Managed IT services / Cybersecurity
Security that
doesn’t wait for the attack.
We protect your business in layers —people, devices, email, network, access and data—, detect threats before they become an incident and train your team. Less risk, more continuity, no surprises.
What layered security is
Defence in depth,
not a single wall.
Cybersecurity is not a product you install and forget: it is a way of operating. No single control stops every attack, so we do not rely on one wall. We work with defence in depth: several layers that cover each other, so that if one fails, the next keeps protecting.
Those layers cover the whole path of an attack. The people, with training and simulations, because the team’s judgement stops what technology cannot see. The endpoints —laptops and phones—, with EDR protection and encryption. The email, the most-used way in, with filtering and anti-phishing. The network, with firewall and segmentation so a problem does not spread. The access, with MFA and identities under least privilege. And the data, with encryption, tested backups and logs of who does what.
The goal is not to promise that nothing will ever happen —that does not exist—, but to reduce risk to a reasonable level and be ready to detect and respond quickly when something does. It is part of ourmanaged IT services: security operated continuously, with a predictable fee and no surprises.
Problems it solves
Where attackers
really get in.
Phishing and email fraud
Most attacks start with an email that looks legitimate. One click, a password typed where it should not be, and someone is already inside.
Ransomware
Software that encrypts your files and demands a ransom can halt the whole company in hours. Recovering without a tested plan is slow and expensive.
Weak passwords and no MFA
Reused, written-down or leaked passwords are still the most-used door. Without a second factor, a single stolen key is enough to get in.
Unprotected endpoints
Laptops and phones without EDR or updates are the easiest link. Every unprotected device is an open way in.
No visibility of threats
If no one is watching, an attacker can spend weeks inside without you knowing. Without detection and logs, you find out when it is too late.
Untrained employees
Technology stops a lot, but people’s judgement stops the rest. A team that cannot spot a scam is the most vulnerable point.
What’s included
The layers we
put in place.
A managed cybersecurity service combines protection, detection, response and people. These are the pieces:
- Endpoint protection (EDR)
- Email security (anti-phishing)
- MFA and identity management
- Firewall and network segmentation
- Patch and update management
- Detection and incident response
- Training and phishing simulations
- Policies and compliance (GDPR, ISO 27001)
Attack vectors and defence
Every threat,
its response.
| Attack vector | How it works | How we defend it |
|---|---|---|
| Phishing | Emails or messages that impersonate someone trusted to steal credentials or slip in malware. | Email filtering, anti-phishing, MFA and training with simulations so the team recognises it. |
| Ransomware | Encrypts your files and demands a ransom; it usually gets in via email or an unpatched machine. | EDR that stops the encryption, patches up to date, network segmentation and tested backups. |
| Credential theft | Reused, weak or leaked passwords that give direct access to email and systems. | MFA everywhere, identity management with least privilege and a Zero Trust approach. |
| Compromised endpoints | Laptops and phones without protection or updates become the way in. | Endpoint protection (EDR/XDR), disk encryption, device policies and automatic patching. |
| Insider threat | An employee —by mistake or intent— with more permissions than needed exposes data. | Least privilege, auditable logs, access monitoring and clear policies. |
In one line
Security isn’t a product: it’s a way of operating.
Benefits and outcomes
What you can
expect.
Less breach risk
We close the most-used ways in —email, credentials, unpatched endpoints— before anyone can take advantage of them.
Easier compliance
Policies, controls and auditable logs that move you toward the GDPR, ISO 27001 or the ENS without starting from scratch each time.
Business continuity
Early detection, response with a plan and tested backups: an incident stops being a multi-day outage and becomes a contained scare.
Customer trust
Being able to show you protect the data entrusted to you is increasingly a condition for working with clients and partners.
Fast response
When something fires, everyone knows what to do: isolate, contain and recover per a plan defined in advance, not improvised.
Predictable cost
A clear fee based on users and scope. You invest in prevention, which is always cheaper than an incident.
Framework and approach
What we
work with.
We don’t apply everything to everyone: we start from your real risk and prioritise what protects most for the least effort.
The CPPA methodology
From exposure
to peace of mind.
Assess risk and surface
We start by understanding what needs protecting: users, devices, access, data and exposed services. We identify the real risks and prioritise by impact, not by fear.
Prioritise and protect in layers
We secure first what protects most for the least effort: MFA, EDR, email security and patches. Each layer covers what the previous one misses, without slowing daily work.
Monitor and respond
We watch continuously, with detection and auditable logs. When something fires, we act: isolate, contain and recover according to a plan defined in advance.
Train and improve
Security is not a project you close. We train the team, run phishing simulations and review the controls as the threats change.
Examples
How it looks
in practice.
MFA + EDR rollout
- Inventory of users, devices and access
- Enable MFA on email and critical systems
- Install EDR on every endpoint
- Device policies and disk encryption
- Verify and close orphaned access
Phishing simulation and training
- Controlled send of a simulated phishing email
- Measure who clicks and who reports it
- Short, practical training for the team
- Repeat regularly to measure the improvement
Incident response
- Detection and alert from EDR and monitoring
- Isolation of the affected machine
- Analysis of scope and containment
- Eradication and recovery from backup
- Report and measures so it does not recur
Compliance plan
- Assessment against GDPR, ISO 27001 or ENS
- Inventory of data, processing and risks
- Policies, controls and auditable logs
- Prioritised, verifiable improvement plan
Risks and mitigation
Every risk,
its countermeasure.
Security is not about fear, but about closing specific gaps. These are the ones we see most and how we mitigate them:
The human factor
No tool makes up for a wrong click. We mitigate it with continuous training and phishing simulations that turn the team into the first line of defence.
Unprotected endpoints
A laptop without protection is an open door. We cover it with EDR/XDR, disk encryption and automatic patching on every device.
Uncontrolled identities
A stolen password should not be enough to get in. We prevent that with MFA everywhere, least privilege and a Zero Trust approach.
No threat visibility
What you cannot see, you cannot stop. We solve it with continuous monitoring, auditable logs and a clear response plan.
Email as the way in
Most attacks arrive by email. We filter them with email security and anti-phishing before they reach the inbox.
Unpatched software
An unpatched system is a known vulnerability waiting to be used. Patch management closes those gaps before they are exploited.
Frequently asked questions
Is antivirus enough on its own?
What are MFA, EDR and Zero Trust?
Do you train employees?
What do I do if I get attacked?
Are you GDPR and ISO 27001 compliant?
How much does it cost?
Related services
Keep exploring.

Backup and recovery
The last line of defence against ransomware: automatic backups and a tested recovery plan so a disaster does not stop you.
View →
IT support
Managed helpdesk and support that resolves quickly, with clear SLAs and no one left stranded when something breaks.
View →
IT infrastructure
Servers, networks and systems designed, segmented and maintained to be stable and secure by design.
View →Do you know how attackers could get in?
Request a proposal →Want to see how we think about a connected, secure operation end to end? Read ourCPPA X-RAY on 100 Montaditos.
