Skip to content

GOVERN · COMPLIANCE & LEADERSHIP

Translate security into business decisions

Strategy, compliance and culture with evidence generated by the same operation, not assembled across three vendors. Reports in financial and reputational impact terms the board actually reads.

NIST CSF 2.0ISO 27001Law 172-13Board of directors
MATURITY BY DOMAIN · NIST CSF 2.0
12-MONTH TARGET
IDENTIFYPROTECTDETECTRESPONDRECOVER
MEASURED LEVEL → ROADMAP → EVIDENCE
SERVICE 01 · LEADERSHIP

Virtual CISO

Tailored executive leadership (C|CISO, CISA, ISO 27001 Lead Auditor, COBIT 2019), with what no external consultant has: live data from your real operation. Risk in the four questions your board already asks: how much can we lose, what does reducing it cost, what is the return, and what happens if we do nothing.

Monthly retainerBoard & committeeBudget & vendors
AT A GLANCE
Dedication 8 to 40 hours a month
Commitment Annual contract
Covers Strategy · committee · budget
Result Governed program with evidence
SERVICE 02 · STRATEGY

Strategic consulting

Where your program stands today, measured against a recognized framework, and what moves the needle in the next twelve months, numbers, not impressions. Includes executive tabletop exercises with the committee.

Measured maturity12-month roadmapExecutive tabletop
AT A GLANCE
Frameworks NIST CSF 2.0 · ISO 27001 · SOC-CMM
Duration 4–6 weeks
Tabletop 3–4 hours with the committee
Result Level per domain + roadmap
SERVICE 03 · COMPLIANCE

Compliance controls assessment

Maturity against NIST CSF and ISO 27001 grounded in your evidence, not an interview: the agentic tool reads policies, records and configurations and backs every level with the document that supports it. The consultant decides and signs the final level, with blind sampling by a senior consultant.

CBRT certified 9001 + 27001Financial sectorCIS IG1
AT A GLANCE
Frameworks ISO 27001:2022 · PCI v4.0 · Law 172-13
Diagnosis From 2 weeks
Certification 90–180 days by maturity
Result Compliance dossier and closure plan
SERVICE 04 · WHEN IT TURNS STRATEGIC

Cyber crisis management

When the incident stops being technical and turns strategic: who decides, what is said, to whom and when, with reputation at stake.

Crisis committeeTrained spokespeopleAnnual drill
AT A GLANCE
Preparation Committee & spokespeople in 6–8 weeks
Activation Crisis team in < 4 h
Covers Decision · communication · regulator
Includes Annual drill with media pressure
SERVICE 05 · HUMAN FACTOR

Awareness, education & culture

A continuous program on the SMARTFENSE platform: interactive modules, phishing and ransomware simulations, educational moments and targeted reinforcement, content adapted to the active threats our intelligence reports, including those powered by generative AI.

Simulated phishingCyberAcademyContent in Spanish
AT A GLANCE
Cadence Monthly campaign + quarterly training
Metrics Click · credentials · reporting
Platform SMARTFENSE · content in Spanish
Result Trend per area and reinforcement
SERVICE 06 · EXECUTIVE DRILL

Tabletop Exercises

Your crisis committee faces a realistic scenario, ransomware, data leak, compromise of a critical third party, designed with your industry actor's TTPs and led by facilitators who respond to real incidents. AI agents generate dynamic injects that adapt the scenario to the decisions your team makes.

Dynamic AI injects3–4 hoursEvidence for the regulator
AT A GLANCE
Duration 3–4 hours + report
Participants 8 to 20 · committee, IT, legal, comms
Scenario Ransomware · leak · critical third party
Result Decision report and improvement plan

Reports the board actually reads.

We don't make you earn more money, we make sure you don't lose it.