Vulnerability assessment
Review of systems, exposed services and configurations, with prior written authorisation and an agreed scope.
We assess the technical, human and public exposure of the organisation and its executives, and prepare the response before an incident occurs.
Most incidents do not begin with a sophisticated attack, but with a forgotten configuration, a reused password or a convincing email. Many organisations do not know what information about them is exposed, nor who would decide what to do if they suffered an intrusion tomorrow.
In addition, executives' personal details, domains similar to the company's and fake profiles are common entry points for fraud and impersonation. It pays to know the starting point and to have a plan that works under pressure.
Review of systems, exposed services and configurations, with prior written authorisation and an agreed scope.
Roles, communication channels, containment steps and notification obligations, prepared before they are needed.
Analysis of the public information about the organisation and its executives, always for lawful purposes and in accordance with data protection law.
Review of access, two-step verification, domain management and email configuration.
Detection of domains and profiles that imitate the company, takedown procedures and a protocol for responding to a crisis.
Vulnerability report with risk levels and prioritised measures.
Documented incident response plan, with contacts and procedures.
Digital exposure report on the company and the executives included in the scope.
List of protection measures for accounts, domains and email.
Impersonation procedure and reputational crisis protocol.
Companies that handle customer data, financial information or intellectual property.
Companies with a recognisable brand or executives with a public profile.
Organisations that have suffered an incident, fraud or impersonation.
They are planned with you, with a scope and schedule agreed in writing, and carried out so as not to disrupt operations. Tests that could have an impact are run in agreed environments or time slots.
It is the analysis of publicly accessible information, such as registers, press, websites or professional profiles. It is only carried out for a lawful purpose and with a sufficient legal basis, and never involves accessing protected information.
We help you activate the response plan, coordinate the technical providers and assess notification obligations, for example to the Spanish Data Protection Agency when personal data is affected.
We cannot guarantee it. We can identify the information, assess whether there is a legal basis to request its removal or de-indexing, and prepare the requests or coordinate them with your legal advisers.
We document the case, assess the risk and follow the procedures available with the registrar, the hosting provider or the domain dispute resolution mechanisms.
Risk analysis, compliance and business continuity.
About this serviceCorporate security, personal and travel risk, and coordination with authorised providers.
About this serviceAdvice to management, family wealth and family offices on risk and technology decisions.
About this serviceTell us about your situation. Every enquiry is handled in confidence and, if you prefer, we will sign a non-disclosure agreement before the first meeting.
Request a meeting