Servicios

Consultoría de ciberseguridad

A customer questionnaire, an auditor's date, a penetration test nobody can rank. Application security, testing and compliance readiness, aimed at the exposure rather than the paperwork.

The questionnaire came attached to a contract, and half of it asks about controls nobody in the building owns. Or a penetration test landed with a page of red findings and no way to tell which one an attacker would reach first. Security work usually begins under somebody else's deadline. The question worth asking is narrower than whether you are secure: what could someone do from where they already stand, and what would stop them.

Paper or exposure

A policy nobody follows changes nothing

Plenty of security spending buys documents: a policy set written against a template and never read, a findings report ageing on a shared drive, a questionnaire answered for the version of the system somebody hoped existed. None of it is dishonest. It does not change what an attacker can do.

  • A finding is closed when the code changes, not when it is acknowledged
  • Every answer on a questionnaire points at something a reviewer can be shown
  • Controls that depend on someone remembering are the ones that quietly stop working
  • Work happens in your repositories and your cloud accounts from the first commit

Compliance is only as good as its evidence

An auditor does not grade your intentions. They ask for the record: who approved that access, when the key was last rotated, what the review of that release found, and they ask for it across a period rather than on the day of the visit. A control that exists in a document but leaves no trace behind it will fail on the second question every time.

Which is why the work aims at the systems rather than the binder. Access reviews that come out of the identity provider, change history that already records who approved what, alerts that prove monitoring was running and not merely configured. Evidence assembled the week before an audit is expensive, and it is the kind a good auditor tends to notice. The sort that falls out of systems working properly costs nothing extra, and it holds up next year too.

Four ways in

Four shapes this work takes

They overlap, and a questionnaire that cannot be answered honestly often turns into a review, which turns into a list of things to fix.

Review

Read the application and its architecture

A reading of the code and the design around it: trust boundaries, how authentication and authorisation are enforced, and where data goes once it leaves the request. The output is a ranked list with the reasoning attached, so your engineers can argue with it rather than receive it.

Testing

Authorised testing, ranked by what is reachable

Scoped testing against agreed targets, carried out only with your written permission and inside a window you set. Findings come back ordered by what an attacker could reach and chain, not by the label a scanner printed. A high-severity issue nothing can reach can wait.

Readiness

Getting ready for someone else's audit

We are not an auditor and cannot certify you; that has to come from an accredited body, and it should. What we do is the preparation: map the framework's requirements onto your systems, find the gaps, fix what is fixable and write down the rest with a plan against it.

Due diligence

Answering the questionnaire that blocks the deal

Your prospect's security team has sent a spreadsheet, and someone in sales is tempted to answer it optimistically. We help you answer it accurately instead, sit on the follow-up call with their engineers, and keep the answers in a form you can reuse for the next one.

What the frameworks ask

FrameworkWhat it asksUsual shortfall
GDPR (EU)Lawful basis, minimisation, breach notificationNo record of what data sits where
KVKK (Türkiye)VERBIS registration, explicit consent, transfer limitsData copied abroad without a lawful basis
SOC 2Your stated controls, evidenced over timeEvidence assembled late, periods with gaps
ISO 27001A management system, not a checklistRisk register written once, never revisited
PCI DSSCardholder data scoped, segmented and scannedScope wider than anyone had assumed
Frameworks overlap more than they differ, so the underlying work is largely shared. The attestation always comes from someone else.

The uncomfortable questions

No. We are not an auditor and cannot issue a certificate or an attestation; depending on the framework that comes from an accredited certification body or a licensed audit firm. A consultancy that offers to do both should worry you. What we do is the readiness work in front of it, and we can sit in the room when the auditor starts asking.

¿No sabes cuál necesitas?

Describe el problema en un párrafo y te diremos qué servicio se aplica realmente.