations
IR-03Active monitoring in TORO

OSINT threat intelligence

What the Internet already knows about your company, before an attacker uses it.

We collect and analyse public information about the organisation, its key people and potential threats: exposed vulnerabilities, data leaks, leaked credentials and reputational risks. Ideal for preventing targeted attacks, monitoring emerging threats and assessing the digital exposure of the company or its executives. The whole process runs on TORO, which keeps watch between one report and the next.

  • DeliveryRemote
  • PlatformTORO
  • RecommendedAnnual or before a pentest
See the service page

What's included

  • Digital footprint of the organisation and key people
  • Credentials and data leaked in breaches and forums
  • Look-alike domains and brand impersonation
  • Reputational and social engineering risks

Deliverables

  • Exposure report
  • Access to the intelligence dashboard in TORO
  • Footprint reduction recommendations
IR-04Takedown and notifications

Incident response and fraud takedown

Fast containment, clear communication and a documented closure.

We support the organisation during a security incident: containment, eradication and recovery, with clear prioritisation criteria and communication that management can understand. We also handle the takedown of fraudulent domains, websites and profiles impersonating the company, coordinating with registrars, hosting providers and INCIBE-CERT, and prepare the documentation for mandatory notifications.

  • DeliveryRemote or on-site
  • AvailabilityOn demand
  • ComplementsIR-01 and IR-02
See the service page

What's included

  • Triage, containment and eradication
  • Takedown of fraudulent domains and sites
  • Coordination with INCIBE-CERT, providers and registrars
  • Support with regulatory notifications (GDPR, NIS2, DORA)

Deliverables

  • Incident report
  • Evidence dossier
  • Closure report
Notification deadlines we help you meet
  • GDPR: notification to the Spanish data protection authority (AEPD) within 72 hours and communication to those affected when the risk is high
  • NIS2: early warning within 24 hours, notification within 72 hours and final report within one month
  • DORA: initial notification within 4 hours of classifying the incident as major, intermediate report within 72 hours and final report within one month
Indicative deadlines: the specific obligation depends on the type of entity, the incident and the applicable regulation.

Cloud and digital workplace

Infrastructure no longer ends at the perimeter. We audit the cloud environments and collaboration platforms where your company's information lives today, and tell you exactly what to change and how.

CL-01CL-02
CL-01CIS Benchmarks

Cloud security

AWS, Azure and Google Cloud, configured the way they should be.

We audit the security of AWS, Azure and Google Cloud environments: identities and permissions, data encryption, network and service configuration, activity logging and regulatory compliance. The result is the recommended configuration for your environment (MFA, network segmentation, monitoring of suspicious activity) with concrete instructions for your team or your provider to apply.

  • DeliveryRemote
  • FrameworkCIS Benchmarks, provider best practices
  • RecommendedAnnual
See the service page

What's included

  • Review of identities, roles and permissions (IAM)
  • Configuration audit against CIS Benchmarks
  • Encryption, backups and storage exposure
  • Logging, alerts and detection of suspicious activity

Deliverables

  • Audit report
  • Recommended configuration, step by step
  • Retest after the changes
Shared responsibilityThe provider protects the cloud (data centres, hypervisors, managed services and availability); the customer protects what they put in it: identities, permissions and MFA, service, network and storage configuration, data, backups and activity logging. Most cloud incidents stem from misconfigurations and exposed credentials, not from provider failures.
CL-02Step-by-step implementation guide

Microsoft 365 security

Email, SharePoint, OneDrive and Teams, protected against phishing and account takeover.

Collaboration platforms such as Microsoft 365 are frequent targets of phishing and business account compromise. We audit email protection, the configuration of SharePoint, OneDrive and Teams, and the ability to detect suspicious activity. We define the policies, filtering rules and settings needed to prevent unauthorised access, and document them step by step for your team or your provider to apply.

  • DeliveryRemote
  • RecommendedAnnual and after licensing changes
See the service page

What's included

  • Review of conditional access and MFA
  • Email: SPF, DKIM, DMARC and filtering rules
  • SharePoint, OneDrive and Teams configuration
  • Logging and alerts for suspicious activity

Deliverables

  • Audit report
  • Recommended policies and settings
  • Step-by-step implementation guide
Talk to usCall