Managed IT services / Cybersecurity

Security that
doesn’t wait for the attack.

We protect your business in layers —people, devices, email, network, access and data—, detect threats before they become an incident and train your team. Less risk, more continuity, no surprises.

What layered security is

Defence in depth,
not a single wall.

Problems it solves

Where attackers
really get in.

What’s included

The layers we
put in place.

A managed cybersecurity service combines protection, detection, response and people. These are the pieces:

Attack vectors and defence

Every threat,
its response.

In one line

Security isn’t a product: it’s a way of operating.

Benefits and outcomes

What you can
expect.

Framework and approach

What we
work with.

The CPPA methodology

From exposure
to peace of mind.

01

Assess risk and surface

We start by understanding what needs protecting: users, devices, access, data and exposed services. We identify the real risks and prioritise by impact, not by fear.

02

Prioritise and protect in layers

We secure first what protects most for the least effort: MFA, EDR, email security and patches. Each layer covers what the previous one misses, without slowing daily work.

03

Monitor and respond

We watch continuously, with detection and auditable logs. When something fires, we act: isolate, contain and recover according to a plan defined in advance.

04

Train and improve

Security is not a project you close. We train the team, run phishing simulations and review the controls as the threats change.

Examples

How it looks
in practice.

Risks and mitigation

Every risk,
its countermeasure.

Security is not about fear, but about closing specific gaps. These are the ones we see most and how we mitigate them:

Frequently asked questions

Is antivirus enough on its own?
Not today. Traditional antivirus detects known threats by their signature, but current attacks change constantly and many leave no file to scan. That is why we work in layers: EDR on the endpoints (which watches behaviour, not just signatures), email security, MFA, patches and monitoring. Each layer covers what the previous one misses.
What are MFA, EDR and Zero Trust?
MFA (multi-factor authentication) is a second factor on top of the password —a code or an app— so a stolen key alone is not enough to get in. EDR (endpoint detection and response) watches the behaviour of each device and can stop an attack in progress, such as ransomware encryption. Zero Trust is a principle: grant no access by default, always verify, and give only the minimum needed.
Do you train employees?
Yes, and it is one of the highest-impact parts. Most incidents start with an email. We run practical training and controlled phishing simulations: we send a simulated email, measure who clicks and who reports it, and train on what we learn. It repeats regularly so the improvement is real and measurable, not a one-off talk.
What do I do if I get attacked?
Act fast and with a plan. With our monitoring, many incidents are detected and contained before they cause harm. If something does happen, we follow a response plan: isolate the affected machine, analyse the scope, contain, eradicate and recover from backup. Afterwards we produce a report with the measures so it does not recur. Having this plan defined in advance is the difference between a scare and a multi-day outage.
Are you GDPR and ISO 27001 compliant?
We design and operate in line with the GDPR: least privilege, encryption in transit and at rest, auditable logs and processing agreements. We also help prepare and maintain frameworks such as ISO 27001 or the Spanish ENS: assessment against the standard, policies, controls and a verifiable improvement plan. Compliance stops being a document and becomes a way of operating.
How much does it cost?
We work with a predictable fee based on the number of users and devices and the scope of the service. First we run a risk assessment to size what you need —no more, no less— and prioritise what protects most for the least effort. You know what you pay each month and what it includes, with no surprises.

Do you know how attackers could get in?

Request a proposal

Want to see how we think about a connected, secure operation end to end? Read ourCPPA X-RAY on 100 Montaditos.