Cybersecurity Resources
Technical guides and articles on pentesting, compliance (NIS2, CRA, DORA), bug bounty, CMS and cloud security, written by our offensive security team.
- What is a penetration test and what is it for in a company?
- How to comply with the NIS2 Directive: a practical guide
- Pentesting vs vulnerability assessment: key differences and when to use each
- Phases of a web pentest: from information gathering to the final report
- DORA vs NIS2: differences, overlaps and what to do if both apply to you
- Types of corporate phishing: how to recognize them and protect your company
- How to protect Active Directory from ransomware and lateral movement attacks
- Cybersecurity for SMBs: a practical guide to protecting your business
- Cybersecurity for startups: what you need to know before scaling
- What security risks does vibe coding carry?
- How to audit the security of AI-generated code
- Security checklist before launching your SaaS startup
- How much does a pentest cost in Spain? 2026 pricing guide
- NIS2 Directive fines and penalties in Spain (2025)
- How to choose a cybersecurity company: 7 criteria that matter
- What is ethical hacking and what is it for in your company?
- What is the Cyber Resilience Act: the EU cybersecurity regulation for digital products
- Cyber Resilience Act timeline: what you must have ready and when
- CRA vs NIS2: differences, overlaps and how to manage them together
- Cyber Resilience Act requirements: what the regulation demands from manufacturers of digital products
- Cyber Resilience Act fines and penalties: the cost of non-compliance
- The most common vulnerabilities in SaaS applications and how to detect them
- SOC 2 Type II and pentesting: what security testing your SaaS needs
- How to secure a SaaS application before scaling: 7 concrete steps
- SaaS pentesting vs web pentesting: how do they really differ?
- How to hire a pentest: a practical guide for businesses
- EN 18031 standard: mandatory cybersecurity for IoT devices and radio equipment
- What is vulnerability triage and why does your team need it?
- How to create a Vulnerability Disclosure Program step by step
- CVSS vs EPSS: which should you use to prioritise vulnerabilities
- False positives in bug bounty: how to reduce them without rejecting valid reports
- Bug bounty vs Vulnerability Disclosure Programme: differences and when to use each
- What is a Vulnerability Disclosure Programme (VDP)?
- How much does it cost to manage a bug bounty programme: in-house vs outsourced
- How to prioritise vulnerabilities when you have a backlog of unprocessed reports
- HackerOne, Bugcrowd, Intigriti and YesWeHack: a real comparison for security teams
- NIS2 and Vulnerability Disclosure: what the directive requires and how to comply
- How to manage a bug bounty program without an in-house security team
- Coordinated Vulnerability Disclosure (CVD): what it is and how to implement it in your company
- Vulnerability triage process: how we analyze every security report
- Responsible disclosure for companies: a guide for handling your first report
- How to calculate a vulnerability's real impact beyond CVSS
- Duplicate reports in bug bounty: how to detect and communicate them correctly
- How to outsource vulnerability triage without losing control
- Bug bounty program metrics: the KPIs that actually matter
- CRA and Vulnerability Disclosure: what the Cyber Resilience Act requires from companies
- How to respond to a security researcher who reports a vulnerability
- Bug bounty vs pentesting: which to choose and when to combine them
- What is EPSS and how to use it to prioritise vulnerabilities more efficiently
- How to launch a private bug bounty program: a step-by-step guide
- Vulnerability triage in AppSec teams: how to structure the process
- CVSS 4.0: what's new and how it impacts vulnerability management
- WordPress security audit for businesses: what it is, what it covers and when you need one
- WordPress penetration testing: real attack vectors and how an installation is analysed
- WordPress hardening for businesses: reducing the attack surface beyond plugins
- WordPress plugin security: the leading compromise vector in enterprise installations
- WooCommerce security: the specific risks of online stores on WordPress
- Magento and Adobe Commerce security audit: what it covers and why it's essential in e-commerce
- Magento and Adobe Commerce penetration testing: how the security of an enterprise store is analysed
- Magento checkout security: Magecart, price tampering and protecting the payment process
- PrestaShop security audit: attack vectors and technical analysis for online stores
- PrestaShop module security: the attack vector that compromises online shops most
- Drupal security audit: technical analysis for institutional and enterprise organisations
- Drupal hardening for organisations: security configurations that reduce the attack surface
- Joomla security audit: technical analysis for enterprise and legacy installations
- CMS penetration testing for businesses: what it is, what it finds and when it's essential
- CMS security vs web maintenance: why they aren't the same and what it means for your business
- Common CMS vulnerabilities: what attackers look for and where they find it
- CMS admin panel security: protecting your installation's most critical access point
- CMS malware: why reinfections happen and how to prevent them for good
- How to choose a CMS security provider: technical criteria and red flags
- CMS security for web agencies: managing the security of multiple client sites
- Google Workspace security for businesses: the complete guide
- Google Workspace hardening: a security checklist for businesses
- How attackers hack a Google Workspace
- How much does a Google Workspace security audit cost
- How to review the third-party apps connected to your Google Workspace
- GDPR and Google Workspace: a compliance guide for businesses
- Google Workspace and NIS2: requirements and how to comply
- OAuth consent phishing in Google Workspace
- Domain-Wide Delegation: the critical and least-audited risk in Google Workspace
- 2FA in Google Workspace: 2-step verification and security keys
- Super admins in Google Workspace: security best practices
- Google Drive security for businesses: prevent data leaks
- Malicious Gmail forwarding rules: the persistence that survives a password change
- Secure offboarding in Google Workspace: a checklist for employee departures
- From Workspace to GCP: how an attacker escalates in the Google ecosystem
- Microsoft 365 security for businesses: the complete guide
- Microsoft 365 hardening: a security checklist for businesses
- How attackers hack Microsoft 365
- Google Workspace vs Microsoft 365 audit: what changes and what stays the same
- How much does cybersecurity cost for an SMB in Spain (real prices)
- What is TLPT (Threat-Led Penetration Testing) and why DORA requires it
- Pentesting and cyber insurance: what insurers require in Spain
- GraphQL pentesting: common vulnerabilities in GraphQL APIs
- Power Platform and Power Automate security: shadow IT in Microsoft 365
- Red Team vs Pentesting: key differences and how to choose
- Purple Team: when to combine Red Team and Blue Team
- Phases of a Red Team exercise: how it works from start to finish
- Microsoft Teams security: external access, guest sharing and federation
- SharePoint Online security: external sharing risks
- Entra ID: privileged roles and Privileged Identity Management (PIM)
- Conditional Access: the most common configuration mistakes
- Azure AD Connect: hybrid sync attacks from on-premises to the cloud
- Microsoft Copilot security: governance and risks in Microsoft 365
- Secure offboarding in Microsoft 365: a checklist for employee departures
- Malicious Exchange Online forwarding rules: the foundation of CEO fraud
- OT/ICS security: why IT pentesting isn't enough for industrial environments
- CI/CD pipeline pentesting: what needs to be audited
- DevSecOps: how to integrate offensive security without slowing releases
- What is OSINT and how it is used in corporate cyber threat intelligence
- Internal and perimeter network penetration testing: what it covers and when your company needs it
- iOS vs Android penetration testing: key differences and what your app needs
- Cybersecurity for SMBs in the Valencian Region: sectors, risks and what the regulation requires
- MSSP vs in-house security team: when to outsource cybersecurity
- Most common vulnerabilities in SAP systems: a technical guide
- Cybersecurity awareness training for employees: a practical guide
- Microsoft Exchange Online security audit
- Spain's National Security Framework (ENS) audit: what it requires and how to prepare
- What investors ask for in your startup's security due diligence
- Cybersecurity audit before selling your company
- Virtual CISO for SMBs: what it is and when it makes sense
- ISO 27001 for SMBs: a practical guide to certifying without an endless project
- Cyber insurance for SMBs: what insurers require before covering you
- ENS for SMBs supplying Spain's Public Administration
- SOC 2 for startups: when you need it and how to approach it
- Security checklist before a funding round
- Cyber due diligence in M&A: what buyers actually check
- AI Act for freelancers and SMBs: what actually applies to you