DRYKO Risk & Advisory

Digital risk and cybersecurity

We assess the technical, human and public exposure of the organisation and its executives, and prepare the response before an incident occurs.

The challenge

Most incidents do not begin with a sophisticated attack, but with a forgotten configuration, a reused password or a convincing email. Many organisations do not know what information about them is exposed, nor who would decide what to do if they suffered an intrusion tomorrow.

In addition, executives' personal details, domains similar to the company's and fake profiles are common entry points for fraud and impersonation. It pays to know the starting point and to have a plan that works under pressure.

What we do

01

Vulnerability assessment

Review of systems, exposed services and configurations, with prior written authorisation and an agreed scope.

02

Incident response plan

Roles, communication channels, containment steps and notification obligations, prepared before they are needed.

03

Digital exposure (OSINT)

Analysis of the public information about the organisation and its executives, always for lawful purposes and in accordance with data protection law.

04

Account and domain security

Review of access, two-step verification, domain management and email configuration.

05

Impersonation and reputational crises

Detection of domains and profiles that imitate the company, takedown procedures and a protocol for responding to a crisis.

Deliverables

Vulnerability report with risk levels and prioritised measures.

Documented incident response plan, with contacts and procedures.

Digital exposure report on the company and the executives included in the scope.

List of protection measures for accounts, domains and email.

Impersonation procedure and reputational crisis protocol.

Who it is for

01

Companies that handle customer data, financial information or intellectual property.

02

Companies with a recognisable brand or executives with a public profile.

03

Organisations that have suffered an incident, fraud or impersonation.

Frequently asked questions

Can the technical tests affect our systems?

They are planned with you, with a scope and schedule agreed in writing, and carried out so as not to disrupt operations. Tests that could have an impact are run in agreed environments or time slots.

What is open-source intelligence and what are its limits?

It is the analysis of publicly accessible information, such as registers, press, websites or professional profiles. It is only carried out for a lawful purpose and with a sufficient legal basis, and never involves accessing protected information.

What happens if we suffer an incident during the project?

We help you activate the response plan, coordinate the technical providers and assess notification obligations, for example to the Spanish Data Protection Agency when personal data is affected.

Can you remove information from the internet?

We cannot guarantee it. We can identify the information, assess whether there is a legal basis to request its removal or de-indexing, and prepare the requests or coordinate them with your legal advisers.

What is done about a domain that imitates ours?

We document the case, assess the risk and follow the procedures available with the registrar, the hosting provider or the domain dispute resolution mechanisms.

Let us discuss your case

Tell us about your situation. Every enquiry is handled in confidence and, if you prefer, we will sign a non-disclosure agreement before the first meeting.

Request a meeting