Frequently Asked Questions

Do we have to sign a long-term contract?

No. Most of our services are closed projects with a concrete deliverable. If there's an ongoing relationship, it's formalized through a managed service agreement, always with defined terms and a flexible exit.

Do you work with companies of all sizes?

Yes. We have clients ranging from 5-person startups to Ibex35 companies. We adapt the scope and price to each organization's reality.

What sets QuantumSec apart from other cybersecurity companies?

Offensive specialization and closeness. We're not a generalist integrator. We're a technical team that understands the language of attackers, translates it into business terms and supports the client throughout the process, not just when we deliver the report.

How do you guarantee confidentiality?

We sign an NDA before starting any work. All access and tests are documented and carried out strictly within the agreed scope.

How much does a penetration test cost in Spain?

The price depends on the scope: number of IPs, URLs, applications and depth of the analysis. A standard web pentest is usually between 1,500 EUR and 5,000 EUR. More complex projects such as a Red Team or a full infrastructure pentest can exceed that. We always start with a free first call to give you a quote tailored to your reality.

Can pentesting affect the availability of my systems?

We define the scope precisely before starting. By default, we avoid actions that could interrupt the service (DoS, data deletion). If any test carries potential risk, we agree it with you and run it during a maintenance window.

What's the difference between a pentest and a vulnerability assessment?

A vulnerability assessment is an automated scan that detects possible flaws but doesn't verify or exploit them. A pentest goes further: a human expert confirms the vulnerability is exploitable, demonstrates its real impact and assesses whether it allows escalating the attack. The result is far more actionable.

What's the difference between a pentest and ethical hacking?

A penetration test is a technical test scoped to one specific system or surface: a web app, an API, a network. Ethical hacking is a broader assessment that combines multiple vectors — OSINT, external perimeter, internal network, privilege escalation — to simulate a full attack campaign against your organization. If you need to assess a specific system, choose penetration testing; if you want to know how far a real attacker would get across your whole organization, choose ethical hacking.

What information do you need to start?

It depends on the type of test. For a black-box pentest, we only need the URLs or IPs in scope. For grey or white box, we may need test credentials, source code access or architecture documentation. We agree everything before starting.

How long does a pentest take?

Between 3 and 10 business days for the technical phase, depending on the scope. The report is usually delivered 2-3 days later. For Red Team projects or complex infrastructures, the timeline can extend.

How do I hire a penetration test for my company?

The process is simple: you describe your environment (URLs, IPs, applications or internal network in scope), we hold a free initial call to understand your needs, and within 24-48 hours you receive a proposal with scope, methodology and price. No fine print, no charges for the initial analysis.

Do you do black, grey or white box testing?

All three. Black box simulates an external attacker with no prior information. Grey box includes standard user credentials to assess access control. White box includes access to the code and architecture and allows a more exhaustive analysis. Most clients choose grey box as a balance between realism and coverage.

Do you assess WordPress and other CMS?

Yes. WordPress is the most attacked CMS in the world precisely because of the proliferation of vulnerable plugins. We assess the core, the installed plugins, the themes, the server configuration and the admin panel access practices.

Can you sign an NDA before starting?

Always. Before you share any data about your infrastructure, we sign a confidentiality agreement.

What happens if you find critical vulnerabilities?

We notify you immediately (same day) if we find something that poses a serious and immediate risk to your business, without waiting for the full test to finish.

Do you need access to the API documentation (Swagger/OpenAPI)?

It's useful but not essential. We can work in black-box mode by intercepting the traffic of the application that consumes the API. Documentation speeds up the process and improves coverage.

Do you audit internal APIs or only internet-facing ones?

Both. In fact, internal APIs are frequently the most vulnerable because it's wrongly assumed that only employees use them. Lateral movement in an attack usually leverages exactly this type of API.

What's the difference between auditing a REST API and a GraphQL one?

GraphQL has specific attack vectors: introspection can reveal the entire data schema, batching enables application-level DoS, and field-level authorization is harder to implement correctly. We cover both with adapted methodologies.

How long does an API audit take?

Between 3 and 7 business days for the technical phase, depending on the number of endpoints and the complexity of the authentication and business flows.

Do you need the app's source code?

It is not essential. We can work from the binary alone (APK or IPA) for the static analysis. Source code, when available, allows a deeper and more efficient review.

Do you audit both iOS and Android apps?

Yes. We work with both platforms. iOS requires jailbroken devices or the use of the simulator for certain dynamic analyses. Android is more accessible for emulator-based analysis.

What impact does it have on store publication?

None directly. The audit is carried out on a test build or the production version already published. Fixes are implemented before the next release.

Can you audit just the API without analysing the app?

Yes. If your app has already been audited or your concern is the backend, we can focus solely on the API. See our API pentesting service.

Do you need admin access to run the audit?

Not necessarily. We can start with a standard user account to simulate exactly what an attacker who has compromised a workstation would do. Depending on the agreed scope, we can escalate to higher privileges in a controlled way.

What impact does the audit have on the production environment?

Minimal. By default we avoid any destructive action or anything that could cause mass account lockouts or service interruptions. Everything is agreed in advance.

Do you also harden AD once the problems are identified?

The audit includes detailed remediation instructions. If you need us to implement the fixes directly, we can quote it as an additional service.

How often should Active Directory be audited?

At least once a year and after major infrastructure changes (migrations, new business units, mergers). More dynamic environments should do it every 6 months.

What's the difference between an audit and a penetration test?

Penetration testing focuses on exploiting vulnerabilities to confirm their real impact. An audit has a broader scope: it reviews configurations, policies, regulatory compliance and overall security posture, not just exploitable technical vulnerabilities.

Can you audit just one specific part?

Yes. We can limit the scope to a single application, a network segment, the code of a specific module or a cloud provider's configuration. We have no mandatory minimum scope.

Can the report be presented to clients or regulators?

Yes, as long as the regulator accepts third-party reports. We structure it with the formality needed for that purpose. If the regulator requires a specific format, we can adapt it.

Will employees know it's a simulation?

Not during the campaign. The learning effect is much greater when the employee discovers, after clicking, that it was a test. It's handled with care: employees aren't publicly identified or penalized, only trained.

Do you need access to our email server?

We need our sending infrastructure to be whitelisted so emails reach inboxes correctly. It's a simple technical process we manage together with you.

What happens to the data on who clicked?

Data is handled with strict confidentiality. The report can be presented anonymized by department if you prefer, without identifying individual employees.

How often should these simulations be run?

The recommended minimum is 2-3 campaigns per year. Awareness fades over time if it isn't reinforced. Ideally it's complemented with short, periodic training modules.

Is NIS2 already in force in Spain?

The directive was due to be transposed into national law before October 2024. Spain is in the process of transposition. Although the specific national law may be pending, the directive already creates obligations for covered entities. The prudent move is to comply now.

What are the penalties for NIS2 non-compliance?

For essential entities: up to €10 million or 2% of global annual turnover, whichever is higher. For important entities: up to €7 million or 1.4% of global turnover.

How does NIS2 differ from the previous NIS1 directive?

NIS2 expands the sectoral scope, increases reporting obligations (notification within 24/72 hours), raises penalties, includes personal liability for management bodies and adds supply chain requirements.

Do we need a pentest to comply with NIS2?

NIS2 requires assessing security risks and applying appropriate technical measures. Penetration testing is one of the most solid ways to meet that obligation in a documented and verifiable way.

How long does it take to comply with NIS2?

It depends on your starting point. Companies with a solid security baseline can complete the process in 3-6 months. Organizations starting from scratch may need 12-18 months for full compliance.

How does DORA differ from NIS2?

NIS2 is a horizontal directive affecting multiple sectors. DORA is a sector-specific regulation for the financial sector, with more detailed and technical requirements, especially regarding resilience testing (TLPT) and ICT provider management.

What is TLPT testing and who must perform it?

TLPT (Threat-Led Penetration Testing) is advanced intrusion testing based on real threat intelligence, targeting the entity's most critical systems. It's only mandatory for significant entities designated by the competent authorities. We can run it with the TIBER-EU methodology.

Does DORA also affect technology providers of financial entities?

Yes. DORA establishes a direct oversight regime for critical ICT providers. And even if you're not a critical ICT provider, if you're a technology provider to a financial entity, they will require you to include DORA contractual clauses in the service agreement.

What's the difference between an ENS declaration of conformity and certification?

The declaration of conformity is an internal document the entity itself issues stating that it complies with the ENS. Certification is issued by a certification body accredited by ENAC after a formal audit. Some public contracts require certification, others accept the declaration.

How often must ENS certification be renewed?

ENS certification is valid for 2 years, with annual follow-up audits.

What if the systems are BASIC category?

BASIC category systems have a less demanding but equally mandatory set of measures. Conformity can be demonstrated through a properly documented internal audit.

Can I hire QuantumSec for the ENS audit, or does it have to be an official body?

Formal ENS certification must be issued by an ENAC-accredited certification body. Our service is the preparatory consulting: gap analysis, system classification, implementing controls and preparing all documentation so the certification audit passes on the first attempt.

Can network pentesting disrupt my services?

Under normal conditions, no. We agree on the scope and exclude disruptive actions. The more aggressive tests are scheduled within maintenance windows. If you operate 24/7, we define windows outside peak hours.

What is the difference between an internal and a perimeter audit?

The perimeter audit analyses what an external attacker sees from the Internet: open ports, exposed services, DMZ configuration. The internal audit simulates an attacker already inside —a malicious employee, a stolen credential— and that is where the most critical findings appear.

How often should I audit the network?

At least once a year, and whenever there are significant changes to the infrastructure: new sites, a change of provider, a cloud migration or an expansion of the corporate WiFi network.

What network size can be audited?

We audit everything from networks of 20 hosts to enterprise environments with thousands of devices. The scope and price are tailored to the real size of your infrastructure.

Do we have to give you access to the repository?

Yes, we need read access to the repository. We sign an NDA beforehand and all access is documented. You can create a dedicated branch or fork for the review if your policy requires it.

Which languages and frameworks do you support?

JavaScript/TypeScript (Node.js, React, Angular, Vue), Python (Django, FastAPI, Flask), Java (Spring), PHP (Laravel), Ruby (Rails), Go and .NET (C#). If you work with another stack, ask us.

How long does it take?

Between 3 and 8 business days depending on the codebase size. A 30,000-line project can be reviewed in about 4 days. Larger projects require more time or a review focused on critical modules.

Do you also review infrastructure as code (IaC)?

Yes. We review Terraform, CloudFormation, Kubernetes manifests and Dockerfiles to detect insecure configurations in infrastructure defined as code.

What happens if an employee falls for the phishing attempt?

Nothing negative. The goal is educational, not punitive. The employee will see a notice page explaining they just took part in an exercise and what signs they should have noticed.

How often should this be done?

At least twice a year to maintain alertness. Organizations with higher exposure or that handle sensitive data should do it quarterly.

Can we exclude certain departments?

Yes. We can segment the scope by department, access level or any criteria you need.

Can you help us with several regulations at once?

Yes, and it makes sense to do so. Many controls in ISO 27001, NIS2 and DORA overlap. Handling them in an integrated way avoids duplication and reduces overall effort.

Do you also run the certification audit?

We're not a certification body (that requires ENAC accreditation), but we work with the main certifying entities and support you throughout the process.

How long does a compliance project take?

It depends on the regulation and your starting point. A gap analysis takes 2-4 weeks. A full ISO 27001 project from scratch takes between 6 and 12 months for an SME.

Is the ENS mandatory for private companies?

The ENS is mandatory for public administrations and private companies that provide ICT services to the administration or process publicly owned data.

ISO 27001:2013 or ISO 27001:2022? Do we need to migrate?

The current version is ISO 27001:2022. Certificates issued under the 2013 version had until October 2025 to migrate. If you're just starting, go straight for the 2022 version.

How many internal resources does the project require?

You need an internal owner (usually the CISO or IT manager) with around 4 to 8 hours per week. The technical team takes part occasionally during the implementation of controls.

Does the ISO 27001 certificate have an expiry date?

The certificate is valid for 3 years, with annual surveillance audits (years 1 and 2) and a recertification audit in year 3.

Can you carry out the annual surveillance audits?

Yes. We offer maintenance contracts for surveillance audits, ISMS updates when things change and preparation for the three-yearly recertification.

Does AI pentesting affect the model's performance in production?

No. Testing is carried out in a staging environment or with controlled traffic. We never interfere with real users or degrade the service.

Do I need access to the model or only to the interface?

It depends on the scope. A black box test only requires access to the final interface. A full pipeline test requires access to the system code and the model configuration.

Do you cover open-source models deployed on-premise?

Yes. We assess both cloud models (OpenAI, Anthropic and Google APIs) and open-source models (Llama, Mistral, Qwen) deployed on your own infrastructure.

Do you need admin credentials for cloud pentesting?

For a complete test, yes, we need an account with read permissions over all services. We can also perform a black-box test from the internet to assess external exposure. We recommend combining both approaches.

Can pentesting affect my production services?

We coordinate all tests to minimize impact. Destructive exploitation (deletion, data modification) always requires explicit approval and is done in test environments.

Do you cover multi-cloud architectures?

Yes. We have experience in environments combining AWS, Azure and GCP, as well as hybrid cloud + on-premise configurations.

Do you need physical access to the device?

For a full test, yes. Some analyses (backend API, mobile app, network communications) can be carried out remotely, but firmware and hardware analysis requires the physical device.

Can you carry out the pentest without affecting industrial production?

We always work with the OT team to define maintenance windows and run the more invasive tests outside production hours. The safety of operations is our priority.

Do you carry out assessments to comply with the RED (Radio Equipment Directive)?

Yes. We help manufacturers prepare the technical security documentation required by the EU's RED directive for IoT devices.

Do you need the source code or just the IPA?

We can work with just the IPA (black/grey box). If you provide the source code, the analysis is deeper and more efficient. We recommend code access for development teams that want actionable results.

Does the test require a physical jailbroken device?

For full dynamic analysis, yes, we recommend a jailbroken device. We can also work with simulators for part of the static and network analysis.

Do you cover the backend API the app uses?

Yes, we include the assessment of the backend API within the scope of the mobile pentest. It is essential for a complete assessment, as many vulnerabilities live in the server layer.

Do you need the source code of the Android app?

It is not essential. We can work directly with the APK through black/grey box analysis. The source code allows a deeper analysis, especially for detecting business logic vulnerabilities.

Can you run the test without a physical device?

Part of the analysis (static and network) can be performed with emulators. For full dynamic analysis with Frida and hardware-backed security analysis, we recommend a rooted physical device.

Does the audit help with GDPR compliance in Android apps?

Yes. We identify where personal data is stored and transmitted, whether it is adequately protected and which permissions are excessive or unnecessary, all of which is key to a privacy impact assessment (DPIA).

Is the CTI service continuous or one-off?

It's an ongoing monitoring service. One-off intelligence (an exposure report or an analysis of a specific threat actor) is also available as an ad-hoc service.

How does CTI integrate with our existing security systems?

We provide feeds in standard formats (STIX/TAXII, CSV, JSON) that integrate with major SIEMs (Splunk, Microsoft Sentinel, QRadar) and SOAR platforms.

What's the difference between CTI and OSINT?

OSINT is a source (information from open sources). CTI is a full process: collection from multiple sources (OSINT, dark web, private feeds), analysis, contextualization and production of actionable intelligence for decision-making.

Do you need to be physically on our premises?

For the full assessment, yes. Wireless network analysis requires physical presence. We schedule visits at times that minimize disruption to your operations.

Does the WiFi audit include guest networks?

Yes, we include every wireless network within the perimeter: corporate, guest, IoT and any unauthorized network we detect.

Do you also assess the security of devices connected to the WiFi?

The standard scope covers the wireless infrastructure. If you want to include an assessment of connected devices (IoT, PCs, printers), we extend it as part of an internal network pentest.

What's the difference between an MSSP and an IT maintenance contract?

An MSSP focuses exclusively on security: threat detection, vulnerability management, incident response and regulatory compliance. We don't manage infrastructure or end-user support.

What's the SLA for incident response?

For critical incidents, the initial response time is under 4 hours. For high-impact incidents, we guarantee forensic analysis begins the same day.

Does the service include the annual pentest?

Yes, mid and top-tier plans include an annual pentest with an agreed scope. It's the ideal combination: continuous monitoring plus periodic offensive assessment.

Is AI-powered pentesting as rigorous as manual testing?

It is more rigorous in coverage (AI does not tire and never skips steps) and less so in pure creativity. That is why we combine both: AI guarantees systematic coverage while the human expert brings creativity, context and advanced exploitation.

Which AI tools do you use?

We combine proprietary tooling with recognised industry solutions, tailored to each type of assessment. We do not rely on a single vendor or on generic AI tools that have not been validated for security work.

Is it cheaper than traditional pentesting?

Generally yes, because automation reduces the hours spent on manual reconnaissance. But the main value is not the cost: it is the broader coverage achieved in the same amount of time.

Is a vulnerability assessment enough to comply with NIS2 or ISO 27001?

It depends on the required maturity level. NIS2 and ISO 27001 require continuous vulnerability management, which a recurring VA can cover. To demonstrate real impact or prepare for Red Team evaluations, pentesting is required.

How often should I run a vulnerability assessment?

We recommend a monthly cycle for critical assets and quarterly for the rest. After significant infrastructure changes (a new application, cloud migration, etc.) we always recommend a one-off assessment.

Does the VA include web applications?

Yes. The scope can include network infrastructure, servers, web applications and APIs. We also offer the vulnerability assessment as a first step before a full web pentest.

What's the difference between external ethical hacking and a network pentest?

External ethical hacking focuses exclusively on what's visible from the internet, starting from zero (no credentials or prior access), including OSINT. A network pentest covers both the external perimeter and the internal network.

Does it include OSINT on employees?

Yes, within the agreed scope. We identify employee data exposed in breaches, LinkedIn and other sources that a real attacker would use for targeted attacks or credential stuffing.

Can it detect if we've already been compromised?

An active compromise assessment is a different service. However, if during reconnaissance we detect indicators of prior compromise, we notify you immediately.

What starting point is used for internal ethical hacking?

We typically simulate a standard domain user (the most realistic scenario: a compromised employee or an attacker with initial access via phishing). We can also start from physical network access (a network cable) or from an unprivileged account on the machine.

Can the test affect production systems?

We coordinate all testing with the IT team. The most invasive techniques (such as modifying AD) are only performed with explicit authorization and within agreed windows. The goal is to simulate an attack, not to cause damage.

What is BloodHound and why does it matter?

BloodHound is the industry-standard tool for analyzing Active Directory relationships and finding privilege escalation paths. Attackers use it; so do we, so you can see exactly what they would see in your AD.

How much does cybersecurity cost for an SMB?

It depends on your size and exposure. An initial diagnostic and a basic vulnerability assessment can run a few hundred euros. A managed security service for a typical SMB ranges from €300 to €800/month. We always start with what has the most impact for the lowest cost.

Am I required to comply with NIS2 as an SMB?

It depends on your sector and size. NIS2 directly obligates medium and large companies in essential and important sectors. However, many SMBs are indirectly obligated because they supply companies that must comply, and those companies require security guarantees from them.

Can you help us even if we don't have an IT manager?

Yes. We work directly with management or whoever handles IT informally at the company. No prior technical knowledge is required to work with us.

How long does it take to set up a cybersecurity plan for my SMB?

The highest-impact immediate measures (MFA, passwords, backups) are set up within days. An initial vulnerability assessment takes 1 to 5 business days depending on size. A full plan with assessment, guided remediation and basic policies is usually completed in 4-8 weeks. We always start with what has the most impact at the lowest cost.

My company has already suffered a cyberattack. What do I do now?

The first step is containment: isolate the affected systems, revoke compromised access and preserve evidence without altering it. Next, a basic forensic analysis determines how they got in, what was affected and whether they're still inside. If the incident involves personal data, you have 72 hours to notify the AEPD. Contact us: we do an initial triage to help you understand the situation before deciding next steps.

Do I need a CISO or an in-house security manager?

For most SMBs it's neither necessary nor viable. A senior CISO in Spain costs between €80,000 and €130,000/year. The alternative is a virtual CISO service or an external security partner: you set the objectives, we execute them and report back periodically. It's far more efficient for companies with fewer than 100 employees.

What is managed security and when does it make sense for an SMB?

It's a continuous monitoring and response service (SOC as a Service) without hiring an in-house team: we watch your systems, detect incidents and act on protocols agreed with you. It makes sense once you have critical assets to protect outside business hours but not the volume to justify an internal SOC.

Do I need cyber insurance on top of cybersecurity services?

They're complementary, not substitutes. Most insurers require minimum controls (MFA, backups, periodic vulnerability assessment) to issue or renew a cyber policy, and lower the premium if you can demonstrate them. We help you identify what your insurer requires and implement it before renewal.

When is the best time to do a first penetration test?

The first pentest should happen when the product is in beta or before public launch. Waiting until you have traction or real users increases both the risk and the cost of remediation.

Can you help us complete an enterprise customer's security questionnaire?

Yes. It's one of the services most requested by startups. We help you answer security questionnaires (CAIQ, SIG, custom questionnaires) and put together the documentation that backs up those answers.

Do you have experience with startups using AI-generated code or vibe coding?

Yes. Code generated by LLMs tends to reproduce known vulnerability patterns (injections, insecure secret handling, weak validation). We have a dedicated review service for AI-generated code.

Is AI-generated code less secure than code written by humans?

Not necessarily, but it introduces different risks. LLMs are very good at reproducing known patterns, but that includes insecure patterns too. The biggest risk is "vibe coding": the developer doesn't understand the code and can't identify the security issues.

Do you need access to the full repository?

Yes, a complete analysis requires read access to the source code. We work with GitHub, GitLab and Bitbucket, and we sign an NDA before any access.

Can you audit code generated with Cursor, Devin or other AI tools?

Yes. The specific AI generation tool matters less than the vulnerability pattern in the resulting code. We evaluate the code regardless of which tool generated it.

How is cybersecurity consulting different from a pentest?

A pentest is a technical test that looks for exploitable vulnerabilities in a specific system. Cybersecurity consulting is a broader service that assesses the organization's overall maturity: technical controls, processes, people and regulatory compliance. Consulting often leads to identifying a pentest as the necessary next step, but not always.

How much does cybersecurity consulting cost?

It depends on the scope and size of the organization. An initial diagnostic consulting engagement for an SME can start from €2,500. A broader project with a full roadmap and implementation support can range between €8,000 and €25,000. We always provide a fixed quote before starting.

Can you act as an external CISO after the consulting engagement?

Yes. We offer a CISO as a Service (CISOaaS) for companies that need a security leadership figure without the cost of hiring one full-time. It includes oversight of the roadmap, attendance at leadership committees and strategic security decision-making.

Does the consulting cover NIS2 compliance?

Yes. We carry out the gap analysis against NIS2, identify whether your company is in scope (regulated sectors), assess existing measures against the directive's requirements and prepare a compliance plan with the necessary technical and organizational controls.

Do I need my own technical team to work with you?

No. We work with companies that have an in-house IT team and with companies that have no technical resources of their own. We adapt the language, level of detail and support to each client's reality.

Do you hold in-person meetings in Valencia?

Yes. We're based in Valencia and can meet in person for the initial call, results presentation or training sessions. Technical execution is carried out remotely or on-site depending on the scope of the service.

Do you work only with large companies or also with Valencian SMEs?

We work with all types of companies, from freelancers with a digital presence to Ibex35 companies. We have offers specifically designed for the Valencian SME fabric, with scopes and pricing adapted to their reality.

How much does a cybersecurity service cost for a company in Valencia?

The cost depends on the scope. A basic vulnerability assessment for an SME starts from €1,500. A full pentest (web + internal network) ranges between €4,000 and €12,000 depending on complexity. Request a free consultation and we'll give you a no-obligation quote within 24 hours.

Can you help us comply with the NIS2 directive from Valencia?

Yes. We advise Valencian companies on NIS2 adaptation, identifying whether they're in scope, performing the gap analysis, implementing the required controls and preparing the documentation for the competent authority (INCIBE-CERT / CCN-CERT).

Do you work with industrial and logistics companies in Valencia?

Yes. We have experience with OT/ICS environments, industrial networks and SCADA systems, common in the Valencian industrial fabric (Paterna Industrial Zone, Port of Valencia, Almussafes industrial estates). Securing industrial environments requires different approaches from conventional IT.

What exactly does an IT security company like QuantumSec do?

An IT security company assesses, protects and monitors your organization's digital systems. At QuantumSec we specialize in the offensive side: penetration testing (simulating real attacks), ethical hacking (auditing your defenses from an attacker's perspective), vulnerability assessment and regulatory compliance (NIS2, ENS, ISO 27001). Unlike a generalist security company, our offensive approach identifies real flaws before third parties exploit them.

When does the Cyber Resilience Act enter into force?

The CRA entered into force on 23 October 2024. Full application of the technical and conformity requirements is 11 December 2027. There are two critical intermediate deadlines: the requirements to report actively exploited incidents to ENISA apply from 11 August 2026, and notified bodies (for third-party assessment) must be designated from 11 September 2026.

Does the CRA apply to all software or only to connected hardware?

The CRA applies to all "products with digital elements": hardware and software with direct or indirect network connectivity. Excluded are open source software released without commercial purpose, pure SaaS services without client-side installable components, medical products regulated by the MDR, civil aviation products and defence equipment. If your SaaS includes a desktop agent or an installable plugin, that component does fall within the scope of the CRA.

What are the penalties for CRA non-compliance?

The CRA sets three levels of penalty: up to €15 million or 2.5% of global annual turnover for breaching the essential cybersecurity requirements; up to €10 million or 2% for breaching other obligations; and up to €5 million or 1% for providing incorrect information to the authorities.

What is the difference between Class I, Class II and Default products?

Default products are the majority and can use self-assessment. Class I includes higher-risk products (identity management systems, browsers, password managers, security software, home routers) and requires third-party assessment unless a harmonised standard is fully applied. Class II includes the most critical products (server operating systems, hypervisors, industrial firewalls, industrial control systems, PKI, TPMs) and mandatorily requires an audit by a notified body.

Does the CRA overlap with NIS2 or other regulations?

Yes. NIS2 regulates the cybersecurity of essential service operators, while the CRA regulates the security of digital products before they are placed on the market. If you are a software manufacturer and also operate an essential service, both apply to you. There are also overlaps with the MDR for connected medical devices (the MDR prevails) and with the EUCS scheme for critical cloud products.

How long does it take to comply with the CRA?

It depends on your starting point and product category. Companies with a secure SDLC already in place and mature vulnerability management processes can complete the process in 6-9 months. Organizations starting from scratch will need 12-24 months for full compliance before the 2027 deadline.

What's the difference between ethical hacking and pentesting?

Ethical hacking is a comprehensive assessment that combines multiple vectors — OSINT, external perimeter, internal network, privilege escalation — to simulate a full attack campaign against your organization. Penetration testing is a technical test scoped to one specific system or surface: a web app, an API, a network. If you need to assess a specific system, choose penetration testing; if you want to know how far a real attacker would get across your whole organization, choose ethical hacking.

Can ethical hacking affect my production systems?

The scope is defined precisely before starting. By default we avoid actions that could disrupt service (DoS, data deletion). If any test carries potential impact risk, we agree it with you and run it during a maintenance window.

Do I need to sign anything before you start?

Yes. Before any activity we sign a scope agreement and an NDA. This protects both your organization and the audit team and defines exactly what's authorized.

How much does an ethical hacking service cost?

It depends on the scope: type of assessment (external, internal, or both), number of assets and test depth. We offer a free initial call to properly size the project and give you an accurate quote.

Do you work with companies outside Valencia?

Yes. We have clients across Spain. External ethical hacking is carried out fully remotely. Internal assessments may require physical presence or VPN access to the environment depending on the agreed scope.

What's the difference between your SME solution and your startup solution?

SMEs usually prioritize protecting the existing business (pentesting, vulnerability assessment, NIS2), while startups usually need to prove their security to investors or enterprise clients (due diligence, SOC2/ISO 27001 compliance, secure SDLC). Although the services overlap, the approach and documentation differ.

Do you work with very small companies, under 10 employees?

Yes. We have experience with microbusinesses and freelancers with specific security needs, especially in regulated sectors like healthcare, legal or fintech. Scope and cost adapt to the size and real critical assets.

Can you support us through the entire ISO 27001 certification process?

Yes. We offer end-to-end support: from the initial gap analysis to preparation for the external certification audit. We also follow up during the control implementation phase.

Does SaaS pentesting require access to the source code?

Not necessarily. Black box or grey box testing (without code access) already detects most critical SaaS vulnerabilities. If you give us access to the source code (white box), we combine the penetration test with static analysis (SAST) for greater coverage.

Can we run the pentest against the staging environment?

Yes. It is the most common option in SaaS: you prepare a staging environment with representative data (not real customer data) and we run the pentest there. The key is that the environment faithfully mirrors production in configuration, infrastructure and business logic.

Does SaaS pentesting also cover the cloud infrastructure?

It can be included as additional scope. A SaaS application pentest covers the application layer (web, API, logic). If you also need to review IAM configuration, security groups, S3 policies or Kubernetes, we add it as a cloud pentesting component.

How long does a SaaS application pentest take?

Between 5 and 10 working days for applications of medium complexity. The duration depends on the number of endpoints, user roles, integrations and the agreed depth. For SaaS with a microservices architecture it can take longer.

Is the report suitable for presenting to enterprise customers or investors?

Yes. The executive report is designed to be presented to management, enterprise customers and in investment due diligence processes. It includes a summary of the scope, methodology, findings and remediation status.

Can you integrate with our current bug bounty platform (HackerOne, Bugcrowd, Intigriti)?

Yes. We work on the client's existing platforms without needing to switch tools. We also integrate with in-house channels: web forms, secured email, Jira, GitHub Issues or any ticketing system. The client keeps full visibility into the entire process.

What's the SLA for responding to a critical report?

For reports classified as critical, the maximum first-response time is 8 business hours and 24 hours on weekends. For high-severity reports, the SLA is 24 business hours. These parameters are configurable to fit your program's needs.

What happens if we disagree with your assessment of a report?

The client always has the final word. If there's disagreement over a report's assessment, we review it together, provide the technical evidence supporting our position and agree on the final classification. It's a collaborative service, not a black box.

How do you guarantee the confidentiality of reports?

We sign a specific NDA for the triage service before starting. All reports and their contents are strictly confidential. Access to reports is restricted to the technical team assigned to the client. We never share information about a client's vulnerabilities with third parties.

How much does external triage cost?

The cost depends on the estimated monthly report volume, the required SLA level and whether the service includes researcher communication. We work with fixed monthly rate models based on report volume. It's significantly cheaper than hiring an in-house triage analyst, and much more flexible.

How is this different from hiring HackerOne or Bugcrowd?

HackerOne and Bugcrowd are platforms: they give you access to a community of researchers and management tools, but you still need an in-house team to triage and validate. We're the external team that does that work. We can operate on the platforms you already use, or design a program independent of them.

Can you manage programs already active on another platform?

Yes. We work on HackerOne, Bugcrowd, Intigriti and any in-house channel. There's no need to change platform or process. We simply add the triage and management layer you're missing.

How long does it take for the service to be up and running?

Standard onboarding takes between 5 and 10 business days: technical briefing, access and integration setup, and workflow definition. For more complex programs or multiple integrations, the timeline can extend.

Do you work on existing platforms or do I need to switch?

We work on any platform you already have: HackerOne, Bugcrowd, Intigriti, YesWeHack or in-house channels. There's no need to switch platform. If you don't have one yet, we recommend the best fit for your case and help with the initial setup.

What do researchers need to know about who manages the program?

You decide the level of transparency. We can operate on your behalf without researchers knowing there's an external provider, or we can mention that triage is handled by a specialized external security team. Both models are valid and common in the market.

How much does it cost to manage a bug bounty program externally?

The cost depends on the monthly report volume, the SLA level and whether the service includes the initial program design. It's significantly lower than hiring an in-house triage analyst, and more flexible because the cost scales with the program's actual volume.

Can you manage private bug bounty programs?

Yes. We manage both public programs (open to any researcher) and private ones (invite-only researchers). Private programs have different dynamics and require more active researcher community management, which we also cover.

Does NIS2 require me to have a VDP?

NIS2 requires essential and important entities to have mechanisms to manage and report vulnerabilities, which includes having a vulnerability notification channel. Although the directive doesn't explicitly use the term VDP, the most common way to meet this requirement is to implement a Vulnerability Disclosure Program. We help you assess exactly what your company needs.

How long does it take for the VDP to be operational?

Standard design and implementation of a VDP takes between 2 and 4 weeks: policy drafting, channel setup, testing and publication. If you need to accelerate it for an audit or compliance process, we can adjust the timeline.

What happens if we receive a critical vulnerability?

Critical reports have an immediate escalation channel. As soon as we identify a report with potential critical impact, we escalate it directly to the client's security lead —regardless of the time of day— and coordinate the emergency response. The SLA for critical reports is 4 business hours.

Can you help coordinate the public disclosure of a vulnerability?

Yes. If a researcher wants to publish their finding (CVE, blog post, conference talk), we manage the coordinated vulnerability disclosure (CVD) process following the ISO 29147 standard: we agree the disclosure timeline, coordinate with the researcher and prepare the necessary communications.

Can you validate vulnerabilities without access to production?

It depends on the vulnerability type. For many findings (XSS, CSRF, business logic, authorization flaws) we can validate with test credentials in a staging environment. For others that require observing production behavior, we work with the client to define a safe validation window and procedure.

How long does report validation take?

Standard SLA is 24 business hours for high and critical severity reports, and 48-72 hours for medium and low severity. For high-volume programs, we agree validation cycles that adapt to the report flow.

What's the difference between CVSS 4.0 and previous versions?

CVSS 4.0, published by FIRST in 2023, introduces a more granular metric taxonomy, improves impact assessment in OT/ICS environments and adds supplemental metrics. We use CVSS 4.0 as our baseline standard because it delivers a more precise score applicable to modern environments. If your program still uses CVSS 3.1, we can work with both versions in parallel.

How does a CMS security audit differ from web maintenance?

Web maintenance updates versions and takes backups. A CMS security audit simulates real attacks to find vulnerabilities that updates do not fix: vulnerable application logic, misconfigurations, extensions with insecure code or CMS-specific vectors that automated scanners do not detect.

Does the pentest disrupt the website's operation?

We coordinate the scope to minimise operational impact. In most cases we work on a staging environment or during low-traffic windows. If production is unavoidable, we agree to run the most invasive tests outside business hours.

Does the CMS pentest also cover hosting and the CDN?

Yes, within the agreed scope. We review the web server configuration, HTTP security headers, access to sensitive paths, file permissions and, where applicable, the WAF and CDN configuration (Cloudflare, Fastly). The hosting environment is part of the CMS attack surface.

Do you also do the remediation or just the report?

We deliver the analysis, the evidence and the remediation plan. The fixes are carried out by your team or your web agency following our instructions. We always include support during the remediation phase and an optional re-test to verify that the findings have been resolved.

Is the report valid for compliance audits (ENS, ISO 27001, PCI-DSS)?

Yes. The report follows recognised methodologies (OWASP, PTES) and is valid as pentesting evidence for ISO 27001 certification, ENS compliance or PCI-DSS processes. We indicate the coverage against the applicable security controls.

Do you need admin access to our Workspace?

For the configuration review, a read-only admin role or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA).

Does the audit disrupt employees' work?

No. Most of it is configuration and attack-surface analysis, which doesn't affect users. The few active tests are agreed and run in a controlled way so they don't impact operations.

How is this different from the recommendations Google already shows?

Google's panels flag recommended settings, but they don't think like an attacker or chain vectors together. We look for the real compromise path: a forgotten OAuth app, a dangerous domain-wide delegation or a forwarding rule that keeps access even after a password change.

Do you also audit Microsoft 365?

Yes. We apply the same offensive methodology to Microsoft 365 (Entra ID, Exchange Online, SharePoint). If you use both, we audit both environments and their integration points.

Is the report valid for compliance (ENS, ISO 27001, NIS2)?

Yes. The report documents the security posture of your email and collaboration environment against recognized frameworks (CIS Benchmark) and is valid as evidence for ENS adequacy, ISO 27001 certification or NIS2 compliance.

Do you need admin access to our tenant?

For the configuration review, a read-only role (Global Reader) or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA).

How is this different from Microsoft's Secure Score?

Secure Score flags recommended settings, but it doesn't think like an attacker or chain vectors together. We look for the real compromise path: an app with illicit consent, a gap in conditional access or a forwarding rule that keeps access even after a password change.

Do you also audit Google Workspace?

Yes. We apply the same offensive methodology to Google Workspace. If you use both, we audit both environments and their integration points.

How is this exactly different from an Active Directory pentest?

An Active Directory pentest analyzes the AD environment in depth within a known technical scope, looking for the maximum number of configuration and privilege escalation flaws. A Red Team starts from outside the perimeter, with a concrete business objective, without the defensive team knowing, and only touches AD if that's the most realistic path to the objective — it's a test of the whole organization, not of the AD environment itself.

Is this the same as the TLPT DORA requires?

TLPT is a Red Team run under the TIBER-EU regulatory framework, with specifically accredited providers and coordination with the supervisor, mandatory for financial entities designated as critical. Our standard Red Team follows the same methodological logic and is the ideal preparation before a formal TLPT; for the regulatory TLPT itself, we guide you through the required accreditation process.

What happens if the defensive team catches us on day one?

That's a valid and valuable outcome — it means your defenses work for that vector. In that case, with your consent, we can adjust the exercise to keep testing other vectors or more advanced evasion techniques, maximizing what you learn from the exercise.

Does it include in-person social engineering and physical access?

Only if explicitly agreed in scope. It's not a default component: some organizations include it (tailgating, USB devices, impersonating technical staff) and others prefer to limit it to digital vectors. It's defined during the rules-of-engagement phase.

How is this different from a phishing simulation (social engineering)?

A phishing simulation tests a single vector — the human one — in isolation, with a scope known in advance by whoever commissions it. A Red Team may use phishing as one of several entry vectors, but only if it serves the defined business objective, combined with technical exploitation and lateral movement; it isn't an end in itself and isn't measured independently.

Is this the same as a segregation of duties (SoD) review for internal audit?

No. An SoD review for internal audit or compliance confirms a documented matrix exists and that, on paper, no prohibited combinations are assigned. Our audit goes further: it confirms which of that is actually exploitable, adds analysis of the RFC/Gateway interface, custom ABAP code and patch status, and simulates the real impact of an attacker, not just the documented theoretical risk.

Do you need access to the production system?

For the configuration and authorization review, a read-only user or access to a pre-production system with the same configuration is enough. For active offensive testing we agree the scope, environment (usually pre-production) and, if needed, a test account in advance. Everything is done with explicit authorization and under a confidentiality agreement (NDA).

Do you cover both on-premise SAP and S/4HANA Cloud?

Yes, adapting the scope: on-premise and S/4HANA Private Cloud analysis includes the infrastructure layer, the Gateway and the underlying operating system; S/4HANA Public Cloud scope focuses on authorizations, integrations and configuration, since SAP directly manages part of the infrastructure.

Does the audit disrupt ERP operations?

No. Most of the work is configuration, role and code analysis, which doesn't affect users. Active tests are agreed in advance, preferably run in a pre-production environment, and if they must touch production, within a window agreed with the Basis team.

Is the report valid for regulatory compliance (NIS2, ENS, ISO 27001)?

Yes. The report documents the security posture of the SAP environment with evidence and is valid as part of the documentation for NIS2 adequacy, ISO 27001 certification or adequacy to the Spanish National Security Framework (ENS) for the systems within its scope.

Who does the AI Act apply to?

It applies to providers who develop AI systems, to deployers who use them within their organization, and to importers and distributors, inside and outside the EU if the system is used in European territory. It applies regardless of company size.

I'm a freelancer using third-party AI tools, do I have obligations?

Yes, as a deployer you have obligations even if you didn't build the system: informing affected people where required, human oversight for high-risk systems, and not using prohibited AI practices such as social scoring.

How much time do I have to comply?

The timeline is progressive: prohibited AI practices have already been illegal since February 2025; governance and general-purpose model obligations apply from August 2025; Annex III high-risk system obligations apply from August 2026.

What penalties does the AI Act impose?

Up to €35M or 7% of global annual turnover for prohibited AI practices; up to €15M or 3% for other regulatory breaches; up to €7.5M or 1% for providing incorrect information to authorities.

Does the AI Act replace GDPR?

No, they're complementary. The AI Act specifically regulates AI systems and their risk level; GDPR still applies to any personal data processing that system performs.

Does this replace the general Microsoft 365 audit?

Not necessarily. If email is your most critical system or you've already had an email-related incident, it makes sense as a standalone engagement. If you want a full tenant review (Entra ID, SharePoint, Teams, OAuth apps), the Microsoft 365 audit is the better fit.

Do you need global admin access?

No. A read-only role over Exchange Online (for example, Exchange Recipient Administrator) is enough for most of the analysis.

Does it disrupt mail flow?

No. The analysis covers configuration and permissions, and doesn't affect production mail flow.

Can you detect an ongoing compromise?

Analyzing forwarding rules and delegated permissions can reveal the persistence of an attacker who already compromised an account, though this isn't an incident response service.

Is the report valid for regulatory compliance?

Yes. The report is valid as technical control evidence for corporate email security under NIS2, ENS or ISO 27001.