# QuantumSec — Full content export for AI crawlers (llms-full.txt) > Generated from the same content source as quantumsec.es. Every fact below is published verbatim on the corresponding URL. See /llms.txt for a short index; this file inlines the actual page content (H1, description, intro/hero text, FAQ pairs) for crawlers that read only one file. --- # Servicios (ES) --- ## Servicios de seguridad informática y ciberseguridad para empresas URL: https://www.quantumsec.es/servicios/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Servicios de seguridad informática para empresas en toda España: pentesting, hacking ético, auditorías y cumplimiento NIS2. Equipo OSCP. Consulta en 24h. Desde un primer análisis de vulnerabilidades hasta el cumplimiento de la directiva NIS2, cubrimos todo el ciclo de seguridad ofensiva y normativa que tu empresa necesita. ¿Por qué externalizar la ciberseguridad técnica? Montar un equipo interno de seguridad ofensiva tiene un coste prohibitivo para la mayoría de empresas. Contratar y retener a un pentester senior en plantilla es caro, y la especialización que necesitas —web, redes, Active Directory, cloud— raramente la encuentra una sola persona. Nosotros ponemos a tu disposición un equipo con más de 10 años de experiencia, sin que tengas que gestionar plantilla ni formación continua. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Tenemos que firmar un contrato de larga duración? A: No. La mayoría de nuestros servicios son proyectos cerrados con entregable concreto. Si hay una relación continua, se formaliza con un acuerdo de servicio gestionado, pero siempre con plazos definidos y salida flexible. Q: ¿Trabajáis con empresas de todos los tamaños? A: Sí. Tenemos clientes desde startups de 5 personas hasta empresas del Ibex35. Adaptamos el alcance y el precio a la realidad de cada organización. Q: ¿Qué distingue a QuantumSec de otras empresas de ciberseguridad? A: La especialización ofensiva y la cercanía. No somos un integrador generalista. Somos un equipo técnico que entiende el lenguaje de los atacantes, lo comunicamos en términos de negocio y acompañamos al cliente durante todo el proceso, no solo cuando entregamos el informe. Q: ¿Cómo garantizáis la confidencialidad? A: Firmamos un NDA antes de comenzar cualquier trabajo. Todos los accesos y pruebas quedan documentados y se realizan dentro del alcance estrictamente acordado. --- ## Pentesting para empresas: encuentra tus vulnerabilidades antes que los atacantes URL: https://www.quantumsec.es/pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pentesting manual para empresas en España: web, APIs, red interna, cloud y móvil. Vulnerabilidades reales con informe PoC y re-test. Presupuesto en 24h. Un pentesting bien hecho no es un escaneo automatizado. Es un experto que piensa como un atacante, busca el camino menos esperado y te demuestra exactamente hasta dónde puede llegar alguien con malas intenciones. ¿Tu empresa es segura o simplemente cree serlo? Muchas de las empresas que sufren un ciberataque grave pensaban tener sus sistemas "al día". Los firewalls, los antivirus y los parches no son suficientes si hay vulnerabilidades en tu aplicación web, en la configuración de tu red interna o en la forma en que tus empleados gestionan las credenciales. El pentesting simula lo que haría un atacante real: busca, explota y te muestra el camino antes de que alguien con malas intenciones lo encuentre primero. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuándo tiene sentido contratar un pentesting? A: Cuando necesitas validar riesgo real con evidencias y no una aproximación teórica o puramente automática: antes de un lanzamiento, tras un cambio de arquitectura relevante, cuando lo exige un cliente o una normativa, o cuando un escáner ha señalado fallos que nadie ha confirmado explotándolos. Si el objetivo es solo marcar una casilla de cumplimiento y no averiguar qué podría hacer un atacante, el pentesting no es la compra adecuada. Q: ¿Qué debo pedir a un proveedor antes de contratar un pentesting? A: Cuatro cosas resuelven la mayoría de decisiones: el CV y las certificaciones de quien va a ejecutar la prueba, no solo la marca de la empresa; un informe de muestra real anonimizado, para ver si explican impacto de negocio o solo vuelcan hallazgos técnicos; la metodología que siguen (OWASP WSTG, PTES, OSSTMM); y si incluyen retest de las correcciones. Un proveedor que no puede enseñar un informe de muestra ni nombra metodología suele estar vendiendo un escaneo automático. Q: ¿Cuánto cuesta un pentesting en España? A: El precio depende del alcance: número de IPs, URLs, aplicaciones y profundidad del análisis. Un pentesting web estándar suele estar entre 1.500 € y 5.000 €. Proyectos más complejos como un Red Team o un pentesting completo de infraestructura pueden superar esa cifra. Siempre hacemos una primera llamada gratuita para darte un presupuesto ajustado a tu realidad. Q: ¿El pentesting puede afectar a la disponibilidad de mis sistemas? A: Definimos el alcance con precisión antes de empezar. Por defecto, evitamos acciones que puedan interrumpir el servicio (DoS, borrado de datos). Si algún test tiene riesgo potencial, lo acordamos contigo y lo hacemos en ventana de mantenimiento. Q: ¿Cuál es la diferencia entre un pentesting y un análisis de vulnerabilidades? A: Un análisis de vulnerabilidades es un escaneo automatizado que detecta posibles fallos pero no los verifica ni los explota. Un pentesting va más allá: un experto humano confirma que la vulnerabilidad es explotable, demuestra su impacto real y evalúa si permite escalar el ataque. El resultado es mucho más accionable. Q: ¿Qué diferencia hay entre un pentesting y el hacking ético? A: Un pentesting es una prueba técnica con alcance acotado a un sistema o superficie concreta: una aplicación web, una API, una red. El hacking ético es una evaluación más amplia que combina varios vectores —OSINT, perímetro externo, red interna, escalada de privilegios— para simular una campaña de ataque completa contra tu organización. Si necesitas evaluar un sistema específico, el pentesting es el servicio adecuado; si quieres saber hasta dónde llegaría un atacante real en toda tu organización, contrata un hacking ético. Q: ¿Qué información necesitáis para empezar? A: Depende del tipo de test. Para un pentesting de caja negra, solo necesitamos las URLs o IPs en alcance. Para uno de caja gris o blanca, podemos necesitar credenciales de prueba, acceso al código fuente o documentación de la arquitectura. Lo acordamos todo antes de empezar. Q: ¿Cuánto tiempo tarda un pentesting? A: Entre 3 y 10 días hábiles para la fase técnica, según el alcance. El informe suele entregarse 2-3 días después. Para proyectos de Red Team o infraestructuras complejas, el plazo puede extenderse. Q: ¿Cómo contratar un pentesting para mi empresa? A: El proceso es sencillo: nos describes tu entorno (URLs, IPs, aplicaciones o red interna en alcance), hacemos una llamada inicial gratuita para entender tus necesidades, y en 24-48 horas recibes una propuesta con alcance, metodología y precio. No hay letra pequeña ni cargos por el análisis inicial. Q: ¿Hacéis pentesting de sistemas de inteligencia artificial? A: Sí, y conviene distinguir dos cosas que suelen confundirse. Una es auditar tu IA: probar tus modelos, chatbots y agentes LLM contra prompt injection, jailbreak, envenenamiento de contexto y fuga de datos del modelo, siguiendo el OWASP Top 10 para LLM y MITRE ATLAS — ese es nuestro servicio de pentesting de inteligencia artificial. La otra es usar IA como herramienta para acelerar un pentesting convencional, que es lo que cubre el pentesting potenciado por IA. Si tu empresa ha puesto un asistente conversacional en producción, lo que necesitas es lo primero. --- ## Pentesting web: auditoría de seguridad de aplicaciones web URL: https://www.quantumsec.es/pentesting/web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de seguridad web: portales, e-commerce y aplicaciones. SQLi, XSS, IDOR, SSRF y OWASP Top 10. Informe técnico + ejecutivo. Análisis gratuito. Tu aplicación web es la puerta de entrada a tus datos, tus clientes y tu negocio. Evaluamos su seguridad como lo haría un atacante real, cubriendo desde el OWASP Top 10 hasta las vulnerabilidades específicas de tu stack tecnológico. Las aplicaciones web son el vector de ataque más explotado Tu aplicación web es la parte de tu empresa expuesta a Internet 24/7 y accesible para cualquiera. El control de acceso roto (Broken Access Control) encabeza el OWASP Top 10 desde la edición de 2021 y sigue siendo el riesgo A01 en la de 2025. Inyecciones SQL, XSS, exposición de datos sensibles, autenticación débil, control de acceso inadecuado... La mayoría de estos fallos son silenciosos: tu app funciona perfectamente mientras hay una puerta trasera abierta. El pentesting web los encuentra y los cierra antes de que lo haga otro. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Hacéis pentesting en caja negra, gris o blanca? A: Los tres. Caja negra simula un atacante externo sin información previa. Caja gris incluye credenciales de usuario estándar para evaluar el control de acceso. Caja blanca incluye acceso al código y la arquitectura, y permite un análisis más exhaustivo. La mayoría de los clientes optan por caja gris como equilibrio entre realismo y cobertura. Q: ¿Evaluáis WordPress y otros CMS? A: Sí. WordPress es el CMS más atacado del mundo precisamente por la proliferación de plugins vulnerables. Evaluamos el core, los plugins instalados, los temas, la configuración del servidor y las prácticas de acceso al panel de administración. Q: ¿Podéis firmar un NDA antes de empezar? A: Siempre. Antes de que compartas ningún dato sobre tu infraestructura, firmamos un acuerdo de confidencialidad. Q: ¿Qué pasa si encontráis vulnerabilidades críticas? A: Te avisamos de inmediato (mismo día) si encontramos algo que suponga un riesgo grave e inmediato para tu negocio, sin esperar a que termine el test completo. --- ## Pentesting de APIs: seguridad REST, GraphQL y OAuth URL: https://www.quantumsec.es/pentesting/apis/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de APIs REST, GraphQL y OAuth/OIDC. Detectamos BOLA, broken auth y exposición de datos. Informe técnico con PoC y remediación paso a paso. Las APIs son el sistema nervioso de tu negocio digital. Conectan servicios, exponen datos y mueven dinero. Auditamos su seguridad siguiendo el OWASP API Security Top 10, con el rigor de un atacante y la precisión de un equipo técnico especializado. Las APIs son el nuevo perímetro de ataque El riesgo número uno del OWASP API Security Top 10 no es la autenticación, sino la autorización a nivel de objeto: "Broken Object Level Authorization" (API1:2023). Un endpoint que devuelve los datos de cualquier usuario si cambias el ID en la URL. Una API interna expuesta sin protección porque "solo es para uso interno". Un token que no caduca nunca. Estos fallos son silenciosos y fáciles de explotar para alguien que sabe buscarlos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso a la documentación de la API (Swagger/OpenAPI)? A: Es útil pero no imprescindible. Podemos trabajar en modo caja negra interceptando el tráfico de la aplicación que consume la API. La documentación acelera el proceso y mejora la cobertura. Q: ¿Auditáis APIs internas o solo las expuestas a internet? A: Las dos. De hecho, las APIs internas son frecuentemente las más vulnerables porque se asume erróneamente que "solo las usan los empleados". El movimiento lateral en un ataque suele aprovechar exactamente este tipo de API. Q: ¿Qué diferencia hay entre auditar una API REST y una GraphQL? A: GraphQL tiene vectores de ataque específicos: la introspección puede revelar el esquema completo de datos, el batching permite DoS a nivel de aplicación y la autorización a nivel de campo es más compleja de implementar correctamente. Cubrimos ambos con metodologías adaptadas. Q: ¿Cuánto tarda una auditoría de API? A: Entre 3 y 7 días hábiles para la fase técnica, según el número de endpoints y la complejidad de los flujos de autenticación y negocio. --- ## Pentesting de aplicaciones móviles: iOS y Android URL: https://www.quantumsec.es/pentesting/aplicaciones-moviles/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de seguridad de apps iOS y Android. Análisis estático, dinámico y de la API backend. OWASP Mobile Top 10. Informe técnico y ejecutivo. Tu app móvil almacena credenciales, accede a APIs sensibles y maneja datos de clientes. ¿Sabes qué pasa cuando alguien la desmonta? Auditamos la app, la API que consume y el canal de comunicación entre ambas. Las apps móviles tienen vulnerabilidades invisibles al usuario A diferencia de una web, el usuario de una app instala el código en su dispositivo. Esto permite a un atacante decompilarla, analizar su tráfico, extraer claves API hardcodeadas, identificar la lógica de negocio y atacar la API backend con el conocimiento de cómo funciona internamente. El OWASP Mobile Top 10 recoge los fallos más explotados, pero la casuística real va mucho más allá. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis el código fuente de la app? A: No es imprescindible. Podemos trabajar solo con el binario (APK o IPA) para el análisis estático. El código fuente, si está disponible, permite una revisión más profunda y eficiente. Q: ¿Auditáis apps tanto de iOS como de Android? A: Sí. Trabajamos con ambas plataformas. iOS requiere dispositivos con jailbreak o el uso del simulador para ciertos análisis dinámicos. Android es más accesible para el análisis con emuladores. Q: ¿Qué impacto tiene en el proceso de publicación en los stores? A: Ninguno directo. La auditoría se hace sobre una versión de prueba o la versión de producción que ya está publicada. Las correcciones se implementan antes de la siguiente release. Q: ¿Podéis hacer solo la auditoría de la API sin analizar la app? A: Sí. Si ya tienes la app auditada o lo que te preocupa es el backend, podemos limitarnos a la API. Ver nuestro servicio de pentesting de APIs. --- ## Pentesting Active Directory: audita la seguridad de tu directorio activo URL: https://www.quantumsec.es/pentesting/active-directory/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de Active Directory: misconfiguraciones, privilegios excesivos y rutas de escalada explotables por ransomware. BloodHound. Informe técnico + ejecutivo. Active Directory es la pieza central de cualquier entorno Microsoft corporativo. Es también el objetivo número uno de los grupos de ransomware. Un AD mal configurado puede darle a un atacante control total sobre tu red en cuestión de horas. AD es el camino más rápido al desastre La mayoría de los ataques de ransomware empresarial siguen el mismo patrón: comprometer una máquina de usuario, moverse lateralmente por la red, obtener credenciales con privilegios elevados y, finalmente, comprometer el Domain Controller. Active Directory es el hilo que une todos esos pasos. Kerberoasting, Pass-the-Hash, ACL Abuse, GPO misconfiguration, cuentas de servicio con privilegios excesivos... Hay centenares de caminos que un atacante puede seguir. Nosotros los mapeamos todos antes de que alguien los use. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso de administrador para hacer la auditoría? A: No necesariamente. Podemos empezar con una cuenta de usuario estándar para simular exactamente lo que haría un atacante que ha comprometido un puesto de trabajo. Dependiendo del alcance acordado, podemos escalar a privilegios superiores de forma controlada. Q: ¿Qué impacto tiene la auditoría sobre el entorno de producción? A: Mínimo. Evitamos por defecto cualquier acción destructiva o que pueda causar bloqueos masivos de cuentas o interrupciones de servicio. Todo se acuerda previamente. Q: ¿Hacéis también hardening de AD una vez identificados los problemas? A: La auditoría incluye instrucciones de remediación detalladas. Si necesitas que implementemos directamente las correcciones, podemos presupuestarlo como servicio adicional. Q: ¿Con qué frecuencia debería auditarse el Active Directory? A: Mínimo una vez al año y tras cambios importantes en la infraestructura (migraciones, incorporación de nuevas unidades de negocio, fusiones). Los entornos más dinámicos deberían hacerlo cada 6 meses. --- ## Auditoría de ciberseguridad: evaluación técnica de tu postura de seguridad URL: https://www.quantumsec.es/auditorias/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditorías técnicas de ciberseguridad: análisis de vulnerabilidades, revisión de código y evaluación de seguridad. Informe ejecutivo + técnico detallado. Una auditoría de ciberseguridad va más allá de un escaneo automático. Revisamos tu infraestructura, tus aplicaciones, tu código y tus procesos para darte una imagen real de tu nivel de exposición, con datos, no con suposiciones. ¿Cuándo fue la última vez que alguien evaluó realmente tu seguridad? Muchas empresas tienen herramientas de seguridad instaladas pero nunca han hecho que alguien competente las evalúe desde fuera. Los firewalls tienen reglas obsoletas. Las aplicaciones tienen versiones vulnerables. El código tiene fallos que pasaron el code review. La auditoría pone nombre y cifra a esos riesgos, para que puedas priorizarlos y resolverlos con criterio. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuál es la diferencia entre una auditoría y un pentesting? A: El pentesting se centra en explotar vulnerabilidades para confirmar su impacto real. La auditoría tiene un alcance más amplio: revisa configuraciones, políticas, cumplimiento normativo y postura general de seguridad, no solo vulnerabilidades técnicas explotables. Q: ¿Podéis hacer solo la auditoría de una parte concreta? A: Sí. Podemos limitar el alcance a una aplicación, un segmento de red, el código de un módulo específico o la configuración de un proveedor cloud. No tenemos mínimos de alcance obligatorios. Q: ¿El informe sirve para presentarlo a clientes o a organismos reguladores? A: Sí, siempre que el regulador acepte informes de terceros. Lo estructuramos con la formalidad necesaria para ese uso. Si el regulador exige un formato específico, podemos adaptarlo. --- ## Simulaciones de phishing: entrena a tu equipo antes de que los ataquen de verdad URL: https://www.quantumsec.es/ingenieria-social/simulaciones-phishing/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Campañas de phishing simulado para empresas. Spear phishing, vishing y smishing corporativo. Informe de resultados y formación de concienciación incluida. El phishing es el principal vector de acceso inicial en la UE: en torno al 60% de los casos observados por ENISA. Tus sistemas pueden ser perfectos; basta con que un empleado haga clic en el enlace equivocado. Las simulaciones miden exactamente eso y ayudan a cambiar el comportamiento, no solo a dar una charla. El firewall no protege el error humano Puedes tener el mejor software de seguridad del mercado y seguir siendo vulnerable si tus empleados no reconocen un email malicioso, un SMS falso o una llamada de alguien que se hace pasar por soporte técnico. La ingeniería social no ataca sistemas, ataca personas. Y la única forma de saber si tu equipo está preparado es ponerlo a prueba de forma controlada. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Los empleados sabrán que es una simulación? A: No durante la campaña. El efecto de aprendizaje es mucho mayor cuando el empleado descubre, después de hacer clic, que era una prueba. Se hace con tacto: no se identifican públicamente ni se usan para sancionar, sino para formar. Q: ¿Necesitáis acceso a nuestro servidor de email? A: Necesitamos que nuestra infraestructura de envío esté en la lista blanca para que los emails lleguen correctamente a las bandejas de entrada. Es un proceso técnico sencillo que gestionamos contigo. Q: ¿Qué pasa con los datos de quién hizo clic? A: Los datos se gestionan con estricta confidencialidad. El informe puede presentarse de forma anonimizada por departamentos si así lo prefieres, sin identificar a empleados individuales. Q: ¿Con qué frecuencia deberían hacerse estas simulaciones? A: Lo mínimo recomendable son 2-3 campañas al año. La concienciación se degrada con el tiempo si no se refuerza. Lo ideal es complementarlo con módulos de formación cortos y periódicos. --- ## Consultoría NIS2: adécuate a la directiva europea de ciberseguridad URL: https://www.quantumsec.es/cumplimiento/nis2/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Adecuación a NIS2 para empresas obligadas. Gap analysis, plan de acción y documentación. Evita sanciones de hasta 10M€ o el 2% de la facturación global. La Directiva NIS2 entró en aplicación en octubre de 2024 y afecta a miles de empresas en España. Las sanciones por incumplimiento llegan al 2% de la facturación anual global o 10 millones de euros. ¿Sabes si tu empresa entra en el ámbito de aplicación y qué debes hacer? ¿Tu empresa está obligada por NIS2? NIS2 amplía enormemente el ámbito de aplicación respecto a NIS1. Ya no afecta solo a infraestructuras críticas clásicas. Ahora incluye sectores como manufactura, alimentación, distribución, servicios digitales, proveedores de cloud, gestión de residuos y muchos más. Si tu empresa opera en uno de los 18 sectores regulados y supera ciertos umbrales de tamaño, probablemente estás obligada. Y si eres proveedor de una empresa obligada, la presión también llega a ti a través de la cadena de suministro. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿NIS2 ya está en vigor en España? A: La directiva debía transponerse al derecho nacional antes de octubre de 2024. España está en proceso de transposición. Aunque la ley nacional específica puede estar pendiente, la directiva ya genera obligaciones para las entidades cubiertas. Lo prudente es adecuarse ahora. Q: ¿Cuáles son las sanciones por incumplimiento de NIS2? A: Para entidades esenciales: hasta 10 millones de euros o el 2% de la facturación anual mundial, la cifra que sea mayor. Para entidades importantes: hasta 7 millones de euros o el 1,4% de la facturación global. Q: ¿En qué se diferencia NIS2 de la anterior directiva NIS1? A: NIS2 amplía el ámbito sectorial, aumenta las obligaciones de reporting (notificación en 24/72 horas), eleva las sanciones, incluye responsabilidad personal para los órganos de dirección y añade requisitos sobre la cadena de suministro. Q: ¿Tenemos que hacer un pentesting para cumplir con NIS2? A: NIS2 exige evaluar los riesgos de seguridad y aplicar medidas técnicas apropiadas. El pentesting es una de las formas más sólidas de cumplir con esa obligación de forma documentada y verificable. Q: ¿Cuánto tiempo lleva adecuarse a NIS2? A: Depende de tu punto de partida. Empresas con una base de seguridad sólida pueden completar el proceso en 3-6 meses. Organizaciones que parten desde cero pueden necesitar 12-18 meses para una adecuación completa. Q: ¿Qué plazos maneja la adaptación a NIS2 en España? A: NIS2 es aplicable desde octubre de 2024, así que no hay periodo de gracia por delante: las obligaciones ya son exigibles para las entidades en ámbito. En la práctica el calendario lo marca tu punto de partida, no la norma. Recomendamos cerrar el análisis de aplicabilidad y el gap analysis en 4-6 semanas para tener un plan de adaptación con plazos defendibles ante el supervisor, aunque la implementación se extienda después varios meses. Q: ¿Qué diferencia hay entre estar en ámbito como entidad esencial o importante? A: Los requisitos de seguridad del artículo 21 son los mismos para ambas. Lo que cambia es la supervisión y el régimen sancionador: las entidades esenciales están sujetas a supervisión proactiva y a multas de hasta 10 M€ o el 2% de la facturación global; las importantes, a supervisión reactiva — tras un incidente o una denuncia — y hasta 7 M€ o el 1,4%. Determinar la categoría correcta es parte del análisis de aplicabilidad. --- ## Cumplimiento DORA: resiliencia operativa digital para el sector financiero URL: https://www.quantumsec.es/cumplimiento/dora/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Adecuación DORA para entidades financieras. Gestión de riesgos TIC, pruebas de resiliencia operativa y cadena de suministro. Equipo especializado. DORA es de obligado cumplimiento desde enero de 2025 para bancos, aseguradoras, gestoras de fondos y un largo listado de entidades financieras en la UE. Evaluamos tu situación actual, identificamos las brechas y te acompañamos en el proceso de adecuación. DORA no es opcional para el sector financiero El Reglamento DORA (Digital Operational Resilience Act) entró en aplicación en enero de 2025. Afecta a miles de entidades financieras en la UE: bancos, aseguradoras, empresas de inversión, gestoras de fondos, proveedores de servicios de pago y sus proveedores tecnológicos críticos. El incumplimiento puede conllevar sanciones significativas y, sobre todo, puede dejar en evidencia la incapacidad de la entidad para gestionar una crisis digital. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿En qué se diferencia DORA de NIS2? A: NIS2 es una directiva horizontal que afecta a múltiples sectores. DORA es un reglamento sectorial específico para el sector financiero, con requisitos más detallados y técnicos, especialmente en lo relativo a las pruebas de resiliencia (TLPT) y la gestión de proveedores TIC. Q: ¿Qué son las pruebas TLPT y quién debe realizarlas? A: Las pruebas TLPT (Threat-Led Penetration Testing) son pruebas avanzadas de intrusión basadas en inteligencia de amenazas reales, dirigidas a los sistemas más críticos de la entidad. Solo son obligatorias para las entidades significativas designadas por las autoridades competentes. Nosotros podemos ejecutarlas con metodología TIBER-EU. Q: ¿DORA afecta también a los proveedores tecnológicos de entidades financieras? A: Sí. DORA establece un régimen de supervisión directa para los proveedores TIC críticos. Y aunque no seas un proveedor TIC crítico, si eres proveedor tecnológico de una entidad financiera, esta te exigirá que incluyas cláusulas contractuales DORA en el acuerdo de servicio. --- ## Auditoría ENS: adecuación al Esquema Nacional de Seguridad URL: https://www.quantumsec.es/cumplimiento/ens/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Servicios de auditoría y consultoría ENS: gap analysis, plan de adecuación y acompañamiento hasta la certificación. Sector público y proveedores tecnológicos. El Esquema Nacional de Seguridad (ENS) es de obligado cumplimiento para las administraciones públicas y sus proveedores tecnológicos. Te ayudamos a entender qué categoría de sistema te corresponde, qué medidas son exigibles y cómo obtener la certificación. ¿Quién debe cumplir el ENS? El Real Decreto 311/2022 que regula el ENS establece su obligatoriedad para las Administraciones Públicas españolas y para cualquier empresa privada que preste servicios tecnológicos al sector público o trate información de los ciudadanos en nombre de la Administración. Si has ganado un contrato público con componente tecnológico, probablemente tienes la obligación (o la tendrás en breve) de certificar bajo ENS. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre la declaración de conformidad ENS y la certificación? A: La declaración de conformidad es un documento interno que la propia entidad emite afirmando que cumple el ENS. La certificación es emitida por una entidad de certificación acreditada por ENAC tras una auditoría formal. Hay contratos públicos que exigen la certificación, otros que aceptan la declaración. Q: ¿Con qué frecuencia hay que renovar la certificación ENS? A: La certificación ENS tiene una vigencia de 2 años, con auditorías de seguimiento anuales. Q: ¿Qué pasa si los sistemas son de categoría BÁSICA? A: Los sistemas de categoría BÁSICA tienen un conjunto de medidas menos exigente, pero igualmente obligatorio. La conformidad puede acreditarse mediante una auditoría interna correctamente documentada. Q: ¿Puedo contratar la auditoría ENS con QuantumSec o tiene que ser un organismo oficial? A: La certificación formal del ENS debe emitirla una entidad de certificación acreditada por ENAC. Nuestro servicio es la consultoría previa: gap analysis, clasificación del sistema, implementación de medidas y preparación de toda la documentación para que la auditoría de certificación se apruebe a la primera. Q: ¿Qué entidades pueden certificar el ENS? A: Cualquier entidad de certificación acreditada por ENAC específicamente para el esquema ENS, como AENOR, Bureau Veritas o DNV. Nosotros no emitimos el certificado —lo hace la entidad acreditada tras la auditoría formal—, pero te ayudamos a elegir y preparamos toda la documentación y evidencias que esa auditoría va a exigir. --- ## Pentesting de red e infraestructura: descubre lo que tu firewall no ve URL: https://www.quantumsec.es/pentesting/red-infraestructura/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de red perimetral, interna y segmentación. Vulnerabilidades en switches, routers, firewalls y VPNs. Informe técnico con remediación. Auditamos la seguridad de tu red interna y perimetral con técnicas reales de ataque. Identificamos configuraciones erróneas, rutas de movimiento lateral y puntos de entrada que los escáneres automáticos no detectan. El problema: la mayoría de brechas empiezan en la red interna Una vez que un atacante supera el perímetro —a través de phishing, una VPN vulnerable o un proveedor comprometido— necesita moverse por tu red para llegar a los activos valiosos. En redes mal segmentadas, sin control de acceso granular o con configuraciones heredadas sin revisar, ese movimiento lateral puede tardar minutos. Y si tu Active Directory está en la misma red que tu WiFi de empleados, el problema es todavía mayor. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting de red puede interrumpir mis servicios? A: En condiciones normales, no. Acordamos el alcance y excluimos acciones disruptivas. Las pruebas más agresivas se planifican en ventanas de mantenimiento. Si trabajas 24/7, definimos ventanas fuera de horas pico. Q: ¿Cuál es la diferencia entre auditoría interna y perimetral? A: La perimetral analiza lo que un atacante externo ve desde Internet: puertos abiertos, servicios expuestos, configuración de DMZ. La interna simula a un atacante ya dentro —empleado malicioso, credencial robada— y es donde aparecen los hallazgos más críticos. Q: ¿Con qué frecuencia debería auditar la red? A: Al menos una vez al año, y siempre que haya cambios significativos en la infraestructura: nuevas sedes, cambio de proveedor, migración cloud o ampliación de red WiFi corporativa. Q: ¿Qué tamaño de red puede auditarse? A: Auditamos desde redes de 20 hosts hasta entornos enterprise de miles de dispositivos. El alcance y precio se adaptan al tamaño real de tu infraestructura. --- ## Auditoría de código fuente: encuentra vulnerabilidades antes de que lleguen a producción URL: https://www.quantumsec.es/auditorias/codigo-fuente/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de código fuente (SAST + revisión manual). Detectamos SQL injection, XSS, secretos expuestos y vulnerabilidades OWASP. Informe con PoC. Revisamos el código de tu aplicación con herramientas de análisis estático y revisión manual experta. Detectamos desde inyecciones SQL hasta lógica de negocio rota, con contexto suficiente para que tu equipo pueda corregirlo. El problema: las herramientas automáticas no entienden el contexto Los escáneres SAST generan un volumen enorme de falsos positivos y no entienden la lógica de negocio de tu aplicación. Un revisor experto sabe distinguir una vulnerabilidad real explotable de un falso positivo, priorizar según impacto real y detectar los fallos de diseño que ningún escáner puede ver: referencias directas a objetos, bypass de autenticación, condiciones de carrera. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Tenemos que dar acceso al repositorio? A: Sí, necesitamos acceso de lectura al repositorio. Firmamos un NDA antes y todo el acceso queda documentado. Puedes crear una rama o fork específico para la revisión si tu política lo requiere. Q: ¿Qué lenguajes y frameworks soportáis? A: JavaScript/TypeScript (Node.js, React, Angular, Vue), Python (Django, FastAPI, Flask), Java (Spring), PHP (Laravel), Ruby (Rails), Go y .NET (C#). Si trabajas con otro stack, consúltanos. Q: ¿Cuánto tiempo tarda? A: Entre 3 y 8 días hábiles según el tamaño del código base. Un proyecto de 30.000 líneas puede revisarse en unos 4 días. Proyectos mayores requieren más tiempo o una revisión focalizada en módulos críticos. Q: ¿También revisáis infraestructura como código (IaC)? A: Sí. Revisamos Terraform, CloudFormation, Kubernetes manifests y Dockerfiles para detectar configuraciones inseguras en la infraestructura definida como código. --- ## Ingeniería social: el vector de ataque que la tecnología no puede bloquear URL: https://www.quantumsec.es/ingenieria-social/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Simulaciones de ingeniería social: phishing dirigido, vishing y pretexting. Medimos la resiliencia humana de tu empresa frente a ataques reales. El factor humano interviene en aproximadamente 6 de cada 10 brechas de datos, según el Verizon DBIR. Simulamos ataques de ingeniería social reales —phishing, vishing, pretexting— para medir y mejorar la resiliencia de tu equipo antes de que lo haga un atacante de verdad. El eslabón más débil no está en tu código Puedes tener el mejor firewall del mercado, los parches al día y una política de contraseñas estricta. Pero si un empleado hace clic en un correo bien construido, te da sus credenciales en una llamada convincente o conecta un USB encontrado en el aparcamiento, todo lo demás se derrumba. La ingeniería social explota la confianza humana, la urgencia y la autoridad —y esos factores no desaparecen con tecnología. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Los empleados sabrán que es una simulación? A: No durante la ejecución, para que los resultados sean representativos. Sí después, en la sesión de concienciación. La dirección siempre es informada antes de comenzar. Q: ¿Qué pasa si un empleado cae en el phishing? A: Nada negativo. El objetivo es formativo, no punitivo. El empleado verá una página de aviso que explica que acaba de participar en un ejercicio y qué señales debería haber detectado. Q: ¿Con qué frecuencia debería hacerse? A: Al menos dos veces al año para mantener el nivel de alerta. Las organizaciones con mayor exposición o que manejan datos sensibles deberían hacerlo trimestralmente. Q: ¿Podemos excluir ciertos departamentos? A: Sí. Podemos segmentar el alcance según departamentos, niveles de acceso o cualquier criterio que necesites. --- ## Cumplimiento normativo en ciberseguridad: de la obligación al activo estratégico URL: https://www.quantumsec.es/cumplimiento/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cumplimiento normativo en ciberseguridad para empresas reguladas: identificamos qué te aplica, hacemos el gap analysis y acompañamos hasta la certificación. NIS2, DORA, ENS, ISO 27001. Las normativas de ciberseguridad se multiplican y endurecen. Te ayudamos a entender qué te aplica, qué te falta y cómo conseguirlo sin convertirlo en un proyecto interminable. El problema con el cumplimiento normativo hoy Las empresas se enfrentan a un mapa normativo que se solapa y contradice: la Directiva NIS2 obliga a los sectores críticos, DORA aplica al sector financiero, el ENS a entidades públicas y sus proveedores, e ISO 27001 es exigida cada vez más por clientes enterprise como requisito contractual. Cada normativa tiene sus plazos, sus controles específicos y su régimen sancionador. Sin un guía que las conozca bien, el riesgo es hacer un esfuerzo enorme para no llegar a ningún lado. Damos soporte de cumplimiento a empresas de toda España — Valencia, Alicante, Sevilla, Barcelona y el resto del territorio — de forma remota, con presencia física cuando la auditoría lo exige. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podéis ayudarnos con varias normativas a la vez? A: Sí, y tiene sentido hacerlo. Muchos controles de ISO 27001, NIS2 y DORA se solapan. Hacerlo de forma integrada evita duplicidades y reduce el esfuerzo total. Q: ¿Hacéis también la auditoría de certificación? A: No somos organismo certificador (requiere acreditación ENAC), pero trabajamos con las principales entidades certificadoras y te acompañamos durante todo el proceso. Q: ¿Cuánto tiempo lleva un proyecto de cumplimiento? A: Depende de la normativa y el estado de partida. Un gap analysis tarda 2-4 semanas. Un proyecto completo de ISO 27001 desde cero tarda entre 6 y 12 meses en una PYME. Q: ¿El ENS es obligatorio para empresas privadas? A: El ENS es obligatorio para administraciones públicas y las empresas privadas que prestan servicios TIC a la Administración o tratan datos de titularidad pública. --- ## ISO 27001: implantación y certificación del sistema de gestión de seguridad URL: https://www.quantumsec.es/cumplimiento/iso-27001/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Implantación y certificación ISO 27001. Gap analysis, diseño del SGSI e implementación de controles. Acompañamiento hasta la auditoría externa. Te acompañamos desde el gap analysis hasta la auditoría de certificación. Diseñamos un SGSI que funcione de verdad en tu empresa, sin burocracia innecesaria y sin perder el foco en lo que importa: reducir el riesgo real. El problema con los proyectos ISO 27001 que fracasan La mayoría de proyectos ISO 27001 fallidos tienen el mismo patrón: un consultor entrega un paquete de documentos genéricos, el equipo los firma sin entenderlos, y cuando llega el auditor externo las políticas no tienen nada que ver con la realidad. Documentar por documentar no reduce el riesgo. Nosotros arrancamos con un gap analysis honesto y construimos un SGSI que refleje cómo trabaja tu empresa de verdad, que el equipo entienda y que el auditor valide. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿ISO 27001:2013 o ISO 27001:2022? ¿Hay que migrar? A: La versión vigente es la ISO 27001:2022. Los certificados emitidos bajo la versión 2013 tenían de plazo hasta octubre de 2025 para migrar. Si estás empezando, arranca directamente con la versión 2022. Q: ¿Cuántos recursos internos necesita el proyecto? A: Se necesita un responsable interno (normalmente el CISO o responsable de IT) con entre 4 y 8 horas semanales. El equipo técnico participa puntualmente en la implementación de controles. Q: ¿El certificado ISO 27001 tiene fecha de caducidad? A: El certificado tiene validez de 3 años, con auditorías de seguimiento anuales (años 1 y 2) y auditoría de renovación en el año 3. Q: ¿Podéis hacer las auditorías de seguimiento anuales? A: Sí. Ofrecemos contratos de mantenimiento para auditorías de seguimiento, actualización del SGSI ante cambios y preparación para la renovación trianual. Q: ¿Con qué entidad de certificación trabajáis? A: No emitimos el certificado nosotros: por incompatibilidad de roles, quien te ayuda a implantar el SGSI no puede ser quien lo certifique. Te acompañamos en el proceso de selección entre entidades acreditadas por ENAC —AENOR, Bureau Veritas, DNV y otras— y damos soporte técnico durante toda la auditoría externa, sea cual sea la que elijas. --- ## Pentesting de Inteligencia Artificial y LLMs URL: https://www.quantumsec.es/pentesting/inteligencia-artificial/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pentesting de sistemas de IA y LLMs para empresas en España: prompt injection, jailbreak y RAG. OWASP Top 10 LLM y MITRE ATLAS. Informe con PoC. Los modelos de lenguaje y los sistemas de IA introducen vectores de ataque completamente nuevos. Evaluamos la seguridad de tu infraestructura de IA antes de que lo haga un adversario real. ¿Por qué la IA necesita un pentesting específico? Un LLM mal protegido puede revelar datos de entrenamiento confidenciales, ejecutar instrucciones arbitrarias mediante prompt injection o ser manipulado para eludir controles de negocio. Las herramientas de pentesting tradicionales no detectan estos vectores. Se requiere metodología específica alineada con OWASP Top 10 for LLMs y MITRE ATLAS. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting de IA afecta al rendimiento del modelo en producción? A: No. Las pruebas se realizan en un entorno de staging o con tráfico controlado. Nunca interferimos con usuarios reales ni degradamos el servicio. Q: ¿Necesito acceso al modelo o solo a la interfaz? A: Depende del alcance. Un test de caja negra solo requiere acceso a la interfaz final. Un test completo de pipeline requiere acceso al código del sistema y configuración del modelo. Q: ¿Cubrís modelos open-source desplegados on-premise? A: Sí. Evaluamos tanto modelos en cloud (APIs de OpenAI, Anthropic, Google) como modelos open-source (Llama, Mistral, Qwen) desplegados en infraestructura propia. --- ## Pentesting de infraestructura cloud (AWS, Azure, GCP) URL: https://www.quantumsec.es/pentesting/cloud/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pentesting cloud en AWS, Azure y GCP. Revisión de IAM, configuraciones erróneas, privilege escalation y cumplimiento CIS Benchmarks. Informe técnico. La mayoría de los incidentes en cloud no vienen de un zero-day, sino de una mala configuración: la NSA y CISA advierten de que los atacantes buscan de forma activa entornos cloud mal configurados, sin asegurar o sin monitorizar. Auditamos tu infraestructura cloud antes de que un atacante la explote. ¿Por qué el cloud necesita un pentesting diferente? La filosofía de shared responsibility del cloud pone la seguridad de configuración, identidad y datos en manos del cliente. Un S3 bucket público, un rol IAM con permisos excesivos o una instancia EC2 con credenciales hardcodeadas son vectores que los escáneres automáticos no contextualizan. Necesitas un equipo que piense como un atacante con conocimiento profundo de AWS, Azure y GCP. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis credenciales de administrador para el pentesting cloud? A: Para un test completo, sí necesitamos una cuenta con permisos de lectura sobre todos los servicios. También podemos realizar un test de caja negra desde internet para evaluar la exposición externa. Te recomendamos combinar ambos enfoques. Q: ¿El pentesting puede afectar a mis servicios en producción? A: Coordinamos todas las pruebas para minimizar el impacto. La explotación destructiva (borrado, modificación de datos) siempre requiere aprobación explícita y se realiza en entornos de prueba. Q: ¿Cubrís arquitecturas multi-cloud? A: Sí. Tenemos experiencia en entornos que combinan AWS, Azure y GCP, así como en configuraciones híbridas cloud + on-premise. --- ## Pentesting IoT y Hardware Hacking URL: https://www.quantumsec.es/pentesting/iot/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Evaluación de seguridad en dispositivos IoT, firmware, hardware industrial y entornos OT/ICS. Metodologías OWASP IoT Top 10 e IEC 62443. Los dispositivos conectados son el nuevo perímetro. Evaluamos la seguridad de tu infraestructura IoT, firmware, comunicaciones y hardware industrial antes de que se conviertan en la puerta de entrada a tu red. ¿Por qué los dispositivos IoT son un riesgo crítico? Un dispositivo IoT comprometido puede servir como pivot para acceder a la red corporativa, exfiltrar datos de producción o paralizar infraestructura crítica. Los fabricantes priorizan funcionalidad sobre seguridad, y los equipos de TI raramente auditan el firmware o las comunicaciones de estos dispositivos. En entornos OT/ICS, el impacto puede ser físico. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso físico al dispositivo? A: Para un test completo, sí. Algunos análisis (API backend, app móvil, comunicaciones de red) se pueden realizar de forma remota, pero el análisis de firmware y hardware requiere el dispositivo físico. Q: ¿Podéis hacer el pentesting sin afectar la producción industrial? A: Siempre trabajamos con el equipo de OT para definir ventanas de mantenimiento y realizar las pruebas más invasivas fuera de horas de producción. La seguridad de la operación es nuestra prioridad. Q: ¿Hacéis evaluaciones para cumplir con la directiva RED (Radio Equipment Directive)? A: Sí. Ayudamos a fabricantes a preparar la documentación técnica de seguridad requerida por la directiva RED de la UE para dispositivos IoT. --- ## Pentesting de aplicaciones iOS URL: https://www.quantumsec.es/pentesting/ios/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de apps iOS (iPhone, iPad). OWASP MASVS y MASTG. Análisis estático, dinámico, almacenamiento inseguro y comunicaciones. Informe técnico. Una app en la App Store no implica que sea segura. Auditamos tu aplicación iOS siguiendo la metodología OWASP MASVS para detectar vulnerabilidades en datos, comunicaciones y lógica de negocio. ¿Por qué las apps iOS necesitan una auditoría específica? La revisión de Apple detecta malware y violaciones de políticas, pero no audita la lógica de seguridad de tu aplicación. Datos almacenados sin cifrar en el keychain, tokens de sesión expuestos en logs, validación de certificados desactivada o comunicaciones con backends inseguros son vulnerabilidades que Apple no revisa y que un atacante con el dispositivo en mano puede explotar. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis el código fuente o solo el IPA? A: Podemos trabajar con solo el IPA (caja negra/gris). Si nos proporcionas el código fuente, el análisis es más profundo y eficiente. Recomendamos el acceso al código para equipos de desarrollo que quieren resultados accionables. Q: ¿El test require un dispositivo físico con jailbreak? A: Para el análisis dinámico completo, sí recomendamos un dispositivo con jailbreak. También podemos trabajar con simuladores para parte del análisis estático y de red. Q: ¿Cubris la API backend que usa la app? A: Sí, incluimos la evaluación del backend API dentro del alcance del pentesting móvil. Es esencial para una evaluación completa, ya que muchas vulnerabilidades están en la capa de servidor. --- ## Pentesting de aplicaciones Android URL: https://www.quantumsec.es/pentesting/android/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de apps Android. OWASP MASVS y MASTG. Análisis APK, almacenamiento inseguro, comunicaciones, permisos y componentes exportados. Android es el sistema operativo móvil más usado del mundo y el objetivo preferido de los atacantes. Auditamos tu app siguiendo OWASP MASVS para garantizar que los datos de tus usuarios están protegidos. ¿Por qué Android es especialmente crítico para la seguridad? La fragmentación de Android, la facilidad para instalar APKs de terceros y la gran variedad de fabricantes con personalizaciones propias amplían enormemente la superficie de ataque. Un componente Activity exportado sin protección, un ContentProvider que expone datos de otros apps o un WebView mal configurado pueden ser explotados sin que el usuario lo perciba. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis el código fuente de la app Android? A: No es imprescindible. Podemos trabajar con el APK directamente mediante análisis de caja negra/gris. El código fuente permite un análisis más profundo, especialmente para detectar vulnerabilidades en lógica de negocio. Q: ¿Podéis hacer el test sin un dispositivo físico? A: Parte del análisis (estático y de red) puede realizarse con emuladores. Para el análisis dinámico completo con Frida y análisis de hardware-backed security, recomendamos un dispositivo físico rooteado. Q: ¿La auditoría sirve para cumplir con GDPR en apps Android? A: Sí. Identificamos dónde se almacenan y transmiten datos personales, si están protegidos adecuadamente y qué permisos son excesivos o innecesarios, lo cual es clave para la evaluación de impacto en privacidad (DPIA). --- ## Ciberinteligencia y Threat Intelligence (CTI) URL: https://www.quantumsec.es/ciberinteligencia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. CTI: monitorización de dark web, credenciales filtradas y amenazas activas. Alertas tempranas y análisis de inteligencia para tu sector. Conoce a tus adversarios antes de que te ataquen. Nuestro servicio de CTI proporciona inteligencia accionable sobre amenazas reales que afectan a tu organización, sector y cadena de suministro. ¿Por qué necesitas inteligencia sobre amenazas? Reaccionar a los ataques cuando ya han ocurrido es demasiado tarde. La ciberinteligencia te permite anticiparte: saber qué grupos de amenaza actúan en tu sector, si tus credenciales circulan en foros de cibercrimen, si tu marca está siendo suplantada o si existe un exploit activo contra el software que usas. La diferencia entre detectar una brecha a los 3 días o a los 200 días puede ser el impacto total del incidente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El servicio de CTI es continuo o puntual? A: Es un servicio continuo de monitorización. La inteligencia puntual (un informe de exposición o un análisis de un actor de amenaza concreto) también está disponible como servicio ad-hoc. Q: ¿Cómo se integra el CTI con nuestros sistemas de seguridad existentes? A: Proporcionamos feeds en formatos estándar (STIX/TAXII, CSV, JSON) integrables con los principales SIEMs (Splunk, Microsoft Sentinel, QRadar) y plataformas SOAR. Q: ¿Qué diferencia hay entre CTI y OSINT? A: OSINT es una fuente (información de fuentes abiertas). CTI es un proceso completo: recolección de múltiples fuentes (OSINT, dark web, feeds privados), análisis, contextualización y producción de inteligencia accionable para la toma de decisiones. --- ## Auditoría de seguridad WiFi y redes inalámbricas URL: https://www.quantumsec.es/auditorias/wifi/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría WiFi corporativa. WPA2/WPA3, redes de invitados, Evil Twin, rogue AP y segmentación inalámbrica según OWISAM. Informe técnico. Una red WiFi corporativa mal configurada es una puerta de entrada directa a tu red interna. Evaluamos la seguridad de tu infraestructura inalámbrica con metodología OWISAM. ¿Por qué el WiFi corporativo es un vector de ataque habitual? Basta una sola red WiFi mal configurada para abrir la puerta a toda la red corporativa, y en la mayoría de oficinas conviven varias. Contraseñas WPA2 débiles susceptibles a ataques de diccionario, redes de invitados sin segmentación, puntos de acceso rogue instalados sin autorización o falta de detección de Evil Twin son vectores reales que los atacantes explotan para ganar acceso inicial a la red corporativa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis estar físicamente en nuestras instalaciones? A: Para la evaluación completa, sí. El análisis de redes inalámbricas requiere presencia física. Coordinamos visitas en horario que minimice la interrupción de la actividad. Q: ¿La auditoría WiFi incluye redes de invitados? A: Sí, incluimos todas las redes inalámbricas en el perímetro: corporativas, de invitados, IoT y cualquier red no autorizada que detectemos. Q: ¿Evaluáis también la seguridad de los dispositivos conectados al WiFi? A: El alcance estándar cubre la infraestructura inalámbrica. Si deseas incluir la evaluación de dispositivos conectados (IoT, PCs, impresoras), lo ampliamos como parte de un pentesting de red interno. --- ## Seguridad gestionada (MSSP): ciberseguridad continua para tu empresa URL: https://www.quantumsec.es/seguridad-gestionada/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. MSSP: monitorización continua, gestión de vulnerabilidades, respuesta a incidentes y CISO virtual para empresas sin equipo de seguridad interno. La ciberseguridad no es un proyecto puntual, es un proceso continuo. Actuamos como tu departamento de seguridad externalizado: monitorizamos, detectamos, respondemos y mejoramos tu postura de seguridad mes a mes. ¿Por qué necesitas seguridad gestionada? La mayoría de las empresas no pueden permitirse un CISO, un SOC y un equipo de respuesta a incidentes internos. Sin embargo, los atacantes no distinguen entre una startup de 20 personas y una empresa del Ibex35. Un servicio MSSP te da acceso a capacidades de seguridad de nivel enterprise por una fracción del coste, con la ventaja de escalar según tus necesidades y tener un único punto de contacto para toda tu ciberseguridad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre MSSP y un contrato de mantenimiento IT? A: Un MSSP se centra exclusivamente en seguridad: detección de amenazas, gestión de vulnerabilidades, respuesta a incidentes y cumplimiento normativo. No gestionamos infraestructura ni soporte de usuario final. Q: ¿Cuál es el SLA de respuesta ante un incidente? A: Para incidentes críticos, el tiempo de respuesta inicial es inferior a 4 horas. Para incidentes de alto impacto, garantizamos inicio del análisis forense en el mismo día. Q: ¿El servicio incluye el pentesting anual? A: Sí, los planes de nivel medio y superior incluyen un pentesting anual de alcance acordado. Es la combinación ideal: monitorización continua + evaluación ofensiva periódica. --- ## Pentesting potenciado por Inteligencia Artificial URL: https://www.quantumsec.es/pentesting/con-ia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Servicio de pentesting con IA para empresas en España: más cobertura en menos tiempo. Herramientas de IA validadas por pentesters OSCP. Informe con PoC real. La IA no reemplaza al pentester: lo hace más efectivo. Combinamos herramientas de IA con el criterio de nuestros expertos para ofrecer auditorías más rápidas, con mayor cobertura y menor coste. ¿Cómo mejora la IA el pentesting tradicional? Las herramientas tradicionales generan ruido: miles de hallazgos en los que los falsos positivos y los avisos de baja relevancia superan con creces a las vulnerabilidades realmente explotables. La IA nos permite priorizar automáticamente, generar payloads adaptativos, analizar grandes volúmenes de código fuente en minutos y correlacionar hallazgos para identificar cadenas de ataque. El resultado: más vulnerabilidades reales en menos tiempo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting con IA es tan riguroso como el manual? A: Es más riguroso en cobertura (la IA no se cansa, no omite pasos) y menos en creatividad pura. Por eso combinamos ambos: la IA garantiza la cobertura sistemática y el experto humano aporta creatividad, contexto y explotación avanzada. Q: ¿Qué herramientas de IA utilizáis? A: Combinamos herramientas propietarias con soluciones reconocidas del sector, adaptadas a cada tipo de evaluación. No dependemos de un único proveedor ni de herramientas de IA genéricas sin validación en seguridad. Q: ¿Es más barato que el pentesting tradicional? A: Generalmente sí, porque la automatización reduce las horas de reconocimiento manual. Pero el valor principal no es el coste: es la mayor cobertura en el mismo tiempo. --- ## Análisis de vulnerabilidades (Vulnerability Assessment) URL: https://www.quantumsec.es/analisis-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Análisis de vulnerabilidades: detección sistemática de brechas sin explotación activa. Diferencias clave con el pentesting y cuándo usar cada uno. El primer paso para mejorar tu seguridad es saber dónde estás expuesto. El análisis de vulnerabilidades te da una foto completa de tus riesgos técnicos, priorizada por criticidad. Análisis de vulnerabilidades vs. Pentesting: ¿qué necesita tu empresa? El análisis de vulnerabilidades (VA) identifica y clasifica vulnerabilidades conocidas en tus sistemas mediante escaneo y revisión técnica, sin explotarlas activamente. El pentesting va un paso más allá: un experto intenta explotar esas vulnerabilidades para demostrar impacto real. El VA es ideal como revisión periódica o punto de partida; el pentesting es necesario para demostrar impacto real, cumplimiento normativo avanzado o preparación ante Red Team. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un análisis de vulnerabilidades es suficiente para cumplir con NIS2 o ISO 27001? A: Depende del nivel de madurez requerido. NIS2 e ISO 27001 requieren gestión continua de vulnerabilidades, que puede cubrirse con un VA recurrente. Para demostraciones de impacto real o evaluaciones de Red Team, se requiere pentesting. Q: ¿Con qué frecuencia debería hacer un análisis de vulnerabilidades? A: Recomendamos un ciclo mensual para activos críticos y trimestral para el resto. Tras cambios significativos en la infraestructura (nueva aplicación, migración cloud, etc.) siempre recomendamos un análisis puntual. Q: ¿El VA incluye aplicaciones web? A: Sí. El alcance puede incluir infraestructura de red, servidores, aplicaciones web y APIs. También ofrecemos el análisis de vulnerabilidades como primer paso antes de un pentesting web completo. --- ## Hacking ético externo: evaluación del perímetro desde internet URL: https://www.quantumsec.es/hacking-etico/externo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Hacking ético externo: seguridad del perímetro desde internet. OSINT, reconocimiento, explotación de servicios expuestos y cadenas de ataque. Un atacante sin credenciales ni acceso previo puede comprometer tu organización desde internet. Evaluamos toda tu superficie de ataque externa con la perspectiva real de un adversario. ¿Qué ve un atacante cuando apunta a tu empresa desde internet? Servicios expuestos sin saberlo, subdominios olvidados con aplicaciones obsoletas, credenciales de empleados en filtraciones de datos, certificados caducados, paneles de administración accesibles desde internet: esta es la realidad del perímetro de la mayoría de las empresas. El hacking ético externo simula un ataque real desde internet para identificar y demostrar exactamente qué puede conseguir un atacante sin acceso previo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre hacking ético externo y un pentesting de red? A: El hacking ético externo se centra exclusivamente en lo que es visible desde internet, comenzando desde cero (sin credenciales ni acceso previo), incluyendo OSINT. El pentesting de red cubre tanto el perímetro externo como la red interna. Q: ¿Incluye el OSINT en empleados? A: Sí, dentro del alcance acordado. Identificamos datos de empleados expuestos en filtraciones, LinkedIn y otras fuentes que un atacante real utilizaría para ataques dirigidos o credential stuffing. Q: ¿Puede detectar si ya hemos sido comprometidos? A: Una evaluación de compromiso activo (Compromise Assessment) es un servicio diferente. Sin embargo, si durante el reconocimiento detectamos indicadores de compromiso previo, te lo comunicamos inmediatamente. --- ## Hacking ético interno: evaluación desde dentro de la red URL: https://www.quantumsec.es/hacking-etico/interno/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Hacking ético interno: seguridad desde dentro de la red corporativa. Movimiento lateral, escalada de privilegios y segmentación de red. El movimiento lateral es la fase que convierte una intrusión puntual en una brecha grave. Simulamos un atacante que ya ha ganado acceso inicial para evaluar hasta dónde puede llegar en tu infraestructura interna. ¿Qué pasa cuando un atacante entra en tu red? La mayoría de las empresas invierten en proteger el perímetro, pero una vez dentro, un atacante puede moverse libremente por la red interna, escalar privilegios, acceder a sistemas críticos y exfiltrar datos durante semanas o meses sin ser detectado. El insider threat (empleado malicioso) y el phishing exitoso son los vectores de entrada más comunes. La pregunta es: ¿hasta dónde puede llegar una vez dentro? Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Desde qué punto de partida se realiza el hacking ético interno? A: Típicamente simulamos un usuario de dominio estándar (el escenario más realista: un empleado comprometido o un atacante con acceso inicial vía phishing). También podemos empezar desde acceso físico a la red (cable de red) o desde una cuenta sin privilegios en el equipo. Q: ¿El test puede afectar a los sistemas en producción? A: Coordinamos todas las pruebas con el equipo de IT. Las técnicas más invasivas (como modificar el AD) se realizan solo con autorización explícita y en ventanas acordadas. El objetivo es simular un ataque, no causar daño. Q: ¿Qué es BloodHound y por qué es relevante? A: BloodHound es la herramienta estándar del sector para analizar relaciones en Active Directory y encontrar caminos de escalada de privilegios. Los atacantes la usan; nosotros también, para que puedas ver exactamente lo que ellos verían en tu AD. --- ## Ciberseguridad para PYMEs: protege tu empresa con un presupuesto real URL: https://www.quantumsec.es/soluciones/pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pentesting, seguridad gestionada y cumplimiento NIS2 para PYMEs y medianas empresas en España. Sin grandes presupuestos. Diagnóstico gratuito en 24h. Las PYMEs y medianas empresas son el objetivo favorito de los ciberdelincuentes, no el de menor prioridad. Diseñamos soluciones de seguridad informática que se adaptan a tu tamaño, presupuesto y recursos. ¿Por qué las PYMEs son objetivo preferente de los ciberataques? Las PYMEs son un objetivo habitual de los ciberataques, no una excepción. Los atacantes saben que las pequeñas y medianas empresas tienen menos defensas, presupuestos limitados y, en muchos casos, ningún especialista en seguridad informática. Un ataque de ransomware puede paralizar una PYME durante semanas y suponer pérdidas de decenas de miles de euros. La buena noticia: no necesitas el presupuesto de una multinacional para tener un nivel de seguridad adecuado. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta la ciberseguridad para una PYME? A: Depende del tamaño y la exposición. Un diagnóstico inicial y un análisis de vulnerabilidades básico puede estar en el rango de unos pocos cientos de euros. Un servicio de seguridad gestionada para una PYME típica oscila entre 300 y 800 €/mes. Siempre empezamos con lo que más impacto tiene por el menor coste. Q: ¿Obligatoriamente tengo que cumplir con NIS2 siendo una PYME? A: Depende de tu sector y tamaño. NIS2 obliga directamente a empresas medianas y grandes en sectores esenciales e importantes. Sin embargo, muchas PYMEs están indirectamente obligadas porque son proveedoras de empresas que sí deben cumplir, y estas les exigen garantías de seguridad. Q: ¿Podéis ayudarnos aunque no tengamos ningún responsable de IT? A: Sí. Trabajamos directamente con gerencia o con quien sea el responsable habitual de IT/informática en la empresa. No es necesario tener conocimientos técnicos previos para trabajar con nosotros. Q: ¿Cuánto tiempo tarda poner en marcha un plan de ciberseguridad para mi PYME? A: Las medidas de mayor impacto inmediato (MFA, contraseñas, copias de seguridad) se configuran en días. Un análisis de vulnerabilidades inicial dura entre 1 y 5 días hábiles según el tamaño. Un plan completo con análisis, remediación acompañada y políticas básicas suele completarse en 4-8 semanas. Siempre empezamos por lo que más impacto tiene al menor coste. Q: ¿Mi empresa ya ha sufrido un ciberataque. ¿Qué hago ahora? A: Lo primero es contener: aislar los sistemas afectados, revocar accesos comprometidos y guardar evidencias sin modificarlas. A continuación, un análisis forense básico determina cómo entraron, qué afectaron y si siguen dentro. Si el incidente involucra datos personales, tienes 72 horas para notificar a la AEPD. Contáctanos: hacemos un triaje inicial para ayudarte a entender la situación antes de decidir los pasos siguientes. Q: ¿Necesito un CISO o responsable de seguridad interno? A: Para la mayoría de las PYMEs no es necesario ni viable. Un CISO senior en plantilla es un coste fijo elevado y un perfil difícil de atraer y retener. La alternativa es un servicio de CISO virtual o un partner de seguridad externo: tú defines los objetivos, nosotros los ejecutamos y te informamos periódicamente. Es mucho más eficiente para empresas de menos de 100 empleados. Q: ¿Qué es la seguridad gestionada y cuándo tiene sentido para una PYME? A: Es un servicio de monitorización y respuesta continua (SOC as a Service) sin necesidad de contratar un equipo propio: nosotros vigilamos tus sistemas, detectamos incidentes y actuamos según protocolos acordados contigo. Tiene sentido cuando ya tienes activos críticos que proteger fuera de horario laboral pero no el volumen para justificar un SOC interno. Q: ¿Necesito un ciberseguro además de contratar servicios de ciberseguridad? A: Son complementarios, no sustitutos. La mayoría de las aseguradoras exigen controles mínimos (MFA, backups, análisis de vulnerabilidades periódico) para emitir o renovar una póliza de ciberriesgo, y reducen la prima si puedes demostrarlos. Te ayudamos a identificar qué exige tu aseguradora y a implementarlo antes de la renovación. --- ## Ciberseguridad para startups: construye seguro desde el día uno URL: https://www.quantumsec.es/soluciones/startups/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Ciberseguridad para startups: pentesting, secure SDLC, compliance SOC2/ISO27001 e informes para due diligence de inversores. Sin deuda de seguridad. La deuda de seguridad es como la deuda técnica: ignorarla es barato a corto plazo y muy caro a largo. Con hacking ético y pentesting real ayudamos a startups y SaaS a construir productos seguros, cumplir con los requisitos de los clientes enterprise y superar el due diligence de inversores. ¿Por qué la seguridad importa desde el primer día en una startup? Una startup que sufre un breach antes de la Serie A puede ver comprometido el proceso de fundraising. Un cliente enterprise que descubre vulnerabilidades críticas durante un security review puede bloquear el contrato. Y una brecha de datos que afecte a usuarios puede significar el fin del negocio. El coste de reparar vulnerabilidades en producción es 30 veces mayor que detectarlas durante el desarrollo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuándo es el mejor momento para hacer un primer pentesting? A: El primer pentesting debería hacerse cuando el producto está en versión beta o antes del lanzamiento público. Esperar a tener tracción o usuarios reales aumenta el riesgo y el coste de la remediación. Q: ¿Podéis ayudarnos a preparar el cuestionario de seguridad de un cliente enterprise? A: Sí. Es uno de los servicios más demandados por startups. Te ayudamos a responder cuestionarios de seguridad (CAIQ, SIG, cuestionarios propios) y a tener la documentación que respalda esas respuestas. Q: ¿Tenéis experiencia con startups que usan código generado por IA o vibe coding? A: Sí. El código generado por LLMs tiende a reproducir patrones de vulnerabilidades conocidos (inyecciones, manejo inseguro de secretos, validación débil). Tenemos un servicio específico de revisión de código generado por IA. --- ## Seguridad en desarrollo con IA: auditoría de código generado por LLMs URL: https://www.quantumsec.es/soluciones/desarrollo-con-ia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de código generado por IA (Copilot, ChatGPT). Riesgos del vibe coding, vulnerabilidades frecuentes y cómo proteger tu producto. El código generado por IA es rápido, pero no es seguro por defecto. Auditamos el código generado por GitHub Copilot, ChatGPT, Claude y otras herramientas para detectar las vulnerabilidades que los LLMs no ven. ¿Por qué el código generado por IA introduce riesgos de seguridad? Los LLMs generan código plausible, no código seguro. El estudio académico de referencia sobre GitHub Copilot ("Asleep at the Keyboard?", NYU, IEEE S&P 2022) generó 1.689 programas en 89 escenarios ligados al CWE Top 25 y encontró que aproximadamente el 40% eran vulnerables. Los modelos reproducen patrones inseguros presentes en su training data, no comprenden el contexto de seguridad de tu aplicación específica y no pueden razonar sobre el impacto de negocio de una vulnerabilidad. El "vibe coding" — desarrollar sin entender el código que genera la IA — amplifica estos riesgos exponencialmente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El código generado por IA es más inseguro que el escrito por humanos? A: No necesariamente, pero introduce riesgos distintos. Los LLMs son muy buenos reproduciendo patrones conocidos, pero pueden reproducir igualmente patrones inseguros. El mayor riesgo es el "vibe coding": el desarrollador no entiende el código y no puede identificar los problemas de seguridad. Q: ¿Necesitáis acceso al repositorio completo? A: Sí, para un análisis completo necesitamos acceso de lectura al código fuente. Trabajamos con GitHub, GitLab y Bitbucket, y firmamos NDA antes de cualquier acceso. Q: ¿Podéis auditar código generado con Cursor, Devin u otras herramientas de IA? A: Sí. La herramienta específica de generación de IA es menos relevante que el patrón de vulnerabilidades del código resultante. Evaluamos el código independientemente de con qué herramienta fue generado. --- ## Consultoría de ciberseguridad para empresas URL: https://www.quantumsec.es/consultoria-ciberseguridad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Consultoría de ciberseguridad a medida: diagnóstico de riesgos, hoja de ruta, cumplimiento NIS2/ISO 27001 y acompañamiento técnico. Sin tecnicismos. No todas las empresas necesitan un pentesting inmediato. A veces lo primero es entender dónde estás, qué riesgos tienes y qué debes hacer primero. Eso es lo que hacemos en una consultoría de ciberseguridad. ¿Cuándo necesita tu empresa una consultoría de ciberseguridad? Muchas empresas no saben por dónde empezar con la ciberseguridad. Tienen dudas sobre si están obligadas por NIS2 o DORA, no saben si sus medidas actuales son suficientes, han sufrido un incidente y quieren evitar que se repita, o quieren certificarse en ISO 27001 pero no saben qué implica. Una consultoría de ciberseguridad te da un diagnóstico real de tu situación, una hoja de ruta priorizada por impacto y coste, y el acompañamiento para ejecutarla correctamente — sin vender servicios que no necesitas. Trabajamos en remoto con empresas de toda España — Valencia, Alicante, Sevilla, Barcelona y el resto del territorio — con reuniones presenciales cuando el proyecto lo requiere. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿En qué se diferencia una consultoría de ciberseguridad de un pentesting? A: El pentesting es una prueba técnica que busca vulnerabilidades explotables en un sistema concreto. La consultoría de ciberseguridad es un servicio más amplio que evalúa la madurez general de la organización: controles técnicos, procesos, personas y cumplimiento normativo. Muchas veces la consultoría lleva a identificar que un pentesting es el siguiente paso necesario, pero no siempre. Q: ¿Cuánto cuesta una consultoría de ciberseguridad? A: Depende del alcance y del tamaño de la organización. Una consultoría de diagnóstico inicial para una PYME puede partir de 2.500 €. Un proyecto más amplio con hoja de ruta completa y acompañamiento en la implantación puede situarse entre 8.000 y 25.000 €. Siempre damos un presupuesto cerrado antes de empezar. Q: ¿Podéis actuar como CISO externo después de la consultoría? A: Sí. Ofrecemos un servicio de CISO as a Service (CISOaaS) para empresas que necesitan una figura de dirección de seguridad sin el coste de contratarla a tiempo completo. Incluye supervisión de la hoja de ruta, asistencia a comités directivos y toma de decisiones estratégicas de seguridad. Q: ¿La consultoría incluye el cumplimiento de NIS2? A: Sí. Realizamos el gap analysis respecto a NIS2, identificamos si tu empresa está en scope (sectores obligados), evaluamos las medidas existentes frente a los requisitos de la directiva y preparamos un plan de adecuación con los controles técnicos y organizativos necesarios. Q: ¿Necesito tener un equipo técnico propio para trabajar con vosotros? A: No. Trabajamos tanto con empresas que tienen equipo IT interno como con empresas sin recursos técnicos propios. Adaptamos el lenguaje, el nivel de detalle y el acompañamiento a la realidad de cada cliente. --- ## Empresa de ciberseguridad en Valencia URL: https://www.quantumsec.es/ciberseguridad-valencia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Empresa de ciberseguridad en Valencia: pentesting real, hacking ético y cumplimiento NIS2 con equipo certificado OSCP. Presupuesto en 24h, sin compromiso. Somos QuantumSec, empresa de seguridad informática y ciberseguridad ofensiva con base en Valencia. Trabajamos como equipo boutique: pocos clientes a la vez, atención directa del equipo técnico y alcance a medida, sea cual sea tu sector, desde la capital hasta cualquier comarca de la Comunitat Valenciana. ¿Por qué las empresas de Valencia necesitan un partner de ciberseguridad local? El tejido empresarial valenciano —industrial, tecnológico, logístico y agroalimentario— es un objetivo prioritario para el cibercrimen, precisamente por la densidad de pymes interconectadas como proveedoras entre sí. Muchas de esas empresas no tienen todavía un plan de respuesta a incidentes documentado, lo que agrava el impacto cuando ocurre un ataque. Un equipo de ciberseguridad externo con base en Valencia te da la proximidad de un socio local con la profundidad técnica de un equipo especializado: sin los costes de una plantilla propia ni la distancia de una consultora nacional. Damos servicio a empresas de toda la Comunitat Valenciana —el área metropolitana de Valencia, La Ribera, La Safor, el Camp de Morvedre, La Costera y las provincias de Castellón y Alicante— con el mismo equipo y el mismo nivel de detalle, con independencia del sector en el que operes. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Hacéis reuniones presenciales en Valencia? A: Sí. Tenemos base en Valencia y podemos reunirnos presencialmente para la llamada inicial, presentación de resultados o sesiones de formación. La ejecución técnica se realiza de forma remota o in situ según el alcance del servicio. Q: ¿En qué municipios de la Comunitat Valenciana dais servicio? A: En toda la Comunitat Valenciana. Nuestra oficina está en Valencia capital y desde ahí nos desplazamos con normalidad al área metropolitana (Paterna, Torrent, Manises, Burjassot, Mislata), La Ribera (Alzira, Algemesí, Carcaixent), La Safor (Gandia, Oliva), el litoral (Cullera, Sueca, Sagunto, Dénia), La Costera (Xàtiva, Canals) y La Vall d'Albaida (Ontinyent). También atendemos empresas de Castellón y Alicante. No tenemos oficina en cada municipio: tenemos una sede en Valencia y un equipo que se desplaza, que es lo que permite mantener el trato directo sin encarecer el servicio. Q: ¿Trabajáis solo con grandes empresas o también con PYMEs valencianas? A: Trabajamos con todo tipo de empresas, desde autónomos con presencia digital hasta empresas del Ibex35. Tenemos propuestas específicamente diseñadas para el tejido PYME valenciano, con alcances y precios adaptados a su realidad. Q: ¿Cuánto cuesta un servicio de ciberseguridad para una empresa en Valencia? A: El coste varía según el alcance. Un análisis de vulnerabilidades básico para una PYME empieza desde 1.500 €. Un pentesting completo (web + red interna) está entre 4.000 y 12.000 € según la complejidad. Solicitanos una consulta gratuita y te damos un presupuesto sin compromiso en 24 horas. Q: ¿Podéis ayudarnos a cumplir la directiva NIS2 desde Valencia? A: Sí. Asesoramos a empresas valencianas en la adaptación a NIS2, identificando si están en scope, realizando el gap analysis, implementando los controles requeridos y preparando la documentación para la autoridad competente (INCIBE-CERT / CCN-CERT). Q: ¿Trabajáis con empresas del sector industrial y logístico de Valencia? A: Sí. Tenemos experiencia con entornos OT/ICS, redes industriales y sistemas SCADA, habituales en el tejido industrial valenciano (Zona Industrial de Paterna, Puerto de Valencia, polígonos de Almussafes). La seguridad de entornos industriales requiere enfoques diferentes a la IT convencional. Q: ¿Qué hace exactamente una empresa de seguridad informática como QuantumSec? A: Una empresa de seguridad informática evalúa, protege y monitoriza los sistemas digitales de tu organización. En QuantumSec nos especializamos en el lado ofensivo: pentesting (simular ataques reales), hacking ético (auditar tus defensas desde la perspectiva del atacante), análisis de vulnerabilidades y cumplimiento normativo (NIS2, ENS, ISO 27001). A diferencia de una empresa de seguridad generalista, nuestro enfoque ofensivo identifica los fallos reales antes de que los exploten terceros. --- ## Consultoría Cyber Resilience Act (CRA): adecuación para fabricantes y proveedores de software y hardware URL: https://www.quantumsec.es/cumplimiento/cra/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Consultoría CRA para fabricantes de productos digitales: gap analysis, evaluación de conformidad y marcado CE. Evita multas de hasta 15M€ o 2,5% de facturación. El Reglamento (UE) 2024/2847 Cyber Resilience Act entró en vigor en octubre de 2024 y será plenamente aplicable en diciembre de 2027. Afecta a todos los fabricantes y distribuidores de productos con elementos digitales vendidos en la UE: desde aplicaciones de escritorio hasta dispositivos IoT, routers y software empresarial. Las sanciones alcanzan los 15 millones de euros o el 2,5% de la facturación global anual. ¿Tu empresa fabrica o distribuye productos digitales en la UE? Si desarrollas software que incluye componentes instalables en el lado del cliente, fabricas dispositivos con conectividad de red —cámaras IP, routers, dispositivos IoT, wearables, sistemas industriales—, distribuyes en la UE productos digitales fabricados fuera de ella, o tus componentes se integran en los productos de otros fabricantes, el CRA te afecta directamente. El reglamento aplica a toda la cadena: fabricante, importador y distribuidor. Muchas empresas asumen erróneamente que solo aplica a los fabricantes de hardware, pero el CRA abarca también a los desarrolladores de software con componentes de red, aplicaciones de escritorio con conectividad remota y sistemas embebidos. El plazo de adecuación plena es diciembre de 2027, pero algunas obligaciones —como el reporte de incidentes activos a ENISA— entran en vigor en agosto de 2026. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuándo entra en vigor el Cyber Resilience Act? A: El CRA entró en vigor el 23 de octubre de 2024. La aplicación plena de los requisitos técnicos y de conformidad es el 11 de diciembre de 2027. Hay dos plazos intermedios críticos: los requisitos de notificación de incidentes activos a ENISA son exigibles desde el 11 de agosto de 2026, y los organismos notificados (para evaluación de terceros) deben estar designados desde el 11 de septiembre de 2026. Q: ¿El CRA aplica a todo el software o solo al hardware conectado? A: El CRA aplica a todos los "productos con elementos digitales": hardware y software con conectividad de red directa o indirecta. Están excluidos el software publicado como open source sin finalidad comercial, los servicios SaaS puros sin componentes instalables en el cliente, los productos médicos regulados por el MDR, los productos de aviación civil y el equipo de defensa. Si tu SaaS incluye un agente de escritorio o un plugin instalable, ese componente sí entra en el ámbito del CRA. Q: ¿Cuáles son las sanciones por incumplimiento del CRA? A: El CRA establece tres niveles de sanción: hasta 15 millones de euros o el 2,5% de la facturación anual global por incumplimiento de los requisitos esenciales de ciberseguridad; hasta 10 millones o el 2% por incumplimiento de otras obligaciones; y hasta 5 millones o el 1% por facilitar información incorrecta a las autoridades. Q: ¿Qué diferencia hay entre los productos Clase I, Clase II y los productos Default? A: Los productos Default son la mayoría y pueden hacer self-assessment. La Clase I incluye productos de mayor riesgo (sistemas de gestión de identidad, navegadores, gestores de contraseñas, software de seguridad, routers domésticos) y requieren evaluación de terceros salvo que apliquen íntegramente una norma armonizada. La Clase II incluye los más críticos (sistemas operativos de servidores, hipervisores, cortafuegos industriales, sistemas de control industrial, PKI, TPMs) y requieren obligatoriamente auditoría por un organismo notificado. Q: ¿El CRA se solapa con NIS2 o con otras normativas? A: Sí. NIS2 regula la ciberseguridad de los operadores de servicios esenciales, mientras que el CRA regula la seguridad de los productos digitales antes de ponerse en el mercado. Si eres fabricante de software y además operas un servicio esencial, te aplican ambas. También hay solapamientos con el MDR para dispositivos médicos conectados (el MDR prevalece) y con el esquema EUCS para productos de cloud crítica. Q: ¿Cuánto tiempo lleva adecuarse al CRA? A: Depende del punto de partida y de la categoría de productos. Empresas con un SDLC seguro ya implementado y procesos de gestión de vulnerabilidades maduros pueden completar el proceso en 6-9 meses. Organizaciones que parten de cero necesitarán 12-24 meses para una adecuación completa antes del plazo de 2027. --- ## Hacking ético para empresas: conoce tus vulnerabilidades antes que los atacantes URL: https://www.quantumsec.es/hacking-etico/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Hacking ético para empresas: evaluación integral multi-vector con OWASP y MITRE ATT&CK. Equipo certificado OSCP. Informe ejecutivo + técnico. El hacking ético es una evaluación integral que combina varios vectores de ataque —OSINT, perímetro externo, red interna— para simular, de forma autorizada y controlada, una campaña de ataque completa. El resultado es una foto exacta de tus riesgos, con los pasos concretos para eliminarlos. ¿Por qué el hacking ético y no un análisis de vulnerabilidades automático? Los escáneres automáticos detectan vulnerabilidades conocidas. Un hacker ético piensa como un adversario real: encadena fallos aparentemente menores, explota la lógica de negocio y descubre caminos que ningún scanner tiene en su base de datos. El resultado no es una lista de CVEs: es una demostración del impacto real que tendría un atacante en tu entorno concreto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre hacking ético y pentesting? A: El hacking ético es una evaluación integral que combina varios vectores —OSINT, perímetro externo, red interna, escalada de privilegios— para simular una campaña de ataque completa contra tu organización. El pentesting es una prueba técnica con alcance acotado a un sistema o superficie concreta: una aplicación web, una API, una red. Si necesitas evaluar un sistema específico, contrata un pentesting; si quieres saber hasta dónde llegaría un atacante real en toda tu organización, el hacking ético es el servicio adecuado. Q: ¿El hacking ético puede afectar a mis sistemas en producción? A: El alcance se define con precisión antes de empezar. Por defecto evitamos acciones que puedan interrumpir el servicio (DoS, borrado de datos). Si algún test tiene riesgo potencial de impacto, lo acordamos contigo y lo ejecutamos en ventana de mantenimiento. Q: ¿Necesito firmar algo antes de que empecéis? A: Sí. Antes de cualquier actividad firmamos un acuerdo de alcance y un NDA. Esto protege tanto a tu organización como al equipo auditor y define exactamente qué está autorizado. Q: ¿Cuánto cuesta un servicio de hacking ético? A: Depende del alcance: tipo de análisis (externo, interno, o ambos), número de activos y profundidad de la prueba. Ofrecemos una primera llamada gratuita para dimensionar correctamente el proyecto y darte un presupuesto ajustado. Q: ¿Trabajáis con empresas fuera de Valencia? A: Sí. Tenemos clientes en toda España. El hacking ético externo se realiza completamente en remoto. Para el análisis interno puede requerirse presencia física o acceso VPN al entorno según el alcance acordado. --- ## Soluciones de ciberseguridad adaptadas a tu tipo de empresa URL: https://www.quantumsec.es/soluciones/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Ciberseguridad adaptada a tu perfil: PYMEs, startups y equipos que desarrollan con IA. Pentesting, cumplimiento y seguridad en el SDLC. No todas las empresas tienen los mismos riesgos ni el mismo punto de partida. Diseñamos soluciones de seguridad ajustadas a tu perfil, presupuesto y objetivos. ¿Por qué la ciberseguridad genérica no funciona? Una PYME con diez empleados no necesita el mismo nivel de ciberseguridad que una empresa cotizada, pero sí necesita protección real. Una startup tecnológica que capta inversión debe demostrar controles de seguridad antes del cierre de ronda. Un equipo que desarrolla con IA tiene riesgos específicos del código generado por LLMs. Cada perfil tiene sus propios vectores de ataque y sus propias exigencias normativas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuál es la diferencia entre vuestra solución para PYMEs y para startups? A: Las PYMEs suelen priorizar la protección del negocio existente (pentesting, análisis de vulnerabilidades, NIS2) mientras que las startups suelen necesitar acreditar su seguridad frente a inversores o clientes enterprise (due diligence, compliance SOC2/ISO 27001, secure SDLC). Aunque los servicios se solapan, el enfoque y la documentación son diferentes. Q: ¿Trabajáis con empresas muy pequeñas, de menos de 10 empleados? A: Sí. Tenemos experiencia con microempresas y autónomos con necesidades específicas de seguridad, especialmente en sectores regulados como salud, legal o fintech. El alcance y el coste se adaptan al tamaño y a los activos críticos reales. Q: ¿Podéis acompañarnos durante todo el proceso de certificación ISO 27001? A: Sí. Ofrecemos acompañamiento completo: desde el gap analysis inicial hasta la preparación para la auditoría externa de certificación. También hacemos el seguimiento durante la fase de implementación de controles. --- ## Pentesting de aplicaciones SaaS: encuentra las vulnerabilidades antes de que las encuentren tus clientes URL: https://www.quantumsec.es/pentesting/saas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pentesting especializado para SaaS: multi-tenancy, APIs, autenticación, lógica de negocio y aislamiento de datos. Informe técnico + ejecutivo. Las aplicaciones SaaS tienen una superficie de ataque única: múltiples tenants sobre la misma infraestructura, APIs críticas, integraciones de terceros y datos de clientes enterprise. Un fallo de aislamiento puede comprometer a todos tus clientes a la vez. ¿Por qué el pentesting para SaaS es diferente al pentesting web estándar? Un pentesting web estándar cubre OWASP Top 10. En un SaaS hay capas adicionales que los scanners automáticos y los tests genéricos pasan por alto: ¿puede un usuario del plan Starter acceder a datos de un usuario del plan Enterprise? ¿Están correctamente aislados los tenants en la base de datos? ¿La lógica de billing puede manipularse? ¿Las webhooks exponen datos entre clientes? ¿Los tokens de API tienen scopes excesivos? Estas vulnerabilidades son específicas del modelo de negocio SaaS y requieren pentesters que entiendan el producto, no solo la tecnología. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting SaaS requiere acceso al código fuente? A: No necesariamente. El pentesting de caja negra o caja gris (sin acceso al código) ya detecta la mayoría de vulnerabilidades críticas en SaaS. Si nos das acceso al código fuente (caja blanca), combinamos el test de intrusión con revisión estática (SAST) para mayor cobertura. Q: ¿Podemos hacer el pentesting sobre el entorno de staging? A: Sí. Es la opción más habitual en SaaS: preparas un entorno de staging con datos representativos (no datos reales de clientes) y ejecutamos el pentesting ahí. Lo importante es que el entorno sea fiel a producción en configuración, infraestructura y lógica de negocio. Q: ¿El pentesting SaaS cubre también la infraestructura cloud? A: Puede incluirse como alcance adicional. El pentesting de aplicación SaaS cubre la capa de aplicación (web, API, lógica). Si necesitas también revisar la configuración de IAM, grupos de seguridad, S3 policies o Kubernetes, lo añadimos como un componente de pentesting cloud. Q: ¿Cuánto tiempo dura un pentesting de una aplicación SaaS? A: Entre 5 y 10 días hábiles para aplicaciones de complejidad media. La duración depende del número de endpoints, roles de usuario, integraciones y la profundidad acordada. Para SaaS con arquitectura de microservicios puede extenderse más. Q: ¿El informe vale para presentar a clientes enterprise o inversores? A: Sí. El informe ejecutivo está diseñado para ser presentado a dirección, clientes enterprise y en procesos de due diligence de inversión. Incluye resumen del alcance, metodología, hallazgos y estado de remediación. --- ## Triage de Vulnerabilidades como Servicio URL: https://www.quantumsec.es/triage-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Externalizamos el triage de vulnerabilidades de tu programa de bug bounty o VDP. Validamos, priorizamos y descartamos reportes con criterio técnico ofensivo. Sin ruido, sin falsos positivos. Tu equipo de seguridad no debería invertir la mayor parte de su tiempo leyendo reportes inválidos para encontrar los 3 que realmente importan. Nos encargamos del triage con el mismo criterio técnico ofensivo con el que hacemos pentesting. El triage de vulnerabilidades te está costando más de lo que crees Cada reporte que llega a tu programa de bug bounty o VDP requiere análisis, reproducción y valoración. Si tu equipo tarda 2-4 horas por reporte y recibes 50 al mes, estás hablando de más de 100 horas de trabajo especializado —sin contar los falsos positivos, los duplicados y los reportes fuera de alcance que consumen tiempo sin generar ningún valor. Y si el reporte llega en fin de semana o vacaciones, la ventana de respuesta se dispara, dañando la experiencia del investigador y tu reputación en la comunidad. Externalizar el triage no es perder control: es recuperar el tiempo de tu equipo para lo que realmente importa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podéis integrarse con nuestra plataforma de bug bounty actual (HackerOne, Bugcrowd, Intigriti)? A: Sí. Trabajamos sobre las plataformas existentes del cliente sin necesidad de cambiar de herramienta. También nos integramos con canales propios: formularios web, email securizado, Jira, GitHub Issues o cualquier sistema de ticketing. El cliente mantiene la visibilidad total de todo el proceso. Q: ¿Cuál es el SLA de respuesta a un reporte crítico? A: Para reportes clasificados como críticos, el tiempo máximo de primera respuesta es de 8 horas en días laborables y 24 horas en fin de semana. Para reportes de severidad alta, el SLA es de 24 horas en días laborables. Estos parámetros son configurables según las necesidades del programa. Q: ¿Qué pasa si discrepamos con vuestra valoración de un reporte? A: El cliente tiene siempre la última palabra. Si hay discrepancia en la valoración de un reporte, lo revisamos conjuntamente, aportamos la evidencia técnica que justifica nuestra posición y acordamos la clasificación final. Es un servicio colaborativo, no una caja negra. Q: ¿Cómo garantizáis la confidencialidad de los reportes? A: Firmamos un NDA específico para el servicio de triage antes de comenzar. Todos los reportes y sus contenidos son estrictamente confidenciales. El acceso a los reportes está restringido al equipo técnico asignado al cliente. Nunca compartimos información sobre vulnerabilidades de un cliente con terceros. Q: ¿Cuánto cuesta el servicio de triage externo? A: El coste depende del volumen estimado de reportes mensuales, el nivel de SLA requerido y si el servicio incluye comunicación con investigadores. Trabajamos con modelos de tarifa fija mensual por volumen de reportes. Es significativamente más económico que contratar un analista de triage interno, y mucho más flexible. --- ## Bug Bounty y Gestión de Vulnerabilidades como Servicio URL: https://www.quantumsec.es/bug-bounty/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Servicios especializados en triage de vulnerabilidades, gestión de programas de bug bounty y Vulnerability Disclosure Programs. Para empresas que reciben reportes de seguridad sin equipo interno suficiente. Ayudamos a empresas que reciben reportes de vulnerabilidades a gestionarlos correctamente. Triage técnico, gestión de programas, VDPs y validación: todo con criterio ofensivo real. Recibir reportes de vulnerabilidades sin equipo para gestionarlos es un riesgo real Un investigador que reporta una vulnerabilidad crítica espera respuesta en horas, no en semanas. Si tu equipo no tiene capacidad para triagar, validar y priorizar los reportes que llegan, estás acumulando riesgo sin saberlo. Los programas de bug bounty y VDP mal gestionados generan falsos positivos que desbordan a los developers, silencian a los investigadores más valiosos y dejan vulnerabilidades reales sin atender. No tienes que construir un equipo interno para tener un programa de seguridad externo de calidad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿En qué se diferencia este servicio de contratar HackerOne o Bugcrowd? A: HackerOne y Bugcrowd son plataformas: te dan acceso a una comunidad de investigadores y herramientas de gestión, pero tú sigues necesitando equipo interno para triagar y validar. Nosotros somos el equipo externo que hace ese trabajo. Podemos operar sobre las plataformas que ya tienes, o diseñar un programa independiente de ellas. Q: ¿Podéis gestionar programas que ya están activos en otra plataforma? A: Sí. Trabajamos sobre HackerOne, Bugcrowd, Intigriti y cualquier canal propio. No es necesario cambiar de plataforma ni de proceso. Simplemente añadimos la capa de triage y gestión que te falta. Q: ¿Cuánto tiempo tarda en estar operativo el servicio? A: El onboarding estándar lleva entre 5 y 10 días laborables: briefing técnico, configuración de accesos e integraciones, y definición de flujos de trabajo. Para programas más complejos o con múltiples integraciones, el plazo puede extenderse. --- ## Gestión Integral de Programas de Bug Bounty URL: https://www.quantumsec.es/bug-bounty/gestion-programa/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diseñamos, lanzamos y gestionamos tu programa de bug bounty de principio a fin. Triage incluido. Sin necesidad de equipo interno dedicado. Consulta sin compromiso. Lanza o profesionaliza tu programa de bug bounty sin aumentar tu equipo. Nos encargamos del diseño, las reglas, la comunicación con investigadores y el triage completo de reportes. Un programa de bug bounty mal gestionado hace más daño que no tenerlo Los programas de bug bounty generan valor cuando los reportes se gestionan rápido, con criterio técnico y con respuestas claras a los investigadores. Cuando el triage tarda semanas, los mejores researchers abandonan tu programa. Cuando los falsos positivos se acumulan, tu equipo de desarrollo pierde la confianza en el proceso. Y cuando una vulnerabilidad crítica espera en la cola porque no hay nadie para procesarla, el riesgo crece en silencio. Gestionar un programa bien requiere tiempo, experiencia técnica y disponibilidad constante. Lo hacemos por ti. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Trabajáis sobre plataformas ya existentes o necesito cambiar? A: Trabajamos sobre cualquier plataforma que ya tengas: HackerOne, Bugcrowd, Intigriti, YesWeHack o canales propios. No es necesario cambiar de plataforma. Si todavía no tienes ninguna, te recomendamos la más adecuada para tu caso y te ayudamos con la configuración inicial. Q: ¿Qué información necesito dar a los investigadores sobre quién gestiona el programa? A: Tú decides el nivel de transparencia. Podemos operar en tu nombre sin que los investigadores sepan que hay un proveedor externo, o podemos mencionar que el triage lo realiza un equipo de seguridad externo especializado. Ambas modalidades son válidas y habituales en el mercado. Q: ¿Cuánto cuesta gestionar un programa de bug bounty externamente? A: El coste depende del volumen de reportes mensuales, el nivel de SLA y si el servicio incluye el diseño inicial del programa. Es significativamente inferior a contratar un analista de triage interno, y más flexible porque el coste se adapta al volumen real del programa. Q: ¿Podéis gestionar programas privados de bug bounty? A: Sí. Gestionamos tanto programas públicos (accesibles a cualquier investigador) como privados (solo investigadores invitados). Los programas privados tienen dinámicas distintas y requieren una gestión de la comunidad de researchers más activa, algo que también cubrimos. --- ## Vulnerability Disclosure Program: Diseño y Gestión Externa URL: https://www.quantumsec.es/bug-bounty/vulnerability-disclosure-program/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diseñamos e implementamos tu Vulnerability Disclosure Program y gestionamos todos los reportes entrantes. Cumplimiento NIS2 y CRA incluido. Operativo en semanas. El VDP ya no es opcional: NIS2 y el Cyber Resilience Act lo exigen. Te ayudamos a tenerlo operativo en semanas y gestionamos todos los reportes que lleguen, sin que necesites equipo interno dedicado. Un canal de divulgación sin gestión es peor que no tenerlo Publicar una política de divulgación responsable es solo el primer paso. Si los reportes que llegan no tienen respuesta en días, si los investigadores no reciben confirmación de recepción, si las vulnerabilidades críticas se pierden en una bandeja de email sin proceso... el daño reputacional puede ser mayor que el beneficio de tener el VDP. Las empresas que publican un canal de divulgación asumen una responsabilidad: responder con seriedad y agilidad a quien les ayuda a ser más seguras. Nosotros nos encargamos de esa responsabilidad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿NIS2 me obliga a tener un VDP? A: NIS2 exige que las entidades esenciales e importantes tengan mecanismos para gestionar y reportar vulnerabilidades, lo que incluye disponer de un canal de notificación de vulnerabilidades. Aunque la directiva no usa explícitamente el término VDP, la práctica más extendida para cumplir con este requisito es implementar un Vulnerability Disclosure Program. Te ayudamos a evaluar exactamente qué necesita tu empresa. Q: ¿Cuánto tiempo tarda en estar operativo el VDP? A: El diseño e implementación estándar de un VDP lleva entre 2 y 4 semanas: redacción de política, configuración del canal, pruebas y publicación. Si necesitáis aceleración por un proceso de auditoría o cumplimiento normativo, podemos ajustar el timeline. Q: ¿Qué pasa si recibimos una vulnerabilidad crítica? A: Los reportes críticos tienen un canal de escalada inmediata. En cuanto identificamos que un reporte podría tener impacto crítico, lo escalamos directamente al responsable de seguridad del cliente —independientemente del horario— y coordinamos la respuesta de emergencia. El SLA para reportes críticos es de 4 horas en días laborables. Q: ¿Podéis ayudarnos a coordinar la divulgación pública de una vulnerabilidad? A: Sí. Si un investigador quiere publicar su hallazgo (CVE, blog post, conferencia), gestionamos el proceso de coordinated vulnerability disclosure (CVD) siguiendo el estándar ISO 29147: acordamos el timeline de divulgación, coordinamos con el investigador y preparamos las comunicaciones necesarias. --- ## Validación Técnica y Priorización de Vulnerabilidades Reportadas URL: https://www.quantumsec.es/bug-bounty/validacion-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Validamos cada reporte de vulnerabilidad con criterio técnico ofensivo. Reproducimos el ataque, confirmamos el impacto real y priorizamos con CVSS 4.0 y EPSS. Cero falsos positivos que hagan perder tiempo. No todos los reportes de vulnerabilidades son iguales. Validamos con la misma mentalidad ofensiva con la que hacemos pentesting. Tu equipo solo recibe lo que realmente importa, con toda la información para actuar. Un reporte sin validación técnica es solo una hipótesis Cuando un investigador reporta una vulnerabilidad, el informe puede ser un hallazgo crítico real o puede ser un error de comprensión del scope, un falso positivo o una vulnerabilidad teórica sin impacto práctico. Sin un proceso de validación técnica real —que implica reproducir el ataque, verificar el impacto y contextualizar el riesgo en tu entorno específico— tu equipo de desarrollo no puede priorizar correctamente. Peor aún: si tratan todos los reportes como urgentes, se paralizan. Si los ignoran por desconfianza, dejan vulnerabilidades reales sin atender. La validación técnica es el filtro que hace que todo lo demás funcione. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podéis validar vulnerabilidades sin acceso a producción? A: Depende del tipo de vulnerabilidad. Para muchos hallazgos (XSS, CSRF, lógica de negocio, fallos de autorización) podemos validar con credenciales de prueba en un entorno de staging. Para otros que requieren observar comportamiento en producción, trabajamos con el cliente para definir la ventana y el procedimiento seguro de validación. Q: ¿Cuánto tarda la validación de un reporte? A: El SLA estándar es de 24 horas laborables para reportes de severidad alta y crítica, y de 48-72 horas para severidades media y baja. Para programas de alto volumen, acordamos ciclos de validación que se adaptan al flujo de reportes. Q: ¿Qué diferencia hay entre CVSS 4.0 y las versiones anteriores? A: CVSS 4.0, publicado por FIRST en 2023, introduce una nueva taxonomía de métricas más granular, mejora la valoración del impacto en entornos OT/ICS y añade métricas adicionales de suplemento. Usamos CVSS 4.0 como estándar base porque proporciona una puntuación más precisa y aplicable a entornos modernos. Si tu programa ya usa CVSS 3.1, podemos trabajar con ambas versiones en paralelo. --- ## Pentesting y auditoría de seguridad para CMS URL: https://www.quantumsec.es/pentesting/cms/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de seguridad y pentesting para CMS: WordPress, Drupal, Magento, PrestaShop y Joomla. Análisis ofensivo real, no escaneo automático. Informe técnico y plan de remediación. WordPress, Drupal, Magento, PrestaShop y Joomla tienen superficies de ataque específicas que los tests genéricos y los escáneres automáticos no cubren. Plugins vulnerables, extensiones de terceros, paneles expuestos, APIs abusables y configuraciones por defecto son vectores reales que un atacante aprovechará antes de que tu equipo los detecte. ¿Por qué el mantenimiento web no equivale a seguridad? Actualizar WordPress o instalar un plugin de seguridad no equivale a un análisis de seguridad real. La mayoría de compromisos en CMS no ocurren por falta de actualizaciones: ocurren por extensiones de terceros mal auditadas, configuraciones de servidor incorrectas, roles de usuario excesivos, endpoints API expuestos o lógica de aplicación vulnerable que ningún escáner automático detecta. Un pentesting de CMS analiza el comportamiento real del sistema bajo ataque, no solo la lista de versiones instaladas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿En qué se diferencia una auditoría de seguridad CMS de un mantenimiento web? A: El mantenimiento web actualiza versiones y hace copias de seguridad. Una auditoría de seguridad CMS simula ataques reales para encontrar vulnerabilidades que las actualizaciones no corrigen: lógica de aplicación vulnerable, configuraciones incorrectas, extensiones con código inseguro o vectores específicos del CMS que los escáneres automáticos no detectan. Q: ¿El pentesting interrumpe el funcionamiento de la web? A: Coordinamos el alcance para minimizar el impacto operativo. En la mayoría de casos trabajamos sobre un entorno de staging o en franjas horarias de bajo tráfico. Si producción es imprescindible, acordamos las pruebas más invasivas fuera del horario comercial. Q: ¿El pentesting CMS cubre también el hosting y el CDN? A: Sí, dentro del alcance acordado. Revisamos la configuración del servidor web, headers de seguridad HTTP, acceso a rutas sensibles, permisos de ficheros y, si aplica, la configuración del WAF y CDN (Cloudflare, Fastly). El entorno de hosting forma parte de la superficie de ataque del CMS. Q: ¿Hacéis también la remediación o solo el informe? A: Entregamos el análisis, las evidencias y el plan de remediación. La corrección la ejecuta tu equipo o tu agencia web siguiendo nuestras instrucciones. Siempre incluimos soporte durante la fase de corrección y re-test opcional para verificar que los hallazgos han sido resueltos. Q: ¿El informe sirve para auditorías de cumplimiento (ENS, ISO 27001, PCI-DSS)? A: Sí. El informe sigue metodologías reconocidas (OWASP, PTES) y es válido como evidencia de pentesting para procesos de certificación ISO 27001, adecuación al ENS o cumplimiento PCI-DSS. Indicamos la cobertura frente a los controles de seguridad aplicables. --- ## Auditoría de seguridad de Google Workspace URL: https://www.quantumsec.es/auditorias/google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditamos tu Google Workspace como un atacante real: súper admins, apps OAuth, Drive, Gmail y delegación de dominio. Informe técnico y ejecutivo. Consulta gratuita. El correo, los documentos, las reuniones y las identidades de tu empresa viven dentro de Google Workspace. Un único error de configuración —un súper administrador sin 2FA, una app OAuth con permisos excesivos o una delegación de dominio olvidada— puede dar a un atacante acceso a todo el negocio. Revisamos tu Workspace con la misma mentalidad de quien quiere comprometerlo. ¿Tu Google Workspace es seguro o solo lo parece? Google protege su infraestructura, pero la configuración de tu organización es responsabilidad tuya. La mayoría de los compromisos en Google Workspace no explotan un fallo de Google: explotan configuraciones por defecto, permisos excesivos, apps de terceros conectadas sin control, reglas de reenvío maliciosas y cuentas de administrador mal protegidas. Una auditoría real no se limita a revisar una lista de ajustes: simula lo que haría un atacante con una cuenta comprometida y te demuestra hasta dónde podría llegar dentro de tu organización. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso de administrador a nuestro Workspace? A: Para la revisión de configuración basta con un rol de administrador de solo lectura o un rol delegado con permisos de auditoría. Para las pruebas ofensivas acordamos previamente el alcance y, si procede, una cuenta de prueba. Todo se realiza con autorización explícita y bajo acuerdo de confidencialidad (NDA). Q: ¿La auditoría interrumpe el trabajo de los empleados? A: No. La mayor parte es análisis de configuración y de la superficie de ataque, que no afecta a los usuarios. Las pocas pruebas activas se acuerdan y se ejecutan de forma controlada para no impactar la operativa. Q: ¿En qué se diferencia de las recomendaciones que ya muestra Google? A: El panel de Google señala ajustes recomendados, pero no piensa como un atacante ni encadena vectores. Nosotros buscamos el camino real de compromiso: una app OAuth olvidada, una delegación de dominio peligrosa o una regla de reenvío que mantiene el acceso aunque cambies la contraseña. Q: ¿Auditáis también Microsoft 365? A: Sí. Aplicamos la misma metodología ofensiva al entorno de Microsoft 365 (Entra ID, Exchange Online, SharePoint). Si trabajáis con ambos, auditamos los dos entornos y sus puntos de integración. Q: ¿El informe sirve para cumplimiento (ENS, ISO 27001, NIS2)? A: Sí. El informe documenta el estado de seguridad del entorno de correo y colaboración frente a marcos reconocidos (CIS Benchmark) y es válido como evidencia para procesos de adecuación al ENS, certificación ISO 27001 o cumplimiento de NIS2. --- ## Auditoría de seguridad de Microsoft 365 URL: https://www.quantumsec.es/auditorias/microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditamos tu Microsoft 365 como un atacante real: Entra ID, Exchange Online, SharePoint, apps OAuth y MFA. Informe técnico y ejecutivo. Consulta gratuita. El correo, los documentos y las identidades de tu empresa viven en Microsoft 365 y Entra ID. Un error de configuración —un administrador global sin MFA reforzado, una app con consentimiento ilícito o un acceso condicional mal definido— puede abrir la puerta a todo el negocio. Revisamos tu tenant con la mentalidad de quien quiere comprometerlo. ¿Tu Microsoft 365 es seguro o solo lo parece? Microsoft protege su plataforma, pero la configuración de tu tenant es responsabilidad tuya. La mayoría de los compromisos en Microsoft 365 no explotan un fallo de Microsoft: explotan MFA mal desplegado, políticas de acceso condicional con huecos, apps OAuth con consentimiento ilícito, reglas de reenvío en Exchange y administradores globales sin protección. Una auditoría real no se limita a mirar el Secure Score: simula lo que haría un atacante con una cuenta comprometida y te muestra hasta dónde podría llegar. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso de administrador a nuestro tenant? A: Para la revisión de configuración basta con un rol de solo lectura (Global Reader) o un rol delegado con permisos de auditoría. Para las pruebas ofensivas acordamos previamente el alcance y, si procede, una cuenta de prueba. Todo se realiza con autorización explícita y bajo acuerdo de confidencialidad (NDA). Q: ¿La auditoría interrumpe el trabajo de los empleados? A: No. La mayor parte es análisis de configuración y de la superficie de ataque, que no afecta a los usuarios. Las pocas pruebas activas se acuerdan y se ejecutan de forma controlada. Q: ¿En qué se diferencia del Secure Score de Microsoft? A: El Secure Score señala ajustes recomendados, pero no piensa como un atacante ni encadena vectores. Nosotros buscamos el camino real de compromiso: una app con consentimiento ilícito, un hueco en el acceso condicional o una regla de reenvío que mantiene el acceso aunque cambies la contraseña. Q: ¿Auditáis también Google Workspace? A: Sí. Aplicamos la misma metodología ofensiva a Google Workspace. Si trabajáis con ambos, auditamos los dos entornos y sus puntos de integración. Q: ¿El informe sirve para cumplimiento (ENS, ISO 27001, NIS2)? A: Sí. El informe documenta el estado de seguridad del entorno frente a marcos reconocidos (CIS Benchmark) y es válido como evidencia para adecuación al ENS, certificación ISO 27001 o cumplimiento NIS2. --- ## Red Team: simulación de adversario real para medir tu capacidad de detección URL: https://www.quantumsec.es/red-team/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Ejercicio de Red Team encubierto: simulamos un ataque real y dirigido —técnico, social y físico— para medir si tu equipo de seguridad detecta y responde a tiempo. Un pentesting encuentra vulnerabilidades en un alcance acotado y conocido de antemano. Un Red Team simula lo que haría un atacante real con un objetivo concreto —acceder a tu ERP, exfiltrar datos de clientes, comprometer el dominio— combinando vectores técnicos, sociales y, cuando aplica, físicos, sin que tu equipo de seguridad sepa que está ocurriendo. La pregunta que responde no es "¿qué vulnerabilidades tenéis?", sino "¿nos habríais detectado?". ¿Por qué un pentesting no basta para saber si estáis preparados? Un pentesting técnico es imprescindible, pero responde a una pregunta distinta: dentro de un alcance definido y en un plazo fijo, ¿qué vulnerabilidades existen? El equipo defensivo suele saber que está ocurriendo, lo que cambia su comportamiento. Un atacante real no avisa, no se limita a un único vector y no se detiene ante el primer control que encuentra: combina phishing dirigido, explotación técnica, movimiento lateral y, si hace falta, ingeniería social presencial, durante semanas, buscando el camino más silencioso hacia un objetivo de negocio concreto. Un Red Team es la única forma de comprobar si tu SOC, tus alertas y tu equipo de respuesta funcionan de verdad cuando nadie les avisa de antemano. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿En qué se diferencia exactamente un Red Team de un pentesting de Active Directory? A: Un pentesting de Active Directory analiza el entorno AD en profundidad con un alcance técnico conocido, buscando el máximo de vulnerabilidades de configuración y escalada de privilegios. Un Red Team parte de fuera del perímetro, con un objetivo de negocio concreto, sin que el equipo defensivo lo sepa, y solo entra en AD si ese es el camino más realista hacia el objetivo — es una prueba de la organización completa, no del entorno AD en sí. Q: ¿Es lo mismo que el TLPT que exige DORA? A: El TLPT es un Red Team ejecutado bajo el marco regulatorio TIBER-EU, con proveedores acreditados específicamente y coordinación con el supervisor, obligatorio para entidades financieras designadas como críticas. Nuestro Red Team estándar sigue la misma lógica metodológica y es la preparación ideal antes de un TLPT formal; para el TLPT regulatorio en sí, te orientamos sobre el proceso de acreditación necesario. Q: ¿Qué pasa si el equipo defensivo nos detecta el primer día? A: Es un resultado válido y valioso — significa que vuestras defensas funcionan para ese vector. En ese caso, con vuestro consentimiento, podemos ajustar el ejercicio para seguir probando otros vectores o técnicas de evasión más avanzadas, maximizando el aprendizaje del ejercicio. Q: ¿Incluye ingeniería social presencial y acceso físico? A: Solo si se acuerda explícitamente en el alcance. No es un componente por defecto: algunas organizaciones lo incluyen (tailgating, dispositivos USB, suplantación de personal técnico) y otras prefieren limitarlo a vectores digitales. Se define en la fase de reglas de intervención. Q: ¿En qué se diferencia de una simulación de phishing (ingeniería social)? A: Una simulación de phishing evalúa un único vector —el humano— de forma aislada y con un alcance conocido de antemano por quien la contrata. Un Red Team puede usar el phishing como uno de varios vectores de entrada, pero solo si sirve para alcanzar el objetivo de negocio definido, combinado con explotación técnica y movimiento lateral; no es un fin en sí mismo ni se mide de forma independiente. --- ## Auditoría de seguridad SAP URL: https://www.quantumsec.es/auditorias/sap/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditamos tu entorno SAP como un atacante real: autorizaciones y SoD, interfaz RFC/Gateway, código ABAP y parcheo. Informe técnico y ejecutivo. Consulta gratuita. SAP concentra los procesos financieros, de compras y de recursos humanos más críticos de tu empresa. Un rol mal diseñado, una interfaz RFC expuesta o una nota de seguridad sin aplicar pueden dar a un atacante —interno o externo— control sobre transacciones que mueven dinero real. Auditamos tu entorno SAP con la misma mentalidad de quien quiere comprometerlo, no solo revisando una checklist de cumplimiento. ¿Tu SAP es seguro o solo cumple la checklist de auditoría interna? La mayoría de las revisiones de seguridad SAP se quedan en el terreno del cumplimiento: comprobar que existe una matriz de segregación de funciones (SoD) documentada, que hay una política de contraseñas o que el sistema está dentro de mantenimiento. Eso no confirma que el entorno resista un ataque real. Los compromisos de SAP suelen explotar combinaciones concretas: una cuenta de servicio con la contraseña por defecto, una interfaz RFC accesible sin control de acceso, código ABAP a medida con una inyección, o notas de seguridad (SAP Security Notes) publicadas hace meses y nunca aplicadas. Una auditoría ofensiva confirma qué de todo eso es explotable de verdad en tu instancia concreta. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es lo mismo que una revisión de segregación de funciones (SoD) para auditoría interna? A: No. Una revisión de SoD para auditoría interna o compliance confirma que existe una matriz documentada y que, sobre el papel, no hay combinaciones prohibidas asignadas. Nuestra auditoría va más allá: confirma qué de eso es explotable de verdad, añade el análisis de la interfaz RFC/Gateway, el código ABAP personalizado y el estado de parcheo, y simula el impacto real de un atacante, no solo el riesgo teórico documentado. Q: ¿Necesitáis acceso al sistema productivo? A: Para la revisión de configuración y autorizaciones basta con un usuario de solo consulta o acceso al sistema de pre-producción con la misma configuración. Para las pruebas ofensivas activas acordamos previamente el alcance, el entorno (habitualmente pre-producción) y, si procede, una cuenta de prueba. Todo se realiza con autorización explícita y bajo acuerdo de confidencialidad (NDA). Q: ¿Cubrís tanto SAP on-premise como S/4HANA Cloud? A: Sí, adaptando el alcance: en on-premise y S/4HANA Private Cloud el análisis incluye la capa de infraestructura, el Gateway y el sistema operativo subyacente; en S/4HANA Public Cloud el alcance se centra en autorizaciones, integraciones y configuración, ya que SAP gestiona directamente parte de la infraestructura. Q: ¿La auditoría interrumpe la operativa del ERP? A: No. La mayor parte del trabajo es análisis de configuración, roles y código, que no afecta a los usuarios. Las pruebas activas se acuerdan previamente, se ejecutan preferentemente en un entorno de pre-producción y, si deben tocar producción, en una ventana pactada con el equipo Basis. Q: ¿El informe sirve para cumplimiento normativo (NIS2, ENS, ISO 27001)? A: Sí. El informe documenta el estado de seguridad del entorno SAP con evidencias y es válido como parte de la documentación de adecuación a NIS2, certificación ISO 27001 o adecuación al Esquema Nacional de Seguridad (ENS) para los sistemas dentro de su alcance. --- ## Consultoría AI Act: adecuación al Reglamento Europeo de Inteligencia Artificial URL: https://www.quantumsec.es/cumplimiento/ai-act/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Adecuación al AI Act para empresas que desarrollan o usan IA. Evita sanciones de hasta 35M€ o el 7% de la facturación global. Gap analysis y plan de acción. El Reglamento (UE) 2024/1689 (AI Act) es la primera ley integral del mundo sobre inteligencia artificial. Clasifica los sistemas de IA por nivel de riesgo y exige obligaciones concretas a quien los desarrolla, distribuye o simplemente usa en su empresa — sí, también a pymes y autónomos. ¿Tu empresa usa o desarrolla sistemas de IA en la UE? Si tu empresa utiliza IA para selección de personal, scoring de crédito, videovigilancia con reconocimiento facial, chatbots de atención al cliente o cualquier sistema que tome decisiones automatizadas sobre personas, el AI Act probablemente te afecta, independientemente de tu tamaño. La obligación no es solo para quien fabrica el sistema de IA: también aplica a quien lo despliega ("deployer") dentro de su organización. Muchas PYMEs y autónomos que usan herramientas de IA de terceros (RRHH, marketing, atención al cliente) asumen erróneamente que la responsabilidad es solo del proveedor. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿A quién aplica el AI Act? A: Aplica a proveedores que desarrollan sistemas de IA, a "deployers" que los usan dentro de su organización, y a importadores y distribuidores, dentro y fuera de la UE si el sistema se usa en territorio europeo. Aplica independientemente del tamaño de la empresa. Q: Soy autónomo y uso herramientas de IA de terceros, ¿tengo obligaciones? A: Sí, como "deployer" tienes obligaciones aunque no hayas desarrollado el sistema: informar a las personas afectadas cuando corresponda, supervisión humana en sistemas de alto riesgo, y no usar sistemas de IA prohibidos (como el scoring social). Q: ¿Cuánto tiempo tengo para adaptarme? A: El calendario es progresivo: las prácticas de IA prohibidas ya son ilegales desde febrero de 2025; las obligaciones de gobernanza y modelos de propósito general aplican desde agosto de 2025; las obligaciones de los sistemas de alto riesgo del Anexo III aplican desde agosto de 2026. Q: ¿Qué sanciones impone el AI Act? A: Hasta 35M€ o el 7% de la facturación global anual por usar prácticas de IA prohibidas; hasta 15M€ o el 3% por incumplir otras obligaciones del reglamento; hasta 7,5M€ o el 1% por proporcionar información incorrecta a las autoridades. Q: ¿El AI Act sustituye al RGPD? A: No, son complementarios. El AI Act regula específicamente los sistemas de inteligencia artificial y su nivel de riesgo; el RGPD sigue aplicando a cualquier tratamiento de datos personales que ese sistema realice. --- ## Auditoría de seguridad de Microsoft Exchange Online URL: https://www.quantumsec.es/auditorias/microsoft-exchange/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditamos tu Microsoft Exchange Online como un atacante real: reglas de reenvío, permisos delegados, conectores y SPF/DKIM/DMARC. Consulta gratuita. El correo corporativo es el canal favorito del fraude del CEO, el phishing dirigido y la persistencia tras un compromiso de cuenta. Analizamos tu Exchange Online más allá del MFA: reglas de reenvío, permisos delegados, conectores y autenticación de dominio. ¿Sabes qué podría hacer un atacante con acceso a un buzón de tu empresa? La mayoría de las revisiones de seguridad de correo se detienen en si el MFA está activado. Pero el fraude del CEO, la persistencia tras un compromiso de cuenta y buena parte del movimiento lateral pasan por reglas de reenvío ocultas, permisos delegados sin revisar, conectores mal configurados y dominios aceptados demasiado permisivos. Una auditoría real de Exchange Online confirma qué podría hacer realmente un atacante con acceso a un buzón, no solo si tienes activada la casilla correcta. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Esto sustituye a la auditoría general de Microsoft 365? A: No necesariamente. Si el correo es tu sistema más crítico o ya has tenido un incidente relacionado con email, tiene sentido contratarla como pieza independiente. Si quieres una revisión completa del tenant (Entra ID, SharePoint, Teams, apps OAuth), la auditoría de Microsoft 365 es más adecuada. Q: ¿Necesitáis acceso de administrador global? A: No. Con un rol de lectura sobre Exchange Online (por ejemplo, Exchange Recipient Administrator) es suficiente para la mayor parte del análisis. Q: ¿Interrumpe el funcionamiento del correo? A: No. El análisis es de configuración y permisos, y no afecta al flujo de correo en producción. Q: ¿Podéis detectar si ya hay un compromiso en curso? A: El análisis de reglas de reenvío y permisos delegados puede revelar la persistencia de un atacante que ya comprometió una cuenta, aunque este no es un servicio de respuesta a incidentes. Q: ¿Sirve el informe para cumplimiento normativo? A: Sí. El informe es válido como evidencia de control técnico sobre la seguridad del correo corporativo para NIS2, ENS o ISO 27001. --- ## Uso seguro de IA: gobierna lo que tu equipo ya está usando URL: https://www.quantumsec.es/soluciones/uso-seguro-de-ia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Política de uso de IA, control de shadow AI y formación de empleados para usar ChatGPT y Copilot sin exponer datos. Diagnóstico y plan en 3 semanas. Tu equipo ya usa IA. La pregunta no es si permitirlo, sino con qué herramientas, con qué datos y con qué supervisión. Ponemos orden: descubrimos qué se está usando, definimos las reglas y formamos a las personas que las tienen que aplicar. El problema no es la IA: es que nadie sabe qué está saliendo de la empresa La adopción de IA en las empresas no ha seguido el camino habitual de compra, evaluación y despliegue: ha entrado por abajo, persona a persona, desde cuentas personales y sin pasar por IT. El resultado es que casi ninguna organización puede responder hoy a tres preguntas básicas: qué herramientas de IA se están usando, qué información se ha pegado en ellas y quién revisa lo que producen antes de que llegue a un cliente. Prohibirlo no funciona —desplaza el uso al móvil personal, donde ya no hay ninguna visibilidad— y no hacer nada tampoco: cada semana que pasa sale más información sin registro. Lo que funciona es gobernarlo: descubrir el uso real, dar alternativas aprobadas cómodas y dejar por escrito qué datos no salen nunca. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Esto me sirve para cumplir el AI Act? A: Es su prerrequisito operativo, no la adecuación legal completa. Sin saber qué sistemas de IA usa tu organización y para qué, no puedes clasificarlos por nivel de riesgo ni demostrar supervisión humana ante nadie. Este servicio te da ese inventario y ese control. La adecuación formal al reglamento —clasificación, rol de proveedor o deployer, documentación técnica— es nuestro servicio de consultoría AI Act, y se apoya en el trabajo que se hace aquí. Q: ¿Cuánto tarda y qué implicación pide a mi equipo? A: El diagnóstico y la política están en unas tres semanas para una organización de tamaño medio. La carga para tu equipo se concentra en el descubrimiento: accesos de solo lectura para revisar aplicaciones conectadas, y unos minutos de cada persona para la encuesta anónima. La formación son sesiones de entre 45 y 90 minutos según el perfil. Q: ¿Vais a prohibirnos las herramientas que ya usamos? A: No es el objetivo. En la mayoría de casos el resultado es lo contrario: se aprueban formalmente las herramientas que ya se usaban, se corrigen sus ajustes de retención y entrenamiento, y se acota únicamente el tipo de dato que no debe entrar. Prohibir sin ofrecer alternativa desplaza el uso al móvil personal y empeora la visibilidad. Q: ¿Sirve si somos una empresa pequeña sin equipo de IT? A: Sí, y suele ser más rápido. En una organización pequeña el inventario se cierra en días y la política cabe en una página. Lo que no cambia con el tamaño es el riesgo: pegar un contrato de cliente en un chatbot público tiene el mismo impacto en una empresa de ocho personas que en una de ochocientas. Q: ¿En qué se diferencia esto de auditar la seguridad de nuestro propio sistema de IA? A: Son cosas distintas. Este servicio gobierna el uso de herramientas de IA de terceros por parte de tu equipo. Si lo que tienes es un producto propio con un modelo, un chatbot de cara al cliente o un pipeline RAG, lo que necesitas es un pentesting de inteligencia artificial, que ataca ese sistema para encontrar sus vulnerabilidades. Muchas empresas acaban necesitando ambos, pero resuelven problemas diferentes. --- ## Formación en ciberseguridad impartida por quien hace los ataques URL: https://www.quantumsec.es/formacion-ciberseguridad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Formación en ciberseguridad para empresas: concienciación de empleados, secure coding y preparación NIS2 y ENS. Sesiones presenciales u online, a medida. La mayoría de la formación en ciberseguridad la imparte gente que nunca ha explotado una vulnerabilidad. Nosotros enseñamos lo que encontramos en las auditorías: los fallos reales que cometen los equipos, explicados por el equipo que los explota. Por qué la formación genérica en ciberseguridad no cambia nada El formato habitual —un vídeo anual, un test de diez preguntas y un certificado— cumple el expediente y no modifica ningún comportamiento. Falla por tres motivos: usa ejemplos genéricos que nadie reconoce como propios, la imparte alguien que no ha visto un incidente real, y se dirige a toda la plantilla por igual cuando un desarrollador y una persona de administración necesitan cosas distintas. La formación que sí funciona parte de hallazgos concretos —idealmente de una auditoría de tu propia organización—, se adapta al perfil de quien escucha y se repite en sesiones cortas en lugar de concentrarse en una jornada al año. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta formar a un equipo en ciberseguridad? A: Depende del formato y del número de sesiones. Una sesión de concienciación para empleados, online y de unos 90 minutos, parte de un precio cerrado por grupo. Un programa de desarrollo seguro con varias sesiones y prácticas sobre vuestro propio código se presupuesta por proyecto. Damos precio cerrado antes de empezar, y la primera llamada para acotar el alcance no tiene coste. Q: ¿Hacéis simulaciones de phishing dentro de la formación? A: La simulación de phishing es un servicio distinto: es un ejercicio ofensivo que mide comportamiento real, no una clase. Los dos se complementan bien —lo habitual es simular primero para saber dónde está el problema, y formar después sobre los resultados—, pero se contratan por separado. Si lo que buscas es medir, empieza por las simulaciones de phishing. Q: ¿La formación sirve como evidencia para NIS2 o el ENS? A: Sí, y es una de las razones habituales para contratarla. NIS2 exige en su artículo 20 formación en ciberseguridad para los órganos de dirección, y el ENS incluye la concienciación y formación del personal entre sus medidas. Entregamos registro de asistencia, contenidos impartidos y evaluación en el formato que un auditor espera, que es lo que realmente se pide en la revisión. Q: ¿Podéis formar a nuestro equipo sobre el uso de la inteligencia artificial? A: Sí, pero eso lo cubrimos desde el servicio de uso seguro de IA, porque no es solo una sesión: implica también descubrir qué herramientas se están usando y redactar la política que la formación explica. Si lo que necesitas es exclusivamente la sesión formativa, se puede contratar de forma aislada dentro de ese servicio. Q: ¿La formación es presencial u online? A: Ambas. Las sesiones de concienciación funcionan bien en remoto y permiten grupos más grandes. Las de desarrollo seguro y las de equipos técnicos rinden más en presencial, porque incluyen práctica y discusión sobre código. Tenemos base en Valencia y nos desplazamos al resto de España según el proyecto. --- ## Auditoría de ciberseguridad para licitaciones públicas y concesiones administrativas URL: https://www.quantumsec.es/auditorias/licitaciones-publicas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Informe de auditoría de ciberseguridad para licitaciones públicas: pentest + cumplimiento RGPD en un solo documento. Sin ENS ni ISO 27001. Entrega en 5-10 días Un pliego exige un informe de auditoría de ciberseguridad como documentación acreditativa y no tienes margen: entregamos un único informe que combina test de intrusión y revisión de cumplimiento RGPD/LOPDGDD, sin necesidad de certificarte en ENS ni ISO 27001. Un pliego te exige un informe de auditoría y el reloj no juega a tu favor Cada vez es más habitual que un pliego de licitación o de concesión administrativa incluya, como obligación esencial, la presentación de un informe de auditoría de ciberseguridad referido al sistema técnico ofertado: análisis de vulnerabilidades o test de intrusión, más una revisión del cumplimiento en materia de protección de datos. Muchos de esos pliegos son explícitos en que no hace falta ENS ni un certificado de INCIBE, solo un informe emitido por una empresa o profesional cualificado. El problema no es encontrar quién lo haga, es el calendario: si tu oferta resulta la mejor valorada, el plazo para presentar toda la documentación acreditativa —incluida esta auditoría— suele ser de solo 5 a 10 días hábiles. Acordar proveedor y alcance con antelación, antes de que se resuelva la licitación, es la única forma de no jugarte la adjudicación a un plazo administrativo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Sirve este informe si el pliego no exige ENS ni ISO 27001? A: Sí, es exactamente el caso que cubre este servicio. Muchos pliegos piden un informe de auditoría de ciberseguridad —pentest y revisión RGPD— sin exigir una certificación formal. Si tu pliego sí exige ENS o ISO 27001, necesitas ese proceso de certificación: consulta nuestro servicio de auditoría y adecuación al ENS. Q: ¿Cuánto tarda el informe? A: Entre 5 y 10 días hábiles desde el inicio, según la complejidad del sistema y el número de integraciones a revisar. Si el plazo del expediente es más corto, dínoslo en la llamada de alcance: priorizamos proyectos con fecha límite conocida. Q: ¿Podemos empezar antes de que se resuelva la licitación? A: Sí, es lo recomendable. Si acordáis proveedor y alcance con antelación, el informe puede estar listo antes de la adjudicación, y solo queda presentarlo cuando llegue el plazo de subsanación. Q: ¿Qué pasa si el pliego exige ENS, ISO 27001 o un certificado específico de INCIBE? A: Este servicio no sustituye una certificación formal. Si el pliego exige ENS o ISO 27001 necesitas ese proceso con una entidad acreditada; podemos ayudarte con la fase de adecuación previa. Consulta cumplimiento ENS o cumplimiento ISO 27001 según lo que pida tu pliego. Q: ¿Cubre sistemas de terceros como pasarelas de pago o dispositivos IoT conectados a la plataforma? A: Sí, siempre que formen parte del sistema ofertado. No auditamos la infraestructura del proveedor de pagos o del fabricante del dispositivo directamente, pero sí revisamos cómo se integra con tu plataforma y qué datos se intercambian. Q: ¿Puede presentar este informe una empresa que actúa como socio local de un proveedor extranjero? A: Sí. Es un caso habitual: una empresa de software extranjera colabora con un socio español que licita, y el informe se emite sobre el sistema técnico ofertado con independencia de dónde esté domiciliada la empresa que lo desarrolla. --- ## Auditoría RGPD y LOPDGDD para empresas URL: https://www.quantumsec.es/auditorias/rgpd-lopdgdd/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de cumplimiento RGPD/LOPDGDD: mapeo de tratamientos, encargados y medidas técnicas. Informe válido para clientes, licitaciones y aseguradoras Tener una política de privacidad no es lo mismo que poder demostrar que tus tratamientos de datos cumplen el RGPD. Auditamos qué datos tratas, con qué base legal, con quién los compartes y si tus medidas de seguridad son las que exige la normativa. Cumplir el RGPD sobre el papel no es lo mismo que poder demostrarlo La mayoría de empresas tiene una política de privacidad en su web, redactada por un abogado, y da por hecho que eso equivale a cumplir el RGPD. En la práctica es habitual encontrar detrás de ese documento un Registro de Actividades de Tratamiento inexistente o desactualizado, contratos de encargado de tratamiento sin firmar con proveedores cloud o pasarelas de pago, y medidas técnicas del artículo 32 RGPD que nadie ha verificado realmente. El problema aparece cuando alguien lo pide: un cliente enterprise, una aseguradora antes de contratar un ciberseguro, un inversor en due diligence o una administración pública en una licitación. Una auditoría RGPD/LOPDGDD te da la fotografía real de tu cumplimiento, no la que asumes que tienes. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Esto sustituye a tener un Delegado de Protección de Datos (DPD/DPO)? A: No necesariamente. Si tu empresa está obligada a tener DPD, esta auditoría es complementaria: evalúa el estado real del cumplimiento y el DPD puede apoyarse en el informe para priorizar su trabajo. Si no tienes DPD, la auditoría te da una fotografía independiente sin necesidad de contratar esa figura de forma permanente. Q: ¿Necesito esta auditoría si ya tengo la política de privacidad de mi web hecha por un abogado? A: La política de privacidad es el documento de cara al usuario; no acredita que los tratamientos internos, los contratos con proveedores o las medidas técnicas estén realmente en regla. Es habitual encontrar empresas con una política de privacidad impecable y sin un Registro de Actividades de Tratamiento real detrás. Q: ¿Cuánto dura el proceso? A: Entre 2 y 4 semanas para una empresa mediana, según el número de tratamientos y proveedores a revisar. Para alcances acotados a un único producto o sistema puede ser más rápido. Q: ¿El informe sirve para presentarlo en una licitación pública? A: Sí, si el pliego pide una revisión de cumplimiento RGPD como parte de la documentación acreditativa. Si además exige un test de intrusión sobre el sistema ofertado, consulta nuestro servicio de auditoría para licitaciones públicas, que combina ambos en un único informe con plazos exprés. Q: ¿Auditáis también el cumplimiento de proveedores externos (cloud, SaaS de terceros)? A: Revisamos los contratos y DPA firmados con ellos y cómo fluyen los datos hacia esos proveedores, pero no auditamos la infraestructura interna del proveedor, salvo que forme parte de un pentest contratado aparte. Q: ¿Qué pasa si encontráis un incumplimiento grave? A: Lo clasificamos por riesgo real, no solo formal, y te damos una hoja de ruta priorizada. La decisión de cómo y cuándo remediarlo es tuya; podemos acompañar la implementación si lo necesitas. --- ## Pruebas TLPT: el red team que DORA exige a las entidades financieras URL: https://www.quantumsec.es/red-team/tlpt/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Pruebas TLPT (Threat-Led Penetration Testing) bajo DORA y TIBER-EU para entidades financieras. Inteligencia de amenazas y red team con equipo OSCP. El TLPT no es un pentest con otro nombre. Es un ejercicio de red team dirigido por inteligencia de amenazas, sobre sistemas en producción y con el equipo defensivo sin previo aviso. DORA lo exige a las entidades financieras designadas por su autoridad competente, y el proveedor debe acreditar independencia y capacidad técnica. Un pentesting convencional no cubre el requisito de TLPT Muchas entidades descubren tarde que las pruebas de seguridad que ya venían haciendo no satisfacen las pruebas avanzadas que regula DORA en sus artículos 26 y 27. El TLPT tiene exigencias que un pentesting al uso no cumple: parte de una fase previa de inteligencia de amenazas específica de la entidad, se ejecuta sobre funciones críticas o importantes en producción —no en preproducción—, mantiene al equipo defensivo sin conocimiento del ejercicio salvo un control team reducido, y exige proveedores que acrediten independencia y capacidad técnica. Presentar un informe de pentesting estándar ante el supervisor no cierra el requisito, y el plazo de remediación posterior se come el margen que quedaba. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: Qué diferencia hay entre un TLPT y un pentesting A: Un pentesting busca vulnerabilidades en un alcance acotado y normalmente con el equipo defensivo informado. El TLPT parte de inteligencia de amenazas real sobre tu entidad, se ejecuta en producción sobre funciones críticas y mantiene al equipo defensivo sin previo aviso, porque lo que mide es la capacidad de detección y respuesta, no solo la existencia de fallos. Q: Todas las entidades financieras tienen que hacer TLPT A: No. DORA exige un programa de pruebas de resiliencia a todas las entidades de su ámbito, pero las pruebas avanzadas tipo TLPT se aplican a las que designa su autoridad competente en función de criterios como tamaño, perfil de riesgo y relevancia. Si tu entidad no está designada, sigue obligada al resto del programa de pruebas. Q: Cada cuánto hay que repetir un TLPT A: DORA plantea una periodicidad mínima de tres años para las entidades sujetas, sin perjuicio de lo que determine la autoridad competente. Conviene planificarlo con antelación: el ciclo completo, con inteligencia previa y remediación posterior, se extiende varios meses. Q: Qué es TIBER-ES y quién lo supervisa en España A: TIBER-ES es la implementación española de TIBER-EU, coordinada por el Banco de España junto con la CNMV y la DGSFP según el tipo de entidad. Es el marco bajo el que se articulan en España las pruebas avanzadas dirigidas por inteligencia de amenazas que exige DORA, y documentar el ejercicio conforme a él es lo que facilita su reconocimiento por el supervisor. Q: Qué relación tiene el TLPT con TIBER-EU A: TIBER-EU es el marco del Banco Central Europeo para pruebas dirigidas por inteligencia de amenazas y es la referencia metodológica sobre la que se apoya el TLPT de DORA. Documentar el ejercicio conforme a TIBER-EU facilita su presentación ante el supervisor. Q: Puede ejecutarlo el mismo equipo que hace nuestras auditorías habituales A: DORA exige que los proveedores de pruebas avanzadas acrediten independencia, reputación y capacidad técnica. Conviene revisar posibles conflictos con quien ya presta servicios recurrentes a la entidad antes de adjudicar el ejercicio. Q: Cuánto dura un ejercicio TLPT completo A: Depende del alcance, pero un TLPT con su fase de inteligencia, ejecución, cierre y remediación rara vez baja de tres meses. Las entidades que lo abordan con el plazo encima acaban recortando alcance, que es justo lo que el supervisor examina. --- # Services (EN) --- ## Cybersecurity services for businesses URL: https://www.quantumsec.es/en/services/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Offensive cybersecurity and regulatory compliance team for regulated businesses in Spain, OSCP-certified. Free consultation within 24 hours. From an initial vulnerability assessment to compliance with the NIS2 directive, we cover the full offensive security and regulatory cycle your business needs. Why outsource technical cybersecurity? Building an in-house offensive security team is prohibitively expensive for most companies. Hiring and retaining a senior penetration tester in-house is expensive, and the specialization you need —web, network, Active Directory, cloud— is rarely found in a single person. We give you a team with over 10 years of experience, without the burden of hiring or ongoing training. Frequently asked questions answered by the QuantumSec team: Q: Do we have to sign a long-term contract? A: No. Most of our services are closed projects with a concrete deliverable. If there's an ongoing relationship, it's formalized through a managed service agreement, always with defined terms and a flexible exit. Q: Do you work with companies of all sizes? A: Yes. We have clients ranging from 5-person startups to Ibex35 companies. We adapt the scope and price to each organization's reality. Q: What sets QuantumSec apart from other cybersecurity companies? A: Offensive specialization and closeness. We're not a generalist integrator. We're a technical team that understands the language of attackers, translates it into business terms and supports the client throughout the process, not just when we deliver the report. Q: How do you guarantee confidentiality? A: We sign an NDA before starting any work. All access and tests are documented and carried out strictly within the agreed scope. --- ## Penetration testing for businesses: find your vulnerabilities before attackers do URL: https://www.quantumsec.es/en/pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Information security company specialized in penetration testing and ethical hacking. Find real vulnerabilities before attackers do. Free consultation. A proper penetration test isn't an automated scan. It's an expert who thinks like an attacker, looks for the least expected path and shows you exactly how far someone with bad intentions could get. Is your company secure, or does it just think it is? Many of the companies that suffer a serious cyberattack thought their systems were up to date. Firewalls, antivirus and patches aren't enough if there are vulnerabilities in your web application, in your internal network configuration or in the way your employees manage credentials. Penetration testing simulates what a real attacker would do: it searches, exploits and shows you the path before someone with bad intentions finds it first. Frequently asked questions answered by the QuantumSec team: Q: When does it make sense to hire a penetration test? A: When you need to validate real risk with evidence rather than a theoretical or purely automated assessment: before a launch, after a significant architecture change, when a client or regulation demands it, or when a vulnerability scan has flagged issues nobody has confirmed by exploiting them. If your goal is a compliance tick-box rather than finding out what an attacker could actually do, a pentest is the wrong purchase. Q: What should I ask a provider before hiring a pentest? A: Four things settle most decisions: the CV and certifications of the people who will run the test, not just the company brand; a real anonymised sample report, to check whether they explain business impact or only dump technical findings; the methodology they follow (OWASP WSTG, PTES, OSSTMM); and whether a retest of the fixes is included. A provider that cannot show a sample report or names no methodology is usually selling an automated scan. Q: How much does a penetration test cost in Spain? A: The price depends on the scope: number of IPs, URLs, applications and depth of the analysis. A standard web pentest is usually between 1,500 EUR and 5,000 EUR. More complex projects such as a Red Team or a full infrastructure pentest can exceed that. We always start with a free first call to give you a quote tailored to your reality. Q: Can pentesting affect the availability of my systems? A: We define the scope precisely before starting. By default, we avoid actions that could interrupt the service (DoS, data deletion). If any test carries potential risk, we agree it with you and run it during a maintenance window. Q: What's the difference between a pentest and a vulnerability assessment? A: A vulnerability assessment is an automated scan that detects possible flaws but doesn't verify or exploit them. A pentest goes further: a human expert confirms the vulnerability is exploitable, demonstrates its real impact and assesses whether it allows escalating the attack. The result is far more actionable. Q: What's the difference between a pentest and ethical hacking? A: A penetration test is a technical test scoped to one specific system or surface: a web app, an API, a network. Ethical hacking is a broader assessment that combines multiple vectors — OSINT, external perimeter, internal network, privilege escalation — to simulate a full attack campaign against your organization. If you need to assess a specific system, choose penetration testing; if you want to know how far a real attacker would get across your whole organization, choose ethical hacking. Q: What information do you need to start? A: It depends on the type of test. For a black-box pentest, we only need the URLs or IPs in scope. For grey or white box, we may need test credentials, source code access or architecture documentation. We agree everything before starting. Q: How long does a pentest take? A: Between 3 and 10 business days for the technical phase, depending on the scope. The report is usually delivered 2-3 days later. For Red Team projects or complex infrastructures, the timeline can extend. Q: How do I hire a penetration test for my company? A: The process is simple: you describe your environment (URLs, IPs, applications or internal network in scope), we hold a free initial call to understand your needs, and within 24-48 hours you receive a proposal with scope, methodology and price. No fine print, no charges for the initial analysis. Q: Do you run penetration tests on artificial intelligence systems? A: Yes, and it's worth separating two things that often get confused. One is auditing your AI: testing your models, chatbots and LLM agents against prompt injection, jailbreak, context poisoning and model data leakage, following the OWASP Top 10 for LLM and MITRE ATLAS — that's our AI penetration testing service. The other is using AI as a tool to speed up a conventional pentest, which is what AI-powered penetration testing covers. If your company has put a conversational assistant into production, the first one is what you need. --- ## Web penetration testing: web application security assessment URL: https://www.quantumsec.es/en/pentesting/web/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Web security assessment: portals, e-commerce and applications. SQLi, XSS, IDOR, SSRF and the OWASP Top 10. Technical + executive report. Free analysis. Your web application is the gateway to your data, your customers and your business. We assess its security the way a real attacker would, covering everything from the OWASP Top 10 to the specific vulnerabilities of your technology stack. Web applications are the most exploited attack vector Your web application is the part of your company exposed to the internet 24/7 and reachable by anyone. Broken Access Control has topped the OWASP Top 10 since the 2021 edition and remains the A01 risk in the 2025 one. SQL injection, XSS, sensitive data exposure, weak authentication, inadequate access control... Most of these flaws are silent: your app works perfectly while a back door stays open. Web pentesting finds them and closes them before someone else does. Frequently asked questions answered by the QuantumSec team: Q: Do you do black, grey or white box testing? A: All three. Black box simulates an external attacker with no prior information. Grey box includes standard user credentials to assess access control. White box includes access to the code and architecture and allows a more exhaustive analysis. Most clients choose grey box as a balance between realism and coverage. Q: Do you assess WordPress and other CMS? A: Yes. WordPress is the most attacked CMS in the world precisely because of the proliferation of vulnerable plugins. We assess the core, the installed plugins, the themes, the server configuration and the admin panel access practices. Q: Can you sign an NDA before starting? A: Always. Before you share any data about your infrastructure, we sign a confidentiality agreement. Q: What happens if you find critical vulnerabilities? A: We notify you immediately (same day) if we find something that poses a serious and immediate risk to your business, without waiting for the full test to finish. --- ## API penetration testing: REST, GraphQL and OAuth security URL: https://www.quantumsec.es/en/pentesting/apis/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Security assessment of REST, GraphQL and OAuth/OIDC APIs. We detect BOLA, broken auth and data exposure. Technical report with PoC and step-by-step remediation. APIs are the nervous system of your digital business. They connect services, expose data and move money. We assess their security following the OWASP API Security Top 10, with an attacker's rigor and the precision of a specialized technical team. APIs are the new attack perimeter The number one risk in the OWASP API Security Top 10 isn't authentication but object level authorization: "Broken Object Level Authorization" (API1:2023). An endpoint that returns any user's data if you change the ID in the URL. An internal API exposed without protection because it's only for internal use. A token that never expires. These flaws are silent and easy to exploit for someone who knows how to look for them. Frequently asked questions answered by the QuantumSec team: Q: Do you need access to the API documentation (Swagger/OpenAPI)? A: It's useful but not essential. We can work in black-box mode by intercepting the traffic of the application that consumes the API. Documentation speeds up the process and improves coverage. Q: Do you audit internal APIs or only internet-facing ones? A: Both. In fact, internal APIs are frequently the most vulnerable because it's wrongly assumed that only employees use them. Lateral movement in an attack usually leverages exactly this type of API. Q: What's the difference between auditing a REST API and a GraphQL one? A: GraphQL has specific attack vectors: introspection can reveal the entire data schema, batching enables application-level DoS, and field-level authorization is harder to implement correctly. We cover both with adapted methodologies. Q: How long does an API audit take? A: Between 3 and 7 business days for the technical phase, depending on the number of endpoints and the complexity of the authentication and business flows. --- ## Mobile application penetration testing: iOS and Android URL: https://www.quantumsec.es/en/pentesting/mobile-applications/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. iOS and Android app security assessment. Static, dynamic and backend API analysis. OWASP Mobile Top 10. Technical and executive report. Get an audit. Your mobile app stores credentials, accesses sensitive APIs and handles customer data. Do you know what happens when someone pulls it apart? We assess the app, the API it consumes and the communication channel between them. Mobile apps have vulnerabilities invisible to the user Unlike a website, the user of an app installs the code on their own device. This lets an attacker decompile it, analyse its traffic, extract hardcoded API keys, identify the business logic and attack the backend API with full knowledge of how it works internally. The OWASP Mobile Top 10 captures the most exploited flaws, but the real-world casuistry goes far beyond that. Frequently asked questions answered by the QuantumSec team: Q: Do you need the app's source code? A: It is not essential. We can work from the binary alone (APK or IPA) for the static analysis. Source code, when available, allows a deeper and more efficient review. Q: Do you audit both iOS and Android apps? A: Yes. We work with both platforms. iOS requires jailbroken devices or the use of the simulator for certain dynamic analyses. Android is more accessible for emulator-based analysis. Q: What impact does it have on store publication? A: None directly. The audit is carried out on a test build or the production version already published. Fixes are implemented before the next release. Q: Can you audit just the API without analysing the app? A: Yes. If your app has already been audited or your concern is the backend, we can focus solely on the API. See our API pentesting service. --- ## Active Directory penetration testing: audit your AD security URL: https://www.quantumsec.es/en/pentesting/active-directory/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Active Directory audit: misconfigurations, excessive privileges and escalation paths exploitable by ransomware. BloodHound. Technical + executive report. Active Directory is the centerpiece of any corporate Microsoft environment. It's also the number one target of ransomware groups. A misconfigured AD can give an attacker full control over your network in a matter of hours. AD is the fastest path to disaster Most enterprise ransomware attacks follow the same pattern: compromise a user machine, move laterally across the network, obtain credentials with elevated privileges and, finally, compromise the Domain Controller. Active Directory is the thread that ties all those steps together. Kerberoasting, Pass-the-Hash, ACL abuse, GPO misconfiguration, service accounts with excessive privileges... There are hundreds of paths an attacker can follow. We map them all before anyone uses them. Frequently asked questions answered by the QuantumSec team: Q: Do you need admin access to run the audit? A: Not necessarily. We can start with a standard user account to simulate exactly what an attacker who has compromised a workstation would do. Depending on the agreed scope, we can escalate to higher privileges in a controlled way. Q: What impact does the audit have on the production environment? A: Minimal. By default we avoid any destructive action or anything that could cause mass account lockouts or service interruptions. Everything is agreed in advance. Q: Do you also harden AD once the problems are identified? A: The audit includes detailed remediation instructions. If you need us to implement the fixes directly, we can quote it as an additional service. Q: How often should Active Directory be audited? A: At least once a year and after major infrastructure changes (migrations, new business units, mergers). More dynamic environments should do it every 6 months. --- ## Cybersecurity audit: a technical assessment of your security posture URL: https://www.quantumsec.es/en/audits/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Technical cybersecurity audits: vulnerability analysis, code review and security assessment. Executive report plus detailed technical report. A cybersecurity audit goes beyond an automated scan. We review your infrastructure, applications, code and processes to give you a real picture of your exposure, backed by data, not assumptions. When was the last time someone actually assessed your security? Many companies have security tools installed but have never had someone competent evaluate them from the outside. Firewalls have outdated rules. Applications run vulnerable versions. Code has flaws that passed code review. The audit puts a name and a number on those risks, so you can prioritize and fix them with judgment. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between an audit and a penetration test? A: Penetration testing focuses on exploiting vulnerabilities to confirm their real impact. An audit has a broader scope: it reviews configurations, policies, regulatory compliance and overall security posture, not just exploitable technical vulnerabilities. Q: Can you audit just one specific part? A: Yes. We can limit the scope to a single application, a network segment, the code of a specific module or a cloud provider's configuration. We have no mandatory minimum scope. Q: Can the report be presented to clients or regulators? A: Yes, as long as the regulator accepts third-party reports. We structure it with the formality needed for that purpose. If the regulator requires a specific format, we can adapt it. --- ## Phishing simulations: train your team before a real attacker does URL: https://www.quantumsec.es/en/social-engineering/phishing-simulations/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Simulated phishing campaigns for businesses. Spear phishing, vishing and corporate smishing. Results report and awareness training included. Phishing is the leading initial access vector in the EU: around 60% of the cases observed by ENISA. Your systems can be flawless; it only takes one employee clicking the wrong link. Simulations measure exactly that and help change behavior, not just deliver a talk. Firewalls don't protect against human error You can have the best security software on the market and still be vulnerable if your employees don't recognize a malicious email, a fake SMS, or a call from someone impersonating IT support. Social engineering doesn't attack systems — it attacks people. And the only way to know if your team is ready is to test them under controlled conditions. Frequently asked questions answered by the QuantumSec team: Q: Will employees know it's a simulation? A: Not during the campaign. The learning effect is much greater when the employee discovers, after clicking, that it was a test. It's handled with care: employees aren't publicly identified or penalized, only trained. Q: Do you need access to our email server? A: We need our sending infrastructure to be whitelisted so emails reach inboxes correctly. It's a simple technical process we manage together with you. Q: What happens to the data on who clicked? A: Data is handled with strict confidentiality. The report can be presented anonymized by department if you prefer, without identifying individual employees. Q: How often should these simulations be run? A: The recommended minimum is 2-3 campaigns per year. Awareness fades over time if it isn't reinforced. Ideally it's complemented with short, periodic training modules. --- ## NIS2 consulting: comply with the EU cybersecurity directive URL: https://www.quantumsec.es/en/compliance/nis2/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. NIS2 compliance for in-scope companies. Gap analysis, action plan and documentation. Avoid fines of up to €10M or 2% of global turnover. The NIS2 Directive entered into force in October 2024 and affects thousands of companies in Spain. Fines for non-compliance reach 2% of global annual turnover or €10 million. Do you know whether your company is in scope and what you need to do? Is your company subject to NIS2? NIS2 greatly expands the scope compared to NIS1. It no longer affects only classic critical infrastructure. It now includes sectors such as manufacturing, food, distribution, digital services, cloud providers, waste management and many more. If your company operates in one of the 18 regulated sectors and exceeds certain size thresholds, you're probably in scope. And if you're a supplier to an in-scope company, the pressure also reaches you through the supply chain. Frequently asked questions answered by the QuantumSec team: Q: Is NIS2 already in force in Spain? A: The directive was due to be transposed into national law before October 2024. Spain is in the process of transposition. Although the specific national law may be pending, the directive already creates obligations for covered entities. The prudent move is to comply now. Q: What are the penalties for NIS2 non-compliance? A: For essential entities: up to €10 million or 2% of global annual turnover, whichever is higher. For important entities: up to €7 million or 1.4% of global turnover. Q: How does NIS2 differ from the previous NIS1 directive? A: NIS2 expands the sectoral scope, increases reporting obligations (notification within 24/72 hours), raises penalties, includes personal liability for management bodies and adds supply chain requirements. Q: Do we need a pentest to comply with NIS2? A: NIS2 requires assessing security risks and applying appropriate technical measures. Penetration testing is one of the most solid ways to meet that obligation in a documented and verifiable way. Q: How long does it take to comply with NIS2? A: It depends on your starting point. Companies with a solid security baseline can complete the process in 3-6 months. Organizations starting from scratch may need 12-18 months for full compliance. --- ## DORA compliance: digital operational resilience for the financial sector URL: https://www.quantumsec.es/en/compliance/dora/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. DORA compliance for financial entities. ICT risk management, operational resilience testing and supply chain. Specialized team. DORA has been mandatory since January 2025 for banks, insurers, fund managers and a long list of financial entities in the EU. We assess your current situation, identify the gaps and support you through the compliance process. DORA is not optional for the financial sector The DORA Regulation (Digital Operational Resilience Act) entered into application in January 2025. It affects thousands of financial entities in the EU: banks, insurers, investment firms, fund managers, payment service providers and their critical technology providers. Non-compliance can lead to significant penalties and, above all, can expose the entity's inability to manage a digital crisis. Frequently asked questions answered by the QuantumSec team: Q: How does DORA differ from NIS2? A: NIS2 is a horizontal directive affecting multiple sectors. DORA is a sector-specific regulation for the financial sector, with more detailed and technical requirements, especially regarding resilience testing (TLPT) and ICT provider management. Q: What is TLPT testing and who must perform it? A: TLPT (Threat-Led Penetration Testing) is advanced intrusion testing based on real threat intelligence, targeting the entity's most critical systems. It's only mandatory for significant entities designated by the competent authorities. We can run it with the TIBER-EU methodology. Q: Does DORA also affect technology providers of financial entities? A: Yes. DORA establishes a direct oversight regime for critical ICT providers. And even if you're not a critical ICT provider, if you're a technology provider to a financial entity, they will require you to include DORA contractual clauses in the service agreement. --- ## ENS audit: compliance with Spain's National Security Framework (ENS) URL: https://www.quantumsec.es/en/compliance/ens/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ENS audit and consulting services: gap analysis, compliance plan and support through certification. For public entities and technology providers. The National Security Framework (ENS) is mandatory for Spanish public administrations and their technology providers. We help you understand which system category applies to you, which measures are required and how to obtain certification. Who must comply with the ENS? Royal Decree 311/2022, which regulates the ENS, makes it mandatory for Spanish Public Administrations and for any private company that provides technology services to the public sector or processes citizens' information on behalf of the Administration. If you've won a public contract with a technology component, you probably have (or will soon have) the obligation to certify under the ENS. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between an ENS declaration of conformity and certification? A: The declaration of conformity is an internal document the entity itself issues stating that it complies with the ENS. Certification is issued by a certification body accredited by ENAC after a formal audit. Some public contracts require certification, others accept the declaration. Q: How often must ENS certification be renewed? A: ENS certification is valid for 2 years, with annual follow-up audits. Q: What if the systems are BASIC category? A: BASIC category systems have a less demanding but equally mandatory set of measures. Conformity can be demonstrated through a properly documented internal audit. Q: Can I hire QuantumSec for the ENS audit, or does it have to be an official body? A: Formal ENS certification must be issued by an ENAC-accredited certification body. Our service is the preparatory consulting: gap analysis, system classification, implementing controls and preparing all documentation so the certification audit passes on the first attempt. Q: Which bodies can certify the ENS? A: Any certification body accredited by ENAC specifically for the ENS scheme, such as AENOR, Bureau Veritas or DNV. We don't issue the certificate ourselves — the accredited body does, after the formal audit — but we help you choose and prepare all the documentation and evidence that audit will require. --- ## Network and infrastructure penetration testing: see what your firewall can't URL: https://www.quantumsec.es/en/pentesting/network-infrastructure/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Perimeter, internal and segmentation network audit. Vulnerabilities in switches, routers, firewalls and VPNs. Technical report with prioritised remediation. We assess the security of your internal and perimeter network using real attack techniques. We identify misconfigurations, lateral movement paths and entry points that automated scanners miss. The problem: most breaches start on the internal network Once an attacker gets past the perimeter —through phishing, a vulnerable VPN or a compromised supplier— they need to move across your network to reach valuable assets. On poorly segmented networks, without granular access control or with unreviewed legacy configurations, that lateral movement can take minutes. And if your Active Directory sits on the same network as your employee WiFi, the problem is even greater. Frequently asked questions answered by the QuantumSec team: Q: Can network pentesting disrupt my services? A: Under normal conditions, no. We agree on the scope and exclude disruptive actions. The more aggressive tests are scheduled within maintenance windows. If you operate 24/7, we define windows outside peak hours. Q: What is the difference between an internal and a perimeter audit? A: The perimeter audit analyses what an external attacker sees from the Internet: open ports, exposed services, DMZ configuration. The internal audit simulates an attacker already inside —a malicious employee, a stolen credential— and that is where the most critical findings appear. Q: How often should I audit the network? A: At least once a year, and whenever there are significant changes to the infrastructure: new sites, a change of provider, a cloud migration or an expansion of the corporate WiFi network. Q: What network size can be audited? A: We audit everything from networks of 20 hosts to enterprise environments with thousands of devices. The scope and price are tailored to the real size of your infrastructure. --- ## Source code audit: find vulnerabilities before they reach production URL: https://www.quantumsec.es/en/audits/source-code/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Source code audit (SAST + expert manual review). We find SQL injection, XSS, exposed secrets and OWASP vulnerabilities. Report with PoC. We review your application's code with static analysis tools and expert manual review. We find everything from SQL injection to broken business logic, with enough context for your team to fix it. The problem: automated tools don't understand context SAST scanners generate a huge volume of false positives and don't understand your application's business logic. An expert reviewer can tell a real, exploitable vulnerability apart from a false positive, prioritize by real impact, and catch the design flaws no scanner can see: insecure direct object references, authentication bypasses, race conditions. Frequently asked questions answered by the QuantumSec team: Q: Do we have to give you access to the repository? A: Yes, we need read access to the repository. We sign an NDA beforehand and all access is documented. You can create a dedicated branch or fork for the review if your policy requires it. Q: Which languages and frameworks do you support? A: JavaScript/TypeScript (Node.js, React, Angular, Vue), Python (Django, FastAPI, Flask), Java (Spring), PHP (Laravel), Ruby (Rails), Go and .NET (C#). If you work with another stack, ask us. Q: How long does it take? A: Between 3 and 8 business days depending on the codebase size. A 30,000-line project can be reviewed in about 4 days. Larger projects require more time or a review focused on critical modules. Q: Do you also review infrastructure as code (IaC)? A: Yes. We review Terraform, CloudFormation, Kubernetes manifests and Dockerfiles to detect insecure configurations in infrastructure defined as code. --- ## Social engineering: the attack vector technology can't block URL: https://www.quantumsec.es/en/social-engineering/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Social engineering simulations: targeted phishing, vishing and pretexting. We measure your company's human resilience against real attacks. The human element is involved in roughly 6 out of every 10 data breaches, according to the Verizon DBIR. We simulate real social engineering attacks — phishing, vishing, pretexting — to measure and improve your team's resilience before a real attacker does. The weakest link isn't in your code You can have the best firewall on the market, up-to-date patches and a strict password policy. But if one employee clicks a well-crafted email, hands over credentials on a convincing call, or plugs in a USB drive found in the parking lot, everything else collapses. Social engineering exploits human trust, urgency and authority — and those factors don't go away with technology. Frequently asked questions answered by the QuantumSec team: Q: Will employees know it's a simulation? A: Not during execution, so the results are representative. They will afterward, during the awareness session. Leadership is always informed before it starts. Q: What happens if an employee falls for the phishing attempt? A: Nothing negative. The goal is educational, not punitive. The employee will see a notice page explaining they just took part in an exercise and what signs they should have noticed. Q: How often should this be done? A: At least twice a year to maintain alertness. Organizations with higher exposure or that handle sensitive data should do it quarterly. Q: Can we exclude certain departments? A: Yes. We can segment the scope by department, access level or any criteria you need. --- ## Cybersecurity compliance: from obligation to strategic asset URL: https://www.quantumsec.es/en/compliance/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Regulatory compliance in cybersecurity for regulated companies: we identify what applies to you, run the gap analysis and support you to certification. NIS2, DORA, ENS, ISO 27001. Cybersecurity regulations keep multiplying and tightening. We help you understand what applies to you, what's missing and how to get there without turning it into a never-ending project. The problem with compliance today Companies face a regulatory map that overlaps and contradicts itself: the NIS2 Directive covers critical sectors, DORA applies to the financial sector, the ENS applies to public entities and their suppliers, and ISO 27001 is increasingly demanded by enterprise clients as a contractual requirement. Each regulation has its own deadlines, specific controls and penalty regime. Without a guide who knows them well, the risk is investing huge effort and getting nowhere. We support compliance projects for companies across Spain — Valencia, Alicante, Seville, Barcelona and beyond — remotely, with on-site presence when the audit requires it. Frequently asked questions answered by the QuantumSec team: Q: Can you help us with several regulations at once? A: Yes, and it makes sense to do so. Many controls in ISO 27001, NIS2 and DORA overlap. Handling them in an integrated way avoids duplication and reduces overall effort. Q: Do you also run the certification audit? A: We're not a certification body (that requires ENAC accreditation), but we work with the main certifying entities and support you throughout the process. Q: How long does a compliance project take? A: It depends on the regulation and your starting point. A gap analysis takes 2-4 weeks. A full ISO 27001 project from scratch takes between 6 and 12 months for an SME. Q: Is the ENS mandatory for private companies? A: The ENS is mandatory for public administrations and private companies that provide ICT services to the administration or process publicly owned data. --- ## ISO 27001: implementing and certifying your information security management system URL: https://www.quantumsec.es/en/compliance/iso-27001/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ISO 27001 implementation and certification. Gap analysis, ISMS design and control implementation. We support you all the way to the external audit. We support you from the gap analysis through to the certification audit. We design an ISMS that genuinely works in your company, without unnecessary bureaucracy and without losing focus on what matters: reducing real risk. The problem with ISO 27001 projects that fail Most failed ISO 27001 projects share the same pattern: a consultant delivers a pack of generic documents, the team signs them off without understanding them, and when the external auditor arrives the policies bear no relation to reality. Documenting for the sake of documenting does not reduce risk. We start with an honest gap analysis and build an ISMS that reflects how your company actually works, that the team understands and that the auditor validates. Frequently asked questions answered by the QuantumSec team: Q: ISO 27001:2013 or ISO 27001:2022? Do we need to migrate? A: The current version is ISO 27001:2022. Certificates issued under the 2013 version had until October 2025 to migrate. If you're just starting, go straight for the 2022 version. Q: How many internal resources does the project require? A: You need an internal owner (usually the CISO or IT manager) with around 4 to 8 hours per week. The technical team takes part occasionally during the implementation of controls. Q: Does the ISO 27001 certificate have an expiry date? A: The certificate is valid for 3 years, with annual surveillance audits (years 1 and 2) and a recertification audit in year 3. Q: Can you carry out the annual surveillance audits? A: Yes. We offer maintenance contracts for surveillance audits, ISMS updates when things change and preparation for the three-yearly recertification. Q: Which certification body do you work with? A: We don't issue the certificate ourselves: due to role incompatibility, whoever helps you implement the ISMS cannot also certify it. We support you in choosing among ENAC-accredited bodies — AENOR, Bureau Veritas, DNV and others — and provide technical support throughout the external audit, whichever one you choose. --- ## AI and LLM Penetration Testing URL: https://www.quantumsec.es/en/pentesting/artificial-intelligence/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. AI and LLM penetration testing for companies: prompt injection, jailbreak, RAG and function calling. OWASP Top 10 for LLMs and MITRE ATLAS. PoC report. Language models and AI systems introduce entirely new attack vectors. We assess the security of your AI infrastructure before a real adversary does. Why does AI need dedicated penetration testing? A poorly protected LLM can leak confidential training data, execute arbitrary instructions through prompt injection or be manipulated into bypassing business controls. Traditional pentesting tools do not detect these vectors. A dedicated methodology aligned with the OWASP Top 10 for LLMs and MITRE ATLAS is required. Frequently asked questions answered by the QuantumSec team: Q: Does AI pentesting affect the model's performance in production? A: No. Testing is carried out in a staging environment or with controlled traffic. We never interfere with real users or degrade the service. Q: Do I need access to the model or only to the interface? A: It depends on the scope. A black box test only requires access to the final interface. A full pipeline test requires access to the system code and the model configuration. Q: Do you cover open-source models deployed on-premise? A: Yes. We assess both cloud models (OpenAI, Anthropic and Google APIs) and open-source models (Llama, Mistral, Qwen) deployed on your own infrastructure. --- ## Cloud infrastructure penetration testing (AWS, Azure, GCP) URL: https://www.quantumsec.es/en/pentesting/cloud/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cloud pentesting on AWS, Azure and GCP. IAM review, misconfigurations, privilege escalation and CIS Benchmarks compliance. Technical report. Most cloud incidents come from a misconfiguration, not a zero-day: the NSA and CISA warn that attackers actively target misconfigured, unsecured or unmonitored cloud systems. We audit your cloud infrastructure before an attacker exploits it. Why does the cloud need a different pentest? The cloud's shared responsibility model puts the security of configuration, identity and data in the customer's hands. A public S3 bucket, an IAM role with excessive permissions or an EC2 instance with hardcoded credentials are vectors that automated scanners don't contextualize. You need a team that thinks like an attacker with deep knowledge of AWS, Azure and GCP. Frequently asked questions answered by the QuantumSec team: Q: Do you need admin credentials for cloud pentesting? A: For a complete test, yes, we need an account with read permissions over all services. We can also perform a black-box test from the internet to assess external exposure. We recommend combining both approaches. Q: Can pentesting affect my production services? A: We coordinate all tests to minimize impact. Destructive exploitation (deletion, data modification) always requires explicit approval and is done in test environments. Q: Do you cover multi-cloud architectures? A: Yes. We have experience in environments combining AWS, Azure and GCP, as well as hybrid cloud + on-premise configurations. --- ## IoT Penetration Testing and Hardware Hacking URL: https://www.quantumsec.es/en/pentesting/iot/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Security assessment of IoT devices, firmware, industrial hardware and OT/ICS environments. OWASP IoT Top 10 and IEC 62443 methodologies. Request an assessment. Connected devices are the new perimeter. We assess the security of your IoT infrastructure, firmware, communications and industrial hardware before they become the gateway into your network. Why are IoT devices a critical risk? A compromised IoT device can serve as a pivot to access the corporate network, exfiltrate production data or bring critical infrastructure to a halt. Manufacturers prioritise functionality over security, and IT teams rarely audit the firmware or communications of these devices. In OT/ICS environments, the impact can be physical. Frequently asked questions answered by the QuantumSec team: Q: Do you need physical access to the device? A: For a full test, yes. Some analyses (backend API, mobile app, network communications) can be carried out remotely, but firmware and hardware analysis requires the physical device. Q: Can you carry out the pentest without affecting industrial production? A: We always work with the OT team to define maintenance windows and run the more invasive tests outside production hours. The safety of operations is our priority. Q: Do you carry out assessments to comply with the RED (Radio Equipment Directive)? A: Yes. We help manufacturers prepare the technical security documentation required by the EU's RED directive for IoT devices. --- ## iOS application penetration testing URL: https://www.quantumsec.es/en/pentesting/ios/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. iOS app security assessment (iPhone, iPad) following OWASP MASVS & MASTG. Static, dynamic, insecure storage and comms testing. Technical report included. An app being on the App Store does not mean it is secure. We audit your iOS application following the OWASP MASVS methodology to detect vulnerabilities in data, communications and business logic. Why do iOS apps need a dedicated assessment? Apple's review catches malware and policy violations, but it does not audit your application's security logic. Data stored unencrypted in the keychain, session tokens exposed in logs, disabled certificate validation or insecure communications with backends are vulnerabilities Apple does not review and that an attacker with the device in hand can exploit. Frequently asked questions answered by the QuantumSec team: Q: Do you need the source code or just the IPA? A: We can work with just the IPA (black/grey box). If you provide the source code, the analysis is deeper and more efficient. We recommend code access for development teams that want actionable results. Q: Does the test require a physical jailbroken device? A: For full dynamic analysis, yes, we recommend a jailbroken device. We can also work with simulators for part of the static and network analysis. Q: Do you cover the backend API the app uses? A: Yes, we include the assessment of the backend API within the scope of the mobile pentest. It is essential for a complete assessment, as many vulnerabilities live in the server layer. --- ## Android application penetration testing URL: https://www.quantumsec.es/en/pentesting/android/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Android app security audit following OWASP MASVS and MASTG. APK analysis, insecure storage, communications, permissions and exported components. Request an audit. Android is the most widely used mobile operating system in the world and attackers' favourite target. We audit your app against OWASP MASVS to ensure your users' data stays protected. Why is Android especially critical for security? Android's fragmentation, the ease of installing third-party APKs and the wide variety of manufacturers with their own customisations vastly expand the attack surface. An exported Activity with no protection, a ContentProvider that exposes data to other apps or a misconfigured WebView can all be exploited without the user ever noticing. Frequently asked questions answered by the QuantumSec team: Q: Do you need the source code of the Android app? A: It is not essential. We can work directly with the APK through black/grey box analysis. The source code allows a deeper analysis, especially for detecting business logic vulnerabilities. Q: Can you run the test without a physical device? A: Part of the analysis (static and network) can be performed with emulators. For full dynamic analysis with Frida and hardware-backed security analysis, we recommend a rooted physical device. Q: Does the audit help with GDPR compliance in Android apps? A: Yes. We identify where personal data is stored and transmitted, whether it is adequately protected and which permissions are excessive or unnecessary, all of which is key to a privacy impact assessment (DPIA). --- ## Cyber Threat Intelligence (CTI) URL: https://www.quantumsec.es/en/threat-intelligence/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CTI: dark web monitoring, leaked credentials and active threats. Early alerts and intelligence analysis tailored to your sector. Know your adversaries before they attack you. Our CTI service delivers actionable intelligence on real threats affecting your organization, sector and supply chain. Why do you need threat intelligence? Reacting to attacks after they've happened is too late. Cyber threat intelligence lets you get ahead: knowing which threat groups target your sector, whether your credentials are circulating on cybercrime forums, whether your brand is being impersonated, or whether an exploit is actively being used against software you run. The difference between detecting a breach at day 3 or day 200 can be the entire impact of the incident. Frequently asked questions answered by the QuantumSec team: Q: Is the CTI service continuous or one-off? A: It's an ongoing monitoring service. One-off intelligence (an exposure report or an analysis of a specific threat actor) is also available as an ad-hoc service. Q: How does CTI integrate with our existing security systems? A: We provide feeds in standard formats (STIX/TAXII, CSV, JSON) that integrate with major SIEMs (Splunk, Microsoft Sentinel, QRadar) and SOAR platforms. Q: What's the difference between CTI and OSINT? A: OSINT is a source (information from open sources). CTI is a full process: collection from multiple sources (OSINT, dark web, private feeds), analysis, contextualization and production of actionable intelligence for decision-making. --- ## WiFi and wireless network security audit URL: https://www.quantumsec.es/en/audits/wifi/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Corporate WiFi security audit. WPA2/WPA3, guest networks, Evil Twin, rogue APs and wireless segmentation per OWISAM. Technical report. A misconfigured corporate WiFi network is a direct gateway into your internal network. We assess the security of your wireless infrastructure using the OWISAM methodology. Why is corporate WiFi a common attack vector? A single misconfigured WiFi network is enough to open the door to your whole corporate network, and most offices run several. Weak WPA2 passwords susceptible to dictionary attacks, unsegmented guest networks, rogue access points installed without authorization, or a lack of Evil Twin detection are real vectors attackers exploit to gain initial access to the corporate network. Frequently asked questions answered by the QuantumSec team: Q: Do you need to be physically on our premises? A: For the full assessment, yes. Wireless network analysis requires physical presence. We schedule visits at times that minimize disruption to your operations. Q: Does the WiFi audit include guest networks? A: Yes, we include every wireless network within the perimeter: corporate, guest, IoT and any unauthorized network we detect. Q: Do you also assess the security of devices connected to the WiFi? A: The standard scope covers the wireless infrastructure. If you want to include an assessment of connected devices (IoT, PCs, printers), we extend it as part of an internal network pentest. --- ## Managed security (MSSP): continuous cybersecurity for your business URL: https://www.quantumsec.es/en/managed-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. MSSP: continuous monitoring, vulnerability management, incident response and virtual CISO for businesses without an in-house security team. Cybersecurity isn't a one-off project, it's an ongoing process. We act as your outsourced security department: monitoring, detecting, responding and improving your security posture month after month. Why do you need managed security? Most companies can't afford an in-house CISO, SOC and incident response team. Yet attackers don't distinguish between a 20-person startup and an Ibex35 company. An MSSP service gives you access to enterprise-grade security capabilities for a fraction of the cost, with the advantage of scaling to your needs and having a single point of contact for all your cybersecurity. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between an MSSP and an IT maintenance contract? A: An MSSP focuses exclusively on security: threat detection, vulnerability management, incident response and regulatory compliance. We don't manage infrastructure or end-user support. Q: What's the SLA for incident response? A: For critical incidents, the initial response time is under 4 hours. For high-impact incidents, we guarantee forensic analysis begins the same day. Q: Does the service include the annual pentest? A: Yes, mid and top-tier plans include an annual pentest with an agreed scope. It's the ideal combination: continuous monitoring plus periodic offensive assessment. --- ## AI-powered penetration testing URL: https://www.quantumsec.es/en/pentesting/ai-powered/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. AI-powered penetration testing for companies: broader coverage in less time. AI tooling validated by OSCP-certified pentesters. Report with real PoC. AI does not replace the pentester: it makes them more effective. We combine AI tooling with the judgement of our experts to deliver faster audits, with broader coverage and lower cost. How does AI improve traditional pentesting? Traditional tools generate noise: thousands of findings in which false positives and low-relevance alerts vastly outnumber the genuinely exploitable vulnerabilities. AI lets us prioritise automatically, generate adaptive payloads, analyse large volumes of source code in minutes and correlate findings to identify attack chains. The result: more real vulnerabilities in less time. Frequently asked questions answered by the QuantumSec team: Q: Is AI-powered pentesting as rigorous as manual testing? A: It is more rigorous in coverage (AI does not tire and never skips steps) and less so in pure creativity. That is why we combine both: AI guarantees systematic coverage while the human expert brings creativity, context and advanced exploitation. Q: Which AI tools do you use? A: We combine proprietary tooling with recognised industry solutions, tailored to each type of assessment. We do not rely on a single vendor or on generic AI tools that have not been validated for security work. Q: Is it cheaper than traditional pentesting? A: Generally yes, because automation reduces the hours spent on manual reconnaissance. But the main value is not the cost: it is the broader coverage achieved in the same amount of time. --- ## Vulnerability Assessment URL: https://www.quantumsec.es/en/vulnerability-assessment/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Vulnerability assessment: systematic detection of security gaps without active exploitation. Key differences from pentesting and when to use each. The first step to improving your security is knowing where you're exposed. A vulnerability assessment gives you a complete picture of your technical risks, prioritized by criticality. Vulnerability assessment vs. pentesting: what does your company need? A vulnerability assessment (VA) identifies and classifies known vulnerabilities in your systems through scanning and technical review, without actively exploiting them. Pentesting goes a step further: an expert attempts to exploit those vulnerabilities to demonstrate real impact. A VA is ideal as a periodic review or starting point; pentesting is necessary to demonstrate real impact, meet advanced regulatory requirements, or prepare for a Red Team. Frequently asked questions answered by the QuantumSec team: Q: Is a vulnerability assessment enough to comply with NIS2 or ISO 27001? A: It depends on the required maturity level. NIS2 and ISO 27001 require continuous vulnerability management, which a recurring VA can cover. To demonstrate real impact or prepare for Red Team evaluations, pentesting is required. Q: How often should I run a vulnerability assessment? A: We recommend a monthly cycle for critical assets and quarterly for the rest. After significant infrastructure changes (a new application, cloud migration, etc.) we always recommend a one-off assessment. Q: Does the VA include web applications? A: Yes. The scope can include network infrastructure, servers, web applications and APIs. We also offer the vulnerability assessment as a first step before a full web pentest. --- ## External ethical hacking: perimeter assessment from the internet URL: https://www.quantumsec.es/en/ethical-hacking/external/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. External ethical hacking: perimeter security from the internet. OSINT, reconnaissance, exploitation of exposed services and attack chains. An attacker with no credentials or prior access can compromise your organization from the internet. We assess your entire external attack surface from a real adversary's perspective. What does an attacker see when they target your company from the internet? Services exposed without your knowledge, forgotten subdomains running outdated applications, employee credentials in data breaches, expired certificates, admin panels reachable from the internet: this is the reality of the perimeter at most companies. External ethical hacking simulates a real attack from the internet to identify and demonstrate exactly what an attacker can achieve without prior access. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between external ethical hacking and a network pentest? A: External ethical hacking focuses exclusively on what's visible from the internet, starting from zero (no credentials or prior access), including OSINT. A network pentest covers both the external perimeter and the internal network. Q: Does it include OSINT on employees? A: Yes, within the agreed scope. We identify employee data exposed in breaches, LinkedIn and other sources that a real attacker would use for targeted attacks or credential stuffing. Q: Can it detect if we've already been compromised? A: An active compromise assessment is a different service. However, if during reconnaissance we detect indicators of prior compromise, we notify you immediately. --- ## Internal ethical hacking: assessment from inside the network URL: https://www.quantumsec.es/en/ethical-hacking/internal/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Internal ethical hacking: security testing from inside the corporate network. Lateral movement, privilege escalation and network segmentation. Lateral movement is the stage that turns a single intrusion into a serious breach. We simulate an attacker who has already gained initial access to assess how far they can get inside your internal infrastructure. What happens once an attacker is inside your network? Most companies invest in protecting the perimeter, but once inside, an attacker can move freely through the internal network, escalate privileges, reach critical systems and exfiltrate data for weeks or months without being detected. Insider threats and successful phishing are the most common entry vectors. The question is: how far can they get once they're in? Frequently asked questions answered by the QuantumSec team: Q: What starting point is used for internal ethical hacking? A: We typically simulate a standard domain user (the most realistic scenario: a compromised employee or an attacker with initial access via phishing). We can also start from physical network access (a network cable) or from an unprivileged account on the machine. Q: Can the test affect production systems? A: We coordinate all testing with the IT team. The most invasive techniques (such as modifying AD) are only performed with explicit authorization and within agreed windows. The goal is to simulate an attack, not to cause damage. Q: What is BloodHound and why does it matter? A: BloodHound is the industry-standard tool for analyzing Active Directory relationships and finding privilege escalation paths. Attackers use it; so do we, so you can see exactly what they would see in your AD. --- ## Cybersecurity for SMBs: protect your business on a real budget URL: https://www.quantumsec.es/en/solutions/smb/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Penetration testing, managed security and NIS2 compliance for SMBs and mid-sized companies in Spain. No big budgets required. Free diagnostic in 24h. SMBs and mid-sized companies are cybercriminals' favorite target, not their lowest priority. We design security solutions that fit your size, budget and resources. Why are SMBs a preferred target for cyberattacks? SMBs are a routine target for cyberattacks, not an exception. Attackers know that small and mid-sized businesses have weaker defenses, limited budgets and, in many cases, no dedicated security specialist. A ransomware attack can paralyze an SMB for weeks and cause losses of tens of thousands of euros. The good news: you don't need a multinational's budget to reach an adequate level of security. Frequently asked questions answered by the QuantumSec team: Q: How much does cybersecurity cost for an SMB? A: It depends on your size and exposure. An initial diagnostic and a basic vulnerability assessment can run a few hundred euros. A managed security service for a typical SMB ranges from €300 to €800/month. We always start with what has the most impact for the lowest cost. Q: Am I required to comply with NIS2 as an SMB? A: It depends on your sector and size. NIS2 directly obligates medium and large companies in essential and important sectors. However, many SMBs are indirectly obligated because they supply companies that must comply, and those companies require security guarantees from them. Q: Can you help us even if we don't have an IT manager? A: Yes. We work directly with management or whoever handles IT informally at the company. No prior technical knowledge is required to work with us. Q: How long does it take to set up a cybersecurity plan for my SMB? A: The highest-impact immediate measures (MFA, passwords, backups) are set up within days. An initial vulnerability assessment takes 1 to 5 business days depending on size. A full plan with assessment, guided remediation and basic policies is usually completed in 4-8 weeks. We always start with what has the most impact at the lowest cost. Q: My company has already suffered a cyberattack. What do I do now? A: The first step is containment: isolate the affected systems, revoke compromised access and preserve evidence without altering it. Next, a basic forensic analysis determines how they got in, what was affected and whether they're still inside. If the incident involves personal data, you have 72 hours to notify the AEPD. Contact us: we do an initial triage to help you understand the situation before deciding next steps. Q: Do I need a CISO or an in-house security manager? A: For most SMBs it's neither necessary nor viable. A senior in-house CISO is a high fixed cost and a profile that is hard to attract and retain. The alternative is a virtual CISO service or an external security partner: you set the objectives, we execute them and report back periodically. It's far more efficient for companies with fewer than 100 employees. Q: What is managed security and when does it make sense for an SMB? A: It's a continuous monitoring and response service (SOC as a Service) without hiring an in-house team: we watch your systems, detect incidents and act on protocols agreed with you. It makes sense once you have critical assets to protect outside business hours but not the volume to justify an internal SOC. Q: Do I need cyber insurance on top of cybersecurity services? A: They're complementary, not substitutes. Most insurers require minimum controls (MFA, backups, periodic vulnerability assessment) to issue or renew a cyber policy, and lower the premium if you can demonstrate them. We help you identify what your insurer requires and implement it before renewal. --- ## Cybersecurity for startups: build secure from day one URL: https://www.quantumsec.es/en/solutions/startups/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity for startups: penetration testing, secure SDLC, SOC 2/ISO 27001 compliance and investor due diligence reports. No security debt. Security debt is like technical debt: cheap to ignore in the short term, very expensive in the long run. With ethical hacking and real penetration testing, we help startups and SaaS build secure products, meet enterprise customer requirements and pass investor due diligence. Why does security matter from day one at a startup? A startup that suffers a breach before its Series A can see its fundraising process derailed. An enterprise customer that discovers critical vulnerabilities during a security review can block the deal. And a data breach affecting users can mean the end of the business. The cost of fixing vulnerabilities in production is 30 times higher than catching them during development. Frequently asked questions answered by the QuantumSec team: Q: When is the best time to do a first penetration test? A: The first pentest should happen when the product is in beta or before public launch. Waiting until you have traction or real users increases both the risk and the cost of remediation. Q: Can you help us complete an enterprise customer's security questionnaire? A: Yes. It's one of the services most requested by startups. We help you answer security questionnaires (CAIQ, SIG, custom questionnaires) and put together the documentation that backs up those answers. Q: Do you have experience with startups using AI-generated code or vibe coding? A: Yes. Code generated by LLMs tends to reproduce known vulnerability patterns (injections, insecure secret handling, weak validation). We have a dedicated review service for AI-generated code. --- ## Security in AI-assisted development: auditing LLM-generated code URL: https://www.quantumsec.es/en/solutions/ai-development/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. AI-generated code audit (Copilot, ChatGPT). Vibe coding risks, common vulnerabilities and how to protect your product. AI-generated code is fast, but it isn't secure by default. We audit code generated by GitHub Copilot, ChatGPT, Claude and other tools to catch the vulnerabilities LLMs don't see. Why does AI-generated code introduce security risks? LLMs generate plausible code, not secure code. The reference academic study on GitHub Copilot ("Asleep at the Keyboard?", NYU, IEEE S&P 2022) generated 1,689 programs across 89 scenarios tied to the CWE Top 25 and found roughly 40% of them to be vulnerable. Models reproduce insecure patterns present in their training data, don't understand the security context of your specific application, and can't reason about the business impact of a vulnerability. "Vibe coding" — developing without understanding the code the AI generates — amplifies these risks exponentially. Frequently asked questions answered by the QuantumSec team: Q: Is AI-generated code less secure than code written by humans? A: Not necessarily, but it introduces different risks. LLMs are very good at reproducing known patterns, but that includes insecure patterns too. The biggest risk is "vibe coding": the developer doesn't understand the code and can't identify the security issues. Q: Do you need access to the full repository? A: Yes, a complete analysis requires read access to the source code. We work with GitHub, GitLab and Bitbucket, and we sign an NDA before any access. Q: Can you audit code generated with Cursor, Devin or other AI tools? A: Yes. The specific AI generation tool matters less than the vulnerability pattern in the resulting code. We evaluate the code regardless of which tool generated it. --- ## Cybersecurity consulting for businesses URL: https://www.quantumsec.es/en/cybersecurity-consulting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Tailored cybersecurity consulting: risk assessment, roadmap, NIS2/ISO 27001 compliance and technical guidance. No jargon. Not every company needs a pentest right away. Sometimes the first step is understanding where you stand, what risks you face and what to tackle first. That's what we do in a cybersecurity consulting engagement. When does your company need cybersecurity consulting? Many companies don't know where to start with cybersecurity. They're unsure whether NIS2 or DORA applies to them, don't know if their current measures are enough, have suffered an incident and want to prevent it happening again, or want ISO 27001 certification but don't know what it involves. Cybersecurity consulting gives you a real diagnosis of your situation, a roadmap prioritized by impact and cost, and the guidance to execute it correctly — without selling you services you don't need. We work remotely with companies across Spain — Valencia, Alicante, Seville, Barcelona and beyond — with in-person meetings when the project calls for it. Frequently asked questions answered by the QuantumSec team: Q: How is cybersecurity consulting different from a pentest? A: A pentest is a technical test that looks for exploitable vulnerabilities in a specific system. Cybersecurity consulting is a broader service that assesses the organization's overall maturity: technical controls, processes, people and regulatory compliance. Consulting often leads to identifying a pentest as the necessary next step, but not always. Q: How much does cybersecurity consulting cost? A: It depends on the scope and size of the organization. An initial diagnostic consulting engagement for an SME can start from €2,500. A broader project with a full roadmap and implementation support can range between €8,000 and €25,000. We always provide a fixed quote before starting. Q: Can you act as an external CISO after the consulting engagement? A: Yes. We offer a CISO as a Service (CISOaaS) for companies that need a security leadership figure without the cost of hiring one full-time. It includes oversight of the roadmap, attendance at leadership committees and strategic security decision-making. Q: Does the consulting cover NIS2 compliance? A: Yes. We carry out the gap analysis against NIS2, identify whether your company is in scope (regulated sectors), assess existing measures against the directive's requirements and prepare a compliance plan with the necessary technical and organizational controls. Q: Do I need my own technical team to work with you? A: No. We work with companies that have an in-house IT team and with companies that have no technical resources of their own. We adapt the language, level of detail and support to each client's reality. --- ## Cybersecurity company in Valencia URL: https://www.quantumsec.es/en/cybersecurity-valencia/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity company in Valencia: real penetration testing, ethical hacking and NIS2 compliance from an OSCP-certified team. Free quote in 24h. We are QuantumSec, an IT security and offensive cybersecurity company based in Valencia. We work as a boutique team: few clients at a time, direct access to the technical team and a scope built for you — whatever your sector, from the city itself to any comarca of the Valencia region. Why do Valencian companies need a local cybersecurity partner? The Valencian business fabric —industrial, tech, logistics and agri-food— is a priority target for cybercrime, precisely because of the density of interconnected SMEs acting as suppliers to one another. Many of these companies still don't have a documented incident response plan, which worsens the impact when an attack happens. An external cybersecurity team based in Valencia gives you the proximity of a local partner with the technical depth of a specialized team — without the cost of an in-house workforce or the distance of a national consultancy. We serve companies across the whole Valencia region —the Valencia metropolitan area, La Ribera, La Safor, Camp de Morvedre, La Costera and the provinces of Castellón and Alicante— with the same team and the same level of detail, whatever sector you operate in. Frequently asked questions answered by the QuantumSec team: Q: Do you hold in-person meetings in Valencia? A: Yes. We're based in Valencia and can meet in person for the initial call, results presentation or training sessions. Technical execution is carried out remotely or on-site depending on the scope of the service. Q: Which municipalities in the Valencia region do you cover? A: The whole Valencia region. Our office is in the city of Valencia and from there we travel routinely to the metropolitan area (Paterna, Torrent, Manises, Burjassot, Mislata), La Ribera (Alzira, Algemesí, Carcaixent), La Safor (Gandia, Oliva), the coast (Cullera, Sueca, Sagunto, Dénia), La Costera (Xàtiva, Canals) and La Vall d'Albaida (Ontinyent). We also serve companies in Castellón and Alicante. We don't have an office in every municipality: we have one base in Valencia and a team that travels, which is what keeps the relationship direct without inflating the cost. Q: Do you work only with large companies or also with Valencian SMEs? A: We work with all types of companies, from freelancers with a digital presence to Ibex35 companies. We have offers specifically designed for the Valencian SME fabric, with scopes and pricing adapted to their reality. Q: How much does a cybersecurity service cost for a company in Valencia? A: The cost depends on the scope. A basic vulnerability assessment for an SME starts from €1,500. A full pentest (web + internal network) ranges between €4,000 and €12,000 depending on complexity. Request a free consultation and we'll give you a no-obligation quote within 24 hours. Q: Can you help us comply with the NIS2 directive from Valencia? A: Yes. We advise Valencian companies on NIS2 adaptation, identifying whether they're in scope, performing the gap analysis, implementing the required controls and preparing the documentation for the competent authority (INCIBE-CERT / CCN-CERT). Q: Do you work with industrial and logistics companies in Valencia? A: Yes. We have experience with OT/ICS environments, industrial networks and SCADA systems, common in the Valencian industrial fabric (Paterna Industrial Zone, Port of Valencia, Almussafes industrial estates). Securing industrial environments requires different approaches from conventional IT. Q: What exactly does an IT security company like QuantumSec do? A: An IT security company assesses, protects and monitors your organization's digital systems. At QuantumSec we specialize in the offensive side: penetration testing (simulating real attacks), ethical hacking (auditing your defenses from an attacker's perspective), vulnerability assessment and regulatory compliance (NIS2, ENS, ISO 27001). Unlike a generalist security company, our offensive approach identifies real flaws before third parties exploit them. --- ## Cyber Resilience Act (CRA) consulting: compliance for software and hardware manufacturers and suppliers URL: https://www.quantumsec.es/en/compliance/cra/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CRA compliance consulting for digital product manufacturers. Gap analysis, conformity assessment and CE marking. Avoid fines of up to €15M or 2.5% of turnover. Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force in October 2024 and will be fully applicable in December 2027. It affects every manufacturer and distributor of products with digital elements sold in the EU: from desktop applications to IoT devices, routers and enterprise software. Fines reach €15 million or 2.5% of global annual turnover. Does your company manufacture or distribute digital products in the EU? If you develop software that includes client-side installable components, manufacture devices with network connectivity —IP cameras, routers, IoT devices, wearables, industrial systems—, distribute digital products made outside the EU within it, or your components are integrated into other manufacturers' products, the CRA affects you directly. The regulation applies across the whole chain: manufacturer, importer and distributor. Many companies wrongly assume it only applies to hardware manufacturers, but the CRA also covers software developers with networked components, desktop applications with remote connectivity and embedded systems. The deadline for full compliance is December 2027, but some obligations —such as reporting actively exploited incidents to ENISA— take effect in August 2026. Frequently asked questions answered by the QuantumSec team: Q: When does the Cyber Resilience Act enter into force? A: The CRA entered into force on 23 October 2024. Full application of the technical and conformity requirements is 11 December 2027. There are two critical intermediate deadlines: the requirements to report actively exploited incidents to ENISA apply from 11 August 2026, and notified bodies (for third-party assessment) must be designated from 11 September 2026. Q: Does the CRA apply to all software or only to connected hardware? A: The CRA applies to all "products with digital elements": hardware and software with direct or indirect network connectivity. Excluded are open source software released without commercial purpose, pure SaaS services without client-side installable components, medical products regulated by the MDR, civil aviation products and defence equipment. If your SaaS includes a desktop agent or an installable plugin, that component does fall within the scope of the CRA. Q: What are the penalties for CRA non-compliance? A: The CRA sets three levels of penalty: up to €15 million or 2.5% of global annual turnover for breaching the essential cybersecurity requirements; up to €10 million or 2% for breaching other obligations; and up to €5 million or 1% for providing incorrect information to the authorities. Q: What is the difference between Class I, Class II and Default products? A: Default products are the majority and can use self-assessment. Class I includes higher-risk products (identity management systems, browsers, password managers, security software, home routers) and requires third-party assessment unless a harmonised standard is fully applied. Class II includes the most critical products (server operating systems, hypervisors, industrial firewalls, industrial control systems, PKI, TPMs) and mandatorily requires an audit by a notified body. Q: Does the CRA overlap with NIS2 or other regulations? A: Yes. NIS2 regulates the cybersecurity of essential service operators, while the CRA regulates the security of digital products before they are placed on the market. If you are a software manufacturer and also operate an essential service, both apply to you. There are also overlaps with the MDR for connected medical devices (the MDR prevails) and with the EUCS scheme for critical cloud products. Q: How long does it take to comply with the CRA? A: It depends on your starting point and product category. Companies with a secure SDLC already in place and mature vulnerability management processes can complete the process in 6-9 months. Organizations starting from scratch will need 12-24 months for full compliance before the 2027 deadline. --- ## Ethical hacking for businesses: know your vulnerabilities before attackers do URL: https://www.quantumsec.es/en/ethical-hacking/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Ethical hacking for businesses: comprehensive multi-vector assessment with OWASP and MITRE ATT&CK. OSCP-certified team. Executive + technical report. Ethical hacking is a comprehensive assessment that combines multiple attack vectors — OSINT, external perimeter, internal network — to simulate, in an authorized and controlled way, a full attack campaign. The result is an exact picture of your risks, with concrete steps to eliminate them. Why ethical hacking instead of an automated vulnerability scan? Automated scanners detect known vulnerabilities. An ethical hacker thinks like a real adversary: chains together seemingly minor flaws, exploits business logic and finds paths no scanner has in its database. The result isn't a list of CVEs — it's a demonstration of the real impact an attacker would have in your specific environment. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between ethical hacking and pentesting? A: Ethical hacking is a comprehensive assessment that combines multiple vectors — OSINT, external perimeter, internal network, privilege escalation — to simulate a full attack campaign against your organization. Penetration testing is a technical test scoped to one specific system or surface: a web app, an API, a network. If you need to assess a specific system, choose penetration testing; if you want to know how far a real attacker would get across your whole organization, choose ethical hacking. Q: Can ethical hacking affect my production systems? A: The scope is defined precisely before starting. By default we avoid actions that could disrupt service (DoS, data deletion). If any test carries potential impact risk, we agree it with you and run it during a maintenance window. Q: Do I need to sign anything before you start? A: Yes. Before any activity we sign a scope agreement and an NDA. This protects both your organization and the audit team and defines exactly what's authorized. Q: How much does an ethical hacking service cost? A: It depends on the scope: type of assessment (external, internal, or both), number of assets and test depth. We offer a free initial call to properly size the project and give you an accurate quote. Q: Do you work with companies outside Valencia? A: Yes. We have clients across Spain. External ethical hacking is carried out fully remotely. Internal assessments may require physical presence or VPN access to the environment depending on the agreed scope. --- ## Cybersecurity solutions tailored to your type of business URL: https://www.quantumsec.es/en/solutions/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity tailored to your profile: SMEs, startups and teams building with AI. Pentesting, compliance and SDLC security. Not every company has the same risks or the same starting point. We design security solutions tailored to your profile, budget and goals. Why doesn't generic cybersecurity work? A ten-person SME doesn't need the same level of cybersecurity as a listed company, but it does need real protection. A tech startup raising investment must demonstrate security controls before closing a round. A team building with AI has risks specific to LLM-generated code. Each profile has its own attack vectors and its own regulatory requirements. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between your SME solution and your startup solution? A: SMEs usually prioritize protecting the existing business (pentesting, vulnerability assessment, NIS2), while startups usually need to prove their security to investors or enterprise clients (due diligence, SOC2/ISO 27001 compliance, secure SDLC). Although the services overlap, the approach and documentation differ. Q: Do you work with very small companies, under 10 employees? A: Yes. We have experience with microbusinesses and freelancers with specific security needs, especially in regulated sectors like healthcare, legal or fintech. Scope and cost adapt to the size and real critical assets. Q: Can you support us through the entire ISO 27001 certification process? A: Yes. We offer end-to-end support: from the initial gap analysis to preparation for the external certification audit. We also follow up during the control implementation phase. --- ## SaaS application penetration testing: find the vulnerabilities before your customers do URL: https://www.quantumsec.es/en/pentesting/saas/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Specialised SaaS pentesting: multi-tenant isolation, APIs, authentication, business logic and data segregation. Technical + executive report. Book an assessment. SaaS applications have a unique attack surface: multiple tenants on the same infrastructure, critical APIs, third-party integrations and enterprise customer data. A single isolation flaw can compromise all of your customers at once. Why is SaaS pentesting different from standard web pentesting? A standard web pentest covers the OWASP Top 10. A SaaS product has additional layers that automated scanners and generic tests miss: can a Starter-plan user access an Enterprise-plan user's data? Are tenants properly isolated in the database? Can the billing logic be manipulated? Do webhooks expose data between customers? Do API tokens carry excessive scopes? These vulnerabilities are specific to the SaaS business model and require pentesters who understand the product, not just the technology. Frequently asked questions answered by the QuantumSec team: Q: Does SaaS pentesting require access to the source code? A: Not necessarily. Black box or grey box testing (without code access) already detects most critical SaaS vulnerabilities. If you give us access to the source code (white box), we combine the penetration test with static analysis (SAST) for greater coverage. Q: Can we run the pentest against the staging environment? A: Yes. It is the most common option in SaaS: you prepare a staging environment with representative data (not real customer data) and we run the pentest there. The key is that the environment faithfully mirrors production in configuration, infrastructure and business logic. Q: Does SaaS pentesting also cover the cloud infrastructure? A: It can be included as additional scope. A SaaS application pentest covers the application layer (web, API, logic). If you also need to review IAM configuration, security groups, S3 policies or Kubernetes, we add it as a cloud pentesting component. Q: How long does a SaaS application pentest take? A: Between 5 and 10 working days for applications of medium complexity. The duration depends on the number of endpoints, user roles, integrations and the agreed depth. For SaaS with a microservices architecture it can take longer. Q: Is the report suitable for presenting to enterprise customers or investors? A: Yes. The executive report is designed to be presented to management, enterprise customers and in investment due diligence processes. It includes a summary of the scope, methodology, findings and remediation status. --- ## Vulnerability Triage as a Service URL: https://www.quantumsec.es/en/vulnerability-triage/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We outsource the vulnerability triage for your bug bounty or VDP program. We validate, prioritize and dismiss reports with real offensive judgment. No noise, no false positives. Your security team shouldn't spend most of its time reading invalid reports to find the 3 that actually matter. We handle triage with the same offensive technical judgment we use for penetration testing. Vulnerability triage is costing you more than you think Every report that reaches your bug bounty or VDP program requires analysis, reproduction and assessment. If your team takes 2-4 hours per report and you receive 50 a month, that's over 100 hours of specialized work —not counting the false positives, duplicates and out-of-scope reports that eat up time without creating any value. And if the report arrives over a weekend or during a holiday, the response window stretches out, damaging the researcher's experience and your reputation in the community. Outsourcing triage isn't losing control: it's getting your team's time back for what actually matters. Frequently asked questions answered by the QuantumSec team: Q: Can you integrate with our current bug bounty platform (HackerOne, Bugcrowd, Intigriti)? A: Yes. We work on the client's existing platforms without needing to switch tools. We also integrate with in-house channels: web forms, secured email, Jira, GitHub Issues or any ticketing system. The client keeps full visibility into the entire process. Q: What's the SLA for responding to a critical report? A: For reports classified as critical, the maximum first-response time is 8 business hours and 24 hours on weekends. For high-severity reports, the SLA is 24 business hours. These parameters are configurable to fit your program's needs. Q: What happens if we disagree with your assessment of a report? A: The client always has the final word. If there's disagreement over a report's assessment, we review it together, provide the technical evidence supporting our position and agree on the final classification. It's a collaborative service, not a black box. Q: How do you guarantee the confidentiality of reports? A: We sign a specific NDA for the triage service before starting. All reports and their contents are strictly confidential. Access to reports is restricted to the technical team assigned to the client. We never share information about a client's vulnerabilities with third parties. Q: How much does external triage cost? A: The cost depends on the estimated monthly report volume, the required SLA level and whether the service includes researcher communication. We work with fixed monthly rate models based on report volume. It's significantly cheaper than hiring an in-house triage analyst, and much more flexible. --- ## Bug Bounty and Vulnerability Management as a Service URL: https://www.quantumsec.es/en/bug-bounty/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Specialized services in vulnerability triage, bug bounty program management and Vulnerability Disclosure Programs. For companies receiving security reports without enough in-house capacity. We help companies that receive vulnerability reports manage them properly. Technical triage, program management, VDPs and validation: all with real offensive judgment. Receiving vulnerability reports without a team to manage them is a real risk A researcher who reports a critical vulnerability expects a response in hours, not weeks. If your team lacks the capacity to triage, validate and prioritize incoming reports, you're accumulating risk without knowing it. Poorly managed bug bounty and VDP programs generate false positives that overwhelm developers, silence your most valuable researchers and leave real vulnerabilities unattended. You don't need to build an in-house team to run a high-quality external security program. Frequently asked questions answered by the QuantumSec team: Q: How is this different from hiring HackerOne or Bugcrowd? A: HackerOne and Bugcrowd are platforms: they give you access to a community of researchers and management tools, but you still need an in-house team to triage and validate. We're the external team that does that work. We can operate on the platforms you already use, or design a program independent of them. Q: Can you manage programs already active on another platform? A: Yes. We work on HackerOne, Bugcrowd, Intigriti and any in-house channel. There's no need to change platform or process. We simply add the triage and management layer you're missing. Q: How long does it take for the service to be up and running? A: Standard onboarding takes between 5 and 10 business days: technical briefing, access and integration setup, and workflow definition. For more complex programs or multiple integrations, the timeline can extend. --- ## Full-Service Bug Bounty Program Management URL: https://www.quantumsec.es/en/bug-bounty/program-management/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We design, launch and manage your bug bounty program end to end. Triage included. No need for a dedicated in-house team. No-obligation consultation. Launch or professionalize your bug bounty program without growing your team. We handle the design, the rules, researcher communication and full report triage. A poorly managed bug bounty program does more harm than not having one Bug bounty programs create value when reports are handled fast, with technical judgment and clear responses to researchers. When triage takes weeks, the best researchers abandon your program. When false positives pile up, your development team loses trust in the process. And when a critical vulnerability waits in the queue because no one is available to process it, risk grows silently. Running a program well takes time, technical expertise and constant availability. We do it for you. Frequently asked questions answered by the QuantumSec team: Q: Do you work on existing platforms or do I need to switch? A: We work on any platform you already have: HackerOne, Bugcrowd, Intigriti, YesWeHack or in-house channels. There's no need to switch platform. If you don't have one yet, we recommend the best fit for your case and help with the initial setup. Q: What do researchers need to know about who manages the program? A: You decide the level of transparency. We can operate on your behalf without researchers knowing there's an external provider, or we can mention that triage is handled by a specialized external security team. Both models are valid and common in the market. Q: How much does it cost to manage a bug bounty program externally? A: The cost depends on the monthly report volume, the SLA level and whether the service includes the initial program design. It's significantly lower than hiring an in-house triage analyst, and more flexible because the cost scales with the program's actual volume. Q: Can you manage private bug bounty programs? A: Yes. We manage both public programs (open to any researcher) and private ones (invite-only researchers). Private programs have different dynamics and require more active researcher community management, which we also cover. --- ## Vulnerability Disclosure Program: Design and External Management URL: https://www.quantumsec.es/en/bug-bounty/vulnerability-disclosure-program/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We design and implement your Vulnerability Disclosure Program and manage every incoming report. NIS2 and CRA compliance included. Live within weeks. A VDP is no longer optional: NIS2 and the Cyber Resilience Act require it. We help you get it up and running within weeks and manage every report that comes in, without needing a dedicated in-house team. An unmanaged disclosure channel is worse than not having one Publishing a responsible disclosure policy is only the first step. If incoming reports go unanswered for days, if researchers get no acknowledgment, if critical vulnerabilities get lost in an email inbox with no process... the reputational damage can outweigh the benefit of having a VDP at all. Companies that publish a disclosure channel take on a responsibility: to respond seriously and quickly to those who help them become more secure. We take on that responsibility for you. Frequently asked questions answered by the QuantumSec team: Q: Does NIS2 require me to have a VDP? A: NIS2 requires essential and important entities to have mechanisms to manage and report vulnerabilities, which includes having a vulnerability notification channel. Although the directive doesn't explicitly use the term VDP, the most common way to meet this requirement is to implement a Vulnerability Disclosure Program. We help you assess exactly what your company needs. Q: How long does it take for the VDP to be operational? A: Standard design and implementation of a VDP takes between 2 and 4 weeks: policy drafting, channel setup, testing and publication. If you need to accelerate it for an audit or compliance process, we can adjust the timeline. Q: What happens if we receive a critical vulnerability? A: Critical reports have an immediate escalation channel. As soon as we identify a report with potential critical impact, we escalate it directly to the client's security lead —regardless of the time of day— and coordinate the emergency response. The SLA for critical reports is 4 business hours. Q: Can you help coordinate the public disclosure of a vulnerability? A: Yes. If a researcher wants to publish their finding (CVE, blog post, conference talk), we manage the coordinated vulnerability disclosure (CVD) process following the ISO 29147 standard: we agree the disclosure timeline, coordinate with the researcher and prepare the necessary communications. --- ## Technical Validation and Prioritization of Reported Vulnerabilities URL: https://www.quantumsec.es/en/bug-bounty/vulnerability-validation/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We validate every vulnerability report with real offensive judgment. We reproduce the attack, confirm real impact and prioritize with CVSS 4.0 and EPSS. Zero time-wasting false positives. Not all vulnerability reports are equal. We validate with the same offensive mindset we use for penetration testing. Your team only gets what really matters, with all the information needed to act. A report without technical validation is just a hypothesis When a researcher reports a vulnerability, it can be a real critical finding or it can be a scope misunderstanding, a false positive or a theoretical vulnerability with no practical impact. Without a real technical validation process —which means reproducing the attack, verifying the impact and putting the risk in the context of your specific environment— your development team can't prioritize correctly. Worse: if they treat every report as urgent, they grind to a halt. If they ignore reports out of distrust, real vulnerabilities go unaddressed. Technical validation is the filter that makes everything else work. Frequently asked questions answered by the QuantumSec team: Q: Can you validate vulnerabilities without access to production? A: It depends on the vulnerability type. For many findings (XSS, CSRF, business logic, authorization flaws) we can validate with test credentials in a staging environment. For others that require observing production behavior, we work with the client to define a safe validation window and procedure. Q: How long does report validation take? A: Standard SLA is 24 business hours for high and critical severity reports, and 48-72 hours for medium and low severity. For high-volume programs, we agree validation cycles that adapt to the report flow. Q: What's the difference between CVSS 4.0 and previous versions? A: CVSS 4.0, published by FIRST in 2023, introduces a more granular metric taxonomy, improves impact assessment in OT/ICS environments and adds supplemental metrics. We use CVSS 4.0 as our baseline standard because it delivers a more precise score applicable to modern environments. If your program still uses CVSS 3.1, we can work with both versions in parallel. --- ## CMS penetration testing and security audit URL: https://www.quantumsec.es/en/pentesting/cms/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CMS penetration testing for WordPress, Drupal, Magento, PrestaShop and Joomla. Real offensive analysis, not automated scanning. Technical report and remediation plan. WordPress, Drupal, Magento, PrestaShop and Joomla have specific attack surfaces that generic tests and automated scanners do not cover. Vulnerable plugins, third-party extensions, exposed panels, abusable APIs and default configurations are real vectors an attacker will exploit before your team detects them. Why is web maintenance not the same as security? Updating WordPress or installing a security plugin is not the same as a real security assessment. Most CMS compromises do not happen for lack of updates: they happen because of poorly audited third-party extensions, incorrect server configurations, excessive user roles, exposed API endpoints or vulnerable application logic that no automated scanner detects. A CMS penetration test analyses how the system actually behaves under attack, not just the list of installed versions. Frequently asked questions answered by the QuantumSec team: Q: How does a CMS security audit differ from web maintenance? A: Web maintenance updates versions and takes backups. A CMS security audit simulates real attacks to find vulnerabilities that updates do not fix: vulnerable application logic, misconfigurations, extensions with insecure code or CMS-specific vectors that automated scanners do not detect. Q: Does the pentest disrupt the website's operation? A: We coordinate the scope to minimise operational impact. In most cases we work on a staging environment or during low-traffic windows. If production is unavoidable, we agree to run the most invasive tests outside business hours. Q: Does the CMS pentest also cover hosting and the CDN? A: Yes, within the agreed scope. We review the web server configuration, HTTP security headers, access to sensitive paths, file permissions and, where applicable, the WAF and CDN configuration (Cloudflare, Fastly). The hosting environment is part of the CMS attack surface. Q: Do you also do the remediation or just the report? A: We deliver the analysis, the evidence and the remediation plan. The fixes are carried out by your team or your web agency following our instructions. We always include support during the remediation phase and an optional re-test to verify that the findings have been resolved. Q: Is the report valid for compliance audits (ENS, ISO 27001, PCI-DSS)? A: Yes. The report follows recognised methodologies (OWASP, PTES) and is valid as pentesting evidence for ISO 27001 certification, ENS compliance or PCI-DSS processes. We indicate the coverage against the applicable security controls. --- ## Google Workspace security audit URL: https://www.quantumsec.es/en/audits/google-workspace/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We audit your Google Workspace like a real attacker: super admins, OAuth apps, Drive, Gmail and domain-wide delegation. Technical and executive report. Free consultation. Your company's email, documents, meetings and identities all live inside Google Workspace. A single misconfiguration —a super admin without 2FA, an OAuth app with excessive permissions or a forgotten domain-wide delegation— can give an attacker access to the entire business. We review your Workspace with the same mindset as someone trying to compromise it. Is your Google Workspace secure, or does it just look secure? Google secures its infrastructure, but your tenant configuration is your responsibility. Most Google Workspace compromises don't exploit a flaw in Google: they exploit default settings, excessive permissions, uncontrolled third-party apps, malicious forwarding rules and poorly protected admin accounts. A real audit doesn't just review a checklist of settings: it simulates what an attacker would do with a compromised account and shows you how far they could get inside your organization. Frequently asked questions answered by the QuantumSec team: Q: Do you need admin access to our Workspace? A: For the configuration review, a read-only admin role or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA). Q: Does the audit disrupt employees' work? A: No. Most of it is configuration and attack-surface analysis, which doesn't affect users. The few active tests are agreed and run in a controlled way so they don't impact operations. Q: How is this different from the recommendations Google already shows? A: Google's panels flag recommended settings, but they don't think like an attacker or chain vectors together. We look for the real compromise path: a forgotten OAuth app, a dangerous domain-wide delegation or a forwarding rule that keeps access even after a password change. Q: Do you also audit Microsoft 365? A: Yes. We apply the same offensive methodology to Microsoft 365 (Entra ID, Exchange Online, SharePoint). If you use both, we audit both environments and their integration points. Q: Is the report valid for compliance (ENS, ISO 27001, NIS2)? A: Yes. The report documents the security posture of your email and collaboration environment against recognized frameworks (CIS Benchmark) and is valid as evidence for ENS adequacy, ISO 27001 certification or NIS2 compliance. --- ## Microsoft 365 security audit URL: https://www.quantumsec.es/en/audits/microsoft-365/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We audit your Microsoft 365 like a real attacker: Entra ID, Exchange Online, SharePoint, OAuth apps and MFA. Technical and executive report. Free consultation. Your company's email, documents and identities live in Microsoft 365 and Entra ID. A configuration error —a global admin without strong MFA, an app with illicit consent or a poorly defined conditional access policy— can open the door to the entire business. We review your tenant with the mindset of someone trying to compromise it. Is your Microsoft 365 secure, or does it just look secure? Microsoft secures its platform, but your tenant configuration is your responsibility. Most Microsoft 365 compromises don't exploit a flaw in Microsoft: they exploit poorly deployed MFA, conditional access policies with gaps, OAuth apps with illicit consent, Exchange forwarding rules and unprotected global admins. A real audit doesn't just look at the Secure Score: it simulates what an attacker would do with a compromised account and shows you how far they could get. Frequently asked questions answered by the QuantumSec team: Q: Do you need admin access to our tenant? A: For the configuration review, a read-only role (Global Reader) or a delegated role with audit permissions is enough. For offensive testing we agree the scope in advance and, if needed, a test account. Everything is done with explicit authorization and under a confidentiality agreement (NDA). Q: Does the audit disrupt employees' work? A: No. Most of it is configuration and attack-surface analysis, which doesn't affect users. The few active tests are agreed and run in a controlled way. Q: How is this different from Microsoft's Secure Score? A: Secure Score flags recommended settings, but it doesn't think like an attacker or chain vectors together. We look for the real compromise path: an app with illicit consent, a gap in conditional access or a forwarding rule that keeps access even after a password change. Q: Do you also audit Google Workspace? A: Yes. We apply the same offensive methodology to Google Workspace. If you use both, we audit both environments and their integration points. Q: Is the report valid for compliance (ENS, ISO 27001, NIS2)? A: Yes. The report documents the environment's security posture against recognized frameworks (CIS Benchmark) and is valid as evidence for ENS adequacy, ISO 27001 certification or NIS2 compliance. --- ## Red Team: real adversary simulation to measure your detection capability URL: https://www.quantumsec.es/en/red-team/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Covert Red Team exercise: we simulate a real, targeted attack — technical, social and physical — to measure whether your security team detects and responds in time. A pentest finds vulnerabilities within a scoped, known target. A Red Team simulates what a real attacker would do with a concrete objective — reaching your ERP, exfiltrating customer data, compromising the domain — combining technical, social and, where applicable, physical vectors, without your security team knowing it's happening. The question it answers isn't "what vulnerabilities do you have?" — it's "would you have caught us?" Why isn't a pentest enough to know if you're ready? A technical pentest is essential, but it answers a different question: within a defined scope and a fixed timeframe, what vulnerabilities exist? The defensive team usually knows it's happening, which changes their behavior. A real attacker doesn't warn you, doesn't limit itself to one vector, and doesn't stop at the first control it hits: it combines targeted phishing, technical exploitation, lateral movement and, if needed, in-person social engineering, over weeks, looking for the quietest path to a concrete business objective. A Red Team is the only way to check whether your SOC, your alerts and your response team actually work when no one warns them in advance. Frequently asked questions answered by the QuantumSec team: Q: How is this exactly different from an Active Directory pentest? A: An Active Directory pentest analyzes the AD environment in depth within a known technical scope, looking for the maximum number of configuration and privilege escalation flaws. A Red Team starts from outside the perimeter, with a concrete business objective, without the defensive team knowing, and only touches AD if that's the most realistic path to the objective — it's a test of the whole organization, not of the AD environment itself. Q: Is this the same as the TLPT DORA requires? A: TLPT is a Red Team run under the TIBER-EU regulatory framework, with specifically accredited providers and coordination with the supervisor, mandatory for financial entities designated as critical. Our standard Red Team follows the same methodological logic and is the ideal preparation before a formal TLPT; for the regulatory TLPT itself, we guide you through the required accreditation process. Q: What happens if the defensive team catches us on day one? A: That's a valid and valuable outcome — it means your defenses work for that vector. In that case, with your consent, we can adjust the exercise to keep testing other vectors or more advanced evasion techniques, maximizing what you learn from the exercise. Q: Does it include in-person social engineering and physical access? A: Only if explicitly agreed in scope. It's not a default component: some organizations include it (tailgating, USB devices, impersonating technical staff) and others prefer to limit it to digital vectors. It's defined during the rules-of-engagement phase. Q: How is this different from a phishing simulation (social engineering)? A: A phishing simulation tests a single vector — the human one — in isolation, with a scope known in advance by whoever commissions it. A Red Team may use phishing as one of several entry vectors, but only if it serves the defined business objective, combined with technical exploitation and lateral movement; it isn't an end in itself and isn't measured independently. --- ## SAP security audit URL: https://www.quantumsec.es/en/audits/sap/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We audit SAP like a real attacker: authorizations & SoD, RFC/Gateway, ABAP code, patch gaps — full security checklist. Technical + executive report. Free quote. SAP holds your company's most critical financial, procurement and HR processes. A poorly designed role, an exposed RFC interface or an unapplied security note can give an attacker —internal or external— control over transactions that move real money. We audit your SAP environment with the same mindset as someone trying to compromise it, not just by checking a compliance checklist. Is your SAP secure, or does it just pass the internal audit checklist? Most SAP security reviews stay in compliance territory: confirming a segregation of duties (SoD) matrix is documented, that a password policy exists, or that the system is under maintenance. That doesn't confirm the environment can withstand a real attack. SAP compromises typically exploit specific combinations: a service account with its default password, an RFC interface reachable without access control, a custom ABAP program with an injection flaw, or SAP Security Notes published months ago and never applied. An offensive audit confirms which of all that is actually exploitable in your specific instance. Frequently asked questions answered by the QuantumSec team: Q: Is this the same as a segregation of duties (SoD) review for internal audit? A: No. An SoD review for internal audit or compliance confirms a documented matrix exists and that, on paper, no prohibited combinations are assigned. Our audit goes further: it confirms which of that is actually exploitable, adds analysis of the RFC/Gateway interface, custom ABAP code and patch status, and simulates the real impact of an attacker, not just the documented theoretical risk. Q: Do you need access to the production system? A: For the configuration and authorization review, a read-only user or access to a pre-production system with the same configuration is enough. For active offensive testing we agree the scope, environment (usually pre-production) and, if needed, a test account in advance. Everything is done with explicit authorization and under a confidentiality agreement (NDA). Q: Do you cover both on-premise SAP and S/4HANA Cloud? A: Yes, adapting the scope: on-premise and S/4HANA Private Cloud analysis includes the infrastructure layer, the Gateway and the underlying operating system; S/4HANA Public Cloud scope focuses on authorizations, integrations and configuration, since SAP directly manages part of the infrastructure. Q: Does the audit disrupt ERP operations? A: No. Most of the work is configuration, role and code analysis, which doesn't affect users. Active tests are agreed in advance, preferably run in a pre-production environment, and if they must touch production, within a window agreed with the Basis team. Q: Is the report valid for regulatory compliance (NIS2, ENS, ISO 27001)? A: Yes. The report documents the security posture of the SAP environment with evidence and is valid as part of the documentation for NIS2 adequacy, ISO 27001 certification or adequacy to the Spanish National Security Framework (ENS) for the systems within its scope. --- ## AI Act Compliance Consulting: Adapting to the EU AI Regulation URL: https://www.quantumsec.es/en/compliance/ai-act/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. AI Act compliance for companies developing or using AI in the EU. Avoid fines of up to €35M or 7% of global turnover. Gap analysis and action plan. Regulation (EU) 2024/1689 (the AI Act) is the world's first comprehensive AI law. It classifies AI systems by risk level and imposes concrete obligations on anyone who develops, distributes or simply uses AI in their business — yes, SMBs and freelancers too. Does your business use or develop AI systems in the EU? If your business uses AI for hiring, credit scoring, facial recognition surveillance, customer service chatbots, or any system that makes automated decisions about people, the AI Act likely affects you, regardless of your size. The obligation isn't limited to whoever builds the AI system: it also applies to whoever deploys it within their organization. Many SMBs and freelancers using third-party AI tools (HR, marketing, customer service) wrongly assume the responsibility lies only with the provider. Frequently asked questions answered by the QuantumSec team: Q: Who does the AI Act apply to? A: It applies to providers who develop AI systems, to deployers who use them within their organization, and to importers and distributors, inside and outside the EU if the system is used in European territory. It applies regardless of company size. Q: I'm a freelancer using third-party AI tools, do I have obligations? A: Yes, as a deployer you have obligations even if you didn't build the system: informing affected people where required, human oversight for high-risk systems, and not using prohibited AI practices such as social scoring. Q: How much time do I have to comply? A: The timeline is progressive: prohibited AI practices have already been illegal since February 2025; governance and general-purpose model obligations apply from August 2025; Annex III high-risk system obligations apply from August 2026. Q: What penalties does the AI Act impose? A: Up to €35M or 7% of global annual turnover for prohibited AI practices; up to €15M or 3% for other regulatory breaches; up to €7.5M or 1% for providing incorrect information to authorities. Q: Does the AI Act replace GDPR? A: No, they're complementary. The AI Act specifically regulates AI systems and their risk level; GDPR still applies to any personal data processing that system performs. --- ## Microsoft Exchange Online security audit URL: https://www.quantumsec.es/en/audits/microsoft-exchange/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. We audit your Microsoft Exchange Online like a real attacker: forwarding rules, delegated permissions, connectors and SPF/DKIM/DMARC. Free consultation. Corporate email is the favorite channel for CEO fraud, targeted phishing and persistence after an account compromise. We analyze your Exchange Online beyond MFA: forwarding rules, delegated permissions, connectors and domain authentication. Do you know what an attacker could do with access to a mailbox in your company? Most email security reviews stop at whether MFA is enabled. But CEO fraud, persistence after an account compromise and much of the lateral movement that follows go through hidden forwarding rules, unreviewed delegated permissions, misconfigured connectors and overly permissive accepted domains. A real Exchange Online audit confirms what an attacker could actually do with access to a mailbox, not just whether the right checkbox is ticked. Frequently asked questions answered by the QuantumSec team: Q: Does this replace the general Microsoft 365 audit? A: Not necessarily. If email is your most critical system or you've already had an email-related incident, it makes sense as a standalone engagement. If you want a full tenant review (Entra ID, SharePoint, Teams, OAuth apps), the Microsoft 365 audit is the better fit. Q: Do you need global admin access? A: No. A read-only role over Exchange Online (for example, Exchange Recipient Administrator) is enough for most of the analysis. Q: Does it disrupt mail flow? A: No. The analysis covers configuration and permissions, and doesn't affect production mail flow. Q: Can you detect an ongoing compromise? A: Analyzing forwarding rules and delegated permissions can reveal the persistence of an attacker who already compromised an account, though this isn't an incident response service. Q: Is the report valid for regulatory compliance? A: Yes. The report is valid as technical control evidence for corporate email security under NIS2, ENS or ISO 27001. --- ## Safe AI use: govern what your team is already doing URL: https://www.quantumsec.es/en/solutions/secure-ai-use/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. AI usage policy, shadow AI control and employee training to use ChatGPT and Copilot without leaking company data. Assessment and rollout plan in 3 weeks. Your team already uses AI. The question is not whether to allow it, but with which tools, which data and which oversight. We bring order: we discover what is actually in use, define the rules and train the people who have to apply them. The problem is not AI: it is that nobody knows what is leaving the company AI adoption in companies has not followed the usual path of purchase, evaluation and rollout: it came in from the bottom, person by person, from personal accounts and without going through IT. The result is that almost no organisation can answer three basic questions today: which AI tools are in use, what information has been pasted into them, and who reviews their output before it reaches a client. Banning it does not work —it pushes usage to personal phones, where there is no visibility at all— and doing nothing does not either: every week more information leaves with no record. What works is governing it: discover the real usage, provide convenient approved alternatives, and put in writing which data never leaves. Frequently asked questions answered by the QuantumSec team: Q: Does this make me compliant with the AI Act? A: It is its operational prerequisite, not full legal compliance. Without knowing which AI systems your organisation uses and for what, you cannot classify them by risk level or demonstrate human oversight to anyone. This service gives you that inventory and that control. Formal compliance with the regulation —classification, provider or deployer role, technical documentation— is our AI Act consulting service, and it builds on the work done here. Q: How long does it take and what does it ask of my team? A: The assessment and the policy take around three weeks for a mid-sized organisation. The load on your team is concentrated in discovery: read-only access to review connected applications, and a few minutes from each person for the anonymous survey. Training runs as sessions of 45 to 90 minutes depending on the audience. Q: Are you going to ban the tools we already use? A: That is not the goal. In most cases the outcome is the opposite: the tools already in use get formally approved, their retention and training settings get corrected, and only the type of data that must not go in is restricted. Banning without an alternative pushes usage to personal phones and makes visibility worse. Q: Does it work for a small company with no IT team? A: Yes, and it is usually faster. In a small organisation the inventory closes within days and the policy fits on one page. What does not change with size is the risk: pasting a client contract into a public chatbot has the same impact in an eight-person company as in an eight-hundred-person one. Q: How is this different from auditing the security of our own AI system? A: They are different things. This service governs your team's use of third-party AI tools. If what you have is your own product with a model, a customer-facing chatbot or a RAG pipeline, what you need is AI penetration testing, which attacks that system to find its vulnerabilities. Many companies end up needing both, but they solve different problems. --- ## Cybersecurity training delivered by the people running the attacks URL: https://www.quantumsec.es/en/cybersecurity-training/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity training for companies: employee awareness, secure coding and NIS2 and ENS readiness. On-site or online sessions, tailored to your team. Most cybersecurity training is delivered by people who have never exploited a vulnerability. We teach what we find in audits: the real mistakes teams make, explained by the team that exploits them. Why generic cybersecurity training changes nothing The usual format —an annual video, a ten-question quiz and a certificate— ticks the box and changes no behaviour. It fails for three reasons: it uses generic examples nobody recognises as their own, it is delivered by someone who has never seen a real incident, and it addresses the whole workforce identically when a developer and someone in finance need different things. Training that works starts from concrete findings —ideally from an audit of your own organisation—, adapts to the audience profile, and repeats in short sessions instead of concentrating into one day a year. Frequently asked questions answered by the QuantumSec team: Q: How much does it cost to train a team in cybersecurity? A: It depends on format and number of sessions. An employee awareness session, online and around 90 minutes, starts from a fixed price per group. A secure coding programme with several sessions and hands-on work over your own code is quoted per project. We give a fixed price before starting, and the first scoping call is free. Q: Do you run phishing simulations as part of the training? A: Phishing simulation is a separate service: it is an offensive exercise that measures real behaviour, not a class. The two complement each other well —the usual sequence is to simulate first to find where the problem is, then train on the results— but they are contracted separately. If what you want is to measure, start with phishing simulations. Q: Does the training count as evidence for NIS2 or the ENS? A: Yes, and it is one of the common reasons for contracting it. NIS2 requires cybersecurity training for management bodies in article 20, and the ENS includes staff awareness and training among its measures. We deliver attendance records, contents covered and evaluation in the format an auditor expects, which is what actually gets asked for in the review. Q: Can you train our team on the use of artificial intelligence? A: Yes, but we cover that from the safe AI use service, because it is not just a session: it also involves discovering which tools are in use and drafting the policy the training explains. If you only need the training session, it can be contracted standalone within that service. Q: Is the training on-site or online? A: Both. Awareness sessions work well remotely and allow larger groups. Secure coding and technical team sessions perform better on-site, because they include hands-on work and discussion over code. We are based in Valencia and travel across Spain depending on the project. --- ## Cybersecurity audit for public tenders and administrative concessions in Spain URL: https://www.quantumsec.es/en/audits/public-tenders/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. One report covering a penetration test and GDPR compliance review for Spanish public tenders. No ENS or ISO 27001 required. Delivered in 5-10 business days A Spanish public tender requires a cybersecurity audit report as accreditation documentation and the clock is against you: we deliver a single report combining a penetration test and a GDPR/LOPDGDD compliance review, with no need to certify under ENS or ISO 27001. A tender requires an audit report and the clock isn't on your side It's increasingly common for a Spanish public tender or administrative concession to include, as an essential obligation, submitting a cybersecurity audit report covering the technical system being offered: a vulnerability analysis or penetration test, plus a data protection compliance review. Many of these tenders explicitly state that ENS or an INCIBE certificate isn't required, just a report issued by a qualified company or professional. The problem isn't finding who can do it, it's the calendar: if your bid is ranked best, the deadline to submit all accreditation documentation — including this audit — is usually only 5 to 10 business days. Agreeing on a provider and scope in advance, before the tender is resolved, is the only way to avoid risking the award over an administrative deadline. Frequently asked questions answered by the QuantumSec team: Q: Does this report work if the tender doesn't require ENS or ISO 27001? A: Yes, that's exactly the case this service covers. Many tenders ask for a cybersecurity audit report — pentest and GDPR review — without requiring formal certification. If your tender does require ENS or ISO 27001, you need that certification process: see our ENS audit and compliance service. Q: How long does the report take? A: Between 5 and 10 business days from kickoff, depending on the system's complexity and the number of integrations to review. If the tender deadline is shorter, tell us during the scoping call: we prioritize projects with a known hard deadline. Q: Can we start before the tender is resolved? A: Yes, and we recommend it. If you agree on a provider and scope in advance, the report can be ready before the award, and you only need to submit it once the remediation deadline arrives. Q: What if the tender requires ENS, ISO 27001 or a specific INCIBE certificate? A: This service doesn't replace formal certification. If the tender requires ENS or ISO 27001 you need that process with an accredited body; we can help with the prior compliance phase. See ENS compliance or ISO 27001 compliance depending on what your tender asks for. Q: Does it cover third-party systems like payment gateways or IoT devices connected to the platform? A: Yes, as long as they're part of the tendered system. We don't audit the payment provider's or device manufacturer's infrastructure directly, but we do review how it integrates with your platform and what data is exchanged. Q: Can this report be submitted by a company acting as the local partner of a foreign vendor? A: Yes. It's a common case: a foreign software company partners with a Spanish bidder, and the report is issued on the tendered technical system regardless of where the company that built it is based. --- ## GDPR and LOPDGDD compliance audit for businesses URL: https://www.quantumsec.es/en/audits/gdpr-compliance/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. GDPR/LOPDGDD compliance audit: data processing mapping, processor agreement review and technical safeguards. Evidence-ready for clients, tenders and insurers Having a privacy policy isn't the same as being able to prove your data processing complies with GDPR. We audit what data you process, on what legal basis, who you share it with, and whether your security measures meet what the regulation requires. Complying with GDPR on paper isn't the same as being able to prove it Most companies have a privacy policy on their website, drafted by a lawyer, and assume that's equivalent to GDPR compliance. In practice, it's common to find behind that document a non-existent or outdated Record of Processing Activities, unsigned data processing agreements with cloud providers or payment gateways, and Article 32 GDPR technical measures that nobody has actually verified. The problem shows up when someone asks for proof: an enterprise client, an insurer before underwriting a cyber policy, an investor in due diligence, or a public administration in a tender. A GDPR/LOPDGDD audit gives you the real picture of your compliance, not the one you assume you have. Frequently asked questions answered by the QuantumSec team: Q: Does this replace having a Data Protection Officer (DPO)? A: Not necessarily. If your company is required to have a DPO, this audit is complementary: it assesses the real state of compliance, and the DPO can use the report to prioritize their work. If you don't have a DPO, the audit gives you an independent snapshot without needing to hire that role permanently. Q: Do I need this audit if a lawyer already wrote my website's privacy policy? A: The privacy policy is the user-facing document; it doesn't evidence that internal processing, vendor contracts or technical measures are actually in order. It's common to find companies with a flawless privacy policy and no real Record of Processing Activities behind it. Q: How long does the process take? A: Between 2 and 4 weeks for a mid-sized company, depending on the number of processing activities and vendors to review. For a scope narrowed to a single product or system it can be faster. Q: Is the report valid for submission in a public tender? A: Yes, if the tender asks for a GDPR compliance review as part of the accreditation documentation. If it also requires a penetration test of the tendered system, see our public tenders audit service, which combines both in a single report on express timelines. Q: Do you also audit third-party vendor compliance (cloud, third-party SaaS)? A: We review the contracts and DPAs you have signed with them and how data flows to those vendors, but we don't audit the vendor's internal infrastructure unless it's part of a separately contracted pentest. Q: What happens if you find a serious non-compliance issue? A: We classify it by real risk, not just formal risk, and give you a prioritized roadmap. How and when to remediate it is your call; we can support the implementation if you need it. --- ## TLPT testing: the red team exercise DORA requires from financial entities URL: https://www.quantumsec.es/en/red-team/tlpt/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Threat-Led Penetration Testing (TLPT) under DORA and TIBER-EU for financial entities. Threat intelligence and red team led by an OSCP-certified team. TLPT is not a penetration test under another name. It is a threat intelligence-led red team exercise, run against production systems with the defensive team unaware. DORA requires it from financial entities designated by their competent authority, and the provider must demonstrate independence and technical capability. A conventional penetration test does not meet the TLPT requirement Many entities find out late that the security testing they already run does not satisfy the advanced testing DORA regulates in articles 26 and 27. TLPT has requirements a standard penetration test does not meet: it starts from a threat intelligence phase specific to the entity, runs against critical or important functions in production rather than staging, keeps the defensive team unaware except for a small control team, and requires providers who can evidence independence and technical capability. Submitting a standard penetration test report to the supervisor does not close the requirement, and the remediation window afterwards eats whatever margin was left. Frequently asked questions answered by the QuantumSec team: Q: What is the difference between TLPT and a penetration test A: A penetration test looks for vulnerabilities within a defined scope, usually with the defensive team informed. TLPT starts from real threat intelligence about your entity, runs in production against critical functions and keeps the defensive team unaware, because what it measures is detection and response capability, not just the presence of flaws. Q: Do all financial entities have to run TLPT A: No. DORA requires a resilience testing programme from every entity in scope, but advanced testing such as TLPT applies to those designated by their competent authority based on criteria including size, risk profile and relevance. If your entity is not designated, the rest of the testing programme still applies. Q: How often must a TLPT be repeated A: DORA sets a minimum frequency of three years for entities in scope, without prejudice to what the competent authority determines. It is worth planning ahead: the full cycle, including prior intelligence and subsequent remediation, runs over several months. Q: How does TLPT relate to TIBER-EU A: TIBER-EU is the European Central Bank framework for threat intelligence-led testing and is the methodological reference underpinning DORA TLPT. Documenting the exercise in line with TIBER-EU eases its submission to the supervisor. Q: Can the team that runs our regular audits also run the TLPT A: DORA requires providers of advanced testing to evidence independence, reputation and technical capability. It is worth reviewing potential conflicts with whoever already delivers recurring services to the entity before awarding the exercise. Q: How long does a full TLPT take A: It depends on scope, but a TLPT covering intelligence, execution, closing and remediation rarely takes less than three months. Entities that start with the deadline already close end up cutting scope, which is precisely what the supervisor examines. --- # Recursos (ES) --- ## ¿Qué es un pentesting y para qué sirve en una empresa? URL: https://www.quantumsec.es/recursos/que-es-un-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es el pentesting, para qué sirve, tipos y cuándo lo necesita tu empresa. Guía técnica y práctica escrita por expertos en hacking ético. El pentesting, abreviatura de penetration testing o prueba de penetración, es una evaluación de seguridad en la que un experto simula de forma controlada y autorizada un ataque real contra los sistemas de una organización. El objetivo no es causar daño, sino descubrir las vulnerabilidades antes de que lo haga un atacante con malas intenciones. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting puede tumbar mis sistemas? A: No si se hace con rigor profesional. El alcance se define previamente y se excluyen las acciones de alto riesgo para la disponibilidad. Si existe riesgo en algún test específico, se acuerda realizarlo en una ventana de mantenimiento. Q: ¿Cuánto tiempo tarda un pentesting? A: Entre 3 y 10 días hábiles para la fase técnica, según el alcance. La entrega del informe se produce 2-3 días después. --- ## Cómo adaptar tu empresa a la Directiva NIS2: guía práctica URL: https://www.quantumsec.es/recursos/como-adaptar-mi-empresa-a-nis2/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo adaptar tu empresa a NIS2: quién está obligado, medidas técnicas y organizativas, y cómo evitar sanciones de hasta el 2% de la facturación global. La Directiva NIS2 (Network and Information Security 2) entró en aplicación en octubre de 2024 y obliga a miles de empresas en España a implementar medidas técnicas y organizativas de ciberseguridad. Si no sabes si te afecta o por dónde empezar, esta guía te da las respuestas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿NIS2 ya es obligatoria en España aunque no se haya transpuesto la directiva? A: La directiva crea obligaciones desde su entrada en aplicación (octubre 2024), aunque la ley nacional específica puede estar pendiente. En todo caso, la tendencia regulatoria es clara y adecuarse ahora es la decisión prudente para evitar sanciones retroactivas. Q: ¿Las PYMEs están obligadas por NIS2? A: NIS2 se aplica principalmente a medianas y grandes empresas (más de 50 empleados o más de 10M€ de facturación). Sin embargo, microempresas y PYMEs que presten servicios en los sectores regulados pueden estar incluidas en casos específicos. --- ## Pentesting vs análisis de vulnerabilidades: diferencias clave y cuándo usar cada uno URL: https://www.quantumsec.es/recursos/diferencia-entre-pentesting-y-analisis-de-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diferencias entre pentesting y análisis de vulnerabilidades: coste, profundidad y metodología. Cuándo usar cada uno. Guía para dirección y seguridad. Son términos que muchas veces se usan indistintamente, pero no son lo mismo. Un análisis de vulnerabilidades automatizado y un pentesting manual tienen objetivos diferentes, producen resultados distintos y tienen costes y tiempos de ejecución muy dispares. Entender la diferencia te ayuda a invertir el presupuesto de seguridad donde realmente importa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un análisis de vulnerabilidades puede sustituir a un pentesting? A: No. Tiene un uso y profundidad distintos. El VA es útil para mantenimiento continuo, pero no confirma explotabilidad ni evalúa impacto real. Para decisiones de negocio críticas o cumplimiento normativo, el pentesting es necesario. Q: ¿El pentesting incluye siempre un análisis de vulnerabilidades previo? A: Habitualmente sí. El pentester suele comenzar con un escaneo automatizado para mapear la superficie y luego focaliza el análisis manual en los hallazgos más relevantes y en vectores de ataque que las herramientas no detectan. --- ## Fases de un pentesting web: de la recopilación de información al informe final URL: https://www.quantumsec.es/recursos/fases-de-un-pentesting-web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las 6 fases de un pentesting web: reconocimiento, enumeración, explotación y post-explotación. Metodología OWASP explicada paso a paso. Un pentesting web no es abrir Burp Suite y empezar a lanzar peticiones al azar. Es un proceso estructurado en fases bien definidas que sigue metodologías como OWASP Testing Guide, PTES o OSSTMM. Conocer estas fases te ayuda a entender qué está haciendo el auditor, qué esperar de cada etapa y cómo interpretar el informe final. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto dura un pentesting web completo? A: Entre 3 y 8 días hábiles para la fase técnica, según el tamaño y complejidad de la aplicación. El informe se entrega 2-3 días después de finalizar las pruebas. Q: ¿Necesito parar la aplicación durante el pentesting? A: No. El pentesting se realiza sobre la aplicación en producción (o en un entorno idéntico acordado) sin interrumpir el servicio. Las pruebas más agresivas pueden planificarse fuera de horas pico si lo prefieres. --- ## DORA vs NIS2: diferencias, solapamientos y qué hacer si te aplican las dos URL: https://www.quantumsec.es/recursos/dora-vs-nis2/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. DORA vs NIS2: sectores, obligaciones técnicas, plazos y sanciones. Cómo gestionar el cumplimiento conjunto. Especialmente útil para el sector financiero. Si tu empresa opera en el sector financiero en Europa, probablemente te aplican tanto DORA como NIS2 —y la pregunta más frecuente es: ¿son redundantes? ¿Tengo que hacer el trabajo dos veces? La respuesta corta es no, pero hay matices importantes que conviene entender antes de arrancar cualquier proyecto de cumplimiento. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿DORA sustituye a NIS2 para el sector financiero? A: No exactamente. DORA es lex specialis respecto a NIS2 para las entidades financieras que entran en su ámbito: cuando haya solapamiento, prevalece DORA. Pero NIS2 puede aplicar a aspectos o entidades no cubiertos por DORA dentro del sector financiero. Q: ¿Los proveedores TIC del sector financiero están obligados por DORA? A: Los proveedores TIC críticos designados por las autoridades supervisoras europeas (ESAs) están sujetos a supervisión directa bajo DORA. Todos los demás proveedores TIC de entidades financieras están cubiertos indirectamente a través de los requisitos de gestión de terceros que DORA impone a sus clientes financieros. --- ## Tipos de phishing corporativo: cómo reconocerlos y proteger a tu empresa URL: https://www.quantumsec.es/recursos/tipos-de-phishing-corporativo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Tipos de phishing corporativo: spear phishing, whaling, BEC, smishing y vishing. Señales de alerta y cómo proteger a tu equipo frente a ellos. El phishing sigue siendo el vector de entrada número uno en las brechas de seguridad corporativas. No porque los ataques sean muy sofisticados, sino porque se adaptan constantemente al contexto, explotan la urgencia y se aprovechan de la confianza inherente al correo electrónico y las comunicaciones digitales. Conocer los tipos de phishing que existen es el primer paso para entrenar a tu equipo en detectarlos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Una simulación de phishing interno afecta a la confianza del equipo? A: Si se gestiona bien, no. La clave es comunicar a la dirección antes, enfocar los resultados de forma formativa (no punitiva) y hacer la sesión de concienciación post-simulación. La mayoría de empleados lo valoran positivamente cuando entienden el objetivo. Q: ¿DMARC protege completamente frente al phishing? A: DMARC protege frente a la suplantación exacta de tu dominio, pero no frente a dominios similares (lookalike domains), cuentas comprometidas o phishing de proveedores. Es una capa importante pero no suficiente por sí sola. --- ## Cómo proteger Active Directory del ransomware y los ataques de movimiento lateral URL: https://www.quantumsec.es/recursos/como-proteger-active-directory-de-ransomware/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo proteger Active Directory frente a ransomware. Hardening de AD, detección de Kerberoasting, Pass-the-Hash y movimiento lateral. Active Directory (AD) es el corazón de la infraestructura de identidades en la mayoría de empresas con entornos Windows. También es el objetivo número uno de los grupos de ransomware: comprometer el Domain Controller equivale a comprometer toda la organización. Esta guía técnica explica por qué AD es tan atacado y qué configuraciones críticas debes revisar. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un pentesting de Active Directory puede realizarse sin interrumpir la operativa? A: Sí. El pentesting de AD se realiza con técnicas de bajo impacto en la fase de reconocimiento y explotación. Las pruebas más agresivas (como DCSync o modificación de GPOs) se coordinan previamente y se realizan en ventanas acordadas. Q: ¿Qué herramientas usa un pentester para auditar Active Directory? A: Las más usadas en un pentest profesional: BloodHound/SharpHound para mapeo de relaciones y rutas de ataque, Impacket para técnicas de autenticación Kerberos, PowerView/PowerSploit para enumeración de AD, Mimikatz (en entorno controlado) para validar extracción de credenciales, y CrackMapExec para validación de movimiento lateral. --- ## 10 medidas de ciberseguridad imprescindibles para tu PYME URL: https://www.quantumsec.es/recursos/seguridad-para-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las 10 medidas de ciberseguridad más efectivas para proteger tu PYME sin un gran presupuesto: MFA, backups, parches, phishing, contraseñas y más. El 43% de los ciberataques van dirigidos a pequeñas y medianas empresas. No por mala suerte: los atacantes eligen las PYMEs deliberadamente porque saben que suelen tener menos defensas. La buena noticia es que no necesitas el presupuesto de una gran corporación para tener un nivel de protección adecuado. Esta guía te explica, en lenguaje directo, las medidas que más impacto tienen por el menor coste. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesito un experto en seguridad o puedo gestionarlo internamente? A: Las medidas básicas puedes implementarlas con tu equipo actual. Para evaluaciones técnicas (análisis de vulnerabilidades, pentesting) o cumplimiento normativo, necesitas apoyo externo. Un buen punto de partida es una consulta gratuita con un especialista para entender tu nivel de exposición real. Q: ¿El seguro de ciberriesgo me protege si sufro un ataque? A: Un seguro de ciberriesgo cubre parte de los costes de un incidente, pero cada vez más aseguradoras exigen controles mínimos de seguridad para mantener la cobertura. Sin medidas básicas implementadas, el seguro puede denegar la reclamación. --- ## Ciberseguridad para startups: lo que necesitas saber antes de escalar URL: https://www.quantumsec.es/recursos/ciberseguridad-para-startups/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía de ciberseguridad para startups: primer pentesting, due diligence de inversores y controles necesarios para clientes enterprise. Fundar una startup es suficientemente difícil sin tener que pensar en seguridad. Pero ignorarla tiene consecuencias muy concretas: un breach puede hundirte antes de la Serie A, un cliente enterprise puede bloquearte el contrato más importante, o un due diligence puede revelar deuda de seguridad que hace caer la valoración. Esta guía te explica, sin rodeos, lo que una startup tecnológica necesita saber sobre seguridad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta el primer pentesting para una startup? A: Para una aplicación web de tamaño medio (MVP SaaS), un pentesting de caja gris incluyendo la API suele estar entre 2.000 y 5.000 €. Existen planes específicos para startups con precios más accesibles. El ROI es inmediato si desbloquea un contrato enterprise o una ronda de inversión. Q: ¿Necesito ISO 27001 para vender a grandes empresas? A: ISO 27001 es la certificación más reconocida, pero no siempre es necesaria. Muchos clientes enterprise aceptan un informe de pentesting + políticas de seguridad documentadas como evidencia suficiente. ISO 27001 suele ser un requisito formal en sectores muy regulados (banca, salud pública) o para contratos de tamaño significativo. --- ## ¿Qué riesgos de seguridad tiene el vibe coding? URL: https://www.quantumsec.es/recursos/que-riesgos-tiene-el-vibe-coding/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El vibe coding introduce vulnerabilidades graves. Analizamos los riesgos reales del código generado por LLMs y cómo mitigarlos en tu empresa. El "vibe coding" es un término acuñado por Andrej Karpathy en 2025 para describir una forma de programar en la que el desarrollador describe lo que quiere en lenguaje natural, acepta el código que genera la IA sin revisarlo en profundidad, y confía en que funcione. Es increíblemente eficaz para prototipar rápido. Y es una fuente potencial de vulnerabilidades de seguridad graves cuando ese código llega a producción. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es el vibe coding inherentemente inseguro? A: No inherentemente, pero sí introduce riesgos específicos que requieren contramedidas específicas. El código generado por IA puede ser perfectamente seguro si es revisado por alguien que sabe qué buscar, si se testea con herramientas de seguridad y si se audita antes de manejar datos sensibles. Q: ¿Qué herramientas de IA generan código más seguro? A: Los modelos más recientes (GPT-4o, Claude Sonnet, Gemini 1.5 Pro) tienden a generar código más seguro que modelos anteriores porque han sido específicamente ajustados para evitar patrones inseguros comunes. Sin embargo, ningún modelo garantiza código seguro por defecto. La herramienta importa menos que el proceso de revisión. --- ## Cómo auditar la seguridad del código generado por IA URL: https://www.quantumsec.es/recursos/como-auditar-codigo-generado-por-ia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Metodología para auditar código generado por IA (Copilot, ChatGPT). SAST, revisión manual, vulnerabilidades frecuentes y checklist de seguridad. Tienes un repositorio lleno de código generado por GitHub Copilot, Cursor o ChatGPT. O quizás no sabes exactamente qué partes escribió un humano y qué partes generó la IA. En cualquier caso, necesitas saber si ese código es seguro antes de que llegue a usuarios reales. Esta guía te explica cómo hacerlo de forma sistemática. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo lleva una auditoría de código generado por IA? A: Depende del tamaño del repositorio y la complejidad de la aplicación. Para un MVP SaaS típico (20-50k líneas de código), una auditoría completa incluyendo análisis estático, revisión manual de áreas críticas y pruebas dinámicas básicas lleva entre 2 y 5 días de trabajo de un experto. Q: ¿Puedo auditar el código yo mismo o necesito contratar a alguien externo? A: Parte de la auditoría (SAST, revisión básica de patrones) puedes hacerla tú mismo con las herramientas adecuadas. Para una evaluación completa que incluya pruebas de explotación y análisis de lógica de negocio, necesitas una perspectiva externa: alguien que no conozca el código y que piense como un atacante. --- ## Checklist de seguridad antes de lanzar tu startup SaaS URL: https://www.quantumsec.es/recursos/checklist-de-seguridad-antes-de-lanzar-una-startup-saas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Checklist de seguridad antes de lanzar tu SaaS. Autenticación, cifrado, gestión de secretos, GDPR, logging y más. Descargable gratuitamente. Estás a punto de lanzar. El producto funciona, el equipo está emocionado, los primeros usuarios esperan. Antes de pulsar el botón, hay una serie de controles de seguridad que deberías haber revisado. No para ser perfecto (ningún sistema lo es), sino para no cometer los errores que hacen que un breach sea cuestión de días en lugar de años. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Tengo que implementar todo esto desde el día uno? A: Los puntos de la sección de autenticación, cifrado y gestión de secretos: sí, desde el día uno. Son el suelo mínimo de cualquier aplicación web. El resto puedes priorizarlo por el tipo de datos que manejas y el perfil de tus primeros usuarios. Pero ten en cuenta que es mucho más fácil y barato implementarlos desde el inicio que remediarlo después con usuarios reales. Q: ¿Este checklist es suficiente o necesito también un pentesting? A: El checklist te ayuda a no cometer los errores más obvios. El pentesting te dice si, aun siguiendo el checklist, hay vulnerabilidades en tu implementación específica que un atacante podría explotar. Ambos son complementarios: el checklist es tu línea base, el pentesting valida que la has alcanzado realmente. --- ## ¿Cuánto cuesta un pentesting en España? Guía de precios 2026 URL: https://www.quantumsec.es/recursos/cuanto-cuesta-un-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Precios reales de un pentesting en España 2026: coste por tipo (web, red, móvil, cloud), qué incluye un presupuesto serio y cómo evitar ofertas trampa. Una de las primeras preguntas que recibimos en QuantumSec es: ¿cuánto cuesta un pentesting? La respuesta honesta es que depende —del alcance, del tipo de sistema y del nivel de profundidad que necesitas. Esta guía desglosa los rangos de precio reales en España para cada tipo de pentesting, qué debería incluir siempre el presupuesto y cómo detectar propuestas que, en el mejor caso, no te aportarán ningún valor. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting más barato es siempre una mala opción? A: No necesariamente, pero sí deberías entender qué compras. Un proyecto más económico puede ser perfectamente válido si el alcance es limitado y bien definido. El problema está en cuando el precio bajo encubre un trabajo superficial vendido como pentesting completo. Compara siempre el alcance, la metodología y las credenciales del equipo, no solo el número. Q: ¿Cuánto cuesta un pentesting web en España? A: Para una aplicación web de tamaño estándar (10-30 endpoints, autenticación de usuario y panel de administración), el rango habitual en España está entre 2.500 € y 6.000 €. Si la aplicación es compleja (lógica de negocio extensa, múltiples roles, integraciones de terceros), el coste puede superar los 8.000 €. Q: ¿Cada cuánto tiempo debería hacer un pentesting? A: Como mínimo, una vez al año. Además, deberías hacer un pentesting siempre que realices cambios significativos en tu aplicación, cuando debas cumplir con NIS2, DORA o ISO 27001, o antes de lanzar un producto nuevo al mercado. Q: ¿Puedo pagar el pentesting en fases? A: Sí. Muchos proveedores ofrecen pagos en dos partes: un porcentaje a la firma del contrato y el resto a la entrega del informe. En proyectos grandes, también es posible acordar fases separadas (por ejemplo, fase web primero, fase de red después), lo que permite distribuir el coste en el ejercicio fiscal. --- ## Multas y sanciones de la directiva NIS2 en España (2026) URL: https://www.quantumsec.es/recursos/nis2-multas-y-sanciones/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Multas NIS2 en España: hasta 10M€ o el 2% de la facturación global. Quién puede ser sancionado, cómo se calcula el importe y qué reduce la exposición. La Directiva NIS2 no es un requisito burocrático más. Lleva aparejado un régimen sancionador que, en los casos más graves, puede suponer multas de hasta 10 millones de euros o el 2% de la facturación global anual. Esta guía explica quién puede ser sancionado, cómo se calculan las multas y qué pasos puedes dar ya mismo para reducir tu exposición. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuándo entra en vigor NIS2 en España? A: NIS2 debería haberse transpuesto al ordenamiento español antes del 17 de octubre de 2024. España está en proceso de transposición con retraso respecto al plazo europeo. Sin embargo, el retraso de transposición no elimina la exposición regulatoria: la Directiva tiene efecto directo en muchos de sus aspectos y las empresas deberían actuar ya. Q: ¿Qué pasa si mi empresa sufrió un ciberataque y no lo notifiqué en 72 horas? A: La falta de notificación en el plazo es una infracción específica bajo NIS2, sancionable con independencia del incidente en sí. La obligación es notificar a la autoridad competente en 72 horas (con alerta temprana en 24 horas) aunque el análisis completo no esté finalizado. El silencio regulatorio ante un incidente grave agrava la situación y puede derivar en sanciones adicionales. Q: ¿NIS2 afecta a las PYMEs? A: Las microempresas (<10 empleados, <2M€ facturación) y pequeñas empresas (<50 empleados, <10M€ facturación) están generalmente excluidas, salvo que operen en sectores esenciales o sean proveedores críticos de infraestructura. Si tu PYME es proveedor tecnológico de una empresa grande sujeta a NIS2, probablemente tendrás que demostrar tu cumplimiento como parte de la cadena de suministro. Q: ¿Hacer un pentesting ayuda al cumplimiento de NIS2? A: Sí. NIS2 exige "evaluaciones periódicas de la eficacia de las medidas de gestión de riesgos". Un pentesting independiente es la evidencia técnica más sólida que puedes presentar ante una auditoría regulatoria. Documentar que realizas tests de penetración periódicos y que actúas sobre los hallazgos demuestra un programa de seguridad activo, no solo una declaración de intenciones. --- ## Cómo elegir una empresa de ciberseguridad: 7 criterios que importan URL: https://www.quantumsec.es/recursos/como-elegir-empresa-de-ciberseguridad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. 7 criterios para elegir empresa de ciberseguridad: certificaciones, metodologías, transparencia, calidad del informe y soporte post-entrega. El mercado de la ciberseguridad en España ha crecido enormemente en los últimos años, y con él también han proliferado proveedores de calidad muy desigual. Elegir al equipo incorrecto no solo es un gasto de dinero: puede darte una falsa sensación de seguridad que es peor que no haber hecho nada. Esta guía te da los siete criterios que deberías evaluar antes de firmar cualquier contrato. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es mejor una empresa grande o una consultora especializada pequeña? A: Depende del proyecto. Las grandes consultoras tienen más recursos pero el trabajo lo suele hacer un equipo junior con supervisión senior. Una consultora especializada mediana suele ofrecer más acceso directo a pentesters senior y mayor personalización. Para PYMEs y empresas medianas, una consultora especializada suele aportar mejor relación calidad-precio. Q: ¿Necesito que la empresa de ciberseguridad esté en mi ciudad? A: Para la mayoría de los servicios (pentesting web, cloud, APIs, código fuente), la presencia física no es necesaria: el trabajo se realiza de forma remota. Para proyectos que impliquen acceso físico a instalaciones (Red Team físico, auditoría de redes inalámbricas en oficina), sí puede ser relevante la proximidad geográfica. Q: ¿Cuánto tiempo tarda un pentesting desde la firma del contrato? A: Un pentesting web estándar suele ejecutarse en 1-2 semanas desde el inicio. Proyectos más complejos (Red Team, pentesting de infraestructura grande) pueden extenderse 3-6 semanas. El informe suele entregarse 3-5 días hábiles después de finalizar la fase técnica. Los proveedores buenos tienen agenda: si tu proyecto es urgente, comunícalo desde el inicio. --- ## ¿Qué es el hacking ético y para qué sirve en tu empresa? URL: https://www.quantumsec.es/recursos/que-es-el-hacking-etico/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es el hacking ético, cómo funciona y por qué tu empresa necesita un test de intrusión profesional. Guía práctica 2026. El hacking ético —también llamado pentesting o test de intrusión— es el proceso de atacar de forma controlada y autorizada los sistemas de una organización para identificar sus vulnerabilidades antes de que lo haga un atacante real. No es un ejercicio teórico: es un ataque real, realizado por profesionales certificados, con reglas claras y el objetivo de proteger, no de dañar. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El hacking ético es legal en España? A: Sí, siempre que exista autorización escrita del propietario del sistema. El Código Penal español (artículo 197 bis) tipifica el acceso no autorizado a sistemas informáticos, pero el hacking ético se realiza con permiso explícito y contrato firmado. Toda empresa seria de hacking ético trabaja con contratos de prestación de servicios y NDAs que delimitan el alcance y protegen tanto al cliente como al proveedor. Q: ¿El hacking ético puede tumbar mis sistemas? A: El riesgo existe pero es muy bajo en proyectos bien planificados. Un pentester experimentado sabe cómo testear sin causar interrupciones de servicio. Antes del inicio, se define el horario en el que se realizarán las pruebas más intrusivas (normalmente fuera del horario de máxima carga) y se excluyen de forma explícita las acciones que podrían causar denegación de servicio. Q: ¿Cuánto tiempo tarda un hacking ético? A: Depende del alcance. Un pentesting web de una aplicación estándar suele ejecutarse en 5-10 días laborables. Un Red Team completo puede extenderse varias semanas. El informe se entrega normalmente 3-5 días después de finalizar la fase técnica. Q: ¿En qué se diferencia el hacking ético del análisis de vulnerabilidades? A: El análisis de vulnerabilidades (VA) usa herramientas automáticas para detectar vulnerabilidades conocidas —es rápido y bueno para tener una foto del estado. El hacking ético va más lejos: el pentester explota activamente las vulnerabilidades, las encadena para simular el recorrido de un atacante real y documenta el impacto real, no solo el potencial. El VA te dice "hay un agujero"; el hacking ético te dice "entré por ese agujero, llegué hasta aquí y esto es lo que podría haber robado". --- ## Qué es el Cyber Resilience Act: el reglamento europeo de ciberseguridad para productos digitales URL: https://www.quantumsec.es/recursos/que-es-el-cyber-resilience-act/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El Cyber Resilience Act (CRA): primer reglamento europeo de ciberseguridad para productos digitales. A quién afecta, qué exige y plazos clave hasta 2027. El Cyber Resilience Act (CRA) es el Reglamento (UE) 2024/2847, aprobado por el Parlamento Europeo y el Consejo de la UE en octubre de 2024. Es el primer marco legal de la Unión Europea que impone requisitos obligatorios de ciberseguridad a los productos con elementos digitales —hardware y software— antes de que puedan ponerse a la venta en el mercado europeo. Si tu empresa fabrica, importa o distribuye cualquier tipo de producto tecnológico en la UE, el CRA te afecta directamente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El CRA aplica solo a las empresas europeas o también a las que venden en la UE desde fuera? A: El CRA aplica a cualquier producto que se comercialice en el mercado europeo, independientemente de dónde esté la sede del fabricante. Un fabricante con sede en EEUU, India o Corea del Sur que venda sus productos en la UE debe cumplir el CRA. Si no tiene presencia en la UE, el importador que introduce el producto en el mercado europeo asume las obligaciones del fabricante. Q: ¿El CRA se aplica a las actualizaciones de software de productos ya en el mercado? A: Sí. El CRA aplica a las actualizaciones significativas de software que modifiquen de forma sustancial las características de seguridad del producto. Las actualizaciones de seguridad menores o los parches de vulnerabilidades no se consideran "puesta en el mercado" de un nuevo producto, pero el fabricante sigue obligado a facilitarlas de forma gratuita durante al menos cinco años. Q: ¿Qué es la declaración de conformidad UE bajo el CRA? A: Es el documento que el fabricante emite bajo su propia responsabilidad declarando que el producto cumple todos los requisitos esenciales de ciberseguridad del CRA. Debe incluir la identificación del producto y del fabricante, los requisitos que se consideran cumplidos, las normas armonizadas aplicadas, y una declaración de responsabilidad. Debe conservarse durante 10 años y estar disponible para las autoridades de vigilancia del mercado. --- ## Plazos del Cyber Resilience Act: qué debes tener listo y cuándo URL: https://www.quantumsec.es/recursos/plazos-cyber-resilience-act/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los plazos de reporte del CRA ya están vigentes: alerta en 24h, notificación en 72h e informe final en 14 días ante ENISA. Aplicación plena: 11-dic-2027. El Cyber Resilience Act no tiene una única fecha de entrada en vigor: tiene cuatro hitos escalonados entre 2024 y 2027, y tres de ellos ya han pasado. Desde el 11 de agosto de 2026 las obligaciones de reporte de vulnerabilidades a ENISA son exigibles, y desde el 11 de septiembre de 2026 los organismos notificados están operativos. Queda un único plazo por delante: el 11 de diciembre de 2027, cuando todo el reglamento pasa a ser sancionable. Si gestionas el desarrollo de productos de software o hardware con conectividad, este calendario te dice qué te obliga ya y qué tienes todavía por delante. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué pasa si no notifico una vulnerabilidad activamente explotada a ENISA en el plazo de 24 horas? A: El incumplimiento de la obligación de notificación a ENISA puede dar lugar a sanciones de hasta 10 millones de euros o el 2% de la facturación anual global. Las autoridades nacionales de vigilancia del mercado son las responsables de investigar e imponer estas sanciones. Q: ¿Los plazos del CRA aplican también a las actualizaciones de software? A: Las obligaciones de notificación de vulnerabilidades activamente explotadas aplican a todos los productos con elementos digitales en el mercado, independientemente de si han sido actualizados recientemente. Si una vulnerabilidad afecta a versiones de tu software que están en uso por clientes, la obligación de notificar a ENISA aplica desde agosto de 2026. --- ## CRA vs NIS2: diferencias, solapamientos y cómo gestionarlos juntos URL: https://www.quantumsec.es/recursos/cra-vs-nis2/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. CRA vs NIS2: qué regula cada norma, a quién aplica y dónde se solapan. Cómo reutilizar tu trabajo de NIS2 para cumplir también el CRA. Guía experta. Con la entrada en vigor del Cyber Resilience Act y la plena aplicación de NIS2 en 2024, muchas empresas se encuentran ante una pregunta lógica: ¿tengo que cumplir las dos? ¿Son redundantes? ¿Puedo reutilizar el trabajo que ya he hecho para NIS2 en mi adecuación al CRA? La respuesta a la primera pregunta es frecuentemente sí, sobre todo si fabricas software o hardware y además operas un servicio digital. La respuesta a la tercera es también sí, parcialmente. Esta guía te ayuda a entender los límites y las intersecciones. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Si cumplo NIS2, estoy automáticamente cumpliendo el CRA? A: No. NIS2 y el CRA regulan cosas distintas. NIS2 te obliga a gestionar la seguridad de tus operaciones; el CRA te obliga a garantizar la seguridad del producto que fabricas y vendes. Hay controles solapados que puedes reutilizar, pero son dos proyectos distintos con distinto objeto y diferentes mecanismos de evaluación. Q: ¿Los proveedores de SaaS están obligados por el CRA? A: Los servicios SaaS puros sin componentes instalables en el cliente están excluidos del CRA. Sin embargo, si tu SaaS incluye un agente de escritorio, un plugin que se instala en el navegador, un SDK que tus clientes integran en sus aplicaciones o cualquier componente que el usuario descarga y ejecuta en su entorno, ese componente sí entra en el ámbito del CRA. --- ## Requisitos del Cyber Resilience Act: qué exige el reglamento a los fabricantes de productos digitales URL: https://www.quantumsec.es/recursos/requisitos-cyber-resilience-act/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Requisitos del CRA: Anexo I, gestión de vulnerabilidades, marcado CE, evaluación de conformidad y documentación. Solicita una revisión de preparación. El Cyber Resilience Act impone dos tipos de obligaciones a los fabricantes de productos con elementos digitales: requisitos técnicos que el producto debe cumplir (Parte I del Anexo I) y requisitos de proceso para la gestión del ciclo de vida de seguridad del producto (Parte II del Anexo I). Además establece un procedimiento de evaluación de conformidad según la categoría del producto y documentación obligatoria que el fabricante debe generar y conservar. Esta guía desglosa todos estos requisitos con el nivel de detalle que necesita un equipo técnico o un responsable de producto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Los productos de código abierto están sujetos a los requisitos del CRA? A: El CRA excluye explícitamente el software de código abierto que se desarrolla de forma no comercial. Sin embargo, si una empresa comercializa un producto basado en software de código abierto (una distribución de Linux comercial, un router con firmware basado en OpenWRT, o un appliance de seguridad basado en Suricata), ese producto comercial sí está sujeto al CRA. El fabricante comercial es responsable del cumplimiento incluso si parte del código es open source. Q: ¿Qué es una norma armonizada del CRA y cuándo estarán disponibles? A: Las normas armonizadas son estándares técnicos europeos (ETSI, CEN-CENELEC) elaborados bajo mandato de la Comisión Europea que, cuando se aplican íntegramente, crean una presunción de conformidad con los requisitos del CRA. Las normas relevantes aún están en desarrollo y se esperan para 2026-2027. En su ausencia, los fabricantes pueden utilizar otras normas técnicas reconocidas como IEC 62443, ETSI EN 303 645, o NIST SP 800-218 para demostrar conformidad, aunque esto requiere un mapeo explícito entre los requisitos de la norma y los del CRA. --- ## Multas y sanciones del Cyber Resilience Act: cuánto puede costar el incumplimiento URL: https://www.quantumsec.es/recursos/multas-cyber-resilience-act/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Multas del CRA: qué infracciones las activan, quién puede ser sancionado (fabricante, importador, distribuidor) y cómo evitarlas. Hasta 15M€ en juego. El Cyber Resilience Act no es una recomendación ni un marco voluntario. Es un reglamento europeo con un régimen sancionador específico que puede alcanzar los 15 millones de euros o el 2,5% de la facturación global anual de la empresa, la cifra que sea mayor. Y no afecta únicamente a los fabricantes: importadores y distribuidores también pueden ser sancionados. Esta guía detalla los tres niveles de sanción, qué infracciones los activan, quién puede ser sancionado y cómo mitigar el riesgo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Las sanciones del CRA son acumulables con las de NIS2 o el RGPD? A: Sí. El CRA, NIS2 y el RGPD son normativas distintas con regímenes sancionadores independientes. Un incidente de seguridad que involucre una vulnerabilidad en un producto puede activar simultáneamente sanciones del CRA (por no haber notificado a ENISA en plazo), del RGPD (por la brecha de datos personales resultante) y de NIS2 (si el afectado es un operador de servicios esenciales). Q: ¿El CRA puede generar responsabilidad civil frente a los usuarios afectados? A: El CRA establece sanciones administrativas, no responsabilidad civil directa. Sin embargo, en muchos Estados miembros el incumplimiento de requisitos regulatorios de seguridad puede ser relevante en procedimientos de responsabilidad civil extracontractual: si un fabricante comercializa un producto sabiendo que no cumple los requisitos del CRA y ese producto es explotado causando daños a un usuario, la no conformidad con el CRA puede usarse como evidencia de negligencia. Q: ¿Puede una startup con pocos recursos asumir el coste de la adecuación al CRA? A: El CRA está diseñado para ser proporcionado al tamaño de la empresa: los procedimientos de evaluación de conformidad más exigentes (con organismos notificados) solo aplican a los productos de Clase II. Para la mayoría de los productos de empresas pequeñas la autoevaluación es suficiente y el coste principal es el del tiempo de los equipos técnicos para implementar los controles del Anexo I, más las herramientas de SBOM y análisis de vulnerabilidades de dependencias, que en muchos casos tienen planes gratuitos para proyectos pequeños. --- ## Vulnerabilidades más comunes en aplicaciones SaaS y cómo detectarlas URL: https://www.quantumsec.es/recursos/vulnerabilidades-comunes-en-saas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las 8 vulnerabilidades más comunes en SaaS: IDOR, broken multi-tenancy, JWT débil, mass assignment y webhooks inseguros. Guía técnica con ejemplos. Las aplicaciones SaaS tienen una superficie de ataque diferente a la de una aplicación web tradicional. Sirven a múltiples clientes sobre la misma infraestructura, exponen APIs complejas, gestionan suscripciones y permisos, e integran decenas de servicios externos. Estas características generan vulnerabilidades específicas que los scanners automáticos raramente detectan y que requieren pentesters que entiendan el modelo de negocio del producto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cómo sé si mi SaaS tiene vulnerabilidades de aislamiento multi-tenant? A: La forma más fiable es contratar un pentesting especializado en SaaS donde el equipo simule ser dos clientes diferentes e intente acceder a los datos de uno desde la cuenta del otro. Como medida previa, puedes revisar manualmente que todos tus endpoints validan que el recurso solicitado pertenece al tenant autenticado, no solo que el usuario está autenticado. Q: ¿Los scanners automáticos detectan estas vulnerabilidades? A: La mayoría no. Los scanners DAST detectan bien vulnerabilidades de inyección (SQLi, XSS) y configuraciones inseguras. Pero los fallos de lógica de negocio, el IDOR entre tenants, la manipulación de billing y los problemas de autorización a nivel de función requieren un pentester que entienda el producto y pruebe manualmente flujos específicos del negocio. Q: ¿Con qué frecuencia debería hacer un pentesting en mi SaaS? A: El estándar del sector para SaaS es al menos una vez al año, y adicionalmente ante cambios mayores en la arquitectura, autenticación o billing. Si estás en proceso de certificación SOC 2 Tipo II o ISO 27001, el pentesting anual suele ser un requisito explícito. --- ## SOC 2 Tipo II y pentesting: qué pruebas de seguridad necesita tu SaaS URL: https://www.quantumsec.es/recursos/soc2-y-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo el pentesting encaja en SOC 2 Tipo II. Qué controles exige, qué tipos de test aceptan los auditores y cómo prepararte. SOC 2 Tipo II es la certificación de seguridad de referencia para SaaS que vende a clientes enterprise, especialmente en mercados anglosajones. No exige explícitamente un pentesting, pero en la práctica los auditores revisan la evidencia de pruebas de seguridad periódicas y los grandes clientes enterprise que requieren el informe SOC 2 preguntan específicamente por el pentesting. Entender qué piden exactamente te ahorra tiempo y dinero. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es obligatorio el pentesting para obtener SOC 2 Tipo II? A: No es técnicamente obligatorio por el estándar, pero en la práctica es muy difícil superar una auditoría SOC 2 Tipo II sin evidencia de pruebas de penetración. Los auditores de firmas como A-LIGN, Schellman o Prescient revisan específicamente los controles de detección de vulnerabilidades y esperan ver pentesting anual. Q: ¿Cuándo debería hacer el pentesting en relación al período de auditoría SOC 2? A: Dentro del período de auditoría (los 12 meses que cubre el informe SOC 2 Tipo II). Si tu período es enero-diciembre, el pentesting debería realizarse dentro de ese año. Muchas empresas lo hacen en Q2 o Q3 para tener tiempo de remediar hallazgos antes del cierre del período. Q: ¿El informe de QuantumSec sirve como evidencia para auditores SOC 2? A: Sí. El informe que entregamos está diseñado para ser compartido con auditores y clientes enterprise. Incluye resumen ejecutivo con alcance y metodología, listado de hallazgos con clasificación CVSS y el estado de remediación. Es exactamente lo que piden los auditores SOC 2. --- ## Cómo asegurar una aplicación SaaS antes de escalar: 7 pasos concretos URL: https://www.quantumsec.es/recursos/como-asegurar-una-aplicacion-saas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía práctica para asegurar tu SaaS: autenticación robusta, aislamiento multi-tenant, APIs seguras, secretos y monitorización. 7 pasos concretos. La seguridad de un SaaS no es un checklist que se hace una vez antes del lanzamiento. Es una práctica continua que debe integrarse en el ciclo de desarrollo desde el primer día. Sin embargo, hay un conjunto de medidas fundamentales que cualquier SaaS debería tener implementadas antes de empezar a escalar: antes de los primeros clientes enterprise, antes de una ronda de inversión y antes de manejar datos sensibles en producción. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es diferente asegurar un SaaS multi-tenant de asegurar una aplicación web normal? A: Sí, significativamente. El reto principal del SaaS es el aislamiento entre tenants: múltiples clientes usan la misma infraestructura y el mismo código. Un fallo de autorización en una aplicación web normal afecta a un usuario. En un SaaS multi-tenant, el mismo fallo puede exponer datos de todos los clientes a la vez. Q: ¿Cuándo debo hacer el primer pentesting de mi SaaS? A: El primer pentesting debería hacerse antes del lanzamiento a clientes enterprise o, como máximo, cuando tengas los primeros clientes con datos sensibles en producción. Esperar hasta que el sistema está completamente construido aumenta el coste de la remediación porque hay más código que cambiar. Q: ¿Puedo usar una herramienta de escaneo automático en lugar de un pentesting? A: Los scanners automáticos (DAST, SAST) son un complemento, no un sustituto del pentesting. Detectan bien vulnerabilidades conocidas como SQLi y XSS, pero no detectan fallos de lógica de negocio, IDOR entre tenants ni problemas de autorización específicos de tu modelo de datos. Un pentesting manual especializado en SaaS cubre lo que los scanners no pueden. --- ## Pentesting SaaS vs pentesting web: ¿en qué se diferencian realmente? URL: https://www.quantumsec.es/recursos/diferencias-pentesting-saas-vs-web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diferencias entre pentesting SaaS y pentesting web estándar: superficie de ataque, pruebas de multi-tenancy, lógica de negocio, duración y coste. Cuando una empresa SaaS busca un servicio de pentesting, a menudo recibe propuestas de pentesting web estándar. El problema es que un pentesting web genérico no cubre las superficies de ataque específicas del modelo SaaS: el aislamiento entre tenants, la lógica de billing, los permisos por plan, los webhooks y las APIs complejas de multi-organización. Esta guía explica exactamente en qué se diferencia un pentesting SaaS de un pentesting web convencional. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puede hacer el mismo pentester un pentesting web y uno SaaS? A: Técnicamente sí, pero el pentesting SaaS requiere experiencia adicional en pruebas de aislamiento multi-tenant y análisis de lógica de negocio. Un pentester con experiencia solo en aplicaciones web tradicionales puede pasar por alto los vectores específicos del modelo SaaS. Asegúrate de que el equipo contratado tiene experiencia específica en SaaS y no solo en OWASP Top 10. Q: ¿El pentesting SaaS cubre tanto la web como la API? A: Sí, el pentesting SaaS es por naturaleza multi-capa: cubre la aplicación web, todas las APIs (REST, GraphQL), los webhooks, las integraciones con terceros y el panel de administración. El scope exacto se define con el cliente antes del inicio del test. Q: ¿Qué documentación necesito preparar para un pentesting SaaS? A: Lo más útil es: documentación de la arquitectura del sistema (aunque sea básica), listado de roles de usuario y sus permisos, acceso a cuentas de prueba en dos tenants diferentes (o instrucciones para crearlas), y documentación de la API si existe (Swagger, Postman collection). Cuanto más contexto tenga el auditor sobre el producto, más profundo y eficiente será el test. --- ## Cómo contratar un pentesting: guía práctica para empresas URL: https://www.quantumsec.es/recursos/contratar-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía práctica para contratar un pentesting: qué pedir al proveedor, qué debe incluir la propuesta, cuánto cuesta y cómo sacar el máximo partido al informe. Contratar un pentesting es una decisión de seguridad crítica, no un trámite. Elegir el proveedor equivocado puede darte una falsa sensación de seguridad: un escaneo automatizado empaquetado como "pentesting" no detecta los fallos que realmente explotaría un atacante. Esta guía te ayuda a contratar el servicio adecuado, hacer las preguntas correctas y sacar el máximo valor al informe. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta contratar un pentesting en España? A: Depende del alcance: lo explicamos con detalle, por tipo de pentesting, en nuestra guía de precios. Como referencia rápida, un pentesting web estándar (una aplicación, caja gris) suele moverse entre 1.500 € y 5.000 €. La llamada inicial para definir tu alcance es gratuita y sin compromiso. Q: ¿Cuánto tiempo lleva contratar y ejecutar un pentesting? A: El proceso completo desde el primer contacto hasta la entrega del informe suele ser de 2 a 4 semanas. El acuerdo de alcance y propuesta tarda 2-5 días. La ejecución técnica dura entre 3 y 10 días hábiles según el alcance. El informe se entrega 2-3 días después de finalizar la fase técnica. Q: ¿Necesito firmar algún documento antes de empezar? A: Sí. Antes de cualquier prueba se firma un acuerdo de alcance (Rules of Engagement) que define exactamente qué sistemas se auditan, desde qué IPs opera el equipo y qué acciones están permitidas o excluidas. También se suele firmar un NDA (Non-Disclosure Agreement). Estos documentos protegen a ambas partes y son estándar en cualquier proveedor serio. --- ## Norma UNE-EN 18031: ciberseguridad obligatoria para dispositivos IoT y equipos radio URL: https://www.quantumsec.es/recursos/norma-une-18031/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Norma UNE-EN 18031 explicada por expertos: a quién aplica, requisitos técnicos y plazos. Obligatoria desde agosto 2025 para IoT y equipos radio en la UE. La norma UNE-EN 18031 (adopción española de la norma europea EN 18031) establece los requisitos de ciberseguridad obligatorios para equipos radio e IoT que se comercializan en la Unión Europea. Desde el 1 de agosto de 2025, todo fabricante que ponga en el mercado de la UE dispositivos con conectividad de red —routers, cámaras IP, wearables, sensores IoT, electrodomésticos conectados, dispositivos médicos o industriales— debe demostrar conformidad con esta norma bajo la Directiva de Equipos Radio (RED 2014/53/UE). Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La norma UNE-EN 18031 es de cumplimiento voluntario u obligatorio? A: Es obligatorio para los productos afectados desde el 1 de agosto de 2025. La norma es "armonizada" bajo la Directiva RED, lo que significa que cumplirla otorga presunción de conformidad con los requisitos legales de la Directiva. No cumplirla no es una opción: los productos no conformes no pueden comercializarse en el mercado de la UE. Q: ¿Cómo demuestro que mi dispositivo cumple con la EN 18031? A: Hay dos vías: (1) Self-assessment: el fabricante redacta la declaración de conformidad UE basándose en la norma armonizada, sin intervención de un tercero (válido para la mayoría de productos Default). (2) Evaluación por organismo notificado (NoBo): obligatoria si el fabricante no sigue la norma armonizada o si el producto pertenece a categorías de mayor riesgo. En ambos casos, es necesario mantener el expediente técnico disponible para las autoridades de vigilancia del mercado. Q: ¿El pentesting forma parte del proceso de cumplimiento de UNE-EN 18031? A: Sí. El pentesting de dispositivos IoT y hardware es la herramienta más eficaz para verificar que los controles exigidos por la EN 18031 funcionan en la práctica: que las credenciales no son reutilizables, que el mecanismo de actualización no es explotable, que las comunicaciones están realmente cifradas y que no existen puertas traseras. Un gap analysis sin pruebas técnicas reales puede pasar por alto fallos de implementación que un auditor con experiencia en IoT detectaría en horas. --- ## ¿Qué es el triage de vulnerabilidades y por qué lo necesita tu equipo? URL: https://www.quantumsec.es/recursos/que-es-el-triage-de-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El triage de vulnerabilidades es el proceso de validar, clasificar y priorizar los reportes de seguridad antes de que lleguen a tu equipo. Aprende cómo funciona y por qué es clave en cualquier programa de bug bounty o VDP. El triage de vulnerabilidades es el proceso mediante el cual cada reporte de seguridad que llega a tu programa —ya sea a través de un bug bounty, un VDP o un canal de divulgación privado— se analiza, se valida técnicamente, se clasifica por severidad y se prioriza antes de llegar al equipo de desarrollo. Sin triage, todos los reportes pesan lo mismo. Con triage, tu equipo solo ve lo que realmente importa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El triage es lo mismo que la validación de vulnerabilidades? A: La validación es parte del triage, pero el triage es más amplio. Incluye también la clasificación del reporte, la comunicación con el investigador, la detección de duplicados, la priorización y la entrega al equipo de remediación. La validación es el paso técnico que confirma que la vulnerabilidad es real y explotable. Q: ¿Cuánto tiempo debería tardar el triage de un reporte? A: Los estándares del sector establecen 24 horas para la primera respuesta y entre 1 y 5 días laborables para la validación completa, dependiendo de la complejidad. Los reportes críticos deben tener prioridad absoluta: la validación debería completarse en menos de 24 horas. Q: ¿Puedo externalizar el triage sin perder visibilidad sobre mis vulnerabilidades? A: Sí. Un buen servicio de triage externo opera de forma completamente transparente: el cliente tiene acceso a todos los reportes, a las valoraciones técnicas y al registro de comunicaciones con investigadores. La externalización elimina la carga operativa, no la visibilidad. --- ## Cómo crear un Vulnerability Disclosure Program paso a paso URL: https://www.quantumsec.es/recursos/como-crear-un-vulnerability-disclosure-program/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía paso a paso para diseñar e implementar un Vulnerability Disclosure Program. Política de divulgación, canal de recepción, proceso de triage y cumplimiento NIS2/CRA incluidos. Un Vulnerability Disclosure Program (VDP) es el canal oficial mediante el cual investigadores de seguridad pueden reportar vulnerabilidades en tus sistemas de forma coordinada y responsable. Implementarlo correctamente requiere más que publicar un email de contacto: necesitas una política clara, un proceso de respuesta y los recursos para gestionarlo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un VDP es lo mismo que un bug bounty? A: No. El VDP es un canal de divulgación responsable que no ofrece recompensas económicas, aunque puede incluir reconocimiento público. El bug bounty sí incluye pagos económicos por vulnerabilidades válidas. Muchas empresas empiezan con un VDP y evolucionan a un bug bounty cuando el programa está maduro. Q: ¿NIS2 obliga a tener un VDP? A: NIS2 exige que las entidades esenciales e importantes dispongan de mecanismos para gestionar y reportar vulnerabilidades. El VDP es la implementación más extendida para cumplir con este requisito. El Cyber Resilience Act también exige canales de notificación de vulnerabilidades para fabricantes de productos con elementos digitales. Q: ¿Cuánto tiempo lleva implementar un VDP desde cero? A: Con recursos internos dedicados, un VDP básico puede estar operativo en 2-4 semanas. Si se externaliza el diseño y la implementación a un proveedor especializado, el plazo puede reducirse a 1-2 semanas para el canal básico, con la gestión de reportes operativa desde el primer día. --- ## CVSS vs EPSS: cuál deberías usar para priorizar vulnerabilidades URL: https://www.quantumsec.es/recursos/cvss-vs-epss/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. CVSS mide la severidad teórica de una vulnerabilidad. EPSS predice la probabilidad de que sea explotada. Descubre cuándo usar cada uno y cómo combinarlos para priorizar correctamente. CVSS y EPSS son las dos métricas más utilizadas en la gestión de vulnerabilidades, pero miden cosas distintas. Usar solo CVSS lleva a priorizar vulnerabilidades teóricamente graves que nunca se explotan en la práctica. Usar solo EPSS puede llevar a ignorar vulnerabilidades críticas con baja probabilidad de explotación inmediata pero impacto devastador. La respuesta, como casi siempre en seguridad, es que necesitas ambas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿EPSS reemplaza a CVSS? A: No, son complementarios. CVSS mide la severidad técnica intrínseca de una vulnerabilidad (qué tan grave es si se explota). EPSS mide la probabilidad de explotación (cuánto probable es que alguien la explote pronto). Necesitas ambas métricas para tomar decisiones de priorización bien fundamentadas. Q: ¿Dónde puedo consultar el score EPSS de una CVE? A: El EPSS se publica diariamente en first.org/epss y está disponible en la mayoría de plataformas de vulnerability management (Tenable, Qualys, Rapid7). También puedes consultarlo directamente en la API pública de FIRST o en NVD. Q: ¿Qué es CVSS 4.0 y en qué mejora a CVSS 3.1? A: CVSS 4.0 introduce una nueva taxonomía de métricas más granular, mejora la valoración para entornos OT/ICS, añade métricas suplementarias (automatización, recuperación) y elimina ambigüedades en la interpretación de las métricas temporales. Para la mayoría de vulnerabilidades web, el cambio más notable es la mayor precisión en la evaluación del impacto. --- ## Falsos positivos en bug bounty: cómo reducirlos sin rechazar reportes válidos URL: https://www.quantumsec.es/recursos/falsos-positivos-en-bug-bounty/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los falsos positivos en bug bounty desgastan al equipo y frustran a los mejores investigadores. Aprende a gestionarlos con criterio técnico real y a construir un proceso que los minimice. Un falso positivo en un programa de bug bounty es un reporte que describe un comportamiento que parece una vulnerabilidad pero no lo es: comportamiento diseñado del sistema, problemas de configuración del entorno del researcher, o vulnerabilidades teóricas sin impacto práctico en tu entorno. Gestionarlos mal —rechazando sin argumentos técnicos o ignorando sin respuesta— es una de las formas más rápidas de destruir la reputación de tu programa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuál es una tasa de falsos positivos normal en un bug bounty? A: Depende del sector y la madurez del programa. En programas bien gestionados con scope claro, la tasa de falsos positivos suele estar entre el 30% y el 50% del total de reportes recibidos. En programas nuevos o con scope ambiguo, puede superar el 70%. El objetivo no es cero falsos positivos, sino gestionarlos bien y reducirlos progresivamente. Q: ¿Cómo diferencio un falso positivo de una vulnerabilidad que no entiendo? A: Si tienes dudas sobre si un reporte es un falso positivo, la respuesta segura es reproducir el ataque. Si no puedes reproducirlo con los pasos del investigador, pide más información antes de rechazarlo. Rechazar sin haber intentado reproducir el hallazgo es un error habitual que daña la reputación del programa. Q: ¿Puedo marcar como inválido un reporte sin pagar si no lo puedo reproducir? A: Sí, pero con cuidado. Si el investigador proporciona evidencia clara (capturas, tokens reales, datos de la respuesta del servidor) y no puedes reproducirlo, lo correcto es comunicarlo y pedir pasos más detallados. Solo si después de un intercambio razonado sigue sin ser reproducible está justificado cerrarlo como no válido. --- ## Bug bounty vs Vulnerability Disclosure Program: diferencias y cuándo usar cada uno URL: https://www.quantumsec.es/recursos/bug-bounty-vs-vdp/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Bug bounty y VDP no son lo mismo. Uno ofrece recompensas económicas; el otro, un canal de divulgación responsable. Aprende cuándo necesitas cada uno y cómo decidir. Bug bounty y Vulnerability Disclosure Program (VDP) son dos mecanismos para que investigadores externos reporten vulnerabilidades en tus sistemas. Pero tienen objetivos, costes y audiencias diferentes. Elegir el equivocado —o lanzar uno sin estar preparado para el otro— puede ser contraproducente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo tener un VDP y un bug bounty a la vez? A: Sí. Muchas empresas grandes tienen un VDP público (para vulnerabilidades generales) y un bug bounty privado para sus activos más críticos. Es una combinación válida que maximiza la cobertura sin comprometer el presupuesto. Q: ¿Un VDP me protege legalmente de los investigadores que hackeen mis sistemas? A: El VDP establece un marco de actuación responsable, pero no otorga inmunidad legal automática. Para protección legal efectiva, la política debe especificar claramente las condiciones de safe harbor: qué actividades están permitidas, qué sistemas están en scope y que no se tomará acción legal contra investigadores que actúen dentro de las reglas. Q: ¿Cuánto cuesta tener un VDP? A: El coste directo de un VDP es el de gestión (no hay bounties). Si lo gestionas internamente, el coste es el tiempo de tu equipo. Si lo externalizas, el coste es el del servicio de gestión. En ambos casos, es significativamente inferior al coste de un bug bounty activo. --- ## ¿Qué es un Vulnerability Disclosure Program (VDP)? URL: https://www.quantumsec.es/recursos/que-es-un-vulnerability-disclosure-program/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Un Vulnerability Disclosure Program (VDP) es el canal oficial para que investigadores reporten vulnerabilidades en tus sistemas. Aprende qué es, cómo funciona y por qué NIS2 y el CRA lo requieren. Un Vulnerability Disclosure Program (VDP) es el mecanismo formal mediante el cual una organización establece cómo los investigadores de seguridad externos pueden reportar vulnerabilidades que encuentren en sus sistemas, aplicaciones o infraestructura. Define las reglas, el canal de comunicación, los tiempos de respuesta y el proceso de resolución. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuál es la diferencia entre un VDP y un bug bounty? A: El VDP no ofrece recompensas económicas; el bug bounty sí. El VDP es un canal de divulgación responsable con reconocimiento no monetario. El bug bounty añade pagos proporcionales a la severidad de los hallazgos. Muchas empresas empiezan con VDP y evolucionan a bug bounty cuando el programa está maduro. Q: ¿Dónde debo publicar mi VDP? A: En el archivo security.txt en /.well-known/security.txt (estándar RFC 9116), en una página dedicada de tu web (security.tuempresa.com o tuempresa.com/security), y en el footer o política de privacidad. Cuanto más visible sea, más fácil es para los investigadores encontrarlo. Q: ¿Necesito una plataforma para tener un VDP? A: No. Puedes tener un VDP con un email dedicado y una política publicada en tu web. Las plataformas como HackerOne Response, Bugcrowd o Intigriti ofrecen VDPs gratuitos o de bajo coste con herramientas de gestión integradas, pero no son obligatorias para empezar. --- ## Cuánto cuesta un programa de bug bounty: bounties, plataforma y triage URL: https://www.quantumsec.es/recursos/cuanto-cuesta-gestionar-un-bug-bounty/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Lo que cuesta de verdad un bug bounty: 45.000-230.000 € al año con equipo interno frente a 28.000-190.000 € externalizado, desglosado partida a partida. El coste de un programa de bug bounty tiene dos componentes principales: el coste de los bounties (las recompensas pagadas a investigadores) y el coste de gestión (el trabajo de triagar, validar y coordinar los reportes). Muchas empresas conocen bien el primer número pero infravaloran el segundo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué es más caro: HackerOne/Bugcrowd o un servicio de gestión externo independiente? A: Las plataformas grandes (HackerOne, Bugcrowd) cobran por el acceso a la plataforma y, si contratas el triage gestionado, añaden un 20-40% adicional. Un proveedor independiente de gestión puede ser más económico porque no cobra por acceso a plataforma y puede operar sobre las herramientas que ya tienes. Q: ¿Puedo tener un bug bounty sin plataforma? A: Sí. Puedes gestionar un programa de bug bounty con un canal propio (formulario web, email) sin necesidad de una plataforma de terceros. La plataforma aporta comunidad de researchers, herramientas de gestión y visibilidad, pero tiene coste. Para programas privados con researchers específicos, un canal propio puede ser suficiente. Q: ¿Cuánto debería ser el presupuesto mínimo para un bug bounty? A: Para un programa privado con 5-10 researchers invitados y scope limitado, un presupuesto mínimo de €5.000-€10.000 anuales en bounties es un punto de partida razonable. Para un programa público, se recomiendan mínimo €20.000-€30.000 anuales en bounties más el coste de gestión. --- ## Cómo priorizar vulnerabilidades cuando tienes un backlog de reportes sin procesar URL: https://www.quantumsec.es/recursos/como-priorizar-vulnerabilidades-backlog/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Si acumulas reportes de vulnerabilidades sin procesar, necesitas un proceso de priorización. Aprende a atacar un backlog con criterio técnico y de negocio. Un backlog de vulnerabilidades sin priorizar es uno de los riesgos más silenciosos en la gestión de seguridad. La empresa cree que está gestionando la situación porque los reportes están registrados, pero en realidad puede haber una vulnerabilidad crítica esperando en la cola detrás de 30 reportes de baja severidad. El backlog necesita un proceso de priorización urgente, no solo más tiempo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuántos reportes sin procesar es demasiado? A: No hay un número absoluto, pero cualquier reporte que lleve más de 7 días sin primera respuesta es un problema. Si tienes reportes con más de 30 días sin validar, es una situación de riesgo activo que necesita atención urgente, independientemente del número total. Q: ¿Qué hago con los reportes muy antiguos que no puedo validar? A: Si un reporte tiene más de 90 días y no puedes reproducirlo, comunica al investigador el estado y ciérralo si no hay respuesta. Si el sistema ha cambiado significativamente, es posible que la vulnerabilidad ya no exista. Documenta el proceso de cierre. Q: ¿Puedo pedirle a alguien externo que procese mi backlog? A: Sí. Un servicio de triage externo puede procesar un backlog de forma puntual o de forma continua. Para el procesamiento de un backlog grande de forma urgente, suele ser la opción más rápida: el proveedor tiene el proceso y las herramientas ya rodadas. --- ## HackerOne, Bugcrowd, Intigriti y YesWeHack: comparativa real para equipos de seguridad URL: https://www.quantumsec.es/recursos/hackerone-bugcrowd-intigriti-comparativa/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Comparativa honesta de las cuatro principales plataformas de bug bounty: HackerOne, Bugcrowd, Intigriti y YesWeHack. Precios, triage, comunidad y alternativas para equipos sin presupuesto enterprise. HackerOne, Bugcrowd, Intigriti y YesWeHack son las cuatro plataformas de bug bounty más utilizadas a nivel global y europeo. Todas ofrecen gestión de programas, comunidad de researchers y herramientas de triage, pero tienen diferencias importantes en precio, cobertura geográfica, comunidad y modelo de gestión. Si estás evaluando cuál usar —o si ya tienes una y dudas si es la correcta—, esta comparativa te ayuda a decidir. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo migrar mi programa de HackerOne o Bugcrowd a un canal propio? A: Sí, aunque hay que planificarlo bien para no perder a los researchers activos. El proceso implica comunicar el cambio con antelación, exportar el histórico de reportes, configurar el nuevo canal y asegurarte de que el proceso de triage externo está operativo antes de la migración. Q: ¿Tienen estas plataformas opciones gratuitas para VDP? A: Sí. HackerOne, Bugcrowd, Intigriti y YesWeHack ofrecen versiones gratuitas o de muy bajo coste para VDPs básicos. El triage gestionado y las funcionalidades avanzadas siempre tienen coste adicional. Para un VDP sin bounties y con gestión propia, estas opciones gratuitas son un buen punto de partida. Q: ¿Qué plataforma tiene la mejor comunidad de researchers para el mercado español? A: Intigriti tiene la mayor presencia en Europa y una comunidad activa de researchers europeos, y sigue siendo la opción más eficiente para la mayoría de programas centrados en España. YesWeHack es una alternativa a considerar si la soberanía de datos es un requisito duro (administración pública, sector financiero bajo DORA, entidades sujetas a NIS2/CRA con exigencias estrictas de jurisdicción europea), gracias a su comunidad creciente en Francia y el resto de la UE. También existen plataformas específicamente españolas como cazHack para programas muy locales. --- ## NIS2 y Vulnerability Disclosure: qué exige la directiva y cómo cumplirlo URL: https://www.quantumsec.es/recursos/nis2-y-vulnerability-disclosure/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. NIS2 obliga a entidades esenciales e importantes a gestionar vulnerabilidades y disponer de canales de disclosure. Descubre qué exige exactamente y cómo cumplirlo. La Directiva NIS2 incluye entre sus requisitos la gestión de vulnerabilidades y la existencia de canales para su notificación. Para muchas empresas, esto implica por primera vez la necesidad de implementar un Vulnerability Disclosure Program (VDP) y un proceso formal de gestión de reportes de seguridad externos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuándo entró en vigor NIS2 en España? A: NIS2 debía trasponerse al derecho nacional de los Estados miembros antes del 17 de octubre de 2024. España está en proceso de transposición. Aunque la ley nacional específica puede estar pendiente, las empresas afectadas deben estar alineando sus controles con los requisitos de la directiva, ya que la transposición formal no cambia las obligaciones de fondo. Q: ¿Qué es INCIBE-CERT y qué relación tiene con el VDP? A: INCIBE-CERT es el equipo de respuesta a incidentes de seguridad del Instituto Nacional de Ciberseguridad de España. NIS2 establece que las entidades esenciales e importantes deben notificar a su CSIRT nacional (INCIBE-CERT en el caso de España) las vulnerabilidades significativas. Un VDP bien implementado incluye el proceso de coordinación con INCIBE-CERT. Q: ¿Puedo externalizar la gestión del VDP requerido por NIS2? A: Sí. Puedes externalizar la gestión del canal de recepción, el triage de reportes y la comunicación con investigadores a un proveedor especializado. La responsabilidad de cumplimiento sigue siendo de la empresa, pero el proveedor gestiona la operativa. Es una solución habitual para empresas sin equipo de seguridad dedicado. --- ## Cómo gestionar un programa de bug bounty sin equipo interno de seguridad URL: https://www.quantumsec.es/recursos/gestionar-bug-bounty-sin-equipo-interno/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Tener un programa de bug bounty sin equipo AppSec interno es posible. Descubre las opciones y cómo un proveedor externo puede gestionar el triage y la operación completa. No todas las empresas que necesitan un bug bounty tienen un equipo de seguridad dedicado. Startups en crecimiento, empresas medianas con un único responsable de seguridad y organizaciones en transición pueden beneficiarse de los reportes de los researchers sin tener la capacidad interna para gestionarlos. La clave está en construir el proceso correcto desde el principio. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo lanzar un bug bounty si solo tengo un responsable de seguridad? A: Sí, con la gestión adecuada. Un único responsable de seguridad no puede gestionar el triage de un programa activo en paralelo con el resto de sus responsabilidades. La solución es externalizar el triage y que el responsable interno actúe como punto de escalada y decisión, no como triager del día a día. Q: ¿Un proveedor externo puede comunicarse con los researchers en mi nombre? A: Sí. Los proveedores de gestión de bug bounty pueden operar en nombre del cliente: enviar confirmaciones de recepción, solicitar información adicional, comunicar el resultado del triage y gestionar el proceso de bounty. El researcher puede o no saber que hay un proveedor externo, según la política de transparencia del cliente. Q: ¿Cuánto tarda el proveedor en empezar a gestionar los reportes? A: El onboarding estándar tarda entre 5 y 10 días laborables. Después de eso, el proveedor puede gestionar los reportes desde el primer día. Para situaciones urgentes (backlog grande, reporte crítico entrante), el plazo puede reducirse. --- ## Coordinated Vulnerability Disclosure (CVD): qué es y cómo implementarlo en tu empresa URL: https://www.quantumsec.es/recursos/coordinated-vulnerability-disclosure/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El Coordinated Vulnerability Disclosure (CVD) es el proceso por el que investigadores y empresas coordinan la publicación de vulnerabilidades. Guía práctica para empresas. El Coordinated Vulnerability Disclosure (CVD), también conocido como responsible disclosure, es el proceso mediante el cual un investigador de seguridad que descubre una vulnerabilidad la comunica al afectado antes de publicarla, y ambas partes coordinan el timeline de divulgación pública. El estándar internacional que define este proceso es la norma ISO/IEC 29147. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo tengo para parchear antes de que el investigador publique? A: El plazo estándar de la industria es 90 días. Google Project Zero popularizó este plazo, que después se convirtió en referencia del sector. Algunas organizaciones usan 60 o 120 días. Lo importante es que el plazo esté establecido en tu política de divulgación antes de que llegue el primer reporte. Q: ¿Qué pasa si la vulnerabilidad afecta a un proveedor externo que no es mi software? A: Si la vulnerabilidad está en software o infraestructura de terceros, tu responsabilidad es notificar al proveedor afectado y coordinar con él. Puedes actuar de intermediario entre el investigador y el proveedor, o derivar el reporte directamente al CERT correspondiente si el proveedor no tiene VDP. Q: ¿Qué es un "safe harbor" en el contexto del VDP? A: El safe harbor es la cláusula de tu política de VDP que establece que no tomarás acciones legales contra investigadores que descubran y reporten vulnerabilidades actuando dentro de las reglas del programa. Es un elemento fundamental para construir confianza con la comunidad de investigadores. --- ## Proceso de triage de vulnerabilidades: cómo analizamos cada reporte de seguridad URL: https://www.quantumsec.es/recursos/proceso-triage-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo funciona el proceso de triage de un reporte de vulnerabilidad: desde la recepción hasta la entrega al equipo de remediación. Metodología y criterios técnicos. El triage de vulnerabilidades no es un proceso de lectura rápida. Cada reporte pasa por una serie de pasos técnicos que permiten confirmar que la vulnerabilidad es real, evaluar su impacto y entregar la información necesaria para que el equipo de remediación pueda actuar sin investigación adicional. Transparencia sobre cómo trabajamos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo lleva triagar un reporte de media? A: Depende de la complejidad. Un reporte bien documentado de XSS o IDOR puede triarse en 1-2 horas. Un reporte de lógica de negocio compleja, una cadena de vulnerabilidades o un hallazgo en infraestructura puede requerir 4-8 horas. La reproducción es la fase más variable en tiempo. Q: ¿Qué herramientas usáis para triagar? A: Las mismas que usamos para pentesting: Burp Suite Pro para análisis web, herramientas de análisis de APIs, entornos de sandbox para pruebas controladas, y acceso a plataformas de threat intelligence para consultar EPSS y contexto de explotación activa. El triage no es solo leer: implica atacar. Q: ¿Podéis triagar reportes de todos los tipos de vulnerabilidad? A: Sí. Nuestro equipo tiene experiencia en vulnerabilidades web (OWASP Top 10 y más allá), APIs, aplicaciones móviles, infraestructura, cloud, Active Directory y lógica de negocio. Para tipos de vulnerabilidad muy especializados (hardware, firmware, OT/ICS), lo evaluamos caso a caso. --- ## Responsible disclosure para empresas: guía para quien recibe su primer reporte URL: https://www.quantumsec.es/recursos/responsible-disclosure-para-empresas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía práctica para empresas que reciben reportes de vulnerabilidades por primera vez. Cómo responder, qué comunicar y cómo construir un proceso de responsible disclosure. Si un investigador de seguridad acaba de enviarte un reporte de vulnerabilidad y no sabes qué hacer, estás leyendo el artículo correcto. El responsible disclosure —o divulgación responsable— es el proceso por el que los investigadores notifican vulnerabilidades a las empresas antes de publicarlas. Cómo respondas en las próximas horas puede determinar si esa vulnerabilidad se gestiona bien o termina siendo un incidente público. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Tengo obligación legal de responder a un reporte de vulnerabilidad? A: Depende de tu sector y normativa aplicable. NIS2 y el Cyber Resilience Act establecen obligaciones de gestión de vulnerabilidades. GDPR puede implicar notificación a autoridades si la vulnerabilidad reportada ha dado lugar a una brecha de datos. En cualquier caso, no responder nunca es la respuesta correcta. Q: ¿Qué hago si la vulnerabilidad ya ha sido explotada? A: Si hay indicios de que la vulnerabilidad reportada ya ha sido explotada, activa tu proceso de respuesta a incidentes. Prioriza la contención y el análisis forense. La comunicación con el investigador puede esperar unas horas mientras evalúas el alcance del incidente. Q: ¿Debo pagar al investigador que me ha reportado la vulnerabilidad? A: Si no tienes un programa de bug bounty con tabla de recompensas publicada, no tienes obligación de pagar. El reconocimiento no económico (mención pública, Hall of Fame) es perfectamente válido. Si quieres incentivar futuros reportes, puedes hacer un pago voluntario o anunciar formalmente un programa de bug bounty. --- ## Cómo calcular el impacto real de una vulnerabilidad más allá del CVSS URL: https://www.quantumsec.es/recursos/impacto-real-de-una-vulnerabilidad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El CVSS base no es suficiente para evaluar el impacto real de una vulnerabilidad. Aprende a contextualizar el riesgo con factores de negocio, EPSS y CVSS ambiental. Una vulnerabilidad con CVSS 9.8 en un servidor interno sin acceso desde internet puede ser menos urgente que una con CVSS 6.5 en tu API de pagos expuesta públicamente. El CVSS base mide la gravedad teórica intrínseca de un fallo —independientemente del contexto donde aparece. Para tomar decisiones de priorización correctas, necesitas ir más allá. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El CVSS ambiental cambia mucho la puntuación base? A: Puede cambiar significativamente. Una vulnerabilidad con CVSS base 8.5 en un sistema interno con datos no sensibles y sin exposición a internet puede bajar a 5.0-6.0 con las métricas ambientales ajustadas. A la inversa, una vulnerabilidad con CVSS base 6.0 en un sistema crítico con datos de alto valor puede subir a 8.0+. Q: ¿Cómo incluyo el contexto de negocio en el scoring sin hacer subjetivo el proceso? A: La clave es definir previamente los criterios: qué sistemas son críticos, qué datos requieren qué nivel de protección, qué controles compensatorios están activos. Si estos criterios están documentados, el scoring ambiental deja de ser subjetivo y se convierte en un proceso reproducible y auditables. Q: ¿Puedo usar EPSS para todas las vulnerabilidades o solo para CVEs? A: EPSS solo existe para vulnerabilidades con CVE asignado. Para vulnerabilidades de lógica de negocio o fallos específicos de tu aplicación que no tienen CVE, no hay EPSS disponible. En esos casos, el impacto real se evalúa exclusivamente con los factores de contexto (exposición, datos, controles). --- ## Duplicados en bug bounty: cómo detectarlos y comunicarlos correctamente URL: https://www.quantumsec.es/recursos/duplicados-en-bug-bounty/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los reportes duplicados en bug bounty son frecuentes y gestionarlos mal destruye la relación con los investigadores. Aprende a detectarlos y comunicarlos correctamente. Un reporte duplicado en un programa de bug bounty es un hallazgo que ya ha sido reportado previamente por otro investigador y está en proceso de resolución. Gestionarlos bien —con transparencia y equidad— es fundamental para mantener la confianza de los researchers y la integridad del programa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Debo pagar al segundo investigador que reporta la misma vulnerabilidad? A: La práctica estándar es que solo el primer reporte recibe el bounty completo. Sin embargo, algunos programas dan un reconocimiento parcial (10-25% del bounty) al segundo reporter si el reporte es de alta calidad y contribuye a la resolución. Esto es una decisión de política del programa. Q: ¿Qué pasa si el segundo reporte tiene más detalle o mejor PoC que el primero? A: El segundo reporte no desplaza al primero en cuanto a prioridad de bounty, pero sí puede contribuir a la resolución. En ese caso, lo más justo es reconocerlo en el changelog o en el Hall of Fame, y considerar un pago simbólico si el programa tiene presupuesto para ello. Q: ¿Cuánto tiempo debo mantener un reporte como "duplicado activo" antes de cerrarlo? A: Un reporte marcado como duplicado debe cerrarse cuando se cierra el reporte original: cuando la vulnerabilidad está parcheada y verificada. Mantener los reporters informados del estado del original (de forma genérica, sin revelar detalles del reporte de otro investigador) es una buena práctica. --- ## Cómo externalizar el triage de vulnerabilidades sin perder el control URL: https://www.quantumsec.es/recursos/como-externalizar-el-triage/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Externalizar el triage de vulnerabilidades no significa perder visibilidad. Aprende qué delegar, qué retener internamente y cómo seleccionar un proveedor de triage. La preocupación más habitual cuando una empresa evalúa externalizar el triage de vulnerabilidades es perder visibilidad sobre sus activos y sus fallos de seguridad. Es una preocupación legítima. La buena noticia es que se puede diseñar un modelo de externalización que elimine la carga operativa sin sacrificar el control estratégico. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puede el proveedor externo ver información confidencial de mi empresa en los reportes? A: Sí, porque los reportes de vulnerabilidades pueden contener tokens de sesión, datos de respuesta del servidor, o información sobre la arquitectura interna. Por eso el NDA es un requisito fundamental antes de cualquier acceso. El proveedor debe tener políticas claras de confidencialidad y acceso restringido. Q: ¿Qué pasa si no estoy de acuerdo con la valoración del proveedor? A: El cliente siempre tiene la última palabra. Si hay discrepancia, se revisa conjuntamente con evidencia técnica. El proveedor debe poder defender su valoración con argumentos técnicos, y el cliente puede modificar la clasificación final. Es un proceso colaborativo, no una decisión unilateral del proveedor. Q: ¿Cuánto tiempo lleva externalizar el triage desde cero? A: El proceso completo de selección de proveedor, firma de NDA y onboarding suele llevar entre 2 y 4 semanas. Si ya tienes un proveedor en mente, el onboarding técnico puede hacerse en 5-10 días laborables. --- ## Métricas para programas de bug bounty: los KPIs que realmente importan URL: https://www.quantumsec.es/recursos/metricas-programa-bug-bounty/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las métricas correctas de un programa de bug bounty van más allá del número de reportes. Aprende los KPIs que realmente miden la salud y eficacia de tu programa. Medir el éxito de un programa de bug bounty por el número de reportes recibidos es como medir la calidad de un pentesting por el grosor del informe. Lo que importa no es el volumen, sino la calidad: cuántas vulnerabilidades reales se encontraron, con qué rapidez se gestionaron y qué impacto tuvieron en la postura de seguridad de la empresa. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Con qué frecuencia debería revisar las métricas del programa? A: Un dashboard de métricas en tiempo real es ideal para el equipo operativo. Para revisiones estratégicas, un informe mensual es suficiente. Si el programa es pequeño (menos de 20 reportes al mes), puede ser quincenal o mensual. Q: ¿Qué TTFR deberían tener mis investigadores para que el programa sea atractivo? A: Los mejores programs del mercado tienen TTFR inferior a 4-8 horas para días laborables. Superar las 48 horas en el primer acuse de recibo es un factor que hace que los researchers marquen el programa como de baja prioridad. La rapidez de respuesta es uno de los factores de reputación más importantes. Q: ¿Cómo mido el ROI de mi programa de bug bounty? A: Compara el coste total del programa (gestión + bounties) con el coste estimado de las vulnerabilidades encontradas si hubieran sido explotadas. Usa como referencia el coste medio de una brecha de datos en tu sector (IBM Cost of a Data Breach es el estudio más citado). La mayoría de los programas tienen un ROI positivo cuando encuentran al menos una vulnerabilidad crítica al año. --- ## CRA y Vulnerability Disclosure: qué exige el Cyber Resilience Act a las empresas URL: https://www.quantumsec.es/recursos/cra-y-vulnerability-disclosure/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Obligaciones de disclosure del Cyber Resilience Act: plazos de notificación a ENISA, canales de reporte y cómo preparar tu proceso antes de 2027. El Cyber Resilience Act (CRA) introduce obligaciones específicas de disclosure de vulnerabilidades para fabricantes y distribuidores de productos con elementos digitales en la UE. Esta guía analiza qué exige el CRA, los plazos de notificación y cómo preparar tu proceso de gestión de vulnerabilidades para cumplir antes de 2027. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El CRA me obliga a crear un programa de bug bounty? A: No directamente, pero sí te obliga a tener un canal de reporte de vulnerabilidades y un proceso de CVD. Un programa de bug bounty es una forma de cumplir con esta obligación y además atraer investigadores que te ayuden a descubrir vulnerabilidades antes de que sean explotadas. Q: ¿Cuándo tengo que empezar a cumplir con las obligaciones de disclosure del CRA? A: Las obligaciones de reporting de vulnerabilidades activamente explotadas aplican desde septiembre de 2026. El reglamento completo aplica desde diciembre de 2027. Sin embargo, preparar los procesos internos lleva meses, así que deberías empezar ya. Q: ¿Qué pasa si recibo un reporte de vulnerabilidad explotada fuera de horario laboral? A: El plazo de 24 horas del CRA no distingue entre horario laboral y no laboral. Necesitas un proceso de guardia o un equipo externo que pueda recibir, evaluar y notificar el reporte en cualquier momento. Este es uno de los argumentos más sólidos para externalizar el triage. --- ## Cómo responder a un investigador de seguridad que reporta una vulnerabilidad URL: https://www.quantumsec.es/recursos/responder-investigador-seguridad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía práctica para empresas: pasos exactos para gestionar un reporte de vulnerabilidad de un hacker ético externo y evitar divulgaciones prematuras. Recibes un email de un investigador de seguridad diciendo que ha encontrado una vulnerabilidad en tu sistema. ¿Qué haces? La forma en que respondas en las próximas horas determinará si el incidente se resuelve de forma profesional o se convierte en un problema reputacional. Esta guía práctica cubre los pasos exactos que debes seguir. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué hago si el investigador no tiene pruebas de que explotó el sistema sino solo describió la vulnerabilidad? A: Evalúa el reporte en sus méritos técnicos. El método de descubrimiento (pasivo vs activo) puede afectar a consideraciones legales, pero en muchos casos los investigadores descubren vulnerabilidades con técnicas perfectamente legales (análisis de código, fuzzing controlado, revisión de APIs públicas). Consulta con tu equipo legal antes de tomar decisiones basadas en el método de descubrimiento. Q: ¿Estoy obligado legalmente a responder a reportes de vulnerabilidades? A: Bajo NIS2, si eres operador de servicios esenciales o importantes, debes tener un proceso de gestión de vulnerabilidades. Bajo el CRA, si fabricas productos digitales, debes tener un canal de reporte. En ambos casos, ignorar los reportes puede constituir incumplimiento regulatorio. Q: ¿Qué pasa si el investigador publica la vulnerabilidad sin darme tiempo a parchear? A: Si has respondido de forma profesional y el investigador publica antes del plazo acordado (o sin haberlo acordado), tienes opciones limitadas pero documentar la comunicación te protege en términos reputacionales. Si la publicación fue sin ningún contacto previo contigo, consúltalo con tu equipo legal — aunque las opciones suelen ser limitadas. --- ## Bug bounty vs pentesting: cuál elegir y cuándo combinarlos URL: https://www.quantumsec.es/recursos/bug-bounty-vs-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Comparativa técnica entre bug bounty y pentesting: ventajas, limitaciones, costes y criterios para elegir el modelo de seguridad ofensiva adecuado. Bug bounty y pentesting son dos modelos de seguridad ofensiva con objetivos distintos, economías distintas y resultados distintos. Confundirlos es un error que puede dejarte con una falsa sensación de seguridad o con un presupuesto mal invertido. Esta guía explica las diferencias reales y cuándo tiene sentido usar cada modelo — o combinarlos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuál es más barato, el bug bounty o el pentesting? A: Depende del alcance y los resultados. Un pentesting básico puede costar entre 5.000 y 30.000€ según el alcance. Un programa de bug bounty tiene costes de gestión fijos más los bounties de las vulnerabilidades encontradas. Para superficies de ataque grandes con muchas vulnerabilidades, el bug bounty puede resultar más económico. Para validaciones puntuales de componentes específicos, el pentesting suele ser más eficiente. Q: ¿El bug bounty puede reemplazar el pentesting para certificaciones como PCI DSS? A: En la mayoría de los casos, no. Los estándares regulatorios como PCI DSS suelen exigir un pentesting estructurado con alcance definido y un informe formal. Algunos estándares evolucionan hacia aceptar programas de bug bounty como complemento, pero rara vez como sustituto para certificaciones formales. Q: ¿Qué hago si el bug bounty me genera demasiados reportes de baja calidad? A: Este es el problema más común de programas sin gestión adecuada. La solución es un triage profesional que filtre duplicados, falsos positivos y reportes fuera de alcance antes de que lleguen a tu equipo técnico. Sin triage, el bug bounty genera más trabajo que seguridad. --- ## Qué es EPSS y cómo usarlo para priorizar vulnerabilidades de forma más eficiente URL: https://www.quantumsec.es/recursos/que-es-epss/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. EPSS (Exploit Prediction Scoring System) explicado por expertos en pentesting: qué es, cómo funciona y cómo combinarlo con CVSS para priorizar parches. El Exploit Prediction Scoring System (EPSS) es un modelo probabilístico desarrollado por FIRST que predice la probabilidad de que una vulnerabilidad sea explotada en los próximos 30 días. A diferencia de CVSS, que mide la severidad teórica, EPSS mide el riesgo real basándose en datos observados de explotación activa. Usarlos juntos transforma la priorización de vulnerabilidades. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿EPSS reemplaza a CVSS? A: No, son complementarios. CVSS mide la severidad técnica intrínseca de la vulnerabilidad. EPSS mide la probabilidad de explotación en el contexto del threat landscape actual. Usarlos juntos da una imagen mucho más completa que cualquiera de los dos por separado. Q: ¿Con qué frecuencia se actualiza EPSS? A: El modelo EPSS se actualiza diariamente. Una vulnerabilidad que tiene EPSS bajo hoy puede subir significativamente mañana si se publica un exploit público o si se detecta explotación activa. Por eso es importante monitorizar EPSS de forma continua, no solo en el momento de la publicación de la CVE. Q: ¿EPSS funciona para vulnerabilidades recién publicadas? A: Para CVEs muy recientes (menos de 30 días), la puntuación EPSS puede ser menos fiable porque el modelo tiene menos datos de observación. En esos casos, CVSS 4.0, KEV (Known Exploited Vulnerabilities) de CISA y el contexto de tu arquitectura específica son criterios adicionales importantes. --- ## Cómo lanzar un programa de bug bounty privado: guía paso a paso URL: https://www.quantumsec.es/recursos/lanzar-bug-bounty-privado/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía práctica para crear un programa de bug bounty privado: alcance, selección de investigadores, tabla de bounties y gestión de los primeros reportes. Un programa de bug bounty privado es el punto de entrada más seguro al ecosistema de bug bounty para la mayoría de las empresas. En lugar de abrir la plataforma a miles de investigadores de golpe, invitas a un grupo selecto y controlado que ya conoces. Esta guía cubre todos los pasos para lanzar correctamente un programa privado, desde la definición de alcance hasta la gestión de los primeros reportes. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta lanzar un programa de bug bounty privado? A: Los costes principales son: tarifa de la plataforma (variable según proveedor, desde 0 hasta miles al mes para plataformas enterprise), bounties pagados a investigadores (muy variable según hallazgos) y coste interno o externo de gestión de reportes. Un programa privado pequeño y bien gestionado puede empezar con presupuesto muy limitado si el alcance y el proceso son correctos. Q: ¿Cuánto tarda en generar resultados un programa de bug bounty privado? A: Los primeros reportes suelen llegar en los primeros días. Los hallazgos más interesantes aparecen en las primeras 4-8 semanas, cuando los investigadores han tenido tiempo de hacer un análisis profundo del alcance. Los programas sin hallazgos después de 3 meses suelen indicar un problema de alcance (demasiado restrictivo) o de bounties (poco competitivos). Q: ¿Necesito un equipo interno de seguridad para gestionar un bug bounty? A: No necesariamente. Muchas empresas externalizan la gestión de reportes a servicios especializados de triage que actúan como capa intermedia entre los investigadores y el equipo de desarrollo. Esto reduce enormemente la carga interna y mejora la calidad de la respuesta a los investigadores. --- ## Triage de vulnerabilidades en equipos AppSec: cómo estructurar el proceso URL: https://www.quantumsec.es/recursos/triage-vulnerabilidades-appsec/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía para equipos AppSec: cómo implementar un proceso de triage de vulnerabilidades eficiente con las cinco fases, métricas y cuándo externalizarlo. Los equipos AppSec son el cuello de botella más común en la gestión de vulnerabilidades. Reciben reportes de múltiples fuentes — escáneres automáticos, pentesters, bug bounty, investigadores externos, SAST/DAST — y tienen que decidir qué parchear primero con recursos limitados. Un proceso de triage bien diseñado transforma ese caos en un flujo de trabajo predecible. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo debería dedicar un equipo AppSec al triage cada semana? A: Depende del volumen de reportes. Como referencia, un equipo de 3 personas gestionando 100 reportes al mes debería dedicar entre 20-30% de su tiempo al triage si el proceso es eficiente. Sin proceso estructurado, ese porcentaje puede subir al 50-60%, dejando poco tiempo para trabajo proactivo de seguridad. Q: ¿SAST y DAST reemplazan el triage manual? A: No. SAST y DAST son herramientas de detección, no de triage. Generan listas de posibles vulnerabilidades (con muchos falsos positivos) pero no pueden evaluar el contexto de negocio, la explotabilidad real en tu configuración específica ni la prioridad relativa entre hallazgos. El triage manual es necesario para convertir el output de los escáneres en acciones priorizadas. Q: ¿Cómo medimos si nuestro proceso de triage AppSec es eficiente? A: Métricas clave: ratio de falsos positivos que llegan al equipo de desarrollo (objetivo <10%), tiempo desde detección hasta asignación de ticket (objetivo <48h para críticos), MTTR por severidad, porcentaje de vulnerabilidades dentro de SLA. Si no mides estas métricas, no puedes mejorar el proceso. --- ## CVSS 4.0: novedades y cómo impacta en la gestión de vulnerabilidades URL: https://www.quantumsec.es/recursos/cvss-4-gestion-vulnerabilidades/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Análisis de CVSS 4.0 vs CVSS 3.1: nuevos grupos de métricas, nomenclatura posicional y cómo adaptar tu proceso de priorización de vulnerabilidades. CVSS 4.0, publicado por FIRST en noviembre de 2023, introduce cambios significativos respecto a CVSS 3.1. Nuevos grupos de métricas, una nomenclatura más clara para los tipos de puntuación y mejoras en la evaluación del contexto de seguridad. Esta guía explica qué cambia con CVSS 4.0 y cómo adaptarte si ya usas CVSS 3.1 en tus procesos de gestión de vulnerabilidades. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿NVD y CVEs ya usan CVSS 4.0? A: NVD está en proceso de adopción de CVSS 4.0. Muchas CVEs todavía solo tienen puntuación CVSS 3.x en NVD. Los fabricantes son los primeros en adoptar CVSS 4.0 para sus propios advisories — por ejemplo, Cisco, Red Hat y Microsoft ya publican algunas puntuaciones CVSS 4.0 en sus security advisories. Q: ¿Debería migrar mis políticas de SLA de CVSS 3.1 a CVSS 4.0 inmediatamente? A: No de golpe. La transición gradual es la más práctica. Mantén las políticas actuales basadas en CVSS 3.1 para el backlog existente. Para vulnerabilidades nuevas, adopta CVSS 4.0 e incluye la versión de CVSS en tu documentación de SLA para evitar comparaciones incorrectas. La transición completa puede llevar 12-18 meses según el tamaño de tu inventario. Q: ¿CVSS 4.0 resuelve el problema de los falsos positivos de severidad? A: Parcialmente. CVSS 4.0 ofrece métricas Environmental más refinadas que permiten ajustar mejor la puntuación a tu contexto específico. Pero ninguna versión de CVSS resuelve el problema completamente porque CVSS sigue siendo una evaluación de severidad, no de riesgo real. Complementar con EPSS y contexto de activos sigue siendo necesario. --- ## Auditoría de seguridad WordPress para empresas: qué es, qué cubre y cuándo necesitarla URL: https://www.quantumsec.es/recursos/auditoria-seguridad-wordpress/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría WordPress para empresas: pentest manual de plugins, wp-admin y API REST. Vulnerabilidades reales con evidencias en 2-5 días. Presupuesto en 24h. WordPress alimenta más del 40% de los sitios web del mundo. También encabeza las estadísticas de CMS comprometidos. No porque sea inherentemente inseguro, sino porque su ecosistema de plugins, temas y configuraciones de terceros genera una superficie de ataque enorme que las herramientas automáticas y el mantenimiento rutinario no cubren de forma suficiente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo dura una auditoría de seguridad WordPress? A: Entre 2 y 5 días hábiles para una instalación de complejidad media. Depende del número de plugins activos, desarrollos custom, endpoints expuestos y la profundidad acordada del análisis. Q: ¿Se puede hacer la auditoría sobre el entorno de producción? A: Sí, aunque lo recomendable es trabajar sobre un clon del entorno de producción (staging) para evitar cualquier impacto en la disponibilidad. Si se trabaja en producción, coordinamos las pruebas más invasivas fuera del horario de mayor tráfico. Q: ¿La auditoría incluye también WooCommerce? A: Si la instalación incluye WooCommerce, lo auditamos dentro del mismo alcance: seguridad del proceso de checkout, gestión de pedidos, integración con pasarelas de pago y acceso a datos de clientes. También cubrimos los plugins específicos de WooCommerce. Q: ¿Cuánto cuesta una auditoría de seguridad WordPress? A: Depende del número de plugins activos, del desarrollo a medida y de si hay tienda online en el alcance. Una web corporativa estándar son 2-3 días de trabajo; una instalación con desarrollo propio o WooCommerce, entre 4 y 6. Cerramos el alcance en una llamada de 20 minutos y enviamos propuesta en 24 horas. Q: ¿Cada cuánto hay que repetir la auditoría? A: Una vez al año como línea base, y adicionalmente ante cualquier cambio relevante: migración de hosting, incorporación de un plugin crítico, desarrollo a medida nuevo o apertura de un canal de pago. Si la web es el canal comercial principal, lo habitual es semestral. Q: ¿En qué se diferencia de contratar mantenimiento web? A: El mantenimiento mantiene el software al día; la auditoría comprueba si esa instalación concreta es explotable. Son complementarios: la mayoría de compromisos que analizamos ocurren en sitios con el mantenimiento perfectamente al día, por vulnerabilidades en código a medida o configuraciones del entorno que ninguna actualización corrige. --- ## Pentesting WordPress: vectores de ataque reales y cómo se analiza una instalación URL: https://www.quantumsec.es/recursos/pentesting-wordpress/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo funciona un pentesting de WordPress, qué vectores de ataque se analizan, qué encuentra que un escáner no ve y cuándo es imprescindible para tu empresa. Un pentesting de WordPress no es pasar WPScan y esperar resultados. Es simular el recorrido que haría un atacante real: desde la enumeración inicial hasta la explotación de una vulnerabilidad en un plugin custom o la escalada de privilegios desde un usuario editor a administrador. Esta guía explica qué cubre un pentesting de WordPress técnico y por qué es diferente de cualquier herramienta automática. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un pentesting de WordPress requiere acceso de administrador? A: No necesariamente. El análisis de caja negra parte sin credenciales. Si se quiere mayor cobertura (análisis de lógica autenticada, escalada de privilegios entre roles), se proporcionan cuentas de prueba con diferentes niveles de acceso. Q: ¿El pentesting afecta al SEO o al ranking de la web? A: Un pentesting bien ejecutado no genera contenido indexable ni modifica datos en producción. Todos los tests se realizan en entorno controlado o staging. Si se trabaja en producción, las pruebas potencialmente destructivas se acuerdan expresamente y se realizan con supervisión. --- ## Hardening WordPress para empresas: reducir la superficie de ataque más allá de los plugins URL: https://www.quantumsec.es/recursos/hardening-wordpress-empresas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Hardening de WordPress para entornos empresariales: qué configuraciones reducen la superficie de ataque real y cómo diferenciarlo de una auditoría de seguridad completa. El hardening de WordPress es el conjunto de medidas de configuración que reducen la superficie de ataque de una instalación antes de que un atacante la encuentre. No sustituye a un pentesting —que analiza vulnerabilidades ya presentes— pero es la base que determina cuánto daño puede hacer un atacante si consigue un primer acceso. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El hardening lo puede hacer nuestra agencia web o necesitamos una empresa de ciberseguridad? A: Una agencia web con experiencia puede aplicar las medidas de hardening básicas. Lo que no puede hacer es validar que son efectivas bajo ataque real ni detectar vulnerabilidades en el código de los plugins. Para eso se necesita un pentesting externo con metodología ofensiva. Q: ¿El hardening afecta al rendimiento o a la funcionalidad del sitio? A: Las medidas de hardening bien aplicadas no afectan al rendimiento. Algunas restricciones (deshabilitar XML-RPC, limitar endpoints REST) pueden requerir ajustes en integraciones existentes, por lo que se revisan antes de aplicarlas. --- ## Seguridad de plugins WordPress: el principal vector de compromiso en instalaciones empresariales URL: https://www.quantumsec.es/recursos/seguridad-plugins-wordpress/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué los plugins de WordPress son el principal vector de compromiso, cómo se audita su seguridad y qué riesgos reales tienen las extensiones de terceros en entornos empresariales. El 97% de los ataques a WordPress no explotan el core —que tiene un historial de seguridad razonablemente sólido—, sino el ecosistema de plugins y temas de terceros. Con más de 60.000 plugins disponibles en el repositorio oficial y decenas de miles más distribuidos de forma independiente, la superficie de ataque de una instalación empresarial típica es mucho mayor de lo que aparenta. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuántos plugins es demasiados para una instalación segura? A: No hay un número mágico. Cada plugin activo es una superficie de ataque adicional. Lo relevante es si cada plugin tiene mantenimiento activo, si tiene vulnerabilidades conocidas sin parchear y si su código ha sido revisado. Una instalación con 5 plugins mal elegidos es más peligrosa que una con 30 bien gestionados. Q: ¿Los plugins premium son más seguros que los gratuitos? A: No necesariamente. Tienen historial de vulnerabilidades críticas tanto en el repositorio oficial como en plugins premium populares. La variable más relevante es la calidad del equipo de desarrollo y su velocidad de respuesta ante informes de seguridad. --- ## Seguridad WooCommerce: riesgos específicos de las tiendas online en WordPress URL: https://www.quantumsec.es/recursos/seguridad-woocommerce/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Riesgos de seguridad específicos de WooCommerce, qué cubre una auditoría técnica y por qué las tiendas online necesitan algo más que un plugin de seguridad y las últimas actualizaciones. WooCommerce convierte WordPress en una plataforma de e-commerce con acceso a datos de tarjetas, historial de pedidos, datos personales de clientes y pasarelas de pago integradas. Esta capa añade obligaciones de seguridad (PCI-DSS en pagos con tarjeta) y vectores de ataque que van mucho más allá de los riesgos habituales de WordPress corporativo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Si usamos Stripe o PayPal, seguimos necesitando auditar la seguridad del checkout? A: Sí. La pasarela de pago tokeniza los datos de tarjeta, pero el entorno de checkout sigue siendo un vector de ataque. Un script malicioso inyectado en la página puede capturar datos de tarjeta antes de que lleguen a Stripe. La auditoría cubre el entorno completo, no solo la pasarela. Q: ¿La auditoría WooCommerce vale como evidencia para PCI-DSS? A: El informe de pentesting es válido como evidencia de las pruebas de seguridad requeridas por PCI-DSS. El alcance específico se adapta a los requisitos del nivel de comerciante aplicable. --- ## Auditoría de seguridad Magento y Adobe Commerce: qué cubre y por qué es imprescindible en e-commerce URL: https://www.quantumsec.es/recursos/auditoria-seguridad-magento/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué cubre una auditoría de seguridad de Magento o Adobe Commerce, por qué las tiendas enterprise necesitan pentesting técnico real y cuáles son los vectores de ataque más habituales. Magento (Adobe Commerce) es la plataforma e-commerce dominante en el segmento mid-market y enterprise. Su complejidad —extensiones de terceros, módulos custom, integraciones con ERP y pasarelas de pago— genera una superficie de ataque que va mucho más allá del OWASP Top 10 estándar. Las tiendas Magento son objetivos de alto valor para atacantes especializados en skimming de tarjetas y fraude. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La auditoría cubre tanto Magento Open Source como Adobe Commerce? A: Sí. La metodología es aplicable a ambas ediciones. Adobe Commerce (la versión enterprise) añade capas adicionales de funcionalidad (B2B, staged content, advanced reporting) que también se incluyen en el alcance. Q: ¿Con qué frecuencia debería auditarse una tienda Magento? A: Al menos una vez al año y siempre que se instalen nuevas extensiones o se realicen cambios significativos en el código. Las tiendas en scope PCI-DSS tienen requisitos específicos de frecuencia de pentesting. --- ## Pentesting Magento y Adobe Commerce: cómo se analiza la seguridad de una tienda enterprise URL: https://www.quantumsec.es/recursos/pentesting-magento/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo funciona un pentesting de Magento o Adobe Commerce, qué vectores de ataque se prueban y por qué las tiendas enterprise necesitan análisis técnico ofensivo específico. Un pentesting de Magento evalúa la seguridad de la tienda simulando el comportamiento de un atacante que conoce la plataforma: las rutas por defecto, las APIs expuestas, los patrones de vulnerabilidad habituales en extensiones de terceros y los flujos de negocio que pueden manipularse. Es un análisis ofensivo real, no un escáner de versiones. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting de Magento requiere acceso al código fuente? A: No para el análisis de caja negra o caja gris. Si se quiere auditar el código de extensiones custom, se facilita el código fuente para el análisis estático complementario. Q: ¿Se puede hacer el pentesting sin afectar a los pedidos reales? A: Sí. Las pruebas que implican creación de pedidos, modificación de datos o inyecciones activas se realizan en un entorno de staging. Si no existe, ayudamos a configurarlo antes del análisis. --- ## Seguridad del checkout en Magento: Magecart, manipulación de precios y protección del proceso de pago URL: https://www.quantumsec.es/recursos/seguridad-checkout-magento/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Vectores de ataque sobre el checkout de Magento, riesgo Magecart, pruebas de manipulación de precios y cómo una auditoría técnica protege el proceso de pago. El proceso de checkout es el componente más crítico de una tienda Magento desde el punto de vista de seguridad y negocio. Un fallo aquí puede significar robo de datos de tarjeta, fraude en pedidos o pérdida de confianza de clientes. Los atacantes lo saben y es donde concentran esfuerzos más sofisticados. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Una política CSP estricta protege completamente frente a Magecart? A: Es la medida de mitigación más eficaz, pero no es suficiente sola. CSP puede estar mal configurada (demasiado permisiva), puede tener excepciones para scripts necesarios del negocio, o el atacante puede explotar un script de primera parte para inyectar el código. La auditoría evalúa la CSP y valida su efectividad real. Q: ¿Se pueden hacer pruebas de manipulación de precios sin generar pedidos reales? A: Sí. Las pruebas se realizan en entorno de staging con datos de prueba. No se generan pedidos reales ni se procesan pagos durante el pentesting. --- ## Auditoría de seguridad PrestaShop: vectores de ataque y análisis técnico para tiendas online URL: https://www.quantumsec.es/recursos/auditoria-seguridad-prestashop/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué cubre una auditoría de seguridad PrestaShop, los vectores de ataque más habituales en tiendas PrestaShop y cuándo necesita tu empresa un análisis técnico real. PrestaShop es la plataforma de e-commerce más extendida en España entre pymes y mid-market. Su popularidad, combinada con un ecosistema de módulos de terceros con control de calidad desigual, hace que las instalaciones de PrestaShop sean objetivos frecuentes de ataques automatizados y campañas de skimming. Una auditoría de seguridad evalúa la resistencia real de la tienda frente a estos ataques. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La auditoría es compatible con PrestaShop 1.7 y PrestaShop 8? A: Sí. La metodología se adapta a la versión instalada. PrestaShop 1.7 tiene particularidades de seguridad distintas a la rama 8 y muchas tiendas siguen en 1.7 por incompatibilidades de módulos. Lo evaluamos en su contexto real. Q: ¿Qué pasa si detectáis un compromiso activo durante la auditoría? A: Lo comunicamos inmediatamente y adaptamos el análisis para identificar el alcance del compromiso: qué ficheros han sido modificados, qué persistencia existe y qué datos pueden haberse visto afectados. Esto deriva normalmente en un servicio de respuesta a incidentes. --- ## Seguridad de módulos PrestaShop: el vector de ataque que más compromete tiendas online URL: https://www.quantumsec.es/recursos/seguridad-modulos-prestashop/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué los módulos de terceros son el principal vector de compromiso en PrestaShop, qué vulnerabilidades son más habituales y cómo se audita su seguridad en entornos empresariales. Los módulos de terceros en PrestaShop son el equivalente a los plugins de WordPress: código PHP de terceros ejecutado con privilegios completos sobre la instalación. La diferencia es que el ecosistema de módulos PrestaShop tiene un historial de vulnerabilidades críticas con exploits públicos activos que han comprometido miles de tiendas, muchas sin que sus propietarios lo supieran. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cómo sé si alguno de mis módulos actuales tiene una vulnerabilidad activa? A: La forma más fiable es un análisis sistemático de todos los módulos instalados contra bases de datos de CVEs actualizadas. También hay servicios de monitorización continua que alertan cuando se publica una vulnerabilidad para un módulo instalado. Q: ¿Los módulos del marketplace oficial de PrestaShop son más seguros? A: Tienen controles de revisión básicos, pero siguen teniendo historial de vulnerabilidades. La validación del marketplace no es equivalente a una auditoría de seguridad. Módulos con miles de instalaciones y años de actividad han tenido CVEs críticos. --- ## Auditoría de seguridad Drupal: análisis técnico para organizaciones institucionales y enterprise URL: https://www.quantumsec.es/recursos/auditoria-seguridad-drupal/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué cubre una auditoría de seguridad Drupal, por qué las organizaciones institucionales y enterprise necesitan análisis técnico ofensivo y cuáles son los vectores de ataque más relevantes. Drupal es el CMS elegido por administraciones públicas, universidades, medios de comunicación y organizaciones complejas que necesitan control avanzado sobre contenido, roles y flujos de publicación. Su robustez como plataforma no elimina los riesgos de seguridad: los módulos de terceros, las configuraciones custom y la complejidad del entorno son vectores de ataque que requieren análisis específico. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La auditoría es compatible con Drupal 7, 9 y 10? A: Sí, aunque Drupal 7 alcanzó el fin de soporte oficial. Si tu organización sigue en Drupal 7, la auditoría documenta el riesgo específico de la versión EOL y prioriza la migración como parte del plan de remediación. Q: ¿La auditoría incluye la revisión de los módulos de workflow y publicación? A: Sí. Los módulos de workflow, content moderation y publicación son componentes con lógica compleja de control de acceso que pueden contener escaladas de privilegios entre roles editoriales. --- ## Hardening Drupal para organizaciones: configuraciones de seguridad que reducen la superficie de ataque URL: https://www.quantumsec.es/recursos/hardening-drupal/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Medidas de hardening de Drupal para organizaciones institucionales y enterprise: permisos, configuración, módulos y cabeceras HTTP. Qué protege y qué no sustituye. El hardening de Drupal establece la línea base de seguridad de la instalación: configuraciones que reducen la superficie de ataque visible antes de que se produzca cualquier intento de explotación. Para organizaciones que usan Drupal en contextos críticos —administraciones, universidades, medios, portales de salud— la configuración correcta es la primera barrera. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El módulo Security Review de Drupal cubre todo el hardening? A: El módulo Security Review automatiza la verificación de algunos controles básicos de configuración, pero no detecta problemas de lógica de permisos complejos, vulnerabilidades en módulos custom ni configuraciones de servidor. Es un punto de partida, no un sustituto de una auditoría. Q: ¿Cuánto tiempo requiere aplicar hardening en una instalación Drupal enterprise? A: Entre 1 y 3 días dependiendo del tamaño de la instalación, el número de módulos y la complejidad de los roles. El tiempo aumenta si hay módulos custom que requieren revisión de código. --- ## Auditoría de seguridad Joomla: análisis técnico para instalaciones empresariales y legadas URL: https://www.quantumsec.es/recursos/auditoria-seguridad-joomla/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué cubre una auditoría de seguridad Joomla, vectores de ataque habituales en extensiones de terceros y cuándo necesita tu organización un análisis técnico ofensivo. Joomla sigue siendo la base de muchos portales corporativos, intranets, webs institucionales y sitios de organizaciones que migraron a él en la primera década de los 2000 y mantienen instalaciones en producción. Estas instalaciones "legadas" acumulan deuda técnica de seguridad: extensiones de terceros sin mantenimiento, versiones antiguas sin actualización y configuraciones que no han seguido la evolución de las amenazas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La auditoría es compatible con Joomla 3 y Joomla 4/5? A: Sí. Joomla 3 alcanzó el fin de soporte en 2023. Si tu instalación sigue en Joomla 3, la auditoría documenta el riesgo específico de la versión EOL y evalúa opciones de mitigación mientras se planifica la migración. Q: ¿Tenemos que migrar a Joomla 5 antes de hacer la auditoría? A: No. La auditoría evalúa la seguridad de la instalación actual. Si la migración está planificada, puede tener sentido hacerla antes para que el análisis cubra el estado futuro. Si la migración no es inmediata, la auditoría en la versión actual es útil para gestionar el riesgo presente. --- ## Pentesting de CMS para empresas: qué es, qué encuentra y cuándo es imprescindible URL: https://www.quantumsec.es/recursos/pentesting-cms-empresas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es un pentesting de CMS para empresas, en qué se diferencia de un escáner automático y cuándo necesita tu organización un análisis de seguridad técnico real sobre WordPress, Drupal o Magento. El término "auditoría de seguridad CMS" cubre un espectro amplio: desde pasar un escáner automático hasta simular un ataque real contra la instalación con metodología ofensiva. Para una empresa que necesita reducir riesgo real, la diferencia entre estos extremos es enorme. Esta guía explica qué es un pentesting de CMS técnico y cuándo necesita tu organización uno. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting CMS cubre también el hosting y la infraestructura? A: El alcance habitual se centra en la capa de aplicación del CMS. La infraestructura (servidor, CDN, WAF, DNS) puede incluirse como alcance adicional. Se define en la fase previa al análisis. Q: ¿Cuánto cuesta un pentesting de CMS? A: Depende del tamaño de la instalación, el número de extensiones, la complejidad de los desarrollos custom y el alcance acordado. El rango habitual para instalaciones de complejidad media está entre 2.000 y 8.000 €. Solicitando una llamada inicial podemos dimensionar el alcance y dar una propuesta concreta. --- ## Seguridad CMS vs mantenimiento web: por qué no son lo mismo y qué implica para tu empresa URL: https://www.quantumsec.es/recursos/seguridad-cms-vs-mantenimiento-web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué actualizar plugins y hacer backups no es suficiente para proteger un CMS empresarial. Diferencias entre mantenimiento web y auditoría de seguridad técnica real. Una de las confusiones más frecuentes en empresas con webs basadas en CMS es equiparar el mantenimiento web con la seguridad. La agencia web actualiza plugins, hace backups y monitoriza uptime. Esto no es seguridad: es gestión operativa. La diferencia tiene consecuencias reales cuando se produce un incidente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podemos pedir a nuestra agencia web que haga también la auditoría de seguridad? A: Depende de si la agencia tiene un equipo de seguridad ofensiva específico. Si la agencia usa las mismas herramientas que usa para el mantenimiento (plugins de seguridad, escáneres automáticos), no es una auditoría técnica real. Una auditoría independiente por un tercero especializado tiene además el valor de la objetividad. Q: ¿Necesitamos una auditoría aunque no hayamos tenido ningún incidente? A: Sí. La ausencia de incidentes detectados no equivale a ausencia de compromiso. Muchos compromisos de CMS pasan desapercibidos durante meses: el atacante mantiene acceso persistente sin interrumpir el servicio. La auditoría detecta compromisos activos además de vulnerabilidades potenciales. --- ## Vulnerabilidades comunes en CMS empresariales: qué buscan los atacantes y dónde las encuentran URL: https://www.quantumsec.es/recursos/vulnerabilidades-comunes-cms/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las vulnerabilidades de seguridad más habituales en CMS empresariales (WordPress, Magento, PrestaShop, Drupal, Joomla) y qué riesgo real representan para tu organización. Los CMS son los sistemas más atacados de Internet. No porque sean los menos seguros, sino porque son los más usados. Entender qué vulnerabilidades buscan los atacantes es el primer paso para priorizar una estrategia de seguridad efectiva. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cómo sé si mi CMS tiene alguna de estas vulnerabilidades activas? A: La forma más fiable es un pentesting técnico que evalúe la instalación real. Para un primer diagnóstico, se puede contratar un análisis de vulnerabilidades (VA) que identifica versiones desactualizadas y CVEs conocidos. El pentesting va más allá y evalúa la explotabilidad real. Q: ¿Estas vulnerabilidades afectan igual a una web pequeña que a una enterprise? A: Sí, aunque el impacto es diferente. Una web pequeña con vulnerabilidades puede usarse como plataforma de ataque a terceros, para alojar phishing o para SEO spam. Una instalación enterprise con los mismos fallos implica exposición de datos de clientes, PCI-DSS y riesgo reputacional y regulatorio mucho mayor. --- ## Seguridad del panel de administración CMS: proteger el acceso más crítico de tu instalación URL: https://www.quantumsec.es/recursos/seguridad-panel-administracion-cms/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo proteger el panel de administración de WordPress, Drupal, Magento, PrestaShop y Joomla frente a ataques de fuerza bruta, credential stuffing y acceso no autorizado. El panel de administración de un CMS es el objetivo de mayor valor para un atacante: desde allí tiene control total sobre el sitio. Es también el punto que más ataques recibe de forma automatizada. Protegerlo correctamente es la primera línea de defensa de cualquier instalación empresarial. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El MFA es suficiente para proteger el panel de administración? A: Es la medida individual más efectiva, pero no elimina todos los riesgos. Los ataques de phishing dirigido pueden capturar OTPs en tiempo real (real-time phishing). Las sesiones robadas tras autenticación válida también eluden el MFA. El MFA es necesario pero no suficiente. Q: ¿Qué pasa si el administrador usa la misma contraseña en varios sitios? A: Es el escenario de credential stuffing: si las credenciales del administrador aparecen en una brecha de otro servicio, un atacante las probará automáticamente contra el panel del CMS. MFA mitiga este riesgo; la monitorización de credenciales comprometidas (servicios como HaveIBeenPwned para dominios corporativos) permite actuar antes de que ocurra el compromiso. --- ## Malware en CMS: por qué se producen reinfecciones y cómo evitarlas de forma definitiva URL: https://www.quantumsec.es/recursos/malware-en-cms-como-evitar-reinfecciones/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué los CMS comprometidos se reinfectan y cómo evitarlo: identificar el vector de entrada original, limpiar completamente y fortalecer la instalación tras un incidente. La reinfección es el patrón más frustrante de los compromisos de CMS: la web se limpia, vuelve a aparecer malware en días o semanas. Ocurre porque la limpieza superficial no elimina el vector de entrada original ni los mecanismos de persistencia que instaló el atacante. Esta guía explica el ciclo de reinfección y cómo romperlo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un escáner de malware es suficiente para confirmar que la web está limpia? A: No. Los escáneres automáticos detectan firmas conocidas de malware. Un atacante con acceso puede ofuscar el código para evadir las firmas o inyectarlo en ficheros legítimos en posiciones que los escáneres no analizan en profundidad. La verificación manual de ficheros modificados y logs de acceso es necesaria. Q: ¿Hay que notificar a los usuarios si la web fue comprometida? A: Depende del tipo de datos expuestos. Si el compromiso afectó a datos personales de usuarios, el RGPD obliga a notificar a la AEPD en 72 horas desde la detección y potencialmente a los afectados. Si solo fue inyección de malware sin acceso a datos, la obligación de notificación depende del análisis forense del alcance. --- ## Cómo elegir un proveedor de seguridad para tu CMS: criterios técnicos y señales de alerta URL: https://www.quantumsec.es/recursos/como-elegir-proveedor-seguridad-cms/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué criterios usar para elegir una empresa de ciberseguridad especializada en CMS, qué diferencia un proveedor técnico real de uno que usa herramientas automáticas, y qué preguntar antes de contratar. El mercado de "seguridad para CMS" mezcla perfiles muy distintos: agencias web que ofrecen "revisiones de seguridad" como servicio de mantenimiento, herramientas automáticas vendidas como soluciones completas, y empresas de ciberseguridad con capacidad técnica real de pentesting. Saber diferenciarlos es crítico para elegir bien. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Nuestra agencia web puede hacer el pentesting o necesitamos un tercero externo? A: Un análisis independiente por un tercero externo tiene más valor tanto técnicamente (perspectiva externa, sin sesgos sobre el código propio) como para cualquier proceso de cumplimiento o due diligence que lo requiera. Las certificaciones ISO 27001 y ENS requieren explícitamente que el pentesting sea realizado por un equipo diferente al que desarrolla y mantiene la aplicación. Q: ¿Cuánto debería costar una auditoría de seguridad CMS de calidad? A: Una auditoría técnica real con análisis manual para una instalación de complejidad media cuesta entre 2.000 y 8.000 € dependiendo del alcance, el número de extensiones y la complejidad del entorno. Ofertas por debajo de 500 € para "auditorías de seguridad" suelen ser escáneres automáticos sin análisis manual. --- ## Seguridad CMS para agencias web: gestionar la seguridad de múltiples sitios de clientes URL: https://www.quantumsec.es/recursos/seguridad-cms-agencias-web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo las agencias web pueden gestionar la seguridad de los CMS de sus clientes, qué responsabilidad asumen y cuándo externalizar la auditoría técnica a un especialista. Las agencias web que gestionan múltiples sitios de clientes sobre WordPress, Drupal, Magento o PrestaShop tienen una superficie de riesgo particular: un compromiso en un servidor compartido o en un proceso de actualización mal gestionado puede afectar a decenas de clientes al mismo tiempo. La gestión de la seguridad en este contexto requiere un enfoque sistemático. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podemos ofrecer seguridad CMS como servicio a nuestros clientes si externalizamos el pentesting? A: Sí. Es el modelo habitual de muchas agencias que quieren añadir seguridad a su portfolio sin contratar equipo interno de seguridad ofensiva. La agencia gestiona la relación con el cliente y la coordinación del proyecto; el proveedor de seguridad ejecuta el análisis y entrega el informe. Q: ¿Qué información necesita el proveedor de seguridad para auditar los sitios de mis clientes? A: Para el análisis inicial: URL del sitio, CMS y versión si se conoce, alcance acordado con el cliente y credenciales de acceso si se hace análisis autenticado. La agencia actúa como intermediaria para obtener el consentimiento del cliente y coordinar la disponibilidad del entorno. --- ## Seguridad de Google Workspace para empresas: guía completa URL: https://www.quantumsec.es/recursos/seguridad-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía completa de seguridad de Google Workspace para empresas: riesgos reales, configuración, apps OAuth, delegación de dominio y cumplimiento. Escrita por hackers éticos. Google Workspace concentra el correo, los documentos, el calendario y las identidades de toda tu empresa en un único entorno. Esa centralización lo convierte en uno de los objetivos más valiosos para un atacante: comprometer un Workspace mal configurado puede dar acceso a todo el negocio. Esta guía explica los riesgos reales, qué revisar y cómo proteger tu entorno más allá de los ajustes por defecto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Google Workspace es seguro por defecto? A: Tiene una base sólida, pero la configuración por defecto no es la más segura: prioriza la facilidad de uso. Para un entorno empresarial hay que endurecerla (2FA obligatorio, control de apps OAuth, restricción de compartición externa, etc.) siguiendo un marco como el CIS Benchmark. Q: ¿Cada cuánto debería revisar la seguridad de mi Workspace? A: Al menos una vez al año, y siempre tras cambios importantes (migración, crecimiento rápido, nuevas integraciones de terceros) o ante cualquier sospecha de acceso no autorizado, phishing o fraude del CEO. --- ## Hardening de Google Workspace: checklist de seguridad para empresas URL: https://www.quantumsec.es/recursos/hardening-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Checklist práctico para endurecer la seguridad de Google Workspace basado en el CIS Benchmark: administradores, 2FA, apps OAuth, Drive, Gmail, dispositivos y registros. La configuración por defecto de Google Workspace prioriza la facilidad de uso, no la seguridad máxima. Este checklist, alineado con el CIS Google Workspace Benchmark, recorre los ajustes de la consola de administración que más reducen tu superficie de ataque, ordenados por impacto. Empieza por las cuentas de administrador y la autenticación: es donde un atacante busca primero. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es suficiente con aplicar el checklist CIS? A: El CIS Benchmark es la mejor base de configuración, pero no sustituye a una auditoría ofensiva: revisa ajustes uno a uno, pero no encadena vectores ni reproduce lo que haría un atacante real (abuso de OAuth, persistencia, escalada). Lo ideal es endurecer con el CIS y validar el resultado con una auditoría. Q: ¿Cuántos súper administradores debería tener? A: Dos o menos, según la recomendación del CIS Benchmark. Tener pocos súper admins reduce la superficie de ataque de las cuentas más valiosas y facilita protegerlas con llaves de seguridad y supervisión reforzada. --- ## Cómo atacan los hackers un Google Workspace URL: https://www.quantumsec.es/recursos/como-atacan-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los vectores reales con los que se compromete un Google Workspace: phishing, consent phishing OAuth, persistencia en Gmail y abuso de delegación de dominio (DeleFriend). Entender cómo se ataca un Google Workspace es el primer paso para defenderlo. La mayoría de los compromisos no explotan un fallo de Google, sino la configuración y el comportamiento de la organización. Estos son los vectores que vemos una y otra vez en auditorías y respuestas a incidentes, explicados desde el punto de vista del atacante. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: Si cambio la contraseña, ¿echo al atacante? A: No necesariamente. Los tokens OAuth, las reglas de reenvío de Gmail, las contraseñas de aplicación y las delegaciones de dominio pueden mantener el acceso aunque cambies la contraseña. Tras un incidente hay que revocar sesiones y tokens, revisar reglas y filtros, y auditar las apps conectadas. Q: ¿El MFA me protege de todos estos ataques? A: El MFA resistente al phishing es esencial, pero no cubre todo: no detiene el consent phishing (donde el usuario autoriza una app maliciosa) ni el abuso de delegación de dominio, que no requiere las credenciales del usuario. Por eso hace falta endurecer la configuración y auditar el entorno. --- ## Cuánto cuesta una auditoría de seguridad de Google Workspace URL: https://www.quantumsec.es/recursos/cuanto-cuesta-auditoria-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué factores determinan el precio de una auditoría de seguridad de Google Workspace, rangos orientativos y qué debe incluir para que merezca la pena. El precio de una auditoría de Google Workspace depende sobre todo del alcance: no cuesta lo mismo una revisión de configuración frente al CIS Benchmark que una auditoría ofensiva completa que reproduce el comportamiento de un atacante. Esta guía explica de qué depende el coste, qué rangos manejar y qué debe incluir una auditoría para aportar valor real. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La auditoría incluye la remediación? A: La auditoría entrega el análisis, las evidencias y un plan de remediación priorizado con instrucciones concretas. La aplicación de los cambios la ejecuta vuestro equipo de IT siguiendo nuestras indicaciones, con soporte durante el proceso y un re-test opcional para verificar que los hallazgos críticos se han corregido. Q: ¿Cada cuánto conviene auditar el Workspace? A: Como mínimo una vez al año, y siempre tras cambios importantes (migraciones, crecimiento de usuarios, nuevas integraciones) o ante sospecha de incidente. Los entornos que conectan muchas apps de terceros se benefician de revisiones más frecuentes. --- ## Cómo revisar las apps de terceros conectadas a tu Google Workspace URL: https://www.quantumsec.es/recursos/apps-conectadas-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las apps OAuth conectadas a Google Workspace son un vector olvidado. Aprende a inventariarlas, clasificarlas por riesgo y restringirlas desde la consola de administración. Cada vez que un empleado pulsa "Permitir" en una aplicación de terceros, esa app obtiene acceso a parte de vuestro Google Workspace mediante OAuth. Con el tiempo se acumulan decenas de apps conectadas, muchas olvidadas y algunas con permisos peligrosos sobre Gmail y Drive. Esta guía te enseña a revisarlas y a recuperar el control desde la consola de administración. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: Si revoco una app, ¿echo al atacante de la cuenta? A: Revocar la app invalida su token de acceso, así que corta ese vector. Pero tras un incidente debes revisar también las reglas de reenvío de Gmail, las contraseñas de aplicación y las sesiones activas, porque el atacante puede haber dejado otros mecanismos de persistencia. Q: ¿Debería bloquear todas las apps de terceros? A: No hace falta bloquearlo todo, pero sí pasar a un modelo de lista de permitidos: bloquear por defecto y aprobar solo las apps que la organización necesita y considera de confianza. Es el equilibrio recomendado entre seguridad y productividad. --- ## RGPD y Google Workspace: guía de cumplimiento para empresas URL: https://www.quantumsec.es/recursos/google-workspace-rgpd/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo cumplir el RGPD usando Google Workspace: responsable y encargado, DPA, ubicación de datos, DLP, retención con Vault y derechos de los usuarios. Usar Google Workspace no te exime de cumplir el RGPD: tu empresa sigue siendo la responsable del tratamiento de los datos personales que se gestionan en Gmail, Drive o Meet. Google actúa como encargado del tratamiento, pero la configuración, los accesos y el control de los datos son tu responsabilidad. Esta guía explica qué necesitas para que tu uso de Workspace sea conforme al RGPD. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Google Workspace cumple el RGPD por mí? A: No. Google, como encargado del tratamiento, ofrece las herramientas y garantías (DPA, SCC, regiones de datos, cifrado), pero el cumplimiento del RGPD es responsabilidad de tu empresa: bases legales, información a los interesados, configuración segura, control de accesos y gestión de brechas. Q: ¿Puedo guardar los datos solo en la Unión Europea? A: En determinadas ediciones de Workspace puedes configurar regiones de datos para almacenar los datos en reposo en la UE. No cubre el 100 % de los metadatos ni todos los servicios, por lo que conviene documentar las transferencias y apoyarte en el DPA y las SCC de Google. Q: ¿Dónde está el acuerdo de tratamiento de datos oficial de Google Workspace? A: El documento oficial lo publica Google en cloud.google.com/terms/data-processing-addendum. Ahora se llama Cloud Data Processing Addendum (CDPA) — es el sucesor del antiguo Data Processing Amendment (DPA), y rige cómo Google procesa tus datos como encargado del tratamiento. Debes revisarlo, aceptarlo desde la consola de administración y conservar esa aceptación como evidencia de cumplimiento del RGPD. --- ## Google Workspace y NIS2: qué exige y cómo cumplir URL: https://www.quantumsec.es/recursos/google-workspace-nis2/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo encaja Google Workspace en NIS2: control de accesos y MFA, registro de eventos, gestión de incidentes y seguridad de la cadena de suministro (apps de terceros). Si tu empresa está sujeta a la directiva NIS2, tu entorno de correo y colaboración entra dentro del alcance. NIS2 no menciona Google Workspace por su nombre, pero exige medidas de seguridad técnicas y organizativas que se aplican directamente a cómo configuras y operas tu Workspace. Esta guía traduce esos requisitos a acciones concretas sobre tu entorno Google. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿NIS2 me obliga literalmente a auditar mi Google Workspace? A: La directiva no menciona auditorías de Workspace de forma explícita, pero exige medidas (control de accesos, MFA, registro, gestión de incidentes, riesgos de terceros) que en la práctica requieren revisar y endurecer tu entorno. Una auditoría es la forma más eficaz de demostrar que esas medidas están implementadas. Q: ¿Cómo sé si mi empresa está sujeta a NIS2? A: Depende del sector y del tamaño de la organización. Lo desarrollamos en nuestra guía de adaptación a NIS2; si tienes dudas, en una llamada inicial te ayudamos a determinar si estás dentro del alcance y qué implica para tu Workspace. --- ## OAuth consent phishing en Google Workspace URL: https://www.quantumsec.es/recursos/oauth-consent-phishing-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. El consent phishing engaña a los usuarios para autorizar apps OAuth maliciosas con acceso a Gmail y Drive. Cómo funciona, por qué el MFA no lo detiene y cómo proteger tu Workspace. El consent phishing es un ataque que no roba contraseñas: roba permisos. En lugar de engañarte para que reveles tu credencial, te engaña para que autorices una aplicación maliciosa que obtiene acceso a tu Gmail y tu Drive. Es uno de los vectores más efectivos contra Google Workspace porque esquiva el MFA y persiste en el tiempo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: Si cambio la contraseña, ¿se soluciona? A: No. El acceso del atacante depende del token OAuth concedido, no de la contraseña. Para cortarlo hay que revocar la autorización de la app (su token) desde la consola de administración, además de revisar reglas de reenvío y sesiones activas. Q: ¿Cómo bloqueo este ataque a nivel de organización? A: Configurando el control de acceso a las APIs en modo restringido: las apps de terceros quedan bloqueadas salvo las que apruebes en una lista de permitidos, y se bloquean las apps no verificadas. Así, aunque un empleado pulse "Permitir", la política de la organización impide el acceso. --- ## Domain-Wide Delegation: el riesgo crítico y peor auditado de Google Workspace URL: https://www.quantumsec.es/recursos/domain-wide-delegation-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. La delegación de dominio (DWD) permite impersonar a cualquier usuario de Google Workspace. Qué es DeleFriend, por qué es crítico y cómo auditar tus cuentas de servicio. La delegación de dominio (Domain-Wide Delegation o DWD) es una de las funciones más potentes —y más peligrosas— de Google Workspace. Permite que una cuenta de servicio actúe en nombre de cualquier usuario del dominio. Bien usada, habilita integraciones legítimas; mal controlada, es un camino directo a la toma de control total del entorno. El estudio "DeleFriend" puso el foco en lo fácil que es abusar de ella. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿DeleFriend sigue siendo explotable? A: El abuso de la delegación de dominio depende del diseño de la función y de la configuración de cada organización, no de un parche puntual. La mitigación está en tu lado: inventario de cuentas de servicio con DWD, mínimo privilegio de scopes, control de quién genera claves en GCP y monitorización. Q: ¿Cómo sé si tengo delegación de dominio activa? A: Se revisa en la consola de administración de Google (gestión de delegación de dominio) cruzándolo con las cuentas de servicio de GCP y sus permisos en IAM. Es precisamente uno de los puntos que cubrimos en una auditoría de Google Workspace. --- ## 2FA en Google Workspace: verificación en dos pasos y llaves de seguridad URL: https://www.quantumsec.es/recursos/2fa-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo configurar la verificación en dos pasos (2SV) y las llaves de seguridad o passkeys en Google Workspace, y por qué el SMS no basta para proteger tu empresa. La verificación en dos pasos es la medida que más ataques detiene en Google Workspace, pero no todos los métodos protegen igual. Esta guía explica cómo desplegar la 2SV en toda la organización y por qué las llaves de seguridad y las passkeys son muy superiores al SMS. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo obligar a todos los empleados a usar 2FA? A: Sí. Desde la consola de administración puedes aplicar la 2SV obligatoria a nivel de organización o de unidad organizativa, con un periodo de inscripción. Es la configuración recomendada para cualquier empresa. Q: ¿Qué pasa si un empleado pierde su llave o su teléfono? A: Se gestiona con códigos de respaldo generados previamente y con un proceso de recuperación controlado por el administrador. Conviene tener definido ese procedimiento antes de hacer la 2SV obligatoria. --- ## Súper administradores en Google Workspace: buenas prácticas de seguridad URL: https://www.quantumsec.es/recursos/super-admins-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo gestionar los súper administradores de Google Workspace con seguridad: cuántos tener, mínimo privilegio, roles delegados y protección reforzada. La cuenta de súper administrador es la llave maestra de tu Google Workspace: accede a todo, cambia cualquier configuración y crea o elimina usuarios. Es también el objetivo más codiciado por un atacante. Gestionarla bien es una de las decisiones de seguridad más importantes de tu entorno. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Por qué no usar una sola cuenta de súper admin para todo? A: Por dos motivos: si esa cuenta se pierde o se bloquea, te quedas sin acceso administrativo; y si se compromete, el atacante lo controla todo. Lo recomendable son dos cuentas protegidas y roles delegados para el resto del equipo. Q: ¿Cómo detecto si se crean nuevos administradores sin autorización? A: Configurando alertas en la consola de administración para los cambios de privilegios y revisando los registros de auditoría. La creación de un nuevo súper admin es uno de los eventos que siempre debería disparar una alerta. --- ## Seguridad de Google Drive para empresas: evita las fugas de datos URL: https://www.quantumsec.es/recursos/seguridad-google-drive-empresas/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo evitar fugas de datos en Google Drive: control de compartición externa, enlaces públicos, permisos, unidades compartidas y DLP. Guía para empresas. Google Drive es donde vive la información de tu empresa: contratos, datos de clientes, propiedad intelectual. Una compartición mal configurada puede exponer todo eso a cualquiera con un enlace. Esta guía explica cómo controlar la compartición y reducir el riesgo de fuga de datos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cómo encuentro los archivos compartidos públicamente? A: Con la herramienta de investigación y los informes de Drive de la consola de administración. En una auditoría de Workspace revisamos precisamente la compartición externa y los enlaces públicos con datos sensibles. Q: ¿Qué pasa con los archivos de un empleado que se va? A: Si están en "Mi unidad", pueden perderse o quedar huérfanos al eliminar la cuenta. Por eso conviene usar unidades compartidas para la información de empresa y transferir la propiedad de los datos como parte del offboarding. --- ## Reglas de reenvío maliciosas en Gmail: la persistencia que sobrevive al cambio de contraseña URL: https://www.quantumsec.es/recursos/reglas-reenvio-gmail-persistencia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las reglas de reenvío y los filtros maliciosos en Gmail son un mecanismo de persistencia tras un compromiso. Cómo detectarlas y prevenirlas en tu empresa. Cuando un atacante compromete una cuenta de Gmail, una de sus primeras acciones es crear una regla de reenvío o un filtro que le envíe copia del correo y oculte las alertas. Estas reglas persisten aunque cambies la contraseña, y son uno de los indicadores de compromiso más pasados por alto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo impedir el reenvío automático a direcciones externas? A: Sí. Desde la consola de administración puedes desactivar o restringir el reenvío automático de correo a direcciones externas a nivel de organización. Es una de las medidas más eficaces para cortar este vector de persistencia. Q: Tras un incidente, ¿qué debo revisar en Gmail? A: Las reglas de reenvío, los filtros, la delegación de buzón, las contraseñas de aplicación y las sesiones activas. Cualquiera de ellos puede mantener el acceso del atacante aunque hayas cambiado la contraseña. --- ## Offboarding seguro en Google Workspace: checklist al dar de baja empleados URL: https://www.quantumsec.es/recursos/offboarding-google-workspace/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Checklist de offboarding seguro en Google Workspace: suspender la cuenta, revocar sesiones y tokens, transferir datos y revisar reglas, delegaciones y dispositivos. Las cuentas de ex-empleados mal gestionadas son una superficie de ataque silenciosa: accesos que siguen activos, datos que se pierden y tokens que nunca se revocan. Este checklist cubre el offboarding seguro de un empleado en Google Workspace, paso a paso. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Debo borrar la cuenta inmediatamente? A: No. Lo recomendable es suspenderla primero, transferir los datos y, solo después, borrarla o archivarla según tu política de retención. Borrarla de golpe puede provocar la pérdida de información y de evidencias. Q: Si la cuenta estaba comprometida, ¿basta con suspenderla? A: Suspenderla corta el inicio de sesión, pero debes revisar también los tokens OAuth, las reglas de reenvío y las delegaciones, porque pueden mantener el acceso del atacante de forma independiente a la contraseña. --- ## Del Workspace a GCP: cómo escala un atacante en el ecosistema Google URL: https://www.quantumsec.es/recursos/workspace-a-gcp-escalada/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Google Workspace y Google Cloud están entrelazados. Cómo un atacante pivota de Workspace a GCP (y al revés) a través de identidades y delegación, y cómo auditarlo. Google Workspace rara vez está aislado: comparte identidades con Google Cloud (GCP) y con decenas de apps SaaS a través de SSO. Esa integración es cómoda, pero crea caminos de escalada que un atacante aprovecha para pasar del correo a la infraestructura. Esta guía explica esa frontera y cómo auditarla. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Auditar solo el Workspace es suficiente? A: No, si también usas Google Cloud. La escalada aprovecha precisamente la integración entre ambos: hay que auditar el IAM de GCP, las cuentas de servicio y las delegaciones de dominio además de la configuración del Workspace. Q: ¿Quién debería preocuparse por esto? A: Cualquier empresa que use Google Workspace y Google Cloud de forma conjunta, especialmente si tiene cuentas de servicio con delegación de dominio o integraciones automatizadas entre ambos entornos. --- ## Seguridad de Microsoft 365 para empresas: guía completa URL: https://www.quantumsec.es/recursos/seguridad-microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía de seguridad de Microsoft 365 para empresas: riesgos reales, Entra ID, acceso condicional, apps OAuth, Exchange y cumplimiento. Escrita por hackers éticos. Microsoft 365 concentra el correo, los documentos y las identidades de tu empresa en Entra ID, Exchange Online, SharePoint y Teams. Esa centralización lo convierte en un objetivo prioritario: comprometer un tenant mal configurado puede dar acceso a todo el negocio. Esta guía explica los riesgos reales y cómo proteger tu entorno más allá de los ajustes por defecto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Microsoft 365 es seguro por defecto? A: Tiene una base sólida, pero la configuración por defecto no es la más segura. Para un entorno empresarial hay que endurecerla (MFA resistente al phishing, acceso condicional, control de consentimientos OAuth, restricción de compartición externa) siguiendo un marco como el CIS Benchmark. Q: ¿Cada cuánto debería revisar la seguridad de Microsoft 365? A: Al menos una vez al año, y siempre tras cambios importantes (migración, crecimiento, nuevas integraciones) o ante cualquier sospecha de acceso no autorizado, phishing o fraude del CEO. --- ## Hardening de Microsoft 365: checklist de seguridad para empresas URL: https://www.quantumsec.es/recursos/hardening-microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Checklist para endurecer Microsoft 365 según el CIS Benchmark: administradores, MFA, acceso condicional, apps OAuth, Exchange, SharePoint y registros. La configuración por defecto de Microsoft 365 prioriza la facilidad de uso. Este checklist, alineado con el CIS Microsoft 365 Benchmark, recorre los ajustes que más reducen tu superficie de ataque, ordenados por impacto. Empieza por la identidad: Entra ID es donde un atacante busca primero. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es suficiente con el Secure Score y el CIS Benchmark? A: Son una excelente base de configuración, pero no sustituyen a una auditoría ofensiva: revisan ajustes uno a uno, pero no encadenan vectores ni reproducen lo que haría un atacante real (consentimiento ilícito, AiTM, robo de tokens). Q: ¿Qué es lo primero que debería endurecer? A: La identidad: MFA resistente al phishing, acceso condicional sin huecos (incluido el bloqueo de la autenticación heredada) y la protección de los administradores globales con PIM. Es donde un atacante busca primero. --- ## Cómo atacan los hackers Microsoft 365 URL: https://www.quantumsec.es/recursos/como-atacan-microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los vectores reales con los que se compromete un Microsoft 365: phishing AiTM y robo de tokens, consentimiento ilícito de apps, persistencia en Exchange y abuso de Entra ID. Entender cómo se ataca un Microsoft 365 es el primer paso para defenderlo. La mayoría de los compromisos no explotan un fallo de Microsoft, sino la configuración y el comportamiento de la organización. Estos son los vectores que vemos una y otra vez en auditorías y respuestas a incidentes. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: Si cambio la contraseña, ¿echo al atacante? A: No necesariamente. Los tokens de sesión robados, los consentimientos de apps OAuth, las reglas de reenvío y las credenciales añadidas a app registrations pueden mantener el acceso. Tras un incidente hay que revocar tokens y sesiones, revisar consentimientos y reglas, y auditar Entra ID. Q: ¿El MFA me protege de todo? A: El MFA resistente al phishing es esencial, pero el phishing AiTM puede robar la sesión y el consentimiento ilícito no requiere la contraseña. Por eso hace falta endurecer el acceso condicional, controlar las apps y auditar el entorno. --- ## Auditoría de Google Workspace vs Microsoft 365: qué cambia y qué se mantiene URL: https://www.quantumsec.es/recursos/auditoria-workspace-vs-microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diferencias entre auditar Google Workspace y Microsoft 365: identidad, apps OAuth, delegación, registros y vectores de ataque. Qué cambia y qué se mantiene. Google Workspace y Microsoft 365 resuelven el mismo problema —correo, identidad y colaboración en la nube— pero con arquitecturas distintas. Auditar uno u otro comparte principios, pero los vectores concretos y las herramientas cambian. Esta guía explica las diferencias para que sepas qué esperar de cada auditoría. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es más seguro Microsoft 365 o Google Workspace? A: Ninguno es intrínsecamente más seguro: ambos tienen una base sólida y los incidentes vienen casi siempre de la configuración del cliente, no de la plataforma. Lo que marca la diferencia es cómo de bien está endurecido y auditado tu tenant. Q: ¿Podéis auditar los dos entornos a la vez? A: Sí. Aplicamos la misma metodología ofensiva a Google Workspace y a Microsoft 365, y prestamos especial atención a las integraciones entre ambos y con la nube (GCP/Azure) cuando coexisten. --- ## Cuánto cuesta la ciberseguridad para una PYME en España (precios reales) URL: https://www.quantumsec.es/recursos/cuanto-cuesta-ciberseguridad-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Guía de precios reales de ciberseguridad para PYMEs en España: análisis de vulnerabilidades, pentesting, seguridad gestionada y cumplimiento NIS2. Una de las preguntas que más nos hacen los gerentes y responsables de IT de pequeñas y medianas empresas es: "¿cuánto me va a costar esto?". La respuesta honesta es que depende del alcance, pero en esta guía desglosamos los rangos de precio reales de los servicios de ciberseguridad más demandados por PYMEs españolas, para que puedas planificar tu presupuesto con datos concretos y no con promesas vagas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Hay ayudas o subvenciones para ciberseguridad en PYMEs? A: Sí. El Kit Digital (programa de digitalización para PYMEs y autónomos del Gobierno de España) incluye la categoría "Ciberseguridad" con bonos de hasta 6.000 € para empresas de 3 a 50 empleados. Además, algunas comunidades autónomas tienen líneas propias de ayuda a la seguridad digital. INCIBE ofrece también recursos y herramientas gratuitos para PYMEs. Q: ¿Puedo hacer una única inversión y estar protegido de forma permanente? A: No. La seguridad es un proceso continuo: aparecen nuevas vulnerabilidades, cambia la infraestructura y evolucionan las técnicas de ataque. Lo recomendable es un análisis de vulnerabilidades anual, un pentesting cada 1-2 años (o tras cambios importantes) y una revisión de políticas periódica. El servicio gestionado cubre la parte de monitorización continua. Q: ¿El precio incluye el IVA? A: Los rangos indicados en esta guía son precios de referencia sin IVA. Los precios finales dependen del alcance concreto de tu empresa. Solicita un presupuesto gratuito y sin compromiso: te lo enviamos en 24 horas. --- ## Qué es el TLPT (Threat-Led Penetration Testing) y por qué DORA lo exige URL: https://www.quantumsec.es/recursos/que-es-el-tlpt/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. TLPT (Threat-Led Penetration Testing): qué es, a qué entidades financieras obliga DORA y en qué se diferencia de un pentesting estándar. Guía técnica. El TLPT (Threat-Led Penetration Testing) es un ejercicio de red team basado en inteligencia de amenazas reales que el Reglamento DORA exige a las entidades financieras más críticas de la UE. No es un pentesting más exhaustivo: es una simulación de adversario completa —red team, no un análisis de vulnerabilidades acotado— diseñada para medir si tu organización detecta y responde a un ataque dirigido, no solo si tiene vulnerabilidades parcheables. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Mi empresa está obligada a hacer TLPT si ya cumplo DORA? A: No necesariamente. DORA aplica de forma general a un amplio abanico de entidades financieras, pero el TLPT solo es obligatorio para las designadas como críticas por la autoridad competente, con una cadencia mínima de cada 3 años. La mayoría de entidades sujetas a DORA no están obligadas a TLPT, pero sí a otras pruebas de resiliencia operativa menos exigentes. Q: ¿Puede QuantumSec ejecutar un TLPT completo? A: Un TLPT conforme a TIBER-EU requiere proveedores acreditados específicamente para las fases de threat intelligence y red team, coordinación con el supervisor y un alcance regulatorio concreto. Podemos ayudarte a preparar tu organización antes de un TLPT (red team previo, hardening, gap analysis frente al marco) y a interpretar tus obligaciones bajo DORA; para el ejercicio TLPT formal, te orientamos sobre el proceso de acreditación y el proveedor adecuado según tu perfil. --- ## Pentesting y seguro de ciberriesgo: qué exigen las aseguradoras en España URL: https://www.quantumsec.es/recursos/pentesting-seguro-ciberriesgo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué evidencia de pentesting piden las aseguradoras antes de emitir una póliza de ciberriesgo en España, cómo reduce la prima y qué pasa si sufres un incidente sin haberte auditado. Contratar un seguro de ciberriesgo sin haber auditado tu seguridad es cada vez más difícil: las aseguradoras han endurecido sus requisitos tras años de siniestralidad alta en ransomware y fraude del CEO, y piden evidencia técnica concreta antes de emitir una póliza o para aplicar mejores condiciones. Un pentesting reciente no es un trámite burocrático para el seguro — es la prueba que la aseguradora usa para estimar cuánto riesgo estás transfiriendo realmente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué antigüedad máxima acepta una aseguradora para un informe de pentesting? A: Depende de la aseguradora y del tamaño de la póliza, pero lo habitual es exigir un informe de los últimos 12 meses. Para pólizas de mayor cobertura o sectores regulados, algunas exigen cadencia anual obligatoria como condición de renovación. Q: ¿Sirve el mismo pentesting para varias aseguradoras o brokers? A: Sí, un informe técnico de pentesting con metodología reconocida (OWASP, PTES) y evidencias claras es válido para presentarlo a distintas aseguradoras o brokers durante el proceso de comparación de pólizas — no necesitas repetir la auditoría para cada cotización. --- ## GraphQL pentesting: vulnerabilidades comunes en APIs GraphQL URL: https://www.quantumsec.es/recursos/graphql-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Vulnerabilidades más comunes en APIs GraphQL: introspection expuesta, batching attacks, BOLA en resolvers y agotamiento de recursos. Cómo se auditan en un pentesting. GraphQL resuelve problemas reales de las APIs REST —over-fetching, under-fetching, versionado— pero introduce una superficie de ataque distinta que los tests pensados para REST no cubren bien. Un único endpoint, un esquema fuertemente tipado y consultas anidadas definidas por el cliente cambian por completo qué hay que probar y cómo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Basta con desactivar introspection en producción para estar seguro? A: No. Desactivar introspection reduce la superficie de reconocimiento fácil, pero no corrige los fallos de control de acceso ni los de agotamiento de recursos — un atacante con conocimiento parcial del esquema (por ejemplo, a través del código cliente) puede seguir explotando resolvers vulnerables sin necesidad de introspection. Q: ¿Un escáner automático detecta estas vulnerabilidades en GraphQL? A: Detecta parcialmente introspection expuesta y algunos patrones conocidos, pero BOLA en resolvers específicos y los límites de complejidad de query requieren entender la lógica de negocio de cada mutación y relación — es terreno de pentesting manual, no de escaneo automático. --- ## Seguridad de Power Platform y Power Automate: shadow IT en Microsoft 365 URL: https://www.quantumsec.es/recursos/seguridad-power-platform/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué Power Automate y Power Platform son un vector de shadow IT y fuga de datos en Microsoft 365, y cómo auditar conectores, flujos y políticas DLP. Power Platform —Power Automate, Power Apps, Power BI— permite a cualquier empleado con una cuenta de Microsoft 365 crear flujos de automatización y aplicaciones sin pasar por IT. Esa accesibilidad es también su mayor riesgo: cientos de flujos creados por usuarios no técnicos, conectados a datos corporativos, sin revisión de seguridad ni inventario centralizado. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Desactivar Power Platform por completo es una opción realista? A: Es posible pero rara vez recomendable: Power Platform aporta automatización legítima de valor real. La alternativa más práctica es gobernarlo —políticas DLP, entornos gestionados, revisión periódica de flujos— en vez de bloquearlo por completo, salvo en organizaciones con requisitos de aislamiento muy estrictos. Q: ¿Este riesgo aparece en una auditoría estándar de Microsoft 365? A: No siempre. Muchas auditorías de M365 se centran en identidades, correo y Drive/SharePoint, y dejan fuera Power Platform por ser una superficie menos conocida. Conviene pedirlo explícitamente como parte del alcance si tu organización lo usa activamente. --- ## Red Team vs Pentesting: diferencias clave y cómo elegir URL: https://www.quantumsec.es/recursos/red-team-vs-pentesting/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Red Team y pentesting no son lo mismo: alcance, objetivo, si el equipo defensivo lo sabe y qué mide cada uno. Cómo decidir cuál necesita tu empresa. Red Team y pentesting comparten herramientas y mentalidad ofensiva, pero responden a preguntas distintas y no son intercambiables. Confundirlos lleva a contratar el servicio equivocado: pedir un Red Team cuando lo que hace falta es un pentesting exhaustivo de una aplicación, o pedir un pentesting cuando la pregunta real es si el SOC detectaría un ataque real. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un Red Team sustituye al pentesting periódico? A: No. Son complementarios, no sustitutivos. El Red Team no busca maximizar la cobertura de vulnerabilidades —puede que ni siquiera toque ciertos sistemas si no forman parte del camino hacia el objetivo—, así que no reemplaza la higiene técnica continua que aporta el pentesting recurrente. Q: ¿Cuánto dura un ejercicio de Red Team frente a un pentesting? A: Un pentesting suele durar entre 1 y 3 semanas según el alcance. Un Red Team se extiende habitualmente varias semanas o incluso meses, porque prioriza el sigilo sobre la velocidad: moverse despacio y evitar detección es parte del objetivo del ejercicio. --- ## Purple Team: cuándo combinar Red Team y Blue Team URL: https://www.quantumsec.es/recursos/purple-team-red-team-blue-team/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es el Purple Teaming, en qué se diferencia de un Red Team encubierto y cuándo tiene más sentido colaborar en directo con tu equipo de detección. El Purple Team no es un tercer equipo: es una forma de trabajar en la que el equipo rojo (atacante) y el equipo azul (defensor) colaboran en tiempo real, en vez de operar de forma encubierta y separada como en un Red Team clásico. El objetivo cambia de "medir si nos detectáis" a "mejorar juntos vuestra detección lo más rápido posible". Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El Purple Team requiere el mismo tiempo que un Red Team? A: Normalmente menos y de forma más predecible: al ser colaborativo y dirigido a técnicas concretas (no a un objetivo libre por descubrir), una sesión de Purple Team puede acotarse a días en vez de semanas, cubriendo un conjunto específico de TTPs de MITRE ATT&CK. Q: ¿Podemos hacer primero un Red Team y luego un Purple Team? A: Es la secuencia más habitual y recomendable: el Red Team revela qué técnicas no detectasteis; el Purple Team posterior trabaja específicamente esas técnicas en modo colaborativo hasta cerrar el hueco, con validación inmediata de que la mejora funciona. --- ## Fases de un ejercicio de Red Team: cómo funciona de principio a fin URL: https://www.quantumsec.es/recursos/fases-de-un-red-team/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las 5 fases de un ejercicio de Red Team real: definición de objetivo, inteligencia de amenazas, intrusión inicial, post-explotación y cierre con el equipo azul. Un ejercicio de Red Team no es un pentesting más largo: es un proceso estructurado en fases distintas, cada una con objetivos y riesgos propios, que puede extenderse varias semanas o meses. Entender cada fase ayuda a fijar expectativas realistas antes de contratarlo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto dura un ejercicio de Red Team completo, de principio a fin? A: Habitualmente entre 4 y 12 semanas, dependiendo de la complejidad del objetivo, el tamaño de la organización y el nivel de sigilo requerido. La fase de post-explotación suele ser la más larga porque prioriza no ser detectado sobre la velocidad. Q: ¿Qué pasa si en la fase 3 no se consigue ningún punto de apoyo inicial? A: Es un resultado legítimo que también aporta información valiosa: significa que el perímetro expuesto y la concienciación frente a phishing son sólidos. En ese caso se suele acordar con el cliente un punto de partida asistido (assumed breach) para poder evaluar las fases posteriores igualmente. --- ## Seguridad de Microsoft Teams: acceso externo, guest sharing y federación URL: https://www.quantumsec.es/recursos/seguridad-microsoft-teams/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Riesgos de seguridad en Microsoft Teams: acceso externo, guest sharing, políticas de federación y comunicación no gestionada. Cómo auditarlos y endurecerlos. Teams dejó de ser solo un chat corporativo: concentra reuniones, archivos, canales y automatizaciones conectadas a SharePoint y Entra ID. Su configuración por defecto favorece la colaboración externa, y eso convierte el acceso externo, los invitados y la federación en una de las superficies peor auditadas de Microsoft 365. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Debo desactivar por completo el acceso externo en Teams? A: No suele ser realista si tu empresa colabora con clientes o proveedores. Lo recomendable es sustituir "todos los dominios" por una lista explícita de dominios permitidos y revisarla periódicamente, en lugar de dejar la federación abierta a cualquier organización. Q: ¿Los invitados de Teams cuentan como licencias de Microsoft 365? A: No, los invitados no consumen licencia, lo que reduce la fricción para añadirlos —y explica por qué se acumulan sin control. Precisamente por eso necesitan una política de revisión y expiración independiente del ciclo de altas y bajas de empleados. --- ## Seguridad de SharePoint Online: riesgos de la compartición externa URL: https://www.quantumsec.es/recursos/seguridad-sharepoint-online/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Riesgos de la compartición externa en SharePoint Online: enlaces "cualquiera con el enlace", herencia de permisos y fuga de datos. Cómo auditarlos. SharePoint Online es donde vive la mayoría de los documentos corporativos de un tenant Microsoft 365, y su modelo de compartición está diseñado para que compartir sea lo más fácil posible. Esa facilidad es también su principal riesgo: enlaces "cualquiera con el enlace" y permisos heredados que nadie revisa acaban exponiendo información sensible fuera de la organización. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es seguro usar enlaces "cualquiera con el enlace" alguna vez? A: Solo para contenido genuinamente público, con caducidad configurada. Para cualquier documento con información de negocio, es preferible compartir con personas o grupos específicos (autenticados), que dejan un registro claro de quién tiene acceso y permiten revocarlo de forma granular. Q: ¿Cómo sé si un sitio tiene permisos "rotos"? A: El Centro de administración de SharePoint y herramientas como el informe de acceso de archivos permiten identificar elementos con permisos únicos (rotos respecto al sitio). Es una de las primeras comprobaciones en cualquier auditoría de SharePoint, porque suele revelar accesos que nadie recuerda haber concedido. --- ## Entra ID: roles privilegiados y Privileged Identity Management (PIM) URL: https://www.quantumsec.es/recursos/entra-id-pim-roles-privilegiados/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo gestionar roles privilegiados en Entra ID con Privileged Identity Management (PIM): acceso just-in-time, revisión de acceso y errores frecuentes. Un administrador global de Entra ID permanente es uno de los objetivos más valiosos para un atacante: comprometer esa cuenta abre la puerta a todo el tenant. Privileged Identity Management (PIM) existe para eliminar precisamente ese riesgo, convirtiendo los roles privilegiados de permanentes en temporales y activados bajo demanda —pero solo si se configura correctamente. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿PIM está incluido en todas las licencias de Microsoft 365? A: No. PIM requiere licencias Entra ID P2 (incluidas en Microsoft 365 E5 o como add-on). Es una inversión que se justifica fácilmente frente al coste de un compromiso de administrador global, pero conviene verificar la cobertura de licencias antes de planificar el despliegue. Q: ¿Cuántos administradores globales debería tener mi organización? A: Microsoft recomienda entre 2 y 4, nunca menos de 2 (para evitar bloqueo si uno pierde acceso) ni muchos más de 4. Cualquier cifra de dos dígitos es una señal de que los roles se han asignado por comodidad en lugar de por necesidad real, y debería revisarse. --- ## Conditional Access: los errores de configuración más comunes URL: https://www.quantumsec.es/recursos/errores-conditional-access/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Los errores más frecuentes al configurar Conditional Access en Entra ID: huecos de cobertura, exclusiones olvidadas y políticas sin probar. Cómo evitarlos. Conditional Access es el control de acceso más potente de Entra ID, pero también uno de los más fáciles de configurar mal de forma silenciosa: una política que parece correcta puede tener un hueco que la deja sin efecto para un subconjunto de usuarios o escenarios, y ese hueco no se descubre hasta que alguien lo explota. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Basta con tener una política de MFA para todos los usuarios? A: No. Una sola política amplia de MFA no cubre autenticación heredada, no diferencia por riesgo de sesión ni por dispositivo, y no protege frente a robo de tokens. Un diseño robusto combina varias políticas específicas: bloqueo de legacy auth, MFA resistente al phishing en cuentas críticas, y políticas basadas en riesgo (Identity Protection). Q: ¿Cómo pruebo una política sin arriesgarme a bloquear a usuarios legítimos? A: Desplégala primero en modo "solo informe" sobre un grupo piloto reducido, revisa los registros de inicio de sesión durante al menos una o dos semanas, y usa la herramienta "What If" de Entra ID para simular su efecto antes de activarla en producción para todos los usuarios. --- ## Azure AD Connect: ataques de sincronización híbrida de on-premise a la nube URL: https://www.quantumsec.es/recursos/ataques-azure-ad-connect/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo un atacante abusa de Azure AD Connect para escalar de on-premise a la nube: cuenta MSOL, ataques a AD FS y compromiso de la sincronización híbrida. Azure AD Connect es el puente que sincroniza tu Active Directory local con Entra ID, y como todo puente entre dos entornos, es también el camino que un atacante recorre para escalar de uno a otro. Comprometer el servidor de sincronización o su cuenta de servicio puede dar acceso completo a Entra ID desde una máquina on-premise. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Migrar a Azure AD Cloud Sync elimina este riesgo? A: Lo reduce significativamente, pero no lo elimina del todo: Cloud Sync usa agentes ligeros con menos permisos que la instalación clásica de Azure AD Connect, pero sigue existiendo un puente entre on-premise y la nube que requiere el mismo nivel de aislamiento y monitorización. Q: ¿Este riesgo aplica si mi empresa es 100% cloud, sin Active Directory local? A: No. Si no tienes un Active Directory on-premise ni sincronización híbrida, este vector concreto no te afecta. Es un riesgo específico de organizaciones en transición o en modelo híbrido permanente, que siguen siendo mayoría en el tejido empresarial español. --- ## Seguridad de Microsoft Copilot: gobernanza y riesgos en Microsoft 365 URL: https://www.quantumsec.es/recursos/seguridad-microsoft-copilot/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Riesgos de seguridad de Microsoft 365 Copilot: herencia de permisos, oversharing preexistente y gobernanza de agentes de Copilot Studio. Cómo auditarlo. Microsoft 365 Copilot no crea vulnerabilidades nuevas por sí mismo: hereda y expone los permisos que ya existían en tu tenant. El problema es que lo hace a una velocidad y con una capacidad de búsqueda que convierte cualquier fallo de permisos previo —un enlace olvidado, una carpeta mal configurada— en un riesgo mucho más visible y fácil de explotar por cualquier usuario con acceso a Copilot. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Copilot puede filtrar información a la que un usuario no debería tener acceso? A: No debería, porque respeta los permisos existentes de Microsoft Graph. El riesgo real no es que Copilot conceda acceso nuevo, sino que haga trivialmente visible contenido que ya era técnicamente accesible por un fallo de permisos previo que nadie había detectado. Q: ¿Debería auditar mi tenant antes de activar Copilot para toda la empresa? A: Sí, es la recomendación estándar. Activar Copilot sin una limpieza previa de oversharing en SharePoint, OneDrive y Teams multiplica el impacto de cualquier permiso mal configurado que ya existiera, en lugar de crear el problema desde cero. --- ## Offboarding seguro en Microsoft 365: checklist al dar de baja empleados URL: https://www.quantumsec.es/recursos/offboarding-microsoft-365/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Checklist de offboarding seguro en Microsoft 365: revocar sesiones y tokens, transferir buzón y OneDrive, revisar reglas, delegaciones y dispositivos. Una cuenta de ex-empleado mal gestionada en Microsoft 365 sigue teniendo acceso a correo, archivos y aplicaciones federadas mucho después de que la persona se haya ido, si el proceso de baja se limita a desactivar el inicio de sesión. Este checklist cubre el offboarding seguro de un empleado en Microsoft 365, paso a paso. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Basta con desactivar la cuenta en Entra ID el día de la baja? A: No es suficiente por sí solo. Desactivar la cuenta bloquea nuevos inicios de sesión, pero no revoca sesiones y tokens ya activos, ni elimina reglas de reenvío, delegaciones o consentimientos de apps OAuth que puedan mantener acceso independiente a la contraseña o al estado de la cuenta. Q: ¿Qué pasa si el empleado tenía Conditional Access con exclusión propia? A: Hay que revisar y eliminar cualquier exclusión de Conditional Access asociada a la cuenta como parte del offboarding, porque una exclusión olvidada puede dejar a esa identidad sin las protecciones de MFA o de dispositivo gestionado que sí aplican al resto de la organización. --- ## Reglas de reenvío maliciosas en Exchange Online: la base del fraude del CEO URL: https://www.quantumsec.es/recursos/reglas-reenvio-exchange-bec/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo las reglas de reenvío en Exchange Online se usan para el fraude del CEO (BEC): persistencia tras el compromiso, ocultación y cómo detectarlas. Casi todos los casos de fraude del CEO (Business Email Compromise) que investigamos comparten un mismo elemento técnico: una regla de reenvío o de bandeja de entrada creada por el atacante tras comprometer una cuenta de Exchange Online, que le permite vigilar las conversaciones de facturación durante semanas antes de intervenir en el momento oportuno. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El MFA me protege del fraude del CEO basado en reglas de reenvío? A: Ayuda a evitar el compromiso inicial de la cuenta, pero no es infalible: el phishing AiTM puede robar la sesión saltándose el MFA, y el consentimiento OAuth ilícito ni siquiera requiere la contraseña. Por eso la detección de reglas de reenvío anómalas es una capa de defensa independiente y necesaria. Q: ¿Cómo distingo una regla de reenvío legítima de una maliciosa? A: Las reglas legítimas suelen reenviar a direcciones corporativas conocidas por un motivo documentado (baja temporal, delegación). Cualquier regla que reenvíe a un dominio externo desconocido, que oculte o elimine automáticamente correos de alerta, o que se haya creado sin conocimiento del usuario, debe tratarse como sospechosa y revisarse de inmediato. --- ## Seguridad OT/ICS: por qué el pentesting de IT no basta para entornos industriales URL: https://www.quantumsec.es/recursos/seguridad-ot-ics-pentesting-it/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué los entornos industriales OT/ICS necesitan un enfoque de seguridad distinto al pentesting de IT convencional: disponibilidad, protocolos y riesgo físico. Aplicar la misma metodología de pentesting de IT a un entorno OT/ICS es, en el mejor de los casos, ineficaz, y en el peor, peligroso. Las redes industriales priorizan la disponibilidad continua y la seguridad física sobre la confidencialidad, usan protocolos que un escáner de IT no entiende, y un fallo en un sistema de control puede tener consecuencias físicas, no solo una brecha de datos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo pedir el mismo pentesting que hago en mi red IT para mi planta industrial? A: No es recomendable. Un escaneo o pentesting pensado para IT puede provocar caídas de disponibilidad en dispositivos OT frágiles, e ignora protocolos y riesgos específicos (Modbus, PLCs, seguridad física) que un enfoque IT no cubre. Se necesita una metodología adaptada, con foco en no interrumpir la producción. Q: ¿Este servicio sustituye a un pentesting IoT? A: No, son complementarios: el pentesting de dispositivos IoT y hardware evalúa la seguridad de dispositivos conectados individuales (firmware, comunicaciones, hardware físico), mientras que una evaluación OT/ICS analiza el entorno industrial completo —segmentación, protocolos, accesos remotos— en el que esos dispositivos operan. --- ## Pentesting de pipelines CI/CD: qué hay que auditar URL: https://www.quantumsec.es/recursos/pentesting-pipelines-cicd/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué se audita en un pentesting de pipelines CI/CD: secretos expuestos, permisos de runners, dependencias y integridad de la cadena de suministro de software. Un pipeline de CI/CD comprometido no da acceso a una sola aplicación: da acceso a la fábrica que construye y despliega todas las aplicaciones. Es una de las superficies con mayor impacto potencial en cualquier organización de desarrollo de software, y sin embargo rara vez se audita con el mismo rigor que la propia aplicación que produce. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un pentesting de pipelines CI/CD sustituye a una auditoría de código fuente? A: No, son complementarios. La auditoría de código fuente revisa la aplicación en sí (SAST, revisión manual de lógica y vulnerabilidades); el pentesting de pipelines revisa la infraestructura que construye y despliega esa aplicación —secretos, permisos, integridad de dependencias—. Ambas superficies importan porque un atacante puede elegir la más débil. Q: ¿Qué plataformas de CI/CD cubre este tipo de evaluación? A: La metodología aplica a cualquier plataforma —GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure DevOps— porque los riesgos (secretos expuestos, permisos de runners, integridad de dependencias) son conceptualmente los mismos, aunque los detalles de configuración cambien entre plataformas. --- ## DevSecOps: cómo integrar seguridad ofensiva sin frenar los releases URL: https://www.quantumsec.es/recursos/devsecops-seguridad-ofensiva-desarrollo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo integrar pentesting y seguridad ofensiva en el ciclo DevSecOps sin frenar releases: SAST/DAST en pipeline, pentesting continuo y gates de seguridad. La objeción más habitual a integrar seguridad ofensiva en un ciclo DevSecOps es que "frena los releases". Es cierta si se integra mal: un pentesting completo de varias semanas no puede vivir dentro de un pipeline que despliega varias veces al día. Pero la alternativa no es elegir entre velocidad y seguridad, es distribuir la seguridad ofensiva en distintas capas con distinta cadencia. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesito parar los despliegues para hacer un pentesting? A: No necesariamente. Un pentesting manual puede ejecutarse sobre un entorno de staging equivalente a producción, en paralelo al desarrollo normal, y solo bloquear el despliegue de la funcionalidad concreta si aparece un hallazgo crítico —no todo el pipeline de la organización. Q: ¿Con qué frecuencia debería auditarse una aplicación con releases continuos? A: Depende del ritmo de cambio, pero una combinación habitual es: SAST/DAST en cada commit, revisión bajo demanda de features de alto riesgo antes de su lanzamiento, y un pentesting manual completo al menos una vez al año o tras cambios arquitectónicos importantes. --- ## Qué es el OSINT y cómo se utiliza en ciberinteligencia empresarial URL: https://www.quantumsec.es/recursos/que-es-el-osint/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. OSINT (Open Source Intelligence): qué es, qué fuentes utiliza y cómo se aplica en ciberinteligencia empresarial. Diferencias con CTI y límites legales. OSINT (Open Source Intelligence, inteligencia de fuentes abiertas) es la disciplina de recopilar y analizar información disponible públicamente —redes sociales, registros públicos, metadatos, código fuente, motores de búsqueda especializados— para obtener conclusiones útiles sobre una persona, empresa o infraestructura. En ciberseguridad es la base sobre la que se construye la ciberinteligencia (CTI): antes de poder anticiparte a una amenaza, necesitas saber qué información sobre tu organización ya es visible para un atacante. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El OSINT es legal? A: Sí, siempre que se limite a información genuinamente pública y no requiera sortear ninguna barrera de acceso (login, autenticación, exploits). El uso posterior de esa información —especialmente si incluye datos personales— debe respetar la normativa de protección de datos aplicable. Q: ¿Qué diferencia hay entre OSINT y hacking? A: El hacking implica acceder a sistemas o datos protegidos, típicamente sin autorización si es malicioso. El OSINT nunca cruza esa barrera: trabaja exclusivamente con información ya accesible públicamente. Son fases distintas de un mismo ejercicio de seguridad ofensiva: el OSINT es reconocimiento: no hay explotación. Q: ¿Necesito herramientas especiales para hacer OSINT? A: Existen herramientas y motores de búsqueda especializados (Shodan, Censys, theHarvester, buscadores de metadatos) que aceleran mucho el proceso, pero el punto de partida —buscadores generales, redes sociales, WHOIS— es de acceso libre. El valor real está en el criterio para correlacionar la información, no solo en la herramienta. --- ## Pentesting de red interna y perimetral: qué cubre y cuándo lo necesita tu empresa URL: https://www.quantumsec.es/recursos/pentesting-de-red-interna-y-perimetral/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué cubre un pentesting de red interna y perimetral, qué vulnerabilidades detecta y cuándo lo necesita tu empresa. Guía técnica y práctica. Un pentesting de red evalúa la seguridad de tu infraestructura de red —perimetral (lo que da la cara a Internet) e interna (lo que hay detrás del firewall)— simulando lo que haría un atacante real una vez dentro. A diferencia de un escaneo automatizado, confirma manualmente qué configuraciones erróneas son explotables, hasta dónde puede moverse un atacante lateralmente y qué activos críticos quedarían expuestos si el perímetro cae. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El pentesting de red interna requiere acceso físico a mis oficinas? A: No necesariamente. Puede ejecutarse de forma remota mediante un dispositivo o VPN desplegado en tu red, o de forma presencial si se prefiere. Ambos enfoques son habituales; se acuerda según la arquitectura de tu red y tus preferencias. Q: ¿Con qué frecuencia debería repetirse un pentesting de red? A: Como mínimo una vez al año, y siempre que haya cambios significativos en la infraestructura (nueva sede, fusión, migración de proveedor de red). Si estás sujeto a NIS2 o al ENS, la normativa puede exigir una cadencia concreta según tu categorización. Q: ¿Un pentesting de red interna interfiere con la operativa diaria? A: El objetivo es que no. Se acuerda una ventana de ejecución y, si se identifica algo de riesgo inmediato para la disponibilidad, se comunica antes de proceder. La mayoría de pruebas son pasivas o de bajo impacto operativo. --- ## Pentesting iOS vs Android: diferencias clave y qué necesita tu app URL: https://www.quantumsec.es/recursos/pentesting-ios-vs-android/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Diferencias entre el pentesting de apps iOS y Android: vectores de ataque, metodología y cómo elegir el alcance si tu app está en ambas plataformas. iOS y Android comparten estándar de auditoría —el OWASP MASVS/MASTG— pero tienen arquitecturas, modelos de permisos y vectores de ataque distintos. Auditar una app en ambas plataformas no es repetir el mismo trabajo dos veces: cada sistema operativo expone superficies de ataque diferentes que requieren metodología y herramientas específicas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuesta lo mismo auditar iOS que Android? A: El esfuerzo suele ser similar cuando ambas apps tienen una complejidad comparable, aunque puede variar según la superficie expuesta de cada binario: una app Android con muchos componentes exportados o una app iOS con mecanismos de ofuscación complejos pueden requerir más tiempo en su plataforma respectiva. Q: ¿Si mi app es híbrida (React Native, Flutter) necesito auditar ambas plataformas igualmente? A: Sí. Aunque el código de negocio esté compartido en un framework multiplataforma, cada compilación nativa (IPA para iOS, APK/AAB para Android) empaqueta ese código de forma distinta y usa mecanismos de almacenamiento y comunicación nativos propios de cada sistema operativo, que pueden introducir vulnerabilidades específicas de la plataforma pese a compartir la misma base de código. Q: ¿El pentesting móvil incluye el backend/API que consume la app? A: El pentesting móvil se centra en el cliente (la app instalada en el dispositivo), pero como la app siempre se comunica con una API, es habitual y recomendable incluir también un pentesting de esa API en el mismo alcance para cubrir el flujo completo de datos. --- ## Ciberseguridad para pymes de la Comunidad Valenciana: sectores, riesgos y qué exige la normativa URL: https://www.quantumsec.es/recursos/ciberseguridad-pymes-comunidad-valenciana/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Ciberseguridad para pymes de la Comunitat Valenciana: sectores más expuestos, riesgos habituales y qué exige la normativa (NIS2, ENS). Guía práctica. La Comunitat Valenciana tiene un tejido empresarial denso en pyme industrial, agroalimentaria y logística —desde la cerámica de Castellón hasta el calzado de la zona de Elche-Alicante, pasando por el entorno logístico del Puerto de Valencia—. Ese perfil, con muchas empresas interconectadas como proveedoras entre sí, hace que un incidente de seguridad en una pyme pueda propagarse por su cadena de suministro. Esta guía repasa qué riesgos son más relevantes para el tejido valenciano y qué exige realmente la normativa vigente, sin depender del tamaño de la empresa para tomárselo en serio. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Las pymes también están obligadas por NIS2? A: NIS2 aplica principalmente a medianas y grandes empresas (más de 50 empleados o más de 10 millones de euros de facturación) en sectores regulados. Sin embargo, una pyme puede quedar incluida igualmente si actúa como proveedor crítico de una entidad esencial o importante, con independencia de su tamaño individual. Q: ¿Hay ayudas para digitalización y ciberseguridad disponibles para empresas de la Comunitat Valenciana? A: Existen programas de ayuda a la digitalización a nivel estatal (como el Kit Digital) y, en ocasiones, convocatorias específicas a nivel autonómico. Las condiciones y la disponibilidad cambian con frecuencia, por lo que lo más fiable es consultar las convocatorias vigentes en el momento en que se necesiten, en lugar de asumir una ayuda concreta. Q: ¿Importa si mi empresa está en Valencia ciudad o en otra zona de la Comunitat (Castellón, Alicante)? A: No, para la ejecución del servicio. Un pentesting, auditoría o programa de ciberinteligencia se presta de forma remota en su mayor parte, con reuniones presenciales o por videollamada según convenga, independientemente de en qué provincia de la Comunitat Valenciana se ubique la empresa. --- ## MSSP vs equipo de seguridad interno: cuándo externalizar la ciberseguridad URL: https://www.quantumsec.es/recursos/mssp-vs-equipo-de-seguridad-interno/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. MSSP vs equipo de seguridad interno: qué cubre cada modelo, cuándo tiene sentido externalizar y cuándo construir equipo propio. Guía para decidir. Un MSSP (Managed Security Service Provider) presta de forma externalizada las funciones de seguridad continua —monitorización, gestión de vulnerabilidades, respuesta a incidentes— que de otro modo requerirían montar un equipo interno con CISO, analistas y herramientas propias. Ninguno de los dos modelos es superior en abstracto: la decisión correcta depende del tamaño de tu empresa, tu presupuesto y cuánto control directo necesitas sobre la función de seguridad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo empezar con un MSSP y pasar a equipo interno más adelante? A: Sí, es una transición habitual a medida que la empresa crece. Un MSSP bien planteado deja documentación y procesos claros que facilitan, si llega el momento, construir un equipo interno sobre una base ya madura en vez de empezar de cero. Q: ¿Un MSSP sustituye completamente a un CISO? A: Puede cubrir la función mediante un CISO virtual —asesoría estratégica y supervisión del programa de seguridad—, pero no sustituye la necesidad de que alguien dentro de la empresa tenga la responsabilidad última y la autoridad para tomar decisiones que afectan al negocio. Q: ¿Qué pasa si ya tengo un analista de seguridad pero no cobertura 24/7? A: Es exactamente el escenario típico del modelo híbrido: tu analista interno gestiona el día a día y las decisiones de negocio, y el MSSP cubre la monitorización fuera de horario y la primera respuesta ante incidentes que ocurren cuando tu equipo no está disponible. --- ## Vulnerabilidades más comunes en sistemas SAP: guía técnica URL: https://www.quantumsec.es/recursos/vulnerabilidades-comunes-en-sap/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Las vulnerabilidades más habituales en entornos SAP: cuentas por defecto, interfaz RFC/Gateway, segregación de funciones rota, código ABAP y parcheo. La mayoría de los compromisos de SAP no explotan un fallo exótico: explotan configuraciones conocidas desde hace años que nadie revisó a fondo. Esta guía repasa las vulnerabilidades más habituales que encontramos al auditar entornos SAP en producción, de la más sencilla de corregir a la que más impacto de negocio suele tener. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es lo mismo una revisión de SoD que un pentest SAP? A: No. Una revisión de SoD confirma, sobre el papel, qué combinaciones de permisos tienen los usuarios. Un pentest SAP confirma si esas combinaciones —y otras vulnerabilidades técnicas como el Gateway, el código ABAP o el estado de parcheo— son explotables de verdad, y demuestra el impacto real de un compromiso. Q: ¿Sigue siendo relevante la vulnerabilidad RECON (CVE-2020-6287)? A: El propio fallo lleva parcheado desde 2020, pero sigue siendo relevante como caso de referencia: meses después de su publicación seguía habiendo sistemas sin parchear siendo escaneados activamente por atacantes, lo que ilustra el riesgo real de acumular SAP Security Notes sin aplicar. Q: ¿Con qué frecuencia debería auditarse un sistema SAP? A: Como mínimo una vez al año, y siempre tras cambios relevantes: una migración a S/4HANA, una ampliación significativa de módulos o roles, o un incidente que haga sospechar de un compromiso o fraude interno. --- ## Formación y concienciación en ciberseguridad para empleados: guía práctica URL: https://www.quantumsec.es/recursos/formacion-concienciacion-ciberseguridad-empleados/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué debe incluir un programa de formación y concienciación en ciberseguridad para empleados, con qué frecuencia repetirlo y cómo medir si funciona. El eslabón más débil de la seguridad de una empresa casi nunca es la tecnología: es la persona que hace clic en el enlace equivocado un día cualquiera. La formación técnica del equipo de IT no llega a la persona de contabilidad que recibe un correo de "el CEO" pidiendo una transferencia urgente. Un programa de concienciación bien diseñado no es un curso online que se hace una vez al año para cumplir el expediente: es un proceso continuo que cambia comportamientos reales. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Basta con un curso online una vez al año? A: No. Genera una mejora temporal que se diluye en semanas. La combinación de sesiones formativas periódicas con simulaciones de phishing recurrentes da resultados mucho más sólidos y sostenidos en el tiempo. Q: ¿Qué diferencia hay entre formación técnica y concienciación en seguridad? A: La formación técnica enseña habilidades (cómo configurar un firewall, cómo revisar un log). La concienciación busca cambiar comportamiento en personas sin perfil técnico: reconocer un intento de phishing, verificar una solicitud de pago inusual, no reutilizar contraseñas. Son complementarias, pero se diseñan y miden de forma distinta. Q: ¿Cómo se mide el retorno de invertir en un programa de concienciación? A: El indicador más directo es la evolución de la tasa de reporte y de clics en simulaciones de phishing a lo largo del tiempo. De forma indirecta, también se refleja en la reducción de incidentes reales gestionados por el equipo de seguridad que tienen su origen en un error humano. --- ## Auditoría de seguridad de Microsoft Exchange Online URL: https://www.quantumsec.es/recursos/auditoria-seguridad-microsoft-exchange/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Auditoría de seguridad de Microsoft Exchange: permisos delegados, reglas de reenvío, conectores y SPF/DKIM/DMARC. Detectamos accesos indebidos y fraude BEC. El correo corporativo es, a la vez, el canal de comunicación más usado de la empresa y uno de los objetivos favoritos de los atacantes: por ahí pasa el fraude del CEO, el phishing dirigido y buena parte del movimiento lateral tras un compromiso de cuenta. Una auditoría de Exchange Online va más allá de revisar si hay MFA activado: analiza permisos delegados, reglas de transporte, conectores y registros de auditoría para confirmar qué podría hacer realmente un atacante con acceso a un buzón. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesitáis acceso de administrador global para auditar Exchange? A: No. Basta con un rol de administrador de Exchange de solo lectura o un rol delegado con permisos de auditoría. Para pruebas activas concretas se acuerda el alcance de antemano. Q: ¿Esta auditoría sustituye a la auditoría general de Microsoft 365? A: No, la complementa. Si nunca habéis auditado el tenant, recomendamos empezar por la auditoría general de Microsoft 365. Esta auditoría centrada en Exchange tiene sentido como pieza independiente cuando el correo es especialmente crítico o tras un incidente relacionado con el correo. Q: ¿Puede detectar si ya hay una regla de reenvío maliciosa activa? A: Sí. La revisión de reglas de transporte y de buzón forma parte del alcance estándar, precisamente porque es una de las técnicas de persistencia más habituales tras un compromiso de cuenta. --- ## Certificación ENS: qué verifica el auditor y cómo llegar preparado URL: https://www.quantumsec.es/recursos/auditoria-esquema-nacional-seguridad-ens/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué exige la auditoría de certificación del Esquema Nacional de Seguridad (ENS): categorías, periodicidad y cómo prepararse. Basado en el RD 311/2022. El Esquema Nacional de Seguridad (ENS) regula la seguridad de los sistemas de información de las administraciones públicas españolas y de las empresas que les prestan servicios. A diferencia de NIS2 o DORA, el ENS lleva vigente desde 2010 y su versión actual (Real Decreto 311/2022) exige un proceso de auditoría periódico y formal, no solo una declaración de intenciones. Esta guía explica qué implica esa auditoría y cómo preparar tu organización antes de pasar por ella. Si ya sabes que necesitas ayuda para conseguirlo, nuestro servicio de auditoría y adecuación al ENS se encarga de todo el proceso, de la clasificación a la certificación. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Una empresa privada puede necesitar cumplir el ENS aunque no sea administración pública? A: Sí. Cualquier empresa privada que preste servicios a una administración pública española que impliquen tratamiento de su información o uso de sus sistemas puede estar obligada a acreditar su adecuación al ENS, habitualmente como requisito de la licitación o el contrato. Q: ¿Con qué frecuencia hay que repetir la auditoría o autoevaluación del ENS? A: Al menos cada dos años, tanto para la autoevaluación de categoría básica como para la auditoría de certificación formal de categorías media y alta. Q: ¿Necesito hacer un pentesting para certificarme en el ENS? A: No es un requisito documental obligatorio en sí mismo, pero es muy recomendable como preparación: ayuda a confirmar que las medidas técnicas que vas a declarar en la auditoría de certificación realmente funcionan frente a un ataque real, no solo sobre el papel. --- ## Qué pide un inversor en el due diligence de seguridad de tu startup URL: https://www.quantumsec.es/recursos/que-pide-un-inversor-en-due-diligence-de-seguridad/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué revisa un inversor de Serie A/B en el due diligence de ciberseguridad de tu startup: pentest, políticas y documentación que te van a pedir. Cuando una startup levanta una ronda de inversión seria, el due diligence técnico ya no se limita a revisar el código o la arquitectura del producto: los fondos de Serie A en adelante casi siempre incluyen una revisión de postura de seguridad. Llegar sin nada preparado no suele frenar la operación, pero sí genera fricción, alarga el cierre y da pie a condiciones menos favorables. Esta guía explica exactamente qué te van a pedir y cómo preparar cada pieza con antelación. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesito SOC 2 o ISO 27001 para una Serie A? A: Normalmente no. Esas certificaciones suelen pedirlas clientes enterprise o inversores en fases posteriores (Serie B en adelante). Para una Serie A, un pentest reciente y documentación básica de seguridad suele ser suficiente. Q: ¿Cuánto tiempo antes del cierre debo empezar? A: Al menos 6-8 semanas, porque un pentest de producto con calidad suele tardar entre 1 y 3 semanas en ejecutarse más el tiempo de agendarlo con el proveedor. Q: ¿Qué pasa si el pentest encuentra vulnerabilidades críticas justo antes del cierre? A: Es mejor encontrarlas tú antes que las encuentre el equipo de due diligence del inversor. Un informe que muestre hallazgos ya corregidos con evidencia de re-test genera más confianza que no tener ningún informe. --- ## Auditoría de ciberseguridad antes de vender tu empresa URL: https://www.quantumsec.es/recursos/auditoria-de-ciberseguridad-antes-de-vender-tu-empresa/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué una auditoría de ciberseguridad previa a la venta (M&A) evita que el comprador rebaje el precio o pare la operación. Qué cubre y cuándo hacerla. En cualquier proceso de venta o fusión (M&A), el comprador va a hacer su propio due diligence técnico, y si es el primero en encontrar un problema de seguridad, esa vulnerabilidad se convierte en su palanca de negociación. Una auditoría de ciberseguridad hecha por tu lado antes de sacar la empresa al mercado te permite llegar al proceso con los deberes hechos: sin sorpresas para el comprador y sin margen para que use un hallazgo técnico como excusa para rebajar el precio. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Esto sustituye al due diligence que hará el comprador? A: No, lo complementa. El comprador hará su propia revisión (o exigirá acceso a la tuya), pero llegar con un informe propio reciente reduce drásticamente lo que encuentran por su cuenta y acelera el proceso. Q: ¿Qué pasa si la auditoría encuentra algo grave? A: Mejor encontrarlo tú con meses de margen que el comprador durante la negociación. Un hallazgo remediado antes de sacar la empresa al mercado no afecta a la valoración; uno descubierto por el comprador, sí. Q: ¿Sirve el mismo informe para varios compradores potenciales? A: Sí, siempre que se mantenga razonablemente actualizado (no más de 6-12 meses) y se acompañe de evidencia de que los hallazgos siguen remediados en el momento del proceso. Q: ¿Y si el comprador pide la auditoría la semana que viene, no con meses de margen? A: Se puede acotar el análisis a los sistemas que sostienen el valor real del negocio y priorizar arranque y equipo dedicado para comprimir el plazo. Lo que no conviene saltarse es la verificación manual y el re-test de lo remediado: en nuestra guía sobre pentesting y auditoría exprés explicamos exactamente qué se puede acelerar y qué no. --- ## CISO virtual para PYMEs: qué es y cuándo tiene sentido contratarlo URL: https://www.quantumsec.es/recursos/ciso-virtual-para-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es un CISO virtual (vCISO), qué hace, cuánto cuesta frente a un CISO interno y cuándo una PYME lo necesita de verdad en vez de contratarlo. Un CISO senior en España cuesta entre 80.000 y 130.000 € al año, una cifra que la mayoría de PYMEs no puede ni necesita asumir a tiempo completo. El CISO virtual (vCISO) es la alternativa: un profesional o equipo externo que asume las responsabilidades estratégicas de seguridad a tiempo parcial, sin el coste ni el compromiso de una contratación interna. Esta guía explica qué hace exactamente, qué no sustituye, y cómo saber si tu empresa lo necesita ya. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un vCISO puede firmar la declaración de conformidad de NIS2 o ENS? A: Puede prepararla y coordinar todo el proceso, pero la responsabilidad legal final recae sobre la dirección de la empresa, no sobre el proveedor externo. Q: ¿Cuántas horas al mes dedica un vCISO a una PYME típica? A: Habitualmente entre 8 y 20 horas mensuales, ajustándose según la fase: más intensivo en los primeros meses (diagnóstico y plan) y más ligero en mantenimiento y seguimiento. Q: ¿Puedo empezar con un vCISO y pasar a un CISO interno más adelante? A: Sí, es un camino habitual. Muchas empresas usan el vCISO para construir el programa de seguridad y, cuando el volumen lo justifica, contratan a alguien interno con el criterio y la documentación ya establecidos. --- ## ISO 27001 para PYMEs: guía práctica para certificarse sin un proyecto eterno URL: https://www.quantumsec.es/recursos/iso-27001-para-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Por qué tu cliente empresa te exige la certificación ISO 27001, qué implica conseguirla siendo una PYME y cómo hacerlo sin un proyecto de dos años. Cada vez más PYMEs se topan con la misma exigencia: un cliente enterprise pide ISO 27001 como condición contractual, o un pliego de licitación pública la exige directamente. La buena noticia es que ISO 27001 no exige la misma estructura documental para una empresa de 15 personas que para una corporación de 5.000: el estándar se adapta al tamaño y complejidad real de la organización. Esta guía explica qué implica certificarse siendo una PYME y cómo evitar que se convierta en un proyecto de dos años. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto cuesta certificarse en ISO 27001 siendo una PYME? A: La consultoría de implementación suele oscilar entre 3.000 y 12.000 € según el punto de partida, más el coste de la auditoría de certificación externa (varía por organismo certificador y tamaño de la empresa). Q: ¿Puedo usar el trabajo de ISO 27001 para cumplir también con NIS2 o ENS? A: En gran parte sí. Los tres marcos comparten controles fundamentales (gestión de accesos, gestión de incidentes, continuidad de negocio), así que la implementación de uno reduce significativamente el esfuerzo para los otros. Q: ¿La certificación caduca? A: Sí, tiene vigencia de tres años con auditorías de seguimiento anuales para mantenerla activa. --- ## Ciberseguro para PYMEs: qué exige la aseguradora antes de cubrirte URL: https://www.quantumsec.es/recursos/ciberseguro-para-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué controles de seguridad exigen hoy las aseguradoras para emitir o renovar una póliza de ciberriesgo, y cómo evitar que te la denieguen o encarezcan. Cada vez es más habitual que una aseguradora rechace una reclamación de ciberseguro, o directamente deniegue emitir la póliza, porque la empresa no tenía implementados los controles mínimos que había declarado en el cuestionario de contratación. El ciberseguro ya no es un cheque en blanco: es un contrato con condiciones técnicas concretas que hay que cumplir antes, durante y en el momento del incidente. Esta guía explica qué controles se exigen hoy y cómo evitar sorpresas. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El ciberseguro sustituye a tener medidas de seguridad? A: No, es complementario. Cubre parte del impacto económico de un incidente (forense, notificación, posibles sanciones, pérdida de negocio), pero no evita el incidente ni te exime de tener controles básicos. Q: ¿Qué pasa si no tengo ninguno de los controles exigidos? A: Puedes contratar igualmente en algunos casos, pero con una prima mucho más alta o exclusiones específicas para los escenarios relacionados con el control que falta. Vale la pena implementarlos antes de contratar, no después. Q: ¿Necesito un análisis de vulnerabilidades antes de contratar el seguro? A: No es obligatorio, pero es la forma más rápida de saber si lo que vas a declarar en el cuestionario es cierto, y de detectar huecos antes de que los detecte la aseguradora en un siniestro. --- ## ENS para PYMEs proveedoras de la Administración Pública URL: https://www.quantumsec.es/recursos/ens-para-pymes-proveedoras-administracion/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo cumplir el Esquema Nacional de Seguridad siendo una PYME proveedora del sector público, sin el presupuesto ni el equipo de una gran consultora. Si tu empresa presta un servicio tecnológico a un ayuntamiento, una consejería o cualquier organismo público, en algún momento te van a pedir que acredites cumplimiento del Esquema Nacional de Seguridad (ENS). Muchas PYMEs asumen que el ENS es solo para grandes proveedoras de la Administración, pero el Real Decreto 311/2022 aplica a cualquier empresa privada que preste servicios tecnológicos al sector público, sin importar su tamaño. Esta guía explica cómo abordarlo siendo una empresa pequeña. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesito una auditoría de certificación externa si soy categoría BÁSICA? A: No necesariamente. Para categoría BÁSICA, la conformidad puede acreditarse mediante una autoevaluación interna correctamente documentada, sin necesidad de un organismo de certificación acreditado por ENAC. Q: ¿Qué pasa si no cumplo el ENS y me lo exige un pliego? A: No podrás optar al contrato o licitación, y si ya tienes un contrato en marcha, el organismo público puede exigir la adecuación como condición para mantenerlo o renovarlo. Q: ¿El trabajo de ENS me sirve para algo más? A: Sí. Comparte controles importantes con ISO 27001 y NIS2, así que el esfuerzo de adecuación al ENS reduce el trabajo si en el futuro necesitas cumplir también esas normativas. --- ## SOC 2 para startups: cuándo lo necesitas y cómo abordarlo URL: https://www.quantumsec.es/recursos/soc2-para-startups/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cuándo tu startup necesita SOC 2, qué tipo (Type I o Type II) te van a pedir tus clientes enterprise, y cuánto tiempo y coste real implica certificarse. SOC 2 es, con diferencia, el requisito de seguridad que más frecuentemente frena un contrato enterprise para una startup SaaS. No es una ley ni una obligación regulatoria: es un estándar de auditoría que tus clientes grandes exigen como prueba de que gestionas sus datos con criterio. Esta guía explica cuándo empezar, qué tipo de informe pedirte, y qué esperar del proceso real. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿SOC 2 es obligatorio por ley? A: No. Es un estándar voluntario de auditoría (AICPA) que tus clientes exigen contractualmente, no una obligación regulatoria como el RGPD o NIS2. Q: ¿Puedo enseñar un pentest en vez de SOC 2? A: Un pentest reciente suele ayudar y a veces basta para clientes menos exigentes, pero la mayoría de compradores enterprise maduros piden específicamente el informe SOC 2, no un sustituto. Q: ¿Qué pasa si pierdo la certificación en la auditoría de seguimiento? A: SOC 2 no es una certificación permanente: cada informe cubre un periodo concreto. Hay que repetir el ciclo de auditoría periódicamente (normalmente cada 12 meses) para mantener informes vigentes. --- ## Checklist de seguridad antes de una ronda de inversión URL: https://www.quantumsec.es/recursos/checklist-seguridad-antes-de-una-ronda-de-inversion/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Lista de comprobación de seguridad antes de levantar una ronda de inversión: qué preparar para que el due diligence técnico no frene el cierre. Preparar el due diligence de seguridad no consiste en improvisar documentos la semana antes del cierre: es una lista corta y concreta de cosas que hacer con 2 meses de antelación. Esta checklist resume, en orden de prioridad, lo que debe estar listo antes de sentarte con el equipo de due diligence del inversor. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesito contratar a alguien externo para esta checklist? A: El pentest sí requiere un proveedor especializado. La documentación de políticas y procesos puede redactarse internamente, aunque contar con apoyo externo suele acelerar el proceso y evita errores de formato que los analistas de due diligence ya conocen. Q: ¿Esta checklist sirve también para una Serie B o C? A: Es la base mínima. En fases posteriores, los inversores suelen añadir exigencias como SOC 2 o ISO 27001, que son proyectos de mayor alcance que esta checklist inicial. Q: ¿Qué pasa si mi startup es muy joven y no tiene nada de esto? A: Es habitual en fases pre-seed o seed. Empieza por el pentest y la política de seguridad: son las dos piezas que primero preguntan y las que dan mejor señal de madurez con menos esfuerzo. Q: ¿Y si el inversor cierra en dos semanas, no en 6-8? A: El pentest sigue siendo la pieza crítica y la que menos margen tiene, pero un proceso acotado al producto principal y con equipo dedicado se puede arrancar en días. En nuestra guía sobre pentesting y auditoría exprés explicamos qué se puede acelerar de verdad y qué no conviene comprimir. --- ## Cyber due diligence en M&A: qué revisa realmente el comprador URL: https://www.quantumsec.es/recursos/cyber-due-diligence-en-ma-que-revisa-el-comprador/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué analiza realmente el comprador en el due diligence técnico de una adquisición: vulnerabilidades activas, incidentes previos y deuda de seguridad oculta. Si estás en el lado comprador de una adquisición, el due diligence técnico de ciberseguridad es donde se descubren los problemas que ni el vendedor sabía que tenía: vulnerabilidades activas, cuentas de antiguos empleados que siguen con acceso, o un incidente de seguridad nunca reportado formalmente. Esta guía explica qué debe cubrir un cyber due diligence bien hecho y cómo traducir los hallazgos en decisiones de negocio (precio, condiciones, o retirarse). Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cuánto tiempo lleva un cyber due diligence en una operación de M&A? A: Depende del alcance y del acceso que facilite el vendedor, pero un análisis razonablemente completo suele requerir entre 1 y 3 semanas. Q: ¿Puedo pedirlo aunque el vendedor ya presente su propio informe? A: Sí, y es recomendable. El informe del vendedor es un buen punto de partida, pero como comprador conviene validar los hallazgos de forma independiente, especialmente si hay mucho en juego en la operación. Q: ¿Qué pasa si encuentro algo grave a mitad de la negociación? A: Se convierte en materia de negociación: ajuste de precio, retención de parte del pago (escrow) condicionada a la remediación, o cláusulas de garantía específicas en el contrato de compraventa. --- ## AI Act para autónomos y PYMEs: qué te obliga realmente URL: https://www.quantumsec.es/recursos/ai-act-para-autonomos-y-pymes/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Si usas ChatGPT, un chatbot o herramientas de IA en tu negocio, el AI Act puede aplicarte aunque seas autónomo. Qué te exige realmente y desde cuándo. Cuando se habla del AI Act, la mayoría piensa en grandes tecnológicas desarrollando modelos de IA. Pero el reglamento también aplica a quien simplemente usa herramientas de IA de terceros en su negocio: un chatbot de atención al cliente, una herramienta de selección de personal, o un asistente de IA para gestionar clientes. Si eres autónomo o PYME y usas alguna de estas herramientas, esta guía te explica qué te obliga de verdad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué relación tiene el AI Act con el RGPD? ¿Cumplir uno me cubre el otro? A: No: son obligaciones distintas que se acumulan. El RGPD regula el tratamiento de datos personales; el AI Act regula el sistema de IA en sí, aunque no trate datos personales. Un chatbot que solo responde dudas de producto puede quedar fuera del RGPD y aun así tener obligación de transparencia bajo el AI Act. Y al revés: usar IA para cribar currículums activa las dos normas a la vez —alto riesgo bajo el AI Act, y decisión automatizada sobre personas bajo el artículo 22 del RGPD—. En la práctica se documentan juntas, pero cumplir una no exime de la otra. Q: ¿Tengo que registrar algo si uso ChatGPT en mi negocio? A: Si lo usas como asistente interno de productividad, normalmente no. Las obligaciones se activan cuando el sistema toma o apoya decisiones sobre personas externas (clientes, candidatos), no por el mero uso interno de una herramienta de IA generativa. Q: ¿El AI Act me exige contratar un DPO como el RGPD? A: No existe una figura equivalente obligatoria para PYMEs pequeñas. Las obligaciones de gobernanza más exigentes (como un responsable de cumplimiento de IA) se dirigen principalmente a proveedores de sistemas de alto riesgo, no a los deployers de pequeño tamaño. Q: ¿Qué pasa si no cumplo y soy autónomo? A: Las sanciones son proporcionales al tamaño de la empresa: el reglamento prevé que para pymes y startups las multas se calculen tomando el importe menor entre los porcentajes fijados y las cifras absolutas, para evitar sanciones desproporcionadas a su facturación. --- ## Auditoría de seguridad WiFi: qué vulnerabilidades busca un pentester URL: https://www.quantumsec.es/recursos/auditoria-seguridad-wifi/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué vulnerabilidades busca una auditoría WiFi profesional: WPA2/WPA3, Evil Twin, rogue AP y segmentación. Metodología OWISAM explicada paso a paso. Una red WiFi corporativa mal configurada es una puerta de entrada directa a la red interna que no requiere ni un cable ni acceso físico a un edificio: basta con estar dentro del alcance de la señal. Aun así, es una de las superficies que menos empresas auditan formalmente. Esta guía explica qué analiza realmente una auditoría de seguridad WiFi y por qué es distinta de una auditoría de red convencional. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Es necesario estar físicamente en mis oficinas para hacer esta auditoría? A: Sí, para la evaluación completa. A diferencia de un pentesting web o de red que puede ejecutarse en remoto, el análisis de redes inalámbricas requiere presencia física dentro del alcance de la señal. Coordinamos la visita en un horario que minimice la interrupción de tu actividad. Q: ¿Puede una auditoría WiFi afectar a la conectividad durante el horario laboral? A: Las pruebas más agresivas (como ataques de desautenticación) se acuerdan previamente y, si hay riesgo de interrupción, se ejecutan fuera de horario o en una ventana de mantenimiento. La mayoría del análisis (inventario, evaluación de configuración) no afecta al servicio. Q: ¿Cuánto dura una auditoría de seguridad WiFi? A: Entre 1 y 3 días según el número de sedes, puntos de acceso y complejidad de la segmentación. El informe suele entregarse 2-3 días después de finalizar el trabajo de campo. --- ## Pentesting de Inteligencia Artificial y LLMs: qué vulnerabilidades busca URL: https://www.quantumsec.es/recursos/pentesting-inteligencia-artificial/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué vulnerabilidades busca un pentesting de IA: prompt injection, jailbreaking y exfiltración de datos. OWASP Top 10 for LLMs y MITRE ATLAS explicados. Un LLM integrado en un producto no es solo "más software que auditar": introduce vectores de ataque que no existían antes, como el prompt injection o la exfiltración del system prompt, que las herramientas de pentesting tradicionales no están diseñadas para detectar. Esta guía explica en qué consiste un pentesting de sistemas de IA y por qué requiere metodología específica. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un escáner de vulnerabilidades automático detecta estos problemas? A: No. Los escáneres tradicionales buscan CVEs y configuraciones incorrectas en software determinista. El prompt injection, el jailbreaking o la exfiltración de contexto requieren un experto que interactúe activamente con el modelo probando variantes, igual que un pentesting manual frente a un simple análisis de vulnerabilidades. Q: ¿Esto aplica solo a chatbots o también a copilots y agentes de IA? A: Aplica a cualquier sistema que use un LLM: chatbots orientados al cliente, copilots de código, agentes con function calling, o pipelines RAG con acceso a datos corporativos. Cada tipo tiene vectores propios que se adaptan durante el alcance del proyecto. Q: ¿Cuánto dura una evaluación de seguridad de un sistema de IA? A: Depende de la complejidad del pipeline: entre 5 y 10 días hábiles para un chatbot o asistente estándar, más si incluye function calling, múltiples integraciones o un pipeline RAG complejo. --- ## Pentesting potenciado por IA: cómo cambia la metodología (y qué no cambia) URL: https://www.quantumsec.es/recursos/pentesting-con-ia/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo la IA mejora el pentesting tradicional: reconocimiento acelerado, priorización de hallazgos y mayor cobertura. Qué sigue siendo trabajo humano. Aquí la IA no es el objetivo de la auditoría, es la herramienta: se usa para acelerar el reconocimiento, generar payloads adaptativos y priorizar miles de hallazgos, mientras el experto humano se dedica a la explotación de lógica de negocio y al encadenamiento de ataques, que es donde de verdad se demuestra impacto real. Esta guía explica exactamente qué hace la IA en un pentesting moderno y por qué no sustituye al pentester. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Esto es lo mismo que un escaneo automatizado con IA? A: No. Un escaneo automatizado, con o sin IA, no explota manualmente los hallazgos ni entiende el contexto de negocio. Aquí la IA acelera tareas concretas dentro de una auditoría dirigida por un experto humano que explota, valida y prioriza cada hallazgo. Q: ¿Es más barato que un pentesting tradicional? A: Habitualmente ofrece mejor ratio cobertura/coste porque el reconocimiento y la priorización se aceleran, liberando tiempo del experto para la explotación. El precio final depende del alcance, igual que en cualquier pentesting. Q: ¿Qué tipo de proyectos se benefician más de este enfoque? A: Aplicaciones grandes y complejas con plazos ajustados, revisiones previas a un lanzamiento, auditorías de código en repositorios extensos, y programas de bug bounty que necesitan un barrido sistemático inicial antes de abrir el alcance a investigadores externos. --- ## Hacking ético externo: qué puede ver y explotar un atacante desde internet URL: https://www.quantumsec.es/recursos/hacking-etico-externo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué puede ver y explotar un atacante desde internet sin credenciales previas: OSINT, subdominios olvidados, paneles expuestos y email spoofing. Un atacante que apunta a tu empresa desde internet no empieza con acceso ni información: empieza con un nombre de dominio y un buscador. El hacking ético externo simula exactamente ese punto de partida para responder a la pregunta que de verdad importa: ¿qué puede conseguir alguien sin ninguna ventaja previa? Esta guía explica en qué consiste y en qué se diferencia de un pentesting de red convencional. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre hacking ético externo y un pentesting de red? A: El hacking ético externo se centra exclusivamente en lo que es visible desde internet, empezando desde cero sin credenciales ni acceso previo, e incluye una fase de OSINT completa. Un pentesting de red puede cubrir tanto el perímetro externo como la red interna, pero normalmente parte de un alcance ya definido. Q: ¿Incluye el OSINT de mis empleados? A: Sí, dentro del alcance acordado. Identificamos qué datos de empleados están expuestos en filtraciones, LinkedIn y otras fuentes abiertas que un atacante real utilizaría para ataques dirigidos de phishing o credential stuffing. Q: ¿Puede esta evaluación tumbar mis sistemas en producción? A: Por defecto evitamos cualquier acción con riesgo real para la disponibilidad (ataques de denegación de servicio, borrado de datos). Si algún test tiene riesgo potencial, se acuerda contigo antes de ejecutarlo. --- ## Hacking ético interno: hasta dónde puede llegar un atacante dentro de tu red URL: https://www.quantumsec.es/recursos/hacking-etico-interno/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué puede hacer un atacante dentro de tu red: movimiento lateral, Kerberoasting y escalada a Domain Admin. Metodología PTES y MITRE ATT&CK explicada. La mayoría de empresas invierten en proteger el perímetro, pero una vez que un atacante entra —por phishing, por una cuenta filtrada, por un empleado malicioso— pocas saben realmente hasta dónde podría llegar. El hacking ético interno simula exactamente ese escenario: un atacante que ya tiene un punto de apoyo dentro de la red. Esta guía explica qué evalúa y por qué Active Directory es casi siempre el objetivo final. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Desde qué punto de partida se realiza el hacking ético interno? A: Habitualmente simulamos un usuario de dominio estándar sin privilegios especiales, el escenario más realista (un empleado comprometido por phishing o un atacante con acceso inicial). También es posible partir de acceso físico a la red o de una cuenta sin privilegios en un equipo concreto, según el alcance acordado. Q: ¿Puede el test afectar a los sistemas en producción? A: Coordinamos todas las pruebas con tu equipo de IT. Las técnicas más invasivas, como modificar objetos de Active Directory, se ejecutan solo con autorización explícita y en ventanas acordadas. El objetivo es demostrar el riesgo, no causar una interrupción. Q: ¿Con qué frecuencia debería repetirse esta evaluación? A: Al menos una vez al año, y siempre después de cambios significativos en Active Directory o en la estructura de red (fusiones, nuevas sedes, migraciones). Si estás sujeto a NIS2 o ISO 27001, la normativa puede exigir una cadencia concreta. --- ## ISO 27001 vs ENS: diferencias clave y cómo saber cuál necesitas URL: https://www.quantumsec.es/recursos/iso-27001-vs-ens/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. ISO 27001 y el ENS no son intercambiables: alcance, obligatoriedad y certificación. Cómo saber cuál necesita tu empresa, o si necesitas ambos. ISO 27001 y el Esquema Nacional de Seguridad (ENS) comparten más de lo que parece —ambos exigen un análisis de riesgos, una declaración de aplicabilidad y una auditoría antes de certificar— pero responden a obligaciones distintas y no siempre son intercambiables. Confundirlos lleva a proyectos mal dimensionados: pedir una certificación ISO 27001 cuando un contrato público exige explícitamente ENS, o al revés. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La certificación ISO 27001 me sirve para acreditar el ENS? A: No automáticamente. Son certificaciones independientes emitidas bajo esquemas de acreditación distintos, aunque comparten una base técnica común. Tener ISO 27001 facilita mucho el proyecto de adecuación al ENS (buena parte de la documentación y controles ya existen), pero no sustituye la certificación formal de conformidad con el ENS si un contrato público la exige explícitamente. Q: ¿Cuál es más rápido de conseguir? A: Depende de la categoría del sistema (en ENS) o del alcance (en ISO 27001), pero como referencia orientativa, un proyecto de categoría BÁSICA del ENS o una ISO 27001 con alcance acotado suelen tardar entre 3 y 6 meses hasta la auditoría de certificación; categorías MEDIA/ALTA o alcances ISO 27001 más amplios pueden extenderse a 6-12 meses. Q: ¿Qué pasa si mi empresa ya tiene NIS2 o DORA en marcha? A: Ambos comparten controles con ENS e ISO 27001 (gestión de riesgos, continuidad de negocio, notificación de incidentes), así que conviene mapear los requisitos comunes desde el principio para no duplicar trabajo entre proyectos de cumplimiento distintos. --- ## Qué es MAGERIT y cómo se usa para el análisis de riesgos URL: https://www.quantumsec.es/recursos/que-es-magerit/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. MAGERIT explicado: qué es, cómo funciona, la herramienta PILAR y por qué el ENS la exige para el análisis de riesgos de tu organización. Guía completa. MAGERIT (Metodología de Análisis y Gestión de Riesgos de los Sistemas de Información) es la metodología de referencia del sector público español para evaluar el riesgo de un sistema de información. La desarrolló el Consejo Superior de Administración Electrónica y hoy la mantiene el Ministerio de Hacienda; el Esquema Nacional de Seguridad la cita explícitamente como marco recomendado de análisis de riesgos. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿MAGERIT es obligatorio para certificarse en el ENS? A: El ENS exige un análisis de riesgos, y MAGERIT es la metodología que cita como referencia, pero no impide usar otra metodología equivalente si está justificada. En la práctica, la inmensa mayoría de proyectos ENS en España usan MAGERIT porque es el estándar reconocido y porque PILAR facilita enormemente la documentación de evidencias. Q: ¿Necesito comprar o instalar PILAR? A: PILAR es una herramienta de distribución controlada por el CCN, disponible para las administraciones públicas y para entidades autorizadas. En un proyecto de consultoría, normalmente es el consultor quien dispone de la herramienta y realiza el análisis, entregando los informes generados como parte del proyecto. Q: ¿Cuánto tarda un análisis de riesgos con MAGERIT? A: Depende del tamaño del inventario de activos, pero para un sistema de categoría BÁSICA o MEDIA suele completarse en 2-4 semanas dentro del proyecto global de adecuación al ENS. --- ## Declaración de Aplicabilidad (SoA): qué es y cómo se elabora en ISO 27001 URL: https://www.quantumsec.es/recursos/declaracion-de-aplicabilidad-iso-27001/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es la Declaración de Aplicabilidad (SoA) de ISO 27001, qué debe incluir y cómo se elabora a partir del análisis de riesgos y los 93 controles del Anexo A. La Declaración de Aplicabilidad —Statement of Applicability o SoA— es, junto con la política de seguridad, el documento más revisado por cualquier auditor de ISO 27001. Es la prueba escrita de que tu empresa ha analizado los 93 controles del Anexo A uno por uno y ha decidido, con criterio, cuáles aplican y cuáles no. Un SoA copiado de una plantilla genérica es la señal más rápida de que el resto del SGSI tampoco es real. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿La SoA se revisa una sola vez o hay que actualizarla? A: Se revisa cada vez que cambia algo relevante: un nuevo activo, un nuevo riesgo identificado, un cambio de alcance del SGSI, o como mínimo en cada revisión anual del sistema. Una SoA desactualizada frente al análisis de riesgos vigente es un hallazgo típico en auditorías de seguimiento. Q: ¿Podemos usar una plantilla de SoA como punto de partida? A: Como estructura, sí. Como contenido, no: cada justificación debe reflejar el análisis de riesgos real de tu organización. Una plantilla con justificaciones genéricas copiadas es exactamente lo que un auditor experimentado detecta y cuestiona en la primera revisión. Q: ¿Quién debe firmar o aprobar la Declaración de Aplicabilidad? A: La alta dirección, como parte de su responsabilidad sobre el SGSI (cláusula 5.1 de ISO 27001). No es un documento exclusivamente técnico: implica una decisión de negocio sobre qué riesgos se asumen y cuáles se mitigan. --- ## Auditoría interna ISO 27001: checklist y cómo prepararla URL: https://www.quantumsec.es/recursos/auditoria-interna-iso-27001/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Cómo preparar la auditoría interna obligatoria de ISO 27001: qué exige la cláusula 9.2, quién puede ejecutarla y checklist antes de la certificación externa. Antes de que un auditor externo revise tu SGSI, la propia norma te obliga a auditarlo tú mismo. La auditoría interna de ISO 27001 no es un trámite burocrático: es el filtro que debería detectar las desviaciones antes de que las encuentre la entidad de certificación, cuando corregirlas ya cuesta tiempo y credibilidad. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Con qué frecuencia hay que hacer la auditoría interna? A: Al menos una vez al año, y siempre antes de cada auditoría de certificación o de seguimiento externa. Muchas organizaciones auditan por bloques a lo largo del año (por ejemplo, controles técnicos en un trimestre, procesos organizativos en otro) en vez de hacerlo todo de una vez. Q: ¿La auditoría interna sustituye a la auditoría de certificación? A: No. Son complementarias y obligatorias ambas: la interna es un requisito de la norma que debes cumplir tú mismo; la de certificación la ejecuta una entidad acreditada externa y es la que emite (o mantiene) el certificado. Q: ¿Qué pasa si la auditoría interna encuentra una no conformidad grave? A: Se documenta, se abre una acción correctiva con plazo y responsable, y se hace seguimiento hasta cerrarla. Encontrar y corregir una no conformidad en la auditoría interna es exactamente lo que se espera del sistema: es peor si la encuentra primero el auditor de certificación. --- ## Entidades certificadoras de ISO 27001 y ENS en España: cómo elegir URL: https://www.quantumsec.es/recursos/entidades-certificadoras-iso-27001-ens/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es una entidad de certificación acreditada por ENAC, cómo elegir entre AENOR, Bureau Veritas, DNV u otras, y qué preguntar antes de contratar la auditoría. La consultoría prepara tu SGSI; la certificación la emite un tercero independiente. En España, esa auditoría de certificación —tanto para ISO 27001 como para el ENS— solo tiene validez si la realiza una entidad acreditada por ENAC (Entidad Nacional de Acreditación). Elegir entre las distintas certificadoras disponibles —AENOR, Bureau Veritas, DNV, SGS y otras— tiene más implicaciones prácticas de las que parece. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo cambiar de certificadora en la renovación del certificado? A: Sí. Al finalizar el ciclo de certificación (3 años en ISO 27001, 2 en ENS) puedes optar por otra entidad acreditada. Es habitual comparar precio y disponibilidad en ese momento, aunque cambiar implica que el nuevo auditor parte sin histórico de tu organización. Q: ¿Todas las certificadoras cuestan lo mismo? A: No. El precio depende de los días de auditoría (calculados según normas como IAF MD 5 en función del número de empleados y la complejidad del alcance) y de la tarifa/día de cada entidad, que sí varía entre certificadoras. Conviene pedir presupuesto a 2-3 entidades acreditadas antes de decidir. Q: ¿Una certificadora puede negarme el certificado aunque haya pagado la auditoría? A: Sí, y es exactamente lo que da valor al certificado: si la auditoría revela no conformidades mayores sin resolver, la entidad no emite el certificado hasta que se corrijan. Pagar la auditoría no compra el resultado, solo el proceso. --- ## Cuánto cuesta certificarse en ISO 27001: desglose de costes real URL: https://www.quantumsec.es/recursos/cuanto-cuesta-certificarse-en-iso-27001/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Desglose de costes de un proyecto ISO 27001: consultoría de implementación, auditoría de certificación y mantenimiento anual. Rangos orientativos por tamaño. El coste de certificarse en ISO 27001 no es una única cifra: son tres partidas distintas —consultoría de implementación, auditoría de certificación y mantenimiento anual— que muchas empresas presupuestan solo a medias porque solo preguntan por la primera. Esta guía desglosa cada partida para que el presupuesto no tenga sorpresas a mitad de proyecto. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿El coste de la auditoría de certificación es negociable? A: El número de días de auditoría se calcula con criterios estandarizados y no debería negociarse a la baja sin justificación real —hacerlo compromete la validez de la certificación—. Lo que sí varía entre entidades es la tarifa por día, ahí es donde tiene sentido comparar presupuestos. Q: ¿Es más barato hacer ENS e ISO 27001 a la vez que por separado? A: Normalmente sí, porque comparten una parte importante del análisis de riesgos, las políticas y los controles. Abordarlos como un único proyecto de consultoría, aunque se certifiquen por separado, reduce el esfuerzo total frente a hacerlos en momentos distintos. Q: ¿Hay ayudas públicas para financiar la certificación ISO 27001? A: En ocasiones existen líneas de ayuda a la digitalización o ciberseguridad (estatales o autonómicas) que pueden cubrir parte del coste. Las convocatorias cambian con frecuencia, así que conviene consultar las vigentes en el momento de arrancar el proyecto en lugar de asumir una ayuda concreta. --- ## ¿Necesitas un pentesting para certificarte en ISO 27001? URL: https://www.quantumsec.es/recursos/necesito-pentesting-para-iso-27001/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. ISO 27001 no exige un pentesting por su nombre, pero el Anexo A y el enfoque basado en riesgo lo hacen casi obligatorio. Cuándo lo pide un auditor. La respuesta corta es: la norma no lo exige literalmente, pero en la práctica es muy difícil pasar una auditoría de certificación sin él si tu organización tiene sistemas expuestos a internet o datos sensibles. La razón está en cómo está construida ISO 27001: no exige herramientas concretas, exige que demuestres que gestionas el riesgo de forma efectiva —y un pentesting es, para muchos riesgos técnicos, la única forma creíble de demostrarlo. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Un análisis de vulnerabilidades automático es suficiente? A: Para riesgos de severidad baja o media, puede serlo. Para activos que tu propio análisis de riesgos clasifica como críticos, un auditor experimentado espera evidencia de pruebas manuales que confirmen explotabilidad real, no solo un listado de CVEs sin verificar. Q: ¿El informe del pentesting hay que entregarlo al auditor completo? A: Normalmente se presenta como evidencia el informe ejecutivo y la confirmación de que las vulnerabilidades críticas fueron remediadas (o el plan de remediación en curso), no necesariamente el detalle técnico completo con PoC, que puede tratarse como información sensible. Q: ¿Qué pasa si el pentesting encuentra vulnerabilidades críticas justo antes de la auditoría? A: Es mejor que las encuentre tu pentesting que el auditor por otra vía. Lo que se evalúa no es "cero vulnerabilidades" sino que existe un proceso de gestión de riesgos que las detecta y las remedia con un plan y plazo razonables. --- ## ISO 31000 vs MAGERIT: qué metodología de análisis de riesgos elegir URL: https://www.quantumsec.es/recursos/iso-31000-vs-magerit/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. ISO 31000 es un marco genérico de gestión de riesgos; MAGERIT es la metodología específica del sector público español. Cuál elegir según tu cumplimiento. Tanto ISO 27001 como el ENS exigen un análisis de riesgos, pero ninguno de los dos impone una metodología única. En España, la elección casi siempre se reduce a dos opciones: ISO 31000, el marco internacional genérico, o MAGERIT, la metodología específica del sector público español. Elegir bien evita rehacer el trabajo si más adelante necesitas el otro marco de cumplimiento. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo usar MAGERIT para un proyecto ISO 27001 sin relación con el sector público? A: Sí. ISO 27001 no exige una metodología concreta, solo que exista un proceso de evaluación de riesgos coherente y repetible. MAGERIT lo satisface perfectamente, aunque en contextos puramente privados es menos habitual que ISO 31000/27005 por ser menos conocido fuera de España. Q: ¿Es obligatorio usar ISO 27005 si eliges ISO 31000? A: No, pero es muy recomendable: ISO 31000 es deliberadamente genérica y no entra en detalles específicos de seguridad de la información, mientras que ISO 27005 sí lo hace, lo que facilita mucho la aplicación práctica dentro de un SGSI. Q: ¿Cambiar de metodología a mitad de proyecto es problemático? A: Es evitable con una buena decisión inicial, pero no catastrófico: lo que un auditor revisa es el resultado (activos identificados, riesgos valorados, tratamiento decidido), no la metodología en sí. Cambiar de metodología implica rehacer parte del ejercicio, no perder la validez de todo el proyecto. --- ## Pentesting y auditoría de seguridad exprés: qué se puede acelerar (y qué no) URL: https://www.quantumsec.es/recursos/pentesting-auditoria-express/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Necesitas un pentesting o una auditoría de seguridad urgente por una ronda, una venta o un plazo normativo. Qué se puede acelerar de verdad y qué no. El inversor cierra en dos semanas. El comprador quiere evidencia de seguridad la semana que viene. La licitación con requisito de ENS o ISO 27001 tiene fecha límite y no queda margen. En los tres casos la pregunta es la misma: ¿se puede hacer un pentesting o una auditoría de seguridad rápido, de verdad, sin que sea un escaneo automático disfrazado de análisis serio? La respuesta honesta es que parte del proceso sí se puede comprimir de forma significativa, y otra parte no debería tocarse si el informe tiene que servir como evidencia real ante un inversor, un comprador o un auditor. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Podéis empezar esta misma semana? A: Depende de la disponibilidad del equipo en ese momento, pero priorizamos proyectos con fecha límite de negocio conocida (cierre de ronda, firma de operación, plazo de licitación) frente a proyectos sin urgencia. La llamada de alcance inicial se puede hacer en 24-48 horas en la mayoría de los casos. Q: ¿Un pentesting exprés es menos fiable que uno normal? A: No si se hace acotando el alcance en vez de acortando el rigor. La diferencia entre un pentesting exprés serio y uno de baja calidad no es la velocidad, es si se sigue comprobando manualmente la explotabilidad real de cada hallazgo o se sustituye por un escaneo automático. Nosotros aceleramos reduciendo el alcance a lo crítico y dedicando más equipo, no saltándonos pasos. Q: ¿Cuánto se puede comprimir realmente el plazo? A: Para un alcance acotado a un activo crítico concreto (una aplicación, un sistema), es habitual reducir a la mitad el tiempo de un proyecto estándar priorizando arranque y dedicación de equipo. Lo que no se comprime es el tiempo mínimo de prueba manual y el re-test posterior a la remediación, porque ahí está el valor real del informe. Q: ¿Y si el plazo es para una certificación formal (ENS, ISO 27001), no solo para un informe técnico? A: Ahí el margen de aceleración es menor: la auditoría de certificación la ejecuta una entidad acreditada externa con sus propios plazos. Lo que sí podemos comprimir es la fase de preparación previa —gap analysis, implementación de controles críticos, documentación— para llegar a esa auditoría lo antes posible con garantías de aprobarla a la primera. --- ## ¿Qué es una auditoría de seguridad web y qué incluye? URL: https://www.quantumsec.es/recursos/que-es-una-auditoria-de-seguridad-web/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué incluye una auditoría de seguridad web, en qué se diferencia de un escaneo automático o de un pentesting, y qué debe llevar el informe final. "Auditoría de seguridad web" es el término que más se busca cuando una empresa quiere saber si su web o su aplicación tiene vulnerabilidades explotables, pero también el que más agencias usan para vender un escaneo automático de 20 minutos disfrazado de análisis serio. Esta guía explica qué debería incluir una auditoría de seguridad web real, en qué se diferencia de un simple escaneo y de un pentesting, y qué debes exigir antes de pagar por una. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Qué diferencia hay entre una auditoría de seguridad web y un pentesting web? A: Cuando ambas están hechas con rigor, ninguna: pruebas manuales, explotación controlada y verificación de impacto real. La diferencia suele ser de marketing —algunas empresas usan "auditoría" para revisiones más orientadas a configuración y "pentesting" para el ejercicio de intrusión activa— pero lo que debes exigir es lo mismo en los dos casos. Q: ¿Un escáner automático como Qualys o Nessus sirve como auditoría de seguridad web? A: Sirve como primer filtro, no como auditoría completa. Detecta vulnerabilidades conocidas por firma o versión, pero no entiende la lógica de negocio de tu aplicación: no ve que dos permisos combinados permiten escalar privilegios, ni que un flujo de compra se puede manipular. Una auditoría real usa el escaneo automático como punto de partida y añade verificación manual. Q: ¿Qué debo exigir para asegurarme de que la auditoría es real y no un escaneo disfrazado? A: Pide el informe de una auditoría anterior (anonimizado) antes de contratar: si solo contiene hallazgos con CVE conocido y sin prueba de concepto propia, es un escaneo con plantilla. Un informe real incluye hallazgos de lógica de negocio específicos de tu aplicación, con evidencia reproducible (capturas, requests/responses) y clasificación CVSS. Q: ¿Cuánto dura una auditoría de seguridad web típica? A: Entre una y tres semanas para una aplicación de tamaño medio, según el número de roles, flujos y endpoints a cubrir. Aplicaciones muy grandes o con múltiples integraciones pueden requerir más tiempo; alcances muy acotados (un solo flujo crítico) se pueden completar en pocos días. Q: ¿Necesitáis acceso al código fuente de la aplicación? A: No para una auditoría en caja negra o gris, que son las más habituales: en caja negra trabajamos sin credenciales, como un atacante externo; en caja gris usamos credenciales de usuario estándar para evaluar el control de acceso. El acceso al código (caja blanca) es opcional y permite un análisis más exhaustivo, pero no es un requisito para que la auditoría sea real. --- ## Política de uso de IA: qué debe incluir y cómo redactarla URL: https://www.quantumsec.es/recursos/politica-de-uso-de-ia-en-la-empresa/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué debe incluir una política de uso de IA en una pyme: herramientas permitidas, datos que nunca se pegan en un chat y quién aprueba cada caso de uso. La mayoría de empresas descubre que necesita una política de uso de IA el día que alguien pega un contrato entero en un chatbot público. Para entonces el dato ya ha salido. Una política de uso de IA no es un documento legal defensivo: es la lista de reglas que permite a tu equipo usar estas herramientas —que va a usar igualmente— sin convertir cada consulta en una fuga de información. Esta guía explica qué debe contener, qué decisiones hay que tomar antes de escribirla y por qué las prohibiciones genéricas no funcionan. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Necesita una política de uso de IA una empresa de 10 personas? A: Sí, y probablemente es más fácil que en una grande. En un equipo pequeño basta con una página: lista de herramientas aprobadas, tres reglas sobre qué datos no salen, y a quién se pregunta ante la duda. El tamaño no cambia el riesgo de que alguien pegue un contrato en un chatbot; solo cambia cuánto papel hace falta para evitarlo. Q: ¿Es suficiente con usar la versión de pago de ChatGPT o Copilot? A: Ayuda, pero no resuelve la política. Los planes empresariales suelen no entrenar con tus datos y permiten desactivar la retención, lo que cubre una parte del riesgo contractual. No cubren quién decide qué se puede pegar, quién revisa la salida antes de que llegue a un cliente, ni qué pasa con los datos regulados. La herramienta es una pieza; la política es el marco. Q: ¿Cada cuánto hay que revisar la política? A: Al menos cada seis meses, y siempre que se apruebe una herramienta nueva o cambien las condiciones de tratamiento de una existente. Los proveedores de IA modifican sus términos con frecuencia, y una política que autoriza una herramienta bajo condiciones que ya no aplican es peor que no tenerla, porque genera una falsa sensación de control. Q: ¿Quién debe firmar y aprobar la política? A: Dirección, porque implica aceptar un nivel de riesgo, con participación de quien lidere IT o seguridad y de al menos un responsable de las áreas que más van a usarla. Si la firma solo legal, el resultado suele ser un documento correcto que nadie aplica. --- ## Shadow AI: la IA que ya usa tu equipo y tú no ves URL: https://www.quantumsec.es/recursos/shadow-ai-en-la-empresa/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué es el shadow AI, por qué tus empleados ya usan ChatGPT sin avisar y cómo detectar qué herramientas de IA hay en tu empresa antes de prohibir nada. El shadow IT llevaba años siendo un problema conocido: aplicaciones que entran en la empresa sin pasar por IT. El shadow AI es su versión acelerada, y se propaga más rápido por dos motivos: no requiere instalar nada y produce un beneficio inmediato y visible para quien lo usa. Basta un navegador y una cuenta personal para que información corporativa empiece a salir de la organización sin que quede ningún registro. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Cómo sé si en mi empresa hay shadow AI si nadie lo reconoce? A: Empieza por las aplicaciones OAuth conectadas a tu tenant de Google Workspace o Microsoft 365 y por los registros de DNS o proxy hacia dominios de proveedores de IA. Esas dos fuentes suelen dar un inventario inicial en pocas horas. Complétalo con una encuesta anónima: el uso desde dispositivos personales no aparece en ningún registro corporativo y solo se descubre preguntando sin consecuencias. Q: ¿Es shadow AI que un empleado use ChatGPT desde su móvil personal? A: Si lo usa con información de la empresa, sí, y es la variante más difícil de controlar porque no deja rastro en la infraestructura corporativa. Por eso el control puramente técnico tiene un techo bajo: la combinación que funciona es una alternativa aprobada cómoda, una política clara sobre qué datos no salen nunca, y formación con ejemplos reales. Q: ¿Qué diferencia hay entre shadow IT y shadow AI? A: El shadow IT clásico suele implicar instalar software o contratar un servicio, lo que deja huella en gasto o en los equipos. El shadow AI necesita solo un navegador y una cuenta personal, se propaga más rápido y, además, aparece de forma pasiva cuando un proveedor activa funciones de IA en una herramienta que ya tenías aprobada, sin que nadie tome ninguna decisión. Q: ¿Bloquear los dominios de las herramientas de IA resuelve el problema? A: Reduce el uso en la red corporativa y sirve como medida temporal, pero desplaza el uso a dispositivos personales, donde pierdes toda visibilidad. Como medida única suele empeorar la situación real: el mismo volumen de información sale de la organización, y ahora sin ningún registro. --- ## Cómo usar la IA de forma segura en el trabajo URL: https://www.quantumsec.es/recursos/como-usar-la-ia-de-forma-segura-en-el-trabajo/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Reglas prácticas para usar ChatGPT, Copilot o Gemini en el trabajo sin filtrar datos de clientes, contratos o código fuente. Con ejemplos y checklist. Casi todas las guías sobre uso seguro de IA están escritas para el equipo de seguridad. Esta está escrita para quien usa la herramienta cada día: la persona que tiene que decidir, en diez segundos, si puede pegar ese correo, ese contrato o ese fragmento de código en un chat. Estas son las reglas prácticas que resuelven la mayoría de esas decisiones, con ejemplos concretos de lo que sale mal. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: ¿Puedo usar ChatGPT para trabajar si mi empresa no tiene política de IA? A: Puedes, con cautela y aplicando las reglas de esta guía: cuenta corporativa si existe, anonimización previa, nunca credenciales ni datos regulados, y revisión de la salida. Dicho esto, la ausencia de política es un problema de la organización, no tuyo: conviene plantear la necesidad de una, porque sin ella cada persona improvisa un criterio distinto y la empresa no tiene visibilidad de nada. Q: ¿Es seguro pegar código de mi empresa en un asistente de IA? A: Depende de la cuenta y del código. En una cuenta corporativa sin entrenamiento sobre tus datos, para depurar una función aislada, el riesgo es bajo. En una cuenta personal, o con código que contiene lógica de negocio propietaria, credenciales o cadenas de conexión, no. Como criterio práctico: comparte el fragmento mínimo que reproduce el problema, nunca el fichero entero ni el repositorio. Q: ¿La IA de Microsoft 365 o Google Workspace es más segura que ChatGPT? A: Cuando está desplegada en el tenant corporativo, sí, en un aspecto concreto: el dato se queda dentro del entorno contratado y bajo el acuerdo de tratamiento que ya tienes con el proveedor. Pero introduce un riesgo distinto: estos asistentes acceden a todo lo que tu usuario puede ver, así que si los permisos de vuestros ficheros están mal puestos, la IA hace visible de golpe información que llevaba años mal compartida pero enterrada. Q: ¿Hay que avisar de que un contenido lo ha generado una IA? A: Para contenido que se publica o se entrega a un tercero, es la práctica recomendable y, en determinados supuestos de interacción con personas, el AI Act exige transparencia explícita. Internamente no suele hacer falta declararlo, pero sí conviene que quede claro quién ha revisado el contenido, que es la parte que asume la responsabilidad. --- ## A quién aplica DORA: cómo saber si tu entidad está obligada y qué debe entregar URL: https://www.quantumsec.es/recursos/a-quien-aplica-dora/ Fuente: QuantumSec (https://www.quantumsec.es) — empresa española de ciberseguridad ofensiva, equipo certificado OSCP, acelerada por INCIBE Ventures. Qué entidades financieras están obligadas por DORA, qué exige a cada una y cómo saber si tu empresa entra en el ámbito de aplicación del reglamento. DORA es de aplicación desde enero de 2025 y su ámbito es mucho más amplio de lo que muchas entidades asumen. No cubre solo a bancos: alcanza a aseguradoras, gestoras de fondos, proveedores de criptoactivos, entidades de pago y, a través de la cadena de suministro, a los proveedores TIC que les prestan servicio. Esta guía responde a la pregunta que se hace primero cualquier responsable de seguridad —si le aplica y qué tiene que entregar— antes de entrar en el detalle técnico del reglamento. Preguntas frecuentes respondidas por el equipo de QuantumSec: Q: DORA aplica solo a bancos A: No. El ámbito cubre unas veinte categorías de entidad financiera, entre ellas aseguradoras, gestoras de fondos, empresas de servicios de inversión, entidades de pago y dinero electrónico, proveedores de servicios de criptoactivos e infraestructuras de mercado. Los bancos son una parte del ámbito, no el ámbito completo. Q: Mi empresa es pequeña, queda fuera de DORA A: El tamaño no exime con carácter general: activa el principio de proporcionalidad. Las microempresas y ciertas entidades pequeñas pueden acogerse a un marco simplificado de gestión del riesgo TIC, pero siguen obligadas a gestionar el riesgo, notificar incidentes graves y probar sus sistemas. Existen exclusiones concretas, pero son tasadas. Q: Somos proveedor de software de un banco, nos aplica DORA A: No de forma directa, salvo que seáis designados proveedor TIC crítico, en cuyo caso pasáis a supervisión europea directa. Lo que sí ocurre siempre es que vuestros clientes financieros os trasladarán por contrato las cláusulas mínimas que DORA les exige: derechos de auditoría, niveles de servicio, notificación de incidentes y estrategia de salida. Q: Estamos obligados a hacer un TLPT A: Solo si vuestra autoridad competente os designa para pruebas avanzadas, atendiendo a tamaño, perfil de riesgo y relevancia. En España esa autoridad es el Banco de España, la CNMV o la DGSFP según el tipo de entidad, y el marco aplicable es TIBER-ES. El resto de entidades del ámbito debe mantener un programa de pruebas de resiliencia, pero no necesariamente un TLPT. Q: Qué pasa si nos aplican DORA y NIS2 a la vez A: Para las entidades financieras cubiertas, DORA actúa como norma especial y prevalece sobre NIS2 en gestión del riesgo TIC y notificación de incidentes. En grupos con filiales de varios sectores pueden convivir ambos marcos, y conviene mapear los controles comunes una sola vez en lugar de duplicar programas. Q: Desde cuándo es exigible DORA A: El reglamento es de aplicación desde el 17 de enero de 2025. No hay periodo transitorio adicional: las obligaciones son exigibles y las autoridades competentes ya pueden requerir evidencia del marco de gestión del riesgo TIC y del programa de pruebas. --- # Resources (EN) --- ## What is a penetration test and what is it for in a company? URL: https://www.quantumsec.es/en/resources/what-is-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What pentesting is, what it's for, types and when your company needs it. A technical, practical guide written by ethical hacking experts. Pentesting, short for penetration testing, is a security assessment in which an expert simulates —in a controlled and authorized way— a real attack against an organization's systems. The goal is not to cause harm, but to discover the vulnerabilities before a malicious attacker does. Frequently asked questions answered by the QuantumSec team: Q: Can a pentest take down my systems? A: Not if it's done with professional rigor. The scope is defined in advance and actions that are high-risk for availability are excluded. If there's risk in a specific test, it's agreed to run it during a maintenance window. Q: How long does a pentest take? A: Between 3 and 10 business days for the technical phase, depending on the scope. The report is delivered 2-3 days later. --- ## How to comply with the NIS2 Directive: a practical guide URL: https://www.quantumsec.es/en/resources/how-to-comply-with-nis2/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to bring your company into compliance with NIS2: who's obligated, what measures are required, and how to avoid fines of up to 2% of global turnover. The NIS2 Directive (Network and Information Security 2) took effect in October 2024 and requires thousands of companies in Spain to implement technical and organizational cybersecurity measures. If you're not sure whether it applies to you or where to start, this guide has the answers. Frequently asked questions answered by the QuantumSec team: Q: Is NIS2 already mandatory in Spain even though the directive hasn't been transposed yet? A: The directive creates obligations from the date it took effect (October 2024), even though the specific national law may still be pending. In any case, the regulatory trend is clear, and complying now is the prudent decision to avoid retroactive penalties. Q: Are SMBs required to comply with NIS2? A: NIS2 mainly applies to medium and large companies (more than 50 employees or over €10M in turnover). However, microenterprises and SMBs providing services in the regulated sectors can be included in specific cases. --- ## Pentesting vs vulnerability assessment: key differences and when to use each URL: https://www.quantumsec.es/en/resources/pentesting-vs-vulnerability-assessment/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Differences between pentesting and vulnerability assessment: cost, depth and methodology. When to use each. A guide for management and security. They're terms often used interchangeably, but they're not the same. An automated vulnerability assessment and a manual pentest have different goals, produce different results and have very different costs and execution times. Understanding the difference helps you invest your security budget where it really matters. Frequently asked questions answered by the QuantumSec team: Q: Can a vulnerability assessment replace a pentest? A: No. They have different uses and depth. A VA is useful for continuous maintenance, but it doesn't confirm exploitability or assess real impact. For critical business decisions or regulatory compliance, a pentest is necessary. Q: Does a pentest always include a prior vulnerability assessment? A: Usually yes. The pentester often starts with an automated scan to map the surface and then focuses the manual analysis on the most relevant findings and on attack vectors the tools don't detect. --- ## Phases of a web pentest: from information gathering to the final report URL: https://www.quantumsec.es/en/resources/phases-of-a-web-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The 6 phases of a web pentest: reconnaissance, enumeration, exploitation and post-exploitation. OWASP methodology explained step by step. A web pentest isn't opening Burp Suite and firing random requests. It's a structured process in well-defined phases that follows methodologies like the OWASP Testing Guide, PTES or OSSTMM. Knowing these phases helps you understand what the auditor is doing, what to expect from each stage and how to interpret the final report. Frequently asked questions answered by the QuantumSec team: Q: How long does a complete web pentest take? A: Between 3 and 8 business days for the technical phase, depending on the size and complexity of the application. The report is delivered 2-3 days after the testing ends. Q: Do I need to stop the application during the pentest? A: No. The pentest is done on the production application (or an agreed identical environment) without interrupting the service. The most aggressive tests can be scheduled outside peak hours if you prefer. --- ## DORA vs NIS2: differences, overlaps and what to do if both apply to you URL: https://www.quantumsec.es/en/resources/dora-vs-nis2/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. DORA vs NIS2: sectors, technical obligations, deadlines and fines. How to manage compliance with both. Especially useful for the financial sector. If your company operates in the financial sector in Europe, both DORA and NIS2 probably apply to you — and the most common question is: are they redundant? Do I have to do the work twice? The short answer is no, but there are important nuances worth understanding before starting any compliance project. Frequently asked questions answered by the QuantumSec team: Q: Does DORA replace NIS2 for the financial sector? A: Not exactly. DORA is lex specialis relative to NIS2 for financial entities within its scope: where there's overlap, DORA prevails. But NIS2 can still apply to aspects or entities not covered by DORA within the financial sector. Q: Are financial-sector ICT providers required to comply with DORA? A: Critical ICT providers designated by the European supervisory authorities (ESAs) are subject to direct supervision under DORA. All other ICT providers to financial entities are covered indirectly, through the third-party management requirements DORA imposes on their financial clients. --- ## Types of corporate phishing: how to recognize them and protect your company URL: https://www.quantumsec.es/en/resources/types-of-corporate-phishing/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Types of corporate phishing: spear phishing, whaling, BEC, smishing and vishing. Warning signs and how to protect your team against them. Phishing remains the number-one entry vector in corporate security breaches. Not because the attacks are highly sophisticated, but because they constantly adapt to context, exploit urgency, and take advantage of the trust inherent to email and digital communications. Knowing the types of phishing that exist is the first step to training your team to spot them. Frequently asked questions answered by the QuantumSec team: Q: Does an internal phishing simulation harm team trust? A: If managed well, no. The key is to inform management beforehand, frame the results in an educational (not punitive) way, and run an awareness session after the simulation. Most employees respond positively once they understand the goal. Q: Does DMARC fully protect against phishing? A: DMARC protects against exact spoofing of your domain, but not against lookalike domains, compromised accounts, or supplier phishing. It's an important layer, but not sufficient on its own. --- ## How to protect Active Directory from ransomware and lateral movement attacks URL: https://www.quantumsec.es/en/resources/how-to-protect-active-directory-from-ransomware/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to protect Active Directory against ransomware. AD hardening, detecting Kerberoasting, Pass-the-Hash and lateral movement. Active Directory (AD) is the heart of identity infrastructure in most companies running Windows environments. It's also the number-one target for ransomware groups: compromising the Domain Controller is equivalent to compromising the entire organization. This technical guide explains why AD is attacked so heavily and which critical configurations you should review. Frequently asked questions answered by the QuantumSec team: Q: Can an Active Directory pentest be run without disrupting operations? A: Yes. AD pentesting uses low-impact techniques during reconnaissance and exploitation. The more aggressive tests (such as DCSync or GPO modification) are coordinated in advance and run in agreed maintenance windows. Q: What tools does a pentester use to audit Active Directory? A: The most commonly used in a professional pentest: BloodHound/SharpHound for mapping relationships and attack paths, Impacket for Kerberos authentication techniques, PowerView/PowerSploit for AD enumeration, Mimikatz (in a controlled environment) to validate credential extraction, and CrackMapExec for validating lateral movement. --- ## 10 essential cybersecurity measures for any SMB URL: https://www.quantumsec.es/en/resources/security-for-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The 10 most effective cybersecurity measures for small and medium businesses: MFA, backups, patching, phishing training and more, no big budget required. 43% of cyberattacks target small and medium businesses. Not out of bad luck: attackers deliberately choose SMBs because they know they typically have weaker defenses. The good news is you don't need a large corporation's budget to reach an adequate level of protection. This guide explains, in plain language, the measures that deliver the most impact for the lowest cost. Frequently asked questions answered by the QuantumSec team: Q: Do I need a security expert or can I manage this internally? A: You can implement the basic measures with your current team. For technical assessments (vulnerability assessment, pentesting) or regulatory compliance, you need external support. A good starting point is a free consultation with a specialist to understand your real level of exposure. Q: Does cyber insurance protect me if I'm attacked? A: Cyber insurance covers part of the cost of an incident, but more and more insurers require minimum security controls to maintain coverage. Without basic measures in place, the insurer can deny the claim. --- ## Cybersecurity for startups: what you need to know before scaling URL: https://www.quantumsec.es/en/resources/cybersecurity-for-startups/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity guide for startups: your first pentest, investor due diligence and the controls enterprise clients require. Founding a startup is hard enough without having to think about security. But ignoring it has very concrete consequences: a breach can sink you before your Series A, an enterprise client can block your most important contract, or a due diligence review can reveal security debt that tanks your valuation. This guide explains, without sugarcoating it, what a tech startup needs to know about security. Frequently asked questions answered by the QuantumSec team: Q: How much does a first pentest cost for a startup? A: For a mid-sized web application (SaaS MVP), a grey-box pentest including the API usually runs between €2,000 and €5,000. Startup-specific plans with more accessible pricing exist. The ROI is immediate if it unlocks an enterprise contract or a funding round. Q: Do I need ISO 27001 to sell to large companies? A: ISO 27001 is the most recognized certification, but it isn't always required. Many enterprise clients accept a pentest report plus documented security policies as sufficient evidence. ISO 27001 is usually a formal requirement in heavily regulated sectors (banking, public health) or for significant contract sizes. --- ## What security risks does vibe coding carry? URL: https://www.quantumsec.es/en/resources/vibe-coding-security-risks/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Vibe coding introduces serious vulnerabilities. We break down the real risks of LLM-generated code and how to mitigate them in your company. "Vibe coding" is a term coined by Andrej Karpathy in 2025 to describe a way of programming where the developer describes what they want in natural language, accepts the AI-generated code without reviewing it in depth, and trusts that it works. It's incredibly effective for rapid prototyping. And it's a potential source of serious security vulnerabilities once that code reaches production. Frequently asked questions answered by the QuantumSec team: Q: Is vibe coding inherently insecure? A: Not inherently, but it does introduce specific risks that require specific countermeasures. AI-generated code can be perfectly secure if it's reviewed by someone who knows what to look for, tested with security tools, and audited before handling sensitive data. Q: Which AI tools generate more secure code? A: The most recent models (GPT-4o, Claude Sonnet, Gemini 1.5 Pro) tend to generate more secure code than earlier models because they've been specifically tuned to avoid common insecure patterns. However, no model guarantees secure code by default. The tool matters less than the review process. --- ## How to audit the security of AI-generated code URL: https://www.quantumsec.es/en/resources/how-to-audit-ai-generated-code/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A methodology for auditing AI-generated code (Copilot, ChatGPT): SAST, manual review, common vulnerabilities and a security checklist. You have a repository full of code generated by GitHub Copilot, Cursor or ChatGPT. Or maybe you're not even sure which parts a human wrote and which parts the AI generated. Either way, you need to know whether that code is secure before it reaches real users. This guide explains how to do it systematically. Frequently asked questions answered by the QuantumSec team: Q: How long does an audit of AI-generated code take? A: It depends on the size of the repository and the complexity of the application. For a typical SaaS MVP (20-50k lines of code), a full audit including static analysis, manual review of critical areas and basic dynamic testing takes an expert between 2 and 5 days of work. Q: Can I audit the code myself or do I need to hire someone external? A: Part of the audit (SAST, basic pattern review) you can do yourself with the right tools. For a full assessment that includes exploitation testing and business-logic analysis, you need an external perspective: someone who doesn't know the code and thinks like an attacker. --- ## Security checklist before launching your SaaS startup URL: https://www.quantumsec.es/en/resources/security-checklist-before-launching-saas/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Security checklist before launching your SaaS: authentication, encryption, secrets management, GDPR, logging and more. Get an expert pre-launch review. You're about to launch. The product works, the team is excited, your first users are waiting. Before you hit the button, there's a set of security controls you should have reviewed. Not to be perfect (no system is), but to avoid the mistakes that make a breach a matter of days rather than years. Frequently asked questions answered by the QuantumSec team: Q: Do I have to implement all of this from day one? A: The items in the authentication, encryption and secrets management sections: yes, from day one. They're the bare minimum floor for any web application. The rest you can prioritise based on the type of data you handle and the profile of your first users. But bear in mind it's far easier and cheaper to implement them from the start than to remediate later with real users. Q: Is this checklist enough or do I also need a penetration test? A: The checklist helps you avoid the most obvious mistakes. The pentest tells you whether, even after following the checklist, there are vulnerabilities in your specific implementation that an attacker could exploit. The two are complementary: the checklist is your baseline, the pentest validates that you've actually reached it. --- ## How much does a pentest cost in Spain? 2026 pricing guide URL: https://www.quantumsec.es/en/resources/how-much-does-a-pentesting-cost/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Real pentest prices in Spain in 2026. Cost by type (web, network, mobile, cloud), what a serious quote includes and how to avoid lowball traps. One of the first questions we get at QuantumSec is: how much does a pentest cost? The honest answer is that it depends —on the scope, the type of system and the depth you need. This guide breaks down the real price ranges in Spain for each type of pentest, what a quote should always include and how to spot proposals that, at best, won't add any value. Frequently asked questions answered by the QuantumSec team: Q: Is the cheapest pentest always a bad choice? A: Not necessarily, but you should understand what you're buying. A cheaper project can be perfectly valid if the scope is limited and well defined. The problem is when a low price hides superficial work sold as a complete pentest. Always compare scope, methodology and team credentials, not just the number. Q: How much does a web pentest cost in Spain? A: For a standard-sized web application (10-30 endpoints, user authentication and an admin panel), the usual range in Spain is between €2,500 and €6,000. If the application is complex (extensive business logic, multiple roles, third-party integrations), the cost can exceed €8,000. Q: How often should I run a pentest? A: At a minimum, once a year. You should also run a pentest whenever you make significant changes to your application, when you need to comply with NIS2, DORA or ISO 27001, or before launching a new product. Q: Can I pay for the pentest in stages? A: Yes. Many providers offer payment in two parts: a percentage on signing the contract and the rest on delivery of the report. On large projects, it's also possible to agree separate phases (e.g., web phase first, network phase later), which spreads the cost across the fiscal year. --- ## NIS2 Directive fines and penalties in Spain (2026) URL: https://www.quantumsec.es/en/resources/nis2-fines-and-penalties-spain/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. NIS2 fines in Spain: up to €10M or 2% of global turnover. Who can be sanctioned, how the amount is calculated and what actually reduces exposure. The NIS2 Directive is not just another bureaucratic requirement. It carries a sanctioning regime that, in the most serious cases, can mean fines of up to 10 million euros or 2% of global annual turnover. This guide explains who can be sanctioned, how fines are calculated and what steps you can take right now to reduce your exposure. Frequently asked questions answered by the QuantumSec team: Q: When does NIS2 come into force in Spain? A: NIS2 should have been transposed into Spanish law before 17 October 2024. Spain is in the process of transposition, behind the European deadline. However, the transposition delay doesn't eliminate regulatory exposure: the Directive has direct effect in many of its aspects and companies should act now. Q: What happens if my company suffered a cyberattack and didn't notify it within 72 hours? A: Failure to notify within the deadline is a specific infringement under NIS2, sanctionable independently of the incident itself. The obligation is to notify the competent authority within 72 hours (with early warning within 24 hours) even if the full analysis isn't finished. Regulatory silence after a serious incident makes the situation worse and can lead to additional sanctions. Q: Does NIS2 affect SMBs? A: Micro-enterprises (<10 employees, <€2M turnover) and small companies (<50 employees, <€10M turnover) are generally excluded, unless they operate in essential sectors or are critical infrastructure providers. If your SMB is a technology provider to a large company subject to NIS2, you'll likely need to demonstrate your compliance as part of the supply chain. Q: Does penetration testing help with NIS2 compliance? A: Yes. NIS2 requires "periodic assessments of the effectiveness of risk management measures". An independent pentest is the strongest technical evidence you can present in a regulatory audit. Documenting that you run regular penetration tests and act on the findings demonstrates an active security programme, not just a statement of intent. --- ## How to choose a cybersecurity company: 7 criteria that matter URL: https://www.quantumsec.es/en/resources/how-to-choose-cybersecurity-company/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. 7 criteria for choosing a cybersecurity provider: certifications, methodologies, transparency, report quality and post-delivery support. The cybersecurity market in Spain has grown enormously in recent years, and with it, providers of wildly uneven quality have proliferated. Choosing the wrong team isn't just a waste of money: it can give you a false sense of security that's worse than doing nothing at all. This guide gives you the seven criteria you should evaluate before signing any contract. Frequently asked questions answered by the QuantumSec team: Q: Is a large company better than a small specialized consultancy? A: It depends on the project. Large consultancies have more resources, but the work is usually done by a junior team with senior oversight. A mid-sized specialized consultancy usually offers more direct access to senior pentesters and greater customization. For SMBs and mid-sized companies, a specialized consultancy usually offers better value for money. Q: Does the cybersecurity company need to be in my city? A: For most services (web, cloud, API, source code pentesting), physical presence isn't necessary: the work is done remotely. For projects involving physical access to facilities (physical Red Team, wireless network audit in the office), geographic proximity can be relevant. Q: How long does a pentest take from contract signing? A: A standard web pentest usually runs in 1-2 weeks from kickoff. More complex projects (Red Team, large infrastructure pentesting) can extend 3-6 weeks. The report is usually delivered 3-5 business days after the technical phase ends. Good providers have a booked schedule: if your project is urgent, say so from the start. --- ## What is ethical hacking and what is it for in your company? URL: https://www.quantumsec.es/en/resources/what-is-ethical-hacking/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What ethical hacking is, how it works and why your company needs a professional penetration test. A practical 2026 guide. Ethical hacking —also called pentesting or penetration testing— is the process of attacking an organization's systems in a controlled and authorized way to identify their vulnerabilities before a real attacker does. It's not a theoretical exercise: it's a real attack, performed by certified professionals, with clear rules and the goal of protecting, not harming. Frequently asked questions answered by the QuantumSec team: Q: Is ethical hacking legal in Spain? A: Yes, as long as there's written authorization from the system owner. The Spanish Criminal Code (article 197 bis) criminalizes unauthorized access to computer systems, but ethical hacking is done with explicit permission and a signed contract. Any serious ethical hacking firm works with service agreements and NDAs that define the scope and protect both client and provider. Q: Can ethical hacking take down my systems? A: The risk exists but is very low in well-planned projects. An experienced pentester knows how to test without causing service interruptions. Before starting, the window for the most intrusive tests is defined (usually outside peak hours) and actions that could cause denial of service are explicitly excluded. Q: How long does ethical hacking take? A: It depends on the scope. A web pentest of a standard application usually runs in 5-10 business days. A full Red Team can extend over several weeks. The report is normally delivered 3-5 days after the technical phase ends. Q: How does ethical hacking differ from a vulnerability assessment? A: A vulnerability assessment (VA) uses automated tools to detect known vulnerabilities —it's fast and good for a snapshot. Ethical hacking goes further: the pentester actively exploits the vulnerabilities, chains them to simulate a real attacker's path and documents the real, not just potential, impact. The VA says there's a hole; ethical hacking says I went in through that hole, got this far and this is what I could have stolen. --- ## What is the Cyber Resilience Act: the EU cybersecurity regulation for digital products URL: https://www.quantumsec.es/en/resources/what-is-the-cyber-resilience-act/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The Cyber Resilience Act (CRA): the EU's first cybersecurity regulation for digital products. Who it affects, what it requires and key deadlines to 2027. The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847, adopted by the European Parliament and the Council of the EU in October 2024. It is the first legal framework in the European Union to impose mandatory cybersecurity requirements on products with digital elements —hardware and software— before they can be placed on the European market. If your company manufactures, imports or distributes any kind of technology product in the EU, the CRA affects you directly. Frequently asked questions answered by the QuantumSec team: Q: Does the CRA apply only to European companies or also to those selling into the EU from abroad? A: The CRA applies to any product placed on the European market, regardless of where the manufacturer is based. A manufacturer based in the US, India or South Korea selling its products in the EU must comply with the CRA. If it has no presence in the EU, the importer that places the product on the European market assumes the manufacturer's obligations. Q: Does the CRA apply to software updates of products already on the market? A: Yes. The CRA applies to significant software updates that substantially modify the product's security characteristics. Minor security updates or vulnerability patches are not considered a 'placing on the market' of a new product, but the manufacturer remains obliged to provide them free of charge for at least five years. Q: What is the EU declaration of conformity under the CRA? A: It is the document the manufacturer issues under its own responsibility declaring that the product meets all the essential cybersecurity requirements of the CRA. It must include the identification of the product and the manufacturer, the requirements deemed met, the harmonised standards applied, and a statement of responsibility. It must be kept for 10 years and be available to the market surveillance authorities. --- ## Cyber Resilience Act timeline: what you must have ready and when URL: https://www.quantumsec.es/en/resources/cyber-resilience-act-timeline/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CRA reporting duties are already live: 24h early warning, 72h notification and a 14-day report to ENISA. One deadline left — full application on 11 Dec 2027. The Cyber Resilience Act doesn't have a single date of entry into force: it has four staggered milestones between 2024 and 2027, and three of them have already passed. Since 11 August 2026 the obligation to report vulnerabilities to ENISA has been enforceable, and since 11 September 2026 the notified bodies have been operational. One deadline remains: 11 December 2027, when the whole regulation becomes punishable. If you manage the development of software products or connected hardware, this timeline tells you what already binds you and what is still ahead. Frequently asked questions answered by the QuantumSec team: Q: What happens if I don't notify ENISA of an actively exploited vulnerability within the 24-hour deadline? A: Failure to comply with the ENISA notification obligation can lead to penalties of up to 10 million euros or 2% of global annual turnover. National market surveillance authorities are responsible for investigating and imposing these penalties. Q: Do the CRA deadlines also apply to software updates? A: The obligations to report actively exploited vulnerabilities apply to all products with digital elements on the market, regardless of whether they have been recently updated. If a vulnerability affects versions of your software that are in use by customers, the obligation to notify ENISA applies from August 2026. --- ## CRA vs NIS2: differences, overlaps and how to manage them together URL: https://www.quantumsec.es/en/resources/cra-vs-nis2/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CRA vs NIS2: what each one regulates, who it applies to, where they overlap — and how to reuse your NIS2 work for CRA compliance. Get expert guidance. With the Cyber Resilience Act entering into force and NIS2 fully applicable since 2024, many companies face a logical question: do I have to comply with both? Are they redundant? Can I reuse the work I've already done for NIS2 in my CRA compliance effort? The answer to the first question is frequently yes, especially if you manufacture software or hardware and also operate a digital service. The answer to the third is also yes, partially. This guide helps you understand the boundaries and the intersections. Frequently asked questions answered by the QuantumSec team: Q: If I comply with NIS2, am I automatically complying with the CRA? A: No. NIS2 and the CRA regulate different things. NIS2 requires you to manage the security of your operations; the CRA requires you to ensure the security of the product you manufacture and sell. There are overlapping controls you can reuse, but they are two distinct projects with a different object and different assessment mechanisms. Q: Are SaaS providers bound by the CRA? A: Pure SaaS services with no client-installable components are excluded from the CRA. However, if your SaaS includes a desktop agent, a plugin that installs in the browser, an SDK your clients embed in their applications or any component the user downloads and runs in their environment, that component does fall within the scope of the CRA. --- ## Cyber Resilience Act requirements: what the regulation demands from manufacturers of digital products URL: https://www.quantumsec.es/en/resources/cyber-resilience-act-requirements/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CRA requirements explained: Annex I, vulnerability management, CE marking, conformity assessment and mandatory documentation. Get an expert readiness review. The Cyber Resilience Act imposes two types of obligations on manufacturers of products with digital elements: technical requirements the product must meet (Annex I, Part I) and process requirements for managing the product's security lifecycle (Annex I, Part II). It also establishes a conformity assessment procedure based on the product category, along with mandatory documentation the manufacturer must produce and retain. This guide breaks down every one of these requirements at the level of detail a technical team or product owner needs. Frequently asked questions answered by the QuantumSec team: Q: Are open-source products subject to the CRA requirements? A: The CRA explicitly excludes open-source software developed on a non-commercial basis. However, if a company markets a product based on open-source software (a commercial Linux distribution, a router with OpenWRT-based firmware, or a security appliance based on Suricata), that commercial product is indeed subject to the CRA. The commercial manufacturer is responsible for compliance even if part of the code is open source. Q: What is a CRA harmonised standard and when will they be available? A: Harmonised standards are European technical standards (ETSI, CEN-CENELEC) developed under a mandate from the European Commission which, when fully applied, create a presumption of conformity with the CRA requirements. The relevant standards are still under development and are expected in 2026-2027. In their absence, manufacturers can use other recognised technical standards such as IEC 62443, ETSI EN 303 645, or NIST SP 800-218 to demonstrate conformity, although this requires an explicit mapping between the standard's requirements and those of the CRA. --- ## Cyber Resilience Act fines and penalties: the cost of non-compliance URL: https://www.quantumsec.es/en/resources/cyber-resilience-act-fines/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CRA fines: up to €15M or 2.5% of global turnover. Which violations trigger them, who can be sanctioned and how to avoid them. Book a CRA readiness review. The Cyber Resilience Act is not a recommendation or a voluntary framework. It is a European regulation with a specific penalty regime that can reach 15 million euros or 2.5% of the company's total annual global turnover — whichever is higher. And it does not only affect manufacturers: importers and distributors can also be sanctioned. This guide details the three penalty tiers, which violations trigger them, who can be sanctioned and how to mitigate the risk. Frequently asked questions answered by the QuantumSec team: Q: Are CRA penalties cumulative with those under NIS2 or the GDPR? A: Yes. The CRA, NIS2 and the GDPR are separate regulations with independent penalty regimes. A security incident involving a product vulnerability can simultaneously trigger CRA penalties (for failing to notify ENISA in time), GDPR penalties (for the resulting personal data breach) and NIS2 penalties (if the affected party is an essential services operator). Q: Can the CRA generate civil liability towards affected users? A: The CRA establishes administrative penalties, not direct civil liability. However, in many Member States non-compliance with regulatory security requirements may be relevant in civil liability proceedings. If a manufacturer places a product knowing it does not meet the CRA requirements and that product is exploited causing harm to a user, non-compliance may be used as evidence of negligence. Q: Can a startup with limited resources afford CRA compliance? A: The CRA is designed to be proportionate to company size. The most demanding assessment procedures (involving notified bodies) only apply to Class II products. For most small-company products, self-assessment is sufficient and the main cost is engineering time to implement the Annex I controls, plus SBOM and dependency vulnerability analysis tooling — which in many cases offer free plans for small projects. --- ## The most common vulnerabilities in SaaS applications and how to detect them URL: https://www.quantumsec.es/en/resources/common-saas-vulnerabilities/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The 8 most common SaaS vulnerabilities: IDOR, broken multi-tenancy, weak JWT, mass assignment and insecure webhooks. A technical guide with examples. SaaS applications have a different attack surface from that of a traditional web application. They serve multiple customers on the same infrastructure, expose complex APIs, manage subscriptions and permissions, and integrate dozens of external services. These characteristics generate specific vulnerabilities that automated scanners rarely detect and that require pentesters who understand the product's business model. Frequently asked questions answered by the QuantumSec team: Q: How do I know if my SaaS has multi-tenant isolation vulnerabilities? A: The most reliable approach is to commission a SaaS-specialised penetration test where the team simulates being two different customers and attempts to access one customer's data from the other's account. As a preliminary measure, you can manually review that all your endpoints validate that the requested resource belongs to the authenticated tenant, not merely that the user is authenticated. Q: Do automated scanners detect these vulnerabilities? A: Most do not. DAST scanners are good at detecting injection vulnerabilities (SQLi, XSS) and insecure configurations. But business logic flaws, IDOR between tenants, billing manipulation and function-level authorization problems require a pentester who understands the product and manually tests specific business flows. Q: How often should I run a penetration test on my SaaS? A: The industry standard for SaaS is at least once a year, and additionally before major changes to the architecture, authentication or billing. If you are in the process of SOC 2 Type II or ISO 27001 certification, an annual pentest is usually an explicit requirement. --- ## SOC 2 Type II and pentesting: what security testing your SaaS needs URL: https://www.quantumsec.es/en/resources/soc2-and-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How pentesting fits into SOC 2 Type II. Which controls auditors expect, what kinds of tests they accept and how to get your SaaS ready. Talk to an expert. SOC 2 Type II is the benchmark security certification for SaaS companies selling to enterprise customers, particularly in English-speaking markets. It does not explicitly mandate a penetration test, but in practice auditors review evidence of periodic security testing, and large enterprise customers who require the SOC 2 report ask specifically about pentesting. Understanding exactly what they expect saves you time and money. Frequently asked questions answered by the QuantumSec team: Q: Is pentesting mandatory to obtain SOC 2 Type II? A: It is not technically mandatory under the standard, but in practice it is very hard to pass a SOC 2 Type II audit without evidence of penetration testing. Auditors at firms such as A-LIGN, Schellman or Prescient specifically review vulnerability detection controls and expect to see an annual pentest. Q: When should I run the pentest relative to the SOC 2 audit period? A: Within the audit period (the 12 months the SOC 2 Type II report covers). If your period runs January to December, the pentest should take place within that year. Many companies run it in Q2 or Q3 to leave time to remediate findings before the period closes. Q: Does the QuantumSec report work as evidence for SOC 2 auditors? A: Yes. The report we deliver is designed to be shared with auditors and enterprise customers. It includes an executive summary with scope and methodology, a list of findings with CVSS classification and the remediation status. It is exactly what SOC 2 auditors ask for. --- ## How to secure a SaaS application before scaling: 7 concrete steps URL: https://www.quantumsec.es/en/resources/how-to-secure-a-saas-application/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A practical guide to securing your SaaS: robust authentication, multi-tenant isolation, secure APIs, secrets and monitoring. 7 concrete steps. SaaS security isn't a checklist you complete once before launch. It's an ongoing practice that needs to be built into the development cycle from day one. That said, there's a core set of measures every SaaS should have in place before it starts to scale: before its first enterprise customers, before a funding round, and before handling sensitive data in production. Frequently asked questions answered by the QuantumSec team: Q: Is securing a multi-tenant SaaS different from securing a regular web application? A: Yes, significantly. The main challenge in SaaS is tenant isolation: multiple customers share the same infrastructure and the same code. An authorization flaw in a regular web application affects one user. In a multi-tenant SaaS, the same flaw can expose every customer's data at once. Q: When should I run my SaaS's first pentest? A: The first pentest should happen before launching to enterprise customers or, at the latest, when you have your first customers with sensitive data in production. Waiting until the system is fully built increases remediation cost because there's more code to change. Q: Can I use an automated scanning tool instead of a pentest? A: Automated scanners (DAST, SAST) are a complement, not a substitute, for a pentest. They're good at catching known vulnerabilities like SQLi and XSS, but they don't catch business-logic flaws, cross-tenant IDORs or authorization issues specific to your data model. A manual, SaaS-specialized pentest covers what scanners can't. --- ## SaaS pentesting vs web pentesting: how do they really differ? URL: https://www.quantumsec.es/en/resources/saas-pentesting-vs-web-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. SaaS pentesting vs standard web pentesting: attack surface, multi-tenancy testing, business logic, duration and cost. Find out which one you need. When a SaaS company looks for a pentesting service, it often receives proposals for standard web pentesting. The problem is that generic web pentesting doesn't cover the attack surfaces specific to the SaaS model: tenant isolation, billing logic, plan-based permissions, webhooks and complex multi-organisation APIs. This guide explains exactly how a SaaS pentest differs from a conventional web pentest. Frequently asked questions answered by the QuantumSec team: Q: Can the same pentester carry out both a web and a SaaS pentest? A: Technically yes, but SaaS pentesting requires additional expertise in multi-tenant isolation testing and business logic analysis. A pentester experienced only in traditional web applications may overlook the vectors specific to the SaaS model. Make sure the team you hire has specific SaaS experience and not just the OWASP Top 10. Q: Does a SaaS pentest cover both the web and the API? A: Yes, SaaS pentesting is multi-layered by nature: it covers the web application, all the APIs (REST, GraphQL), the webhooks, third-party integrations and the administration panel. The exact scope is defined with the client before the test begins. Q: What documentation do I need to prepare for a SaaS pentest? A: The most useful items are: system architecture documentation (even if basic), a list of user roles and their permissions, access to test accounts in two different tenants (or instructions to create them), and API documentation if it exists (Swagger, Postman collection). The more context the auditor has about the product, the deeper and more efficient the test will be. --- ## How to hire a pentest: a practical guide for businesses URL: https://www.quantumsec.es/en/resources/how-to-hire-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Practical guide to hiring a pentest: what to ask the provider, what the proposal should include, how much it costs and how to get the most from the report. Hiring a pentest is a critical security decision, not a formality. Choosing the wrong provider can give you a false sense of security: an automated scan packaged as a pentest won't find the flaws a real attacker would exploit. This guide helps you hire the right service, ask the right questions and get the most value from the report. Frequently asked questions answered by the QuantumSec team: Q: How much does it cost to hire a pentest in Spain? A: It depends on scope: we break it down in detail, by pentest type, in our pricing guide. As a quick reference, a standard web pentest (one application, grey box) typically runs €1,500 to €5,000. The initial call to define your scope is free and with no obligation. Q: How long does it take to hire and run a pentest? A: The full process from first contact to report delivery is usually 2 to 4 weeks. The scope agreement and proposal take 2-5 days. The technical execution lasts between 3 and 10 business days depending on scope. The report is delivered 2-3 days after the technical phase ends. Q: Do I need to sign any document before starting? A: Yes. Before any testing, a scope agreement (Rules of Engagement) is signed defining exactly which systems are audited, from which IPs the team operates and which actions are allowed or excluded. An NDA (Non-Disclosure Agreement) is also usually signed. These documents protect both parties and are standard with any serious provider. --- ## EN 18031 standard: mandatory cybersecurity for IoT devices and radio equipment URL: https://www.quantumsec.es/en/resources/une-en-18031-iot-standard/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. EN 18031 guide: what it is, who it applies to, technical requirements and deadlines. Mandatory since August 2025 for radio equipment and IoT devices in the EU. The EN 18031 standard (adopted in Spain as UNE-EN 18031) establishes mandatory cybersecurity requirements for radio equipment and IoT devices placed on the European Union market. Since 1 August 2025, any manufacturer placing on the EU market devices with network connectivity — routers, IP cameras, wearables, IoT sensors, connected appliances, medical or industrial devices — must demonstrate conformity with this standard under the Radio Equipment Directive (RED 2014/53/EU). Frequently asked questions answered by the QuantumSec team: Q: Is compliance with EN 18031 voluntary or mandatory? A: It is mandatory for affected products since 1 August 2025. The standard is 'harmonised' under the RED Directive, which means complying with it grants a presumption of conformity with the Directive's legal requirements. Non-compliant products cannot be placed on the EU market. Q: How do I demonstrate that my device complies with EN 18031? A: There are two routes: (1) Self-assessment: the manufacturer drafts the EU declaration of conformity based on the harmonised standard, without third-party involvement (valid for most Default products). (2) Assessment by a notified body (NoBo): mandatory if the manufacturer does not follow the harmonised standard or if the product belongs to higher-risk categories. In both cases, the technical file must be maintained and available to market surveillance authorities. Q: Is penetration testing part of the EN 18031 compliance process? A: Yes. Penetration testing of IoT devices and hardware is the most effective tool to verify that the controls required by EN 18031 work in practice: that credentials are not reusable, that the update mechanism is not exploitable, that communications are genuinely encrypted and that there are no backdoors. A gap analysis without real technical testing can miss implementation flaws that an experienced IoT auditor would detect within hours. --- ## What is vulnerability triage and why does your team need it? URL: https://www.quantumsec.es/en/resources/what-is-vulnerability-triage/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Vulnerability triage is the process of validating, classifying and prioritizing security reports before they reach your team. Learn how it works and why it matters for any bug bounty or VDP. Vulnerability triage is the process by which every security report reaching your program —whether through a bug bounty, a VDP or a private disclosure channel— is analyzed, technically validated, classified by severity and prioritized before it reaches the development team. Without triage, every report carries the same weight. With triage, your team only sees what actually matters. Frequently asked questions answered by the QuantumSec team: Q: Is triage the same as vulnerability validation? A: Validation is part of triage, but triage is broader. It also includes classifying the report, communicating with the researcher, detecting duplicates, prioritization and handoff to the remediation team. Validation is the technical step that confirms the vulnerability is real and exploitable. Q: How long should triaging a report take? A: Industry standards call for 24 hours for the first response and between 1 and 5 business days for full validation, depending on complexity. Critical reports should get top priority: validation should be completed in under 24 hours. Q: Can I outsource triage without losing visibility into my vulnerabilities? A: Yes. A good outsourced triage service operates with full transparency: the client has access to every report, the technical assessments and the log of communications with researchers. Outsourcing removes the operational load, not the visibility. --- ## How to create a Vulnerability Disclosure Program step by step URL: https://www.quantumsec.es/en/resources/how-to-create-a-vulnerability-disclosure-program/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A step-by-step guide to designing and implementing a Vulnerability Disclosure Program: disclosure policy, intake channel, triage process and NIS2/CRA compliance. A Vulnerability Disclosure Program (VDP) is the official channel through which security researchers can report vulnerabilities in your systems in a coordinated, responsible way. Implementing one properly takes more than publishing a contact email: you need a clear policy, a response process and the resources to run it. Frequently asked questions answered by the QuantumSec team: Q: Is a VDP the same as a bug bounty? A: No. A VDP is a responsible disclosure channel that doesn't offer monetary rewards, though it can include public recognition. A bug bounty does include monetary payments for valid vulnerabilities. Many companies start with a VDP and evolve into a bug bounty once the program is mature. Q: Does NIS2 require having a VDP? A: NIS2 requires essential and important entities to have mechanisms in place to manage and report vulnerabilities. A VDP is the most widespread implementation for meeting this requirement. The Cyber Resilience Act also requires vulnerability notification channels for manufacturers of products with digital elements. Q: How long does it take to implement a VDP from scratch? A: With dedicated internal resources, a basic VDP can be operational in 2-4 weeks. If the design and implementation are outsourced to a specialized provider, the timeline can shrink to 1-2 weeks for the basic channel, with report management operational from day one. --- ## CVSS vs EPSS: which should you use to prioritise vulnerabilities URL: https://www.quantumsec.es/en/resources/cvss-vs-epss/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. CVSS measures theoretical severity. EPSS predicts the probability of exploitation. Learn when to use each and how to combine them for accurate vulnerability prioritisation. CVSS and EPSS are the two most widely used metrics in vulnerability management, but they measure different things. Using only CVSS leads to prioritising theoretically severe vulnerabilities that are never exploited in practice. Using only EPSS can lead to ignoring critical vulnerabilities with low immediate exploitation probability but devastating impact. The answer, as almost always in security, is that you need both. Frequently asked questions answered by the QuantumSec team: Q: Does EPSS replace CVSS? A: No, they are complementary. CVSS measures the intrinsic technical severity (how severe if exploited). EPSS measures the probability of exploitation (how likely someone is to exploit it soon). You need both metrics to make well-grounded prioritisation decisions. Q: Where can I check the EPSS score for a CVE? A: EPSS is published daily at first.org/epss and is available in most vulnerability management platforms (Tenable, Qualys, Rapid7). You can also query it via the FIRST public API or on the NVD. Q: What is CVSS 4.0 and how does it improve on CVSS 3.1? A: CVSS 4.0 introduces a more granular metric taxonomy, improves scoring for OT/ICS environments, adds supplementary metrics (automation, recovery) and removes ambiguities in temporal metric interpretation. For most web vulnerabilities, the most notable change is greater precision in impact assessment. --- ## False positives in bug bounty: how to reduce them without rejecting valid reports URL: https://www.quantumsec.es/en/resources/false-positives-in-bug-bounty/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. False positives in bug bounty drain your team and frustrate your best researchers. Learn how to manage them with real technical judgment and build a process that minimises them. A false positive in a bug bounty programme is a report that describes behaviour that looks like a vulnerability but is not: intended system behaviour, researcher environment misconfiguration, or theoretical vulnerabilities with no practical impact in your environment. Handling them poorly — rejecting without technical arguments or ignoring without a response — is one of the fastest ways to destroy your programme's reputation. Frequently asked questions answered by the QuantumSec team: Q: What is a normal false positive rate in a bug bounty? A: It depends on the sector and programme maturity. In well-managed programmes with a clear scope, the false positive rate is usually between 30% and 50% of total reports received. In new programmes or those with an ambiguous scope, it can exceed 70%. The goal is not zero false positives, but to manage them well and reduce them progressively. Q: How do I tell a false positive from a vulnerability I don't understand? A: If you are unsure whether a report is a false positive, the safe response is to reproduce the attack. If you cannot reproduce it with the researcher's steps, ask for more information before rejecting it. Rejecting without having attempted to reproduce the finding is a common mistake that damages the programme's reputation. Q: Can I mark a report as invalid without paying if I cannot reproduce it? A: Yes, but carefully. If the researcher provides clear evidence (screenshots, real tokens, server response data) and you cannot reproduce it, the right thing to do is to communicate this and request more detailed steps. Only if after a reasoned exchange it is still not reproducible is it justified to close it as invalid. --- ## Bug bounty vs Vulnerability Disclosure Programme: differences and when to use each URL: https://www.quantumsec.es/en/resources/bug-bounty-vs-vdp/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A bug bounty pays for vulnerabilities found; a VDP is a free responsible-disclosure channel. Compare costs, maturity requirements and when to use each. Bug bounty and Vulnerability Disclosure Programme (VDP) are two mechanisms for external researchers to report vulnerabilities in your systems. But they have different goals, costs and audiences. Choosing the wrong one — or launching one without being prepared for the other — can be counterproductive. Frequently asked questions answered by the QuantumSec team: Q: Can I have a VDP and a bug bounty at the same time? A: Yes. Many large companies have a public VDP (for general vulnerabilities) and a private bug bounty for their most critical assets. It is a valid combination that maximises coverage without compromising the budget. Q: Does a VDP legally protect me from researchers who hack my systems? A: A VDP establishes a framework for responsible action but does not grant automatic legal immunity. For effective legal protection, the policy must clearly specify the safe harbour conditions: which activities are permitted, which systems are in scope and that no legal action will be taken against researchers who act within the rules. Q: How much does it cost to have a VDP? A: The direct cost of a VDP is the management cost (there are no bounties). If you manage it internally, the cost is your team's time. If you outsource it, the cost is the management service fee. In both cases, it is significantly lower than the cost of an active bug bounty. --- ## What is a Vulnerability Disclosure Programme (VDP)? URL: https://www.quantumsec.es/en/resources/what-is-a-vulnerability-disclosure-program/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A Vulnerability Disclosure Programme (VDP) is the official channel for researchers to report vulnerabilities in your systems. Learn what it is, how it works and why NIS2 and the CRA require it. A Vulnerability Disclosure Programme (VDP) is the formal mechanism through which an organisation establishes how external security researchers can report vulnerabilities they find in its systems, applications or infrastructure. It defines the rules, the communication channel, response times and the resolution process. Frequently asked questions answered by the QuantumSec team: Q: What is the difference between a VDP and a bug bounty? A: A VDP does not offer monetary rewards; a bug bounty does. A VDP is a responsible disclosure channel with non-monetary recognition. A bug bounty adds payments proportional to the severity of findings. Many companies start with a VDP and evolve to a bug bounty once the programme is mature. Q: Where should I publish my VDP? A: In the security.txt file at /.well-known/security.txt (RFC 9116 standard), on a dedicated page on your website (security.yourcompany.com or yourcompany.com/security), and in the footer or privacy policy. The more visible it is, the easier it is for researchers to find it. Q: Do I need a platform to have a VDP? A: No. You can have a VDP with a dedicated email address and a policy published on your website. Platforms like HackerOne Response, Bugcrowd or Intigriti offer free or low-cost VDPs with integrated management tools, but they are not required to get started. --- ## How much does a bug bounty program cost: bounties, platform and triage URL: https://www.quantumsec.es/en/resources/how-much-does-bug-bounty-management-cost/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a bug bounty program really costs: €45K-€230K a year in-house vs €28K-€190K outsourced, split into bounties, platform fees and triage work. The cost of a bug bounty programme has two main components: the bounty cost (the rewards paid to researchers) and the management cost (the work of triaging, validating and coordinating reports). Many companies know the first number well but underestimate the second. Frequently asked questions answered by the QuantumSec team: Q: Which is more expensive: HackerOne/Bugcrowd or an independent external management service? A: The large platforms (HackerOne, Bugcrowd) charge for platform access and, if you contract managed triage, add an extra 20-40%. An independent management provider can be cheaper because it does not charge for platform access and can operate on tools you already have. Q: Can I have a bug bounty without a platform? A: Yes. You can manage a bug bounty programme with your own channel (web form, email) without needing a third-party platform. The platform adds researcher community, management tools and visibility, but it has a cost. For private programmes with specific researchers, an in-house channel may be sufficient. Q: What should the minimum budget be for a bug bounty? A: For a private programme with 5-10 invited researchers and a limited scope, a minimum budget of €5,000-€10,000 annually in bounties is a reasonable starting point. For a public programme, a minimum of €20,000-€30,000 annually in bounties plus the management cost is recommended. --- ## How to prioritise vulnerabilities when you have a backlog of unprocessed reports URL: https://www.quantumsec.es/en/resources/how-to-prioritize-vulnerability-backlog/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. If you are accumulating unprocessed vulnerability reports, you need a prioritisation process. Learn how to tackle a backlog with real technical and business judgement. An unprioritised vulnerability backlog is one of the most silent risks in security management. The company believes it is managing the situation because the reports are logged, but in reality there may be a critical vulnerability waiting in the queue behind 30 low-severity reports. The backlog needs an urgent prioritisation process, not just more time. Frequently asked questions answered by the QuantumSec team: Q: How many unprocessed reports is too many? A: There is no absolute number, but any report that has gone more than 7 days without a first response is a problem. If you have reports more than 30 days old without validation, that is an active risk situation that needs urgent attention, regardless of the total number. Q: What do I do with very old reports I cannot validate? A: If a report is more than 90 days old and you cannot reproduce it, communicate the status to the researcher and close it if there is no response. If the system has changed significantly, the vulnerability may no longer exist. Document the closure process. Q: Can I ask someone external to process my backlog? A: Yes. An external triage service can process a backlog on a one-off or ongoing basis. For processing a large backlog urgently, it is usually the fastest option: the provider already has the process and tools running. --- ## HackerOne, Bugcrowd, Intigriti and YesWeHack: a real comparison for security teams URL: https://www.quantumsec.es/en/resources/hackerone-bugcrowd-intigriti-comparison/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. HackerOne, Bugcrowd, Intigriti and YesWeHack compared for 2026: pricing, triage quality, EU data rules — and a lower-cost alternative for SMBs. HackerOne, Bugcrowd, Intigriti and YesWeHack are the four most widely used bug bounty platforms globally and across Europe. All offer programme management, researcher community and triage tools, but they have important differences in price, geographic coverage, community and management model. If you are evaluating which to use — or already have one and are not sure it is the right choice — this comparison helps you decide. Frequently asked questions answered by the QuantumSec team: Q: Can I migrate my programme from HackerOne or Bugcrowd to my own channel? A: Yes, though it needs careful planning to avoid losing active researchers. The process involves communicating the change in advance, exporting the report history, setting up the new channel and ensuring the external triage process is operational before migration. Q: Do these platforms have free options for VDPs? A: Yes. HackerOne, Bugcrowd, Intigriti and YesWeHack all offer free or very low-cost versions for basic VDPs. Managed triage and advanced features always have an additional cost. For a VDP without bounties and self-managed, these free options are a good starting point. Q: Which platform has the best researcher community for the Spanish market? A: Intigriti has the strongest European presence and an active community of European researchers, and remains the most efficient option for most Spain-focused programmes. YesWeHack is worth considering when data sovereignty is a hard requirement (public administration, the financial sector under DORA, entities under NIS2/CRA with strict EU-jurisdiction demands), thanks to its growing community in France and the rest of the EU. There are also specifically Spanish platforms like cazHack for very local programmes. --- ## NIS2 and Vulnerability Disclosure: what the directive requires and how to comply URL: https://www.quantumsec.es/en/resources/nis2-vulnerability-disclosure/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. NIS2 requires essential and important entities to manage vulnerabilities and have disclosure channels. Discover exactly what it demands and how to comply. The NIS2 Directive includes vulnerability management and the existence of notification channels among its requirements. For many companies, this means for the first time the need to implement a Vulnerability Disclosure Programme (VDP) and a formal process for managing external security reports. Frequently asked questions answered by the QuantumSec team: Q: When did NIS2 come into force in Spain? A: NIS2 had to be transposed into national law by EU Member States by 17 October 2024. Spain is in the process of transposition. Although the specific national law may be pending, affected companies should be aligning their controls with the directive's requirements, as the formal transposition does not change the substantive obligations. Q: What is INCIBE-CERT and what does it have to do with the VDP? A: INCIBE-CERT is the security incident response team of Spain's National Cybersecurity Institute. NIS2 establishes that essential and important entities must notify their national CSIRT (INCIBE-CERT in the case of Spain) of significant vulnerabilities. A well-implemented VDP includes the coordination process with INCIBE-CERT. Q: Can I outsource the management of the VDP required by NIS2? A: Yes. You can outsource the management of the reception channel, report triage and researcher communication to a specialist provider. Compliance responsibility remains with the company, but the provider handles the operations. This is a common solution for companies without a dedicated security team. --- ## How to manage a bug bounty program without an in-house security team URL: https://www.quantumsec.es/en/resources/managing-bug-bounty-without-internal-team/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Running a bug bounty program without an in-house AppSec team is possible. Discover your options and how an external provider can manage triage and full operations. Not every company that needs a bug bounty program has a dedicated security team. Growing startups, mid-sized companies with a single security lead, and organizations in transition can all benefit from researcher reports without having the internal capacity to manage them. The key is building the right process from day one. Frequently asked questions answered by the QuantumSec team: Q: Can I launch a bug bounty if I only have one security lead? A: Yes, with the right management. A single security lead can't handle triage for an active program alongside their other responsibilities. The solution is to outsource triage and have the internal lead act as an escalation and decision point, not as the day-to-day triager. Q: Can an external provider communicate with researchers on my behalf? A: Yes. Bug bounty management providers can act on the client's behalf: sending receipt confirmations, requesting additional information, communicating triage outcomes, and managing the bounty process. The researcher may or may not know an external provider is involved, depending on the client's transparency policy. Q: How long does it take the provider to start managing reports? A: Standard onboarding takes between 5 and 10 business days. After that, the provider can manage reports from day one. For urgent situations (large backlog, an incoming critical report), the timeline can be shortened. --- ## Coordinated Vulnerability Disclosure (CVD): what it is and how to implement it in your company URL: https://www.quantumsec.es/en/resources/coordinated-vulnerability-disclosure/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Coordinated Vulnerability Disclosure (CVD) is the process by which researchers and companies coordinate the public disclosure of vulnerabilities. A practical guide for businesses. Coordinated Vulnerability Disclosure (CVD), also known as responsible disclosure, is the process by which a security researcher who discovers a vulnerability reports it to the affected party before publishing it, and both sides coordinate the timeline for public disclosure. The international standard defining this process is ISO/IEC 29147. Frequently asked questions answered by the QuantumSec team: Q: How much time do I have to patch before the researcher publishes? A: The industry standard is 90 days. Google Project Zero popularized this timeframe, which later became an industry reference. Some organizations use 60 or 120 days. What matters is that the timeframe is set in your disclosure policy before the first report ever arrives. Q: What if the vulnerability affects a third-party vendor rather than my own software? A: If the vulnerability is in third-party software or infrastructure, your responsibility is to notify the affected vendor and coordinate with them. You can act as an intermediary between the researcher and the vendor, or forward the report directly to the relevant CERT if the vendor has no VDP. Q: What is a "safe harbor" in the context of a VDP? A: Safe harbor is the clause in your VDP policy stating that you won't take legal action against researchers who discover and report vulnerabilities while acting within the program's rules. It's a fundamental element for building trust with the research community. --- ## Vulnerability triage process: how we analyze every security report URL: https://www.quantumsec.es/en/resources/vulnerability-triage-process/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How the triage process for a vulnerability report works: from receipt to handoff to the remediation team. Methodology and technical criteria. Vulnerability triage isn't a quick read-through. Every report goes through a series of technical steps that confirm the vulnerability is real, assess its impact, and deliver the information the remediation team needs to act without further investigation. Transparency about how we work. Frequently asked questions answered by the QuantumSec team: Q: On average, how long does triaging a report take? A: It depends on complexity. A well-documented XSS or IDOR report can be triaged in 1-2 hours. A complex business-logic report, a vulnerability chain, or an infrastructure finding can take 4-8 hours. Reproduction is the most time-variable phase. Q: What tools do you use for triage? A: The same ones we use for pentesting: Burp Suite Pro for web analysis, API analysis tools, sandbox environments for controlled testing, and access to threat intelligence platforms to check EPSS and active exploitation context. Triage isn't just reading — it involves attacking. Q: Can you triage reports for every type of vulnerability? A: Yes. Our team has experience with web vulnerabilities (OWASP Top 10 and beyond), APIs, mobile applications, infrastructure, cloud, Active Directory, and business logic. For highly specialized vulnerability types (hardware, firmware, OT/ICS), we evaluate on a case-by-case basis. --- ## Responsible disclosure for companies: a guide for handling your first report URL: https://www.quantumsec.es/en/resources/responsible-disclosure-for-companies/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A practical guide for companies receiving vulnerability reports for the first time. How to respond, what to communicate, and how to build a responsible disclosure process. If a security researcher has just sent you a vulnerability report and you don't know what to do, you're reading the right article. Responsible disclosure is the process by which researchers notify companies of vulnerabilities before publishing them. How you respond in the next few hours can determine whether that vulnerability gets handled well or turns into a public incident. Frequently asked questions answered by the QuantumSec team: Q: Am I legally required to respond to a vulnerability report? A: It depends on your sector and applicable regulations. NIS2 and the Cyber Resilience Act establish vulnerability management obligations. GDPR may require notifying authorities if the reported vulnerability led to a data breach. In any case, not responding is never the right answer. Q: What do I do if the vulnerability has already been exploited? A: If there are signs the reported vulnerability has already been exploited, activate your incident response process. Prioritize containment and forensic analysis. Communication with the researcher can wait a few hours while you assess the scope of the incident. Q: Do I have to pay the researcher who reported the vulnerability? A: If you don't have a bug bounty program with a published reward table, you have no obligation to pay. Non-monetary recognition (a public mention, a Hall of Fame entry) is perfectly valid. If you want to incentivize future reports, you can make a voluntary payment or formally announce a bug bounty program. --- ## How to calculate a vulnerability's real impact beyond CVSS URL: https://www.quantumsec.es/en/resources/real-impact-of-a-vulnerability/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Base CVSS isn't enough to assess a vulnerability's real impact. Learn to contextualize risk using business factors, EPSS, and environmental CVSS. A vulnerability with a CVSS of 9.8 on an internal server with no internet access can be less urgent than one with a CVSS of 6.5 on your publicly exposed payments API. Base CVSS measures a flaw's intrinsic theoretical severity — regardless of the context in which it appears. To make correct prioritization decisions, you need to go further. Frequently asked questions answered by the QuantumSec team: Q: Does environmental CVSS change the base score significantly? A: It can change it significantly. A vulnerability with a base CVSS of 8.5 on an internal system with non-sensitive data and no internet exposure can drop to 5.0-6.0 once environmental metrics are applied. Conversely, a vulnerability with a base CVSS of 6.0 on a critical system with high-value data can rise to 8.0+. Q: How do I factor in business context without making scoring subjective? A: The key is defining the criteria up front: which systems are critical, which data requires which level of protection, which compensating controls are active. If those criteria are documented, environmental scoring stops being subjective and becomes a reproducible, auditable process. Q: Can I use EPSS for all vulnerabilities, or only for CVEs? A: EPSS only exists for vulnerabilities with an assigned CVE. For business-logic flaws or issues specific to your application that have no CVE, there's no EPSS score available. In those cases, real impact is assessed exclusively using the contextual factors (exposure, data, controls). --- ## Duplicate reports in bug bounty: how to detect and communicate them correctly URL: https://www.quantumsec.es/en/resources/duplicate-reports-bug-bounty/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Duplicate reports in bug bounty programs are common, and handling them poorly damages your relationship with researchers. Learn how to detect and communicate them correctly. A duplicate report in a bug bounty program is a finding that has already been reported by another researcher and is being resolved. Handling duplicates well — with transparency and fairness — is essential for maintaining researcher trust and the program's integrity. Frequently asked questions answered by the QuantumSec team: Q: Do I have to pay the second researcher who reports the same vulnerability? A: Standard practice is that only the first report receives the full bounty. However, some programs award partial recognition (10-25% of the bounty) to the second reporter if the report is high-quality and contributes to the resolution. This is a program policy decision. Q: What if the second report has more detail or a better PoC than the first? A: The second report doesn't displace the first in bounty priority, but it can still contribute to the resolution. In that case, the fairest approach is to credit it in the changelog or Hall of Fame, and consider a symbolic payment if the program has budget for it. Q: How long should I keep a report marked "active duplicate" before closing it? A: A report marked as a duplicate should be closed when the original report is closed: once the vulnerability is patched and verified. Keeping reporters informed about the status of the original (generically, without revealing details of another researcher's report) is good practice. --- ## How to outsource vulnerability triage without losing control URL: https://www.quantumsec.es/en/resources/how-to-outsource-vulnerability-triage/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Outsourcing vulnerability triage doesn't mean losing visibility. Learn what to delegate, what to keep in-house, and how to choose a triage provider. The most common concern when a company considers outsourcing vulnerability triage is losing visibility into its assets and security flaws. It's a legitimate concern. The good news is that you can design an outsourcing model that removes the operational burden without sacrificing strategic control. Frequently asked questions answered by the QuantumSec team: Q: Can the external provider see confidential company information in the reports? A: Yes, because vulnerability reports can contain session tokens, server response data, or information about internal architecture. That's why an NDA is a fundamental requirement before any access. The provider must have clear confidentiality policies and restricted access. Q: What if I disagree with the provider's assessment? A: The client always has the final say. If there's disagreement, it's reviewed together with technical evidence. The provider must be able to defend its assessment with technical arguments, and the client can change the final classification. It's a collaborative process, not a unilateral decision by the provider. Q: How long does it take to outsource triage from scratch? A: The full process of selecting a provider, signing an NDA, and onboarding usually takes 2 to 4 weeks. If you already have a provider in mind, technical onboarding can be done in 5-10 business days. --- ## Bug bounty program metrics: the KPIs that actually matter URL: https://www.quantumsec.es/en/resources/bug-bounty-program-metrics/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The right bug bounty program metrics go beyond the number of reports received. Learn the KPIs that actually measure your program's health and effectiveness. Measuring the success of a bug bounty program by the number of reports received is like measuring the quality of a pentest by the thickness of the report. What matters isn't volume — it's quality: how many real vulnerabilities were found, how quickly they were handled, and what impact they had on the company's security posture. Frequently asked questions answered by the QuantumSec team: Q: How often should I review the program's metrics? A: A real-time metrics dashboard is ideal for the operational team. For strategic reviews, a monthly report is enough. If the program is small (fewer than 20 reports a month), biweekly or monthly reviews work fine. Q: What TTFR should my researchers see for the program to stay attractive? A: The best programs in the market keep TTFR under 4-8 hours on business days. Going over 48 hours for the first acknowledgment is a factor that makes researchers flag the program as low priority. Response speed is one of the most important reputation factors. Q: How do I measure the ROI of my bug bounty program? A: Compare the total program cost (management + bounties) against the estimated cost of the vulnerabilities found if they had been exploited. Use the average cost of a data breach in your industry as a benchmark (IBM's Cost of a Data Breach is the most widely cited study). Most programs show a positive ROI once they find at least one critical vulnerability per year. --- ## CRA and Vulnerability Disclosure: what the Cyber Resilience Act requires from companies URL: https://www.quantumsec.es/en/resources/cra-vulnerability-disclosure/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Disclosure obligations under the Cyber Resilience Act: notification deadlines to ENISA, reporting channels and how to prepare your process before 2027. The Cyber Resilience Act (CRA) introduces specific vulnerability disclosure obligations for manufacturers and distributors of products with digital elements in the EU. This guide breaks down what the CRA requires, the notification deadlines and how to prepare your vulnerability management process to comply before 2027. Frequently asked questions answered by the QuantumSec team: Q: Does the CRA require me to set up a bug bounty programme? A: Not directly, but it does require you to have a vulnerability reporting channel and a CVD process. A bug bounty programme is one way to meet this obligation while also attracting researchers who help you discover vulnerabilities before they are exploited. Q: When do I have to start complying with the CRA's disclosure obligations? A: The reporting obligations for actively exploited vulnerabilities apply from August 2026. The regulation applies in full from December 2027. However, preparing internal processes takes months, so you should start now. Q: What happens if I receive a report of an exploited vulnerability outside working hours? A: The CRA's 24-hour deadline does not distinguish between working and non-working hours. You need an on-call process or an external team that can receive, assess and notify the report at any time. This is one of the strongest arguments for outsourcing triage. --- ## How to respond to a security researcher who reports a vulnerability URL: https://www.quantumsec.es/en/resources/how-to-respond-to-security-researcher/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Practical guide for companies: exact steps to handle a vulnerability report from an external ethical hacker and avoid premature disclosure. You get an email from a security researcher saying they found a vulnerability in your system. What do you do? How you respond in the next few hours will determine whether the incident gets resolved professionally or turns into a reputational problem. This practical guide covers the exact steps you should follow. Frequently asked questions answered by the QuantumSec team: Q: What do I do if the researcher has no proof of exploitation, just a description of the vulnerability? A: Evaluate the report on its technical merits. The discovery method (passive vs active) can affect legal considerations, but in many cases researchers find vulnerabilities through perfectly legal techniques (code analysis, controlled fuzzing, review of public APIs). Consult your legal team before making decisions based on the discovery method. Q: Am I legally required to respond to vulnerability reports? A: Under NIS2, if you're an operator of essential or important services, you must have a vulnerability management process. Under the CRA, if you manufacture digital products, you must have a reporting channel. In both cases, ignoring reports can amount to regulatory non-compliance. Q: What happens if the researcher discloses the vulnerability without giving me time to patch it? A: If you've responded professionally and the researcher discloses before the agreed deadline (or without ever agreeing one), your options are limited, but documenting the communication protects you reputationally. If the disclosure happened with no prior contact with you at all, consult your legal team — though the options are usually limited. --- ## Bug bounty vs pentesting: which to choose and when to combine them URL: https://www.quantumsec.es/en/resources/bug-bounty-vs-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Technical comparison of bug bounty and pentesting: strengths, limitations, costs and criteria for choosing the right offensive security model. Bug bounty and pentesting are two offensive security models with different goals, different economics and different results. Confusing them is a mistake that can leave you with a false sense of security or a poorly spent budget. This guide explains the real differences and when each model makes sense — or how to combine them. Frequently asked questions answered by the QuantumSec team: Q: Which is cheaper, bug bounty or pentesting? A: It depends on scope and results. A basic pentest can cost between €5,000 and €30,000 depending on scope. A bug bounty program has fixed management costs plus the bounties paid for vulnerabilities found. For large attack surfaces with many vulnerabilities, bug bounty can turn out cheaper. For one-off validation of specific components, pentesting is usually more efficient. Q: Can bug bounty replace pentesting for certifications like PCI DSS? A: In most cases, no. Regulatory standards like PCI DSS typically require a structured pentest with a defined scope and a formal report. Some standards are evolving to accept bug bounty programs as a complement, but rarely as a substitute for formal certifications. Q: What do I do if my bug bounty generates too many low-quality reports? A: This is the most common problem with poorly managed programs. The solution is professional triage that filters out duplicates, false positives and out-of-scope reports before they reach your technical team. Without triage, bug bounty creates more work than security. --- ## What is EPSS and how to use it to prioritise vulnerabilities more efficiently URL: https://www.quantumsec.es/en/resources/what-is-epss/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. EPSS: the probability model for vulnerability exploitation. How it works, how to combine it with CVSS and apply the prioritisation matrix. Practical guide. The Exploit Prediction Scoring System (EPSS) is a probabilistic model developed by FIRST that predicts the likelihood of a vulnerability being exploited within the next 30 days. Unlike CVSS, which measures theoretical severity, EPSS measures real-world risk based on observed exploitation data. Using them together transforms vulnerability prioritisation. Frequently asked questions answered by the QuantumSec team: Q: Does EPSS replace CVSS? A: No, they are complementary. CVSS measures the intrinsic technical severity of the vulnerability. EPSS measures the probability of exploitation within the current threat landscape. Using both together gives a much more complete picture than either on its own. Q: How often is EPSS updated? A: The EPSS model is updated daily. A vulnerability with a low EPSS today may rise significantly tomorrow if a public exploit is published or active exploitation is detected. That is why it is important to monitor EPSS continuously, not only at the time the CVE is published. Q: Does EPSS work for newly published vulnerabilities? A: For very recent CVEs (less than 30 days old), the EPSS score may be less reliable because the model has less observational data. In those cases, CVSS 4.0, CISA's Known Exploited Vulnerabilities (KEV) catalogue and your specific architecture context are additional important criteria. --- ## How to launch a private bug bounty program: a step-by-step guide URL: https://www.quantumsec.es/en/resources/how-to-launch-private-bug-bounty/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Practical guide to creating a private bug bounty program: scope, researcher selection, bounty table and managing your first reports. A private bug bounty program is the safest entry point into the bug bounty ecosystem for most companies. Instead of opening the platform to thousands of researchers at once, you invite a select, controlled group you already know. This guide covers every step to correctly launch a private program, from defining scope to managing your first reports. Frequently asked questions answered by the QuantumSec team: Q: How much does it cost to launch a private bug bounty program? A: The main costs are: the platform fee (varies by provider, from free up to thousands per month for enterprise platforms), bounties paid to researchers (highly variable based on findings), and the internal or external cost of report management. A small, well-managed private program can start with a very limited budget if the scope and process are right. Q: How long does a private bug bounty program take to produce results? A: The first reports usually arrive within the first few days. The most interesting findings appear in the first 4-8 weeks, once researchers have had time to do a deep analysis of the scope. Programs with no findings after 3 months usually point to a scope problem (too restrictive) or a bounty problem (not competitive enough). Q: Do I need an internal security team to manage a bug bounty? A: Not necessarily. Many companies outsource report management to specialized triage services that act as a middle layer between researchers and the development team. This dramatically reduces internal workload and improves the quality of responses to researchers. --- ## Vulnerability triage in AppSec teams: how to structure the process URL: https://www.quantumsec.es/en/resources/vulnerability-triage-appsec/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Guide for AppSec teams: how to implement an efficient vulnerability triage process with five phases, metrics, and when to outsource it. AppSec teams are the most common bottleneck in vulnerability management. They receive reports from multiple sources — automated scanners, pentesters, bug bounty, external researchers, SAST/DAST — and have to decide what to patch first with limited resources. A well-designed triage process turns that chaos into a predictable workflow. Frequently asked questions answered by the QuantumSec team: Q: How much time should an AppSec team spend on triage each week? A: It depends on report volume. As a benchmark, a team of 3 people handling 100 reports a month should spend 20-30% of its time on triage if the process is efficient. Without a structured process, that percentage can climb to 50-60%, leaving little time for proactive security work. Q: Do SAST and DAST replace manual triage? A: No. SAST and DAST are detection tools, not triage tools. They generate lists of possible vulnerabilities (with plenty of false positives) but can't assess business context, real exploitability in your specific configuration, or relative priority between findings. Manual triage is needed to turn scanner output into prioritized actions. Q: How do we measure whether our AppSec triage process is efficient? A: Key metrics: false-positive ratio reaching the development team (target <10%), time from detection to ticket assignment (target <48h for criticals), MTTR by severity, and percentage of vulnerabilities within SLA. If you're not measuring these metrics, you can't improve the process. --- ## CVSS 4.0: what's new and how it impacts vulnerability management URL: https://www.quantumsec.es/en/resources/cvss-4-vulnerability-management/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Analysis of CVSS 4.0 vs CVSS 3.1: new metric groups, positional naming, and how to adapt your vulnerability prioritization process. CVSS 4.0, published by FIRST in November 2023, introduces significant changes compared to CVSS 3.1. New metric groups, clearer naming for score types, and improvements to how security context is assessed. This guide explains what changes with CVSS 4.0 and how to adapt if you're already using CVSS 3.1 in your vulnerability management processes. Frequently asked questions answered by the QuantumSec team: Q: Do NVD and CVEs already use CVSS 4.0? A: NVD is in the process of adopting CVSS 4.0. Many CVEs still only carry a CVSS 3.x score in NVD. Vendors are the first to adopt CVSS 4.0 for their own advisories — for example, Cisco, Red Hat and Microsoft already publish some CVSS 4.0 scores in their security advisories. Q: Should I migrate my SLA policies from CVSS 3.1 to CVSS 4.0 right away? A: Not all at once. A gradual transition is the most practical approach. Keep your current CVSS 3.1-based policies for the existing backlog. For new vulnerabilities, adopt CVSS 4.0 and include the CVSS version in your SLA documentation to avoid incorrect comparisons. The full transition can take 12-18 months depending on the size of your inventory. Q: Does CVSS 4.0 solve the problem of severity false positives? A: Partially. CVSS 4.0 offers more refined Environmental metrics that let you better adjust the score to your specific context. But no version of CVSS fully solves the problem, because CVSS remains a severity assessment, not a real risk assessment. Complementing it with EPSS and asset context is still necessary. --- ## WordPress security audit for businesses: what it is, what it covers and when you need one URL: https://www.quantumsec.es/en/resources/wordpress-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a WordPress security audit covers, when your company needs one and why it's not the same as updating plugins. A technical guide for IT leads and CTOs. WordPress powers more than 40% of the world's websites. It also tops the statistics for compromised CMS platforms. Not because it is inherently insecure, but because its ecosystem of third-party plugins, themes and configurations creates a vast attack surface that automated tools and routine maintenance simply do not cover well enough. Frequently asked questions answered by the QuantumSec team: Q: How long does a WordPress security audit take? A: Between 2 and 5 business days for an installation of medium complexity. It depends on the number of active plugins, custom development, exposed endpoints and the agreed depth of the assessment. Q: Can the audit be run on the production environment? A: Yes, although the recommended approach is to work on a clone of production (staging) to avoid any impact on availability. If we work on production, we schedule the more invasive tests outside peak-traffic hours. Q: Does the audit also cover WooCommerce? A: If the installation includes WooCommerce, we audit it within the same scope: checkout security, order management, payment gateway integration and access to customer data. We also cover WooCommerce-specific plugins. --- ## WordPress penetration testing: real attack vectors and how an installation is analysed URL: https://www.quantumsec.es/en/resources/wordpress-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. WordPress penetration testing for businesses: the real attack vectors on plugins, wp-admin and REST API that a scanner misses. Get a free quote within 24h. A WordPress penetration test is not about running WPScan and waiting for results. It's about simulating the journey a real attacker would take: from initial enumeration to exploiting a vulnerability in a custom plugin or escalating privileges from an editor user to administrator. This guide explains what a technical WordPress penetration test covers and why it's different from any automated tool. Frequently asked questions answered by the QuantumSec team: Q: Does a WordPress penetration test require administrator access? A: Not necessarily. Black-box analysis starts without credentials. If broader coverage is wanted (authenticated logic analysis, privilege escalation between roles), test accounts with different access levels are provided. Q: Does penetration testing affect the website's SEO or ranking? A: A well-executed penetration test does not generate indexable content or modify production data. All tests are carried out in a controlled or staging environment. If work is done on production, potentially destructive tests are expressly agreed and carried out under supervision. --- ## WordPress hardening for businesses: reducing the attack surface beyond plugins URL: https://www.quantumsec.es/en/resources/wordpress-hardening-for-businesses/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. WordPress hardening for enterprise environments: which settings actually reduce your real attack surface, and how it differs from a full security audit. Talk to us. WordPress hardening is the set of configuration measures that reduce the attack surface of an installation before an attacker finds it. It does not replace a penetration test —which analyses vulnerabilities already present— but it is the baseline that determines how much damage an attacker can do if they gain an initial foothold. Frequently asked questions answered by the QuantumSec team: Q: Can our web agency do the hardening, or do we need a cybersecurity company? A: An experienced web agency can apply the basic hardening measures. What it cannot do is validate that they are effective under a real attack, or detect vulnerabilities in plugin code. That requires an external penetration test with an offensive methodology. Q: Does hardening affect the site's performance or functionality? A: Well-applied hardening measures do not affect performance. Some restrictions (disabling XML-RPC, limiting REST endpoints) may require adjustments to existing integrations, so they are reviewed before being applied. --- ## WordPress plugin security: the leading compromise vector in enterprise installations URL: https://www.quantumsec.es/en/resources/wordpress-plugin-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why WordPress plugins are the top compromise vector, how their security is audited and the real risks of third-party extensions. Book a plugin audit. 97% of attacks on WordPress don't exploit the core —which has a reasonably solid security record— but the ecosystem of third-party plugins and themes. With more than 60,000 plugins available in the official repository and tens of thousands more distributed independently, the attack surface of a typical enterprise installation is far larger than it appears. Frequently asked questions answered by the QuantumSec team: Q: How many plugins are too many for a secure installation? A: There's no magic number. Every active plugin is an additional attack surface. What matters is whether each plugin is actively maintained, whether it has known unpatched vulnerabilities and whether its code has been reviewed. An installation with 5 poorly chosen plugins is more dangerous than one with 30 well-managed ones. Q: Are premium plugins more secure than free ones? A: Not necessarily. There's a history of critical vulnerabilities both in the official repository and in popular premium plugins. The most relevant variable is the quality of the development team and its response speed when security reports come in. --- ## WooCommerce security: the specific risks of online stores on WordPress URL: https://www.quantumsec.es/en/resources/woocommerce-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. WooCommerce-specific security risks, what a technical audit covers and why online stores need more than a security plugin. Request your WooCommerce audit. WooCommerce turns WordPress into an e-commerce platform with access to card data, order history, customer personal data and integrated payment gateways. This layer adds security obligations (PCI-DSS for card payments) and attack vectors that go well beyond the usual risks of a corporate WordPress site. Frequently asked questions answered by the QuantumSec team: Q: If we use Stripe or PayPal, do we still need to audit checkout security? A: Yes. The payment gateway tokenises card data, but the checkout environment is still an attack vector. A malicious script injected into the page can capture card data before it reaches Stripe. The audit covers the whole environment, not just the gateway. Q: Does a WooCommerce audit count as evidence for PCI-DSS? A: The pentest report is valid as evidence of the security testing required by PCI-DSS. The specific scope is tailored to the requirements of the applicable merchant level. --- ## Magento and Adobe Commerce security audit: what it covers and why it's essential in e-commerce URL: https://www.quantumsec.es/en/resources/magento-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a Magento or Adobe Commerce security audit covers: core, extensions, admin panel, checkout and APIs. Real pentesting for enterprise stores. Free quote. Magento (Adobe Commerce) is the dominant e-commerce platform in the mid-market and enterprise segment. Its complexity —third-party extensions, custom modules, ERP and payment gateway integrations— creates an attack surface that goes far beyond the standard OWASP Top 10. Magento stores are high-value targets for attackers who specialise in card skimming and fraud. Frequently asked questions answered by the QuantumSec team: Q: Does the audit cover both Magento Open Source and Adobe Commerce? A: Yes. The methodology applies to both editions. Adobe Commerce (the enterprise version) adds further layers of functionality (B2B, staged content, advanced reporting) that are also included in the scope. Q: How often should a Magento store be audited? A: At least once a year and whenever new extensions are installed or significant code changes are made. Stores within PCI-DSS scope have specific requirements for pentesting frequency. Q: Does the audit cover Magento 2 fraud detection? A: Yes, as part of the payment and checkout review: we test for price manipulation, order integrity issues and Magecart-style card skimming — the main fraud vectors specific to Magento 2 stores — rather than relying only on the fraud-scoring rules built into the platform. Q: Is this an automated Magento code audit tool? A: No — it's a manual, expert-led audit. We do use automated scanners and static analysis as a first pass, but every finding is manually verified and exploited where relevant. An automated tool alone produces false positives and misses business-logic flaws (like Magecart injection points) that only manual testing catches. --- ## Magento and Adobe Commerce penetration testing: how the security of an enterprise store is analysed URL: https://www.quantumsec.es/en/resources/magento-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How a Magento or Adobe Commerce penetration test works, which attack vectors are tested and why enterprise stores need offensive analysis. Talk to our team. A Magento penetration test assesses store security by simulating the behaviour of an attacker who knows the platform: the default paths, the exposed APIs, the common vulnerability patterns in third-party extensions and the business flows that can be manipulated. It's a real offensive analysis, not a version scanner. Frequently asked questions answered by the QuantumSec team: Q: Does Magento penetration testing require access to the source code? A: Not for black-box or grey-box analysis. If you want to audit the code of custom extensions, the source code is provided for complementary static analysis. Q: Can the penetration test be done without affecting real orders? A: Yes. Tests that involve creating orders, modifying data or active injections are carried out in a staging environment. If one doesn't exist, we help set it up before the analysis. --- ## Magento checkout security: Magecart, price tampering and protecting the payment process URL: https://www.quantumsec.es/en/resources/magento-checkout-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Magento checkout attack vectors, Magecart card-skimming risk, price-tampering tests and how a technical audit protects your payment process. Book an audit. The checkout process is the most critical component of a Magento store from both a security and a business standpoint. A failure here can mean stolen card data, order fraud or loss of customer trust. Attackers know this, and it's where they focus their most sophisticated efforts. Frequently asked questions answered by the QuantumSec team: Q: Does a strict CSP policy fully protect against Magecart? A: It is the most effective mitigation, but it is not enough on its own. A CSP can be misconfigured (too permissive), can have exceptions for business-critical scripts, or an attacker can exploit a first-party script to inject the code. The audit evaluates the CSP and validates its real-world effectiveness. Q: Can price-tampering tests be carried out without generating real orders? A: Yes. The tests are run in a staging environment with test data. No real orders are generated and no payments are processed during the pentest. --- ## PrestaShop security audit: attack vectors and technical analysis for online stores URL: https://www.quantumsec.es/en/resources/prestashop-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a PrestaShop security audit covers, the most common attack vectors against PrestaShop stores and when your business needs a real technical assessment. PrestaShop is the most widely used e-commerce platform in Spain among SMBs and mid-market companies. Its popularity, combined with a third-party module ecosystem of uneven quality control, makes PrestaShop installations frequent targets of automated attacks and skimming campaigns. A security audit assesses the store's real resilience against these attacks. Frequently asked questions answered by the QuantumSec team: Q: Is the audit compatible with PrestaShop 1.7 and PrestaShop 8? A: Yes. The methodology adapts to the installed version. PrestaShop 1.7 has security particularities distinct from the 8 branch, and many stores remain on 1.7 due to module incompatibilities. We assess it in its real context. Q: What happens if you detect an active compromise during the audit? A: We report it immediately and adapt the analysis to identify the scope of the compromise: which files have been modified, what persistence exists and what data may have been affected. This typically leads to an incident response engagement. --- ## PrestaShop module security: the attack vector that compromises online shops most URL: https://www.quantumsec.es/en/resources/prestashop-module-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why third-party modules are the main compromise vector in PrestaShop, which vulnerabilities are most common and how their security is audited. Request an audit. Third-party modules in PrestaShop are the equivalent of WordPress plugins: third-party PHP code executed with full privileges over the installation. The difference is that the PrestaShop module ecosystem has a track record of critical vulnerabilities with active public exploits that have compromised thousands of shops, many without their owners ever knowing. Frequently asked questions answered by the QuantumSec team: Q: How do I know if any of my current modules has an active vulnerability? A: The most reliable approach is a systematic analysis of every installed module against up-to-date CVE databases. There are also continuous monitoring services that alert you when a vulnerability is published for an installed module. Q: Are modules from the official PrestaShop marketplace more secure? A: They have basic review controls, but they still have a history of vulnerabilities. Marketplace validation is not equivalent to a security audit. Modules with thousands of installations and years of activity have had critical CVEs. --- ## Drupal security audit: technical analysis for institutional and enterprise organisations URL: https://www.quantumsec.es/en/resources/drupal-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a Drupal security audit covers for government, universities and enterprise: modules, roles, REST API and ENS compliance evidence. Get a free quote. Drupal is the CMS of choice for public administrations, universities, media outlets and complex organisations that need advanced control over content, roles and publishing workflows. Its robustness as a platform does not eliminate security risks: third-party modules, custom configurations and the complexity of the environment are attack vectors that require specific analysis. Frequently asked questions answered by the QuantumSec team: Q: Is the audit compatible with Drupal 7, 9 and 10? A: Yes, although Drupal 7 has reached official end of support. If your organisation is still on Drupal 7, the audit documents the version-specific risk of running EOL software and prioritises migration as part of the remediation plan. Q: Does the audit include a review of the workflow and publishing modules? A: Yes. Workflow, content moderation and publishing modules are components with complex access-control logic that may contain privilege escalation between editorial roles. Q: What does a Drupal site audit evaluation actually deliver? A: A prioritised findings report (each issue rated by exploitability and business impact), proof-of-concept evidence for anything exploitable, and a remediation plan mapped to your module/contrib inventory — not just a vulnerability scan output. A free re-test after fixes is included. --- ## Drupal hardening for organisations: security configurations that reduce the attack surface URL: https://www.quantumsec.es/en/resources/drupal-hardening/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Drupal hardening for institutional and enterprise organisations: permissions, configuration, modules and HTTP headers. What it protects and what it doesn't replace. Drupal hardening sets the security baseline of the installation: configurations that reduce the visible attack surface before any exploitation attempt occurs. For organisations using Drupal in critical contexts —public administrations, universities, media outlets, healthcare portals— the right configuration is the first barrier. Frequently asked questions answered by the QuantumSec team: Q: Does Drupal's Security Review module cover all hardening? A: The Security Review module automates the verification of some basic configuration controls, but it does not detect complex permission logic issues, vulnerabilities in custom modules or server configurations. It is a starting point, not a substitute for an audit. Q: How long does it take to apply hardening to an enterprise Drupal installation? A: Between 1 and 3 days depending on the size of the installation, the number of modules and the complexity of the roles. The time increases if there are custom modules that require code review. --- ## Joomla security audit: technical analysis for enterprise and legacy installations URL: https://www.quantumsec.es/en/resources/joomla-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a Joomla security audit covers: extension vulnerabilities, legacy core risk and access control. Technical assessment for enterprise sites. Free quote. Joomla still underpins many corporate portals, intranets, institutional websites and the sites of organisations that migrated to it in the first decade of the 2000s and keep installations in production. These "legacy" installations accumulate security technical debt: unmaintained third-party extensions, outdated versions left without updates and configurations that have not kept pace with the evolution of threats. Frequently asked questions answered by the QuantumSec team: Q: Is the audit compatible with Joomla 3 and Joomla 4/5? A: Yes. Joomla 3 reached end of support in 2023. If your installation is still on Joomla 3, the audit documents the specific risk of the EOL version and assesses mitigation options while the migration is planned. Q: Do we have to migrate to Joomla 5 before running the audit? A: No. The audit assesses the security of the current installation. If the migration is planned, it may make sense to do it first so the analysis covers the future state. If the migration is not imminent, auditing the current version is useful for managing present-day risk. --- ## CMS penetration testing for businesses: what it is, what it finds and when it's essential URL: https://www.quantumsec.es/en/resources/cms-pentesting-for-businesses/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What CMS penetration testing is, how it differs from a scanner and when your business needs a real security assessment of WordPress, Drupal or Magento. Book a call. The term "CMS security audit" covers a broad spectrum: from running an automated scanner to simulating a real attack against the installation with offensive methodology. For a business that needs to reduce real risk, the difference between these extremes is enormous. This guide explains what a technical CMS penetration test is and when your organisation needs one. Frequently asked questions answered by the QuantumSec team: Q: Does CMS penetration testing also cover hosting and infrastructure? A: The usual scope focuses on the CMS application layer. The infrastructure (server, CDN, WAF, DNS) can be included as additional scope. This is defined in the phase prior to the assessment. Q: How much does a CMS penetration test cost? A: It depends on the size of the installation, the number of extensions, the complexity of any custom development and the agreed scope. The usual range for medium-complexity installations is between €2,000 and €8,000. By requesting an initial call we can scope the work and give you a concrete proposal. --- ## CMS security vs web maintenance: why they aren't the same and what it means for your business URL: https://www.quantumsec.es/en/resources/cms-security-vs-web-maintenance/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why updating plugins and running backups isn't enough to protect an enterprise CMS. Learn the difference and book a real CMS security audit with our experts. One of the most common misconceptions in companies with CMS-based websites is treating web maintenance as if it were security. The web agency updates plugins, runs backups and monitors uptime. That isn't security: it's operational management. The difference has real consequences when an incident occurs. Frequently asked questions answered by the QuantumSec team: Q: Can we ask our web agency to carry out the security audit as well? A: It depends on whether the agency has a dedicated offensive security team. If the agency uses the same tools it uses for maintenance (security plugins, automated scanners), it isn't a real technical audit. An independent audit by a specialised third party also brings the value of objectivity. Q: Do we need an audit even if we've never had an incident? A: Yes. The absence of detected incidents does not mean the absence of compromise. Many CMS compromises go unnoticed for months: the attacker keeps persistent access without interrupting the service. An audit detects active compromises as well as potential vulnerabilities. --- ## Common CMS vulnerabilities: what attackers look for and where they find it URL: https://www.quantumsec.es/en/resources/common-cms-vulnerabilities/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The most common security vulnerabilities in enterprise CMS (WordPress, Magento, PrestaShop, Drupal, Joomla) and the real risk they pose. Request your CMS audit. CMS platforms are the most attacked systems on the internet. Not because they are the least secure, but because they are the most widely used. Understanding which vulnerabilities attackers look for is the first step to prioritising an effective security strategy. Frequently asked questions answered by the QuantumSec team: Q: How do I know if my CMS has any of these vulnerabilities active? A: The most reliable approach is a technical penetration test that assesses the real installation. For an initial diagnosis, you can commission a vulnerability assessment (VA) that identifies outdated versions and known CVEs. Pentesting goes further and assesses real exploitability. Q: Do these vulnerabilities affect a small website the same as an enterprise one? A: Yes, although the impact differs. A small website with vulnerabilities can be used as a platform to attack third parties, to host phishing or for SEO spam. An enterprise installation with the same flaws means exposure of customer data, PCI-DSS implications and a far greater reputational and regulatory risk. --- ## CMS admin panel security: protecting your installation's most critical access point URL: https://www.quantumsec.es/en/resources/cms-admin-panel-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Protect your CMS admin panel (WordPress, Drupal, Magento) from brute force, credential stuffing and unauthorised access. Request a CMS admin access audit. A CMS admin panel is the highest-value target for an attacker: from there they hold full control over the site. It's also the point that receives the most automated attacks. Protecting it properly is the first line of defence for any enterprise installation. Frequently asked questions answered by the QuantumSec team: Q: Is MFA enough to protect the admin panel? A: It's the single most effective measure, but it doesn't eliminate every risk. Targeted phishing attacks can capture OTPs in real time (real-time phishing). Sessions stolen after valid authentication also bypass MFA. MFA is necessary but not sufficient. Q: What happens if the administrator reuses the same password across several sites? A: This is the credential stuffing scenario: if the administrator's credentials appear in a breach of another service, an attacker will automatically try them against the CMS panel. MFA mitigates this risk; monitoring compromised credentials (services such as HaveIBeenPwned for corporate domains) lets you act before the compromise occurs. --- ## CMS malware: why reinfections happen and how to prevent them for good URL: https://www.quantumsec.es/en/resources/cms-malware-reinfection-prevention/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why compromised CMS sites get reinfected and how to stop it: find the original entry vector, clean thoroughly and harden the install after an incident. Talk to us. Reinfection is the most frustrating pattern in CMS compromises: the site is cleaned, and malware reappears within days or weeks. It happens because surface-level cleaning removes neither the original entry vector nor the persistence mechanisms the attacker installed. This guide explains the reinfection cycle and how to break it. Frequently asked questions answered by the QuantumSec team: Q: Is a malware scanner enough to confirm the site is clean? A: No. Automated scanners detect known malware signatures. An attacker with access can obfuscate the code to evade signatures or inject it into legitimate files in positions the scanners don't analyse in depth. Manual review of modified files and access logs is necessary. Q: Do you have to notify users if the site was compromised? A: It depends on the type of data exposed. If the compromise affected users' personal data, the GDPR requires notifying the supervisory authority within 72 hours of detection and potentially the affected individuals. If it was only malware injection without access to data, the notification obligation depends on the forensic analysis of the scope. --- ## How to choose a CMS security provider: technical criteria and red flags URL: https://www.quantumsec.es/en/resources/how-to-choose-cms-security-provider/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What criteria to use when choosing a CMS security provider, how to tell a genuine technical firm from automated-tool resellers, and what to ask before you hire. The "CMS security" market mixes very different profiles: web agencies offering "security reviews" as a maintenance service, automated tools sold as complete solutions, and cybersecurity firms with genuine technical pentesting capability. Knowing how to tell them apart is critical to choosing well. Frequently asked questions answered by the QuantumSec team: Q: Can our web agency do the pentest, or do we need an external third party? A: An independent assessment by an external third party carries more weight both technically (an outside perspective, free of bias about your own code) and for any compliance or due-diligence process that requires it. ISO 27001 and ENS certifications explicitly require the pentest to be carried out by a team different from the one that develops and maintains the application. Q: How much should a quality CMS security audit cost? A: A genuine technical audit with manual analysis for a medium-complexity installation costs between €2,000 and €8,000 depending on the scope, the number of extensions and the complexity of the environment. Offers below €500 for a "security audit" are usually automated scanners with no manual analysis. --- ## CMS security for web agencies: managing the security of multiple client sites URL: https://www.quantumsec.es/en/resources/cms-security-for-agencies/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How web agencies can manage CMS security across multiple client sites, what liability they take on and when to outsource the technical audit. Talk to our team. Web agencies managing multiple client sites on WordPress, Drupal, Magento or PrestaShop face a particular risk surface: a compromise on a shared server or a poorly managed update process can affect dozens of clients at the same time. Managing security in this context calls for a systematic approach. Frequently asked questions answered by the QuantumSec team: Q: Can we offer CMS security as a service to our clients if we outsource the pentesting? A: Yes. It's the usual model for many agencies that want to add security to their portfolio without hiring an in-house offensive security team. The agency manages the client relationship and project coordination; the security provider runs the analysis and delivers the report. Q: What information does the security provider need to audit my clients' sites? A: For the initial analysis: the site URL, the CMS and version if known, the scope agreed with the client and access credentials if an authenticated assessment is performed. The agency acts as the intermediary to obtain the client's consent and coordinate availability of the environment. --- ## Google Workspace security for businesses: the complete guide URL: https://www.quantumsec.es/en/resources/google-workspace-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Complete guide to Google Workspace security for businesses: real risks, configuration, OAuth apps, domain-wide delegation and compliance. Written by ethical hackers. Google Workspace concentrates the email, documents, calendar and identities of your entire company in a single environment. That centralization makes it one of the most valuable targets for an attacker: compromising a misconfigured Workspace can grant access to the whole business. This guide explains the real risks, what to review and how to protect your environment beyond the default settings. Frequently asked questions answered by the QuantumSec team: Q: Is Google Workspace secure by default? A: It has a solid baseline, but the default configuration isn't the most secure: it prioritizes ease of use. For a business environment it must be hardened (mandatory 2FA, OAuth app control, restricted external sharing, etc.) following a framework such as the CIS Benchmark. Q: How often should I review my Workspace security? A: At least once a year, and always after major changes (migration, rapid growth, new third-party integrations) or any suspicion of unauthorized access, phishing or CEO fraud. --- ## Google Workspace hardening: a security checklist for businesses URL: https://www.quantumsec.es/en/resources/google-workspace-hardening/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Practical checklist to harden Google Workspace based on the CIS Benchmark: admins, 2FA, OAuth apps, Drive, Gmail, devices and logging. Google Workspace's default configuration prioritizes ease of use, not maximum security. This checklist, aligned with the CIS Google Workspace Benchmark, walks through the admin console settings that most reduce your attack surface, ordered by impact. Start with admin accounts and authentication: that's where an attacker looks first. Frequently asked questions answered by the QuantumSec team: Q: Is applying the CIS checklist enough? A: The CIS Benchmark is the best configuration baseline, but it doesn't replace an offensive audit: it reviews settings one by one, but it doesn't chain vectors or reproduce what a real attacker would do (OAuth abuse, persistence, escalation). The ideal is to harden with CIS and validate the result with an audit. Q: How many super admins should I have? A: Two or fewer, per the CIS Benchmark recommendation. Having few super admins reduces the attack surface of the most valuable accounts and makes it easier to protect them with security keys and enhanced monitoring. --- ## How attackers hack a Google Workspace URL: https://www.quantumsec.es/en/resources/how-attackers-hack-google-workspace/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The real vectors used to compromise a Google Workspace: phishing, OAuth consent phishing, Gmail persistence and domain-wide delegation abuse (DeleFriend). Understanding how a Google Workspace is attacked is the first step to defending it. Most compromises don't exploit a Google flaw, but the organization's configuration and behavior. These are the vectors we see again and again in audits and incident response, explained from the attacker's point of view. Frequently asked questions answered by the QuantumSec team: Q: If I change the password, do I lock the attacker out? A: Not necessarily. OAuth tokens, Gmail forwarding rules, app passwords and domain-wide delegations can keep access even if you change the password. After an incident you must revoke sessions and tokens, review rules and filters, and audit connected apps. Q: Does MFA protect me from all these attacks? A: Phishing-resistant MFA is essential, but it doesn't cover everything: it doesn't stop consent phishing (where the user authorizes a malicious app) or domain-wide delegation abuse, which doesn't require the user's credentials. That's why you need to harden the configuration and audit the environment. --- ## How much does a Google Workspace security audit cost URL: https://www.quantumsec.es/en/resources/google-workspace-audit-cost/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What determines the price of a Google Workspace security audit, indicative ranges and what it should include to be worthwhile. The price of a Google Workspace audit depends above all on scope: a configuration review against the CIS Benchmark doesn't cost the same as a complete offensive audit that reproduces an attacker's behavior. This guide explains what drives the cost, what ranges to expect and what an audit should include to deliver real value. Frequently asked questions answered by the QuantumSec team: Q: Does the audit include remediation? A: The audit delivers the analysis, the evidence and a prioritized remediation plan with concrete instructions. Applying the changes is done by your IT team following our guidance, with support during the process and an optional re-test to verify that critical findings have been fixed. Q: How often should I audit my Workspace? A: At least once a year, and always after major changes (migrations, user growth, new integrations) or any suspicion of an incident. Environments that connect many third-party apps benefit from more frequent reviews. --- ## How to review the third-party apps connected to your Google Workspace URL: https://www.quantumsec.es/en/resources/google-workspace-connected-apps/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Connected OAuth apps are a forgotten attack vector in Google Workspace. Learn to inventory them, classify them by risk and restrict them from the admin console. Every time an employee clicks Allow on a third-party application, that app gains access to part of your Google Workspace through OAuth. Over time, dozens of connected apps pile up, many forgotten and some with dangerous permissions over Gmail and Drive. This guide teaches you to review them and regain control from the admin console. Frequently asked questions answered by the QuantumSec team: Q: If I revoke an app, do I lock the attacker out of the account? A: Revoking the app invalidates its access token, so it cuts that vector. But after an incident you should also review Gmail forwarding rules, app passwords and active sessions, because the attacker may have left other persistence mechanisms. Q: Should I block all third-party apps? A: You don't need to block everything, but you should move to an allowlist model: block by default and approve only the apps the organization needs and trusts. It's the recommended balance between security and productivity. --- ## GDPR and Google Workspace: a compliance guide for businesses URL: https://www.quantumsec.es/en/resources/google-workspace-gdpr/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Is your Google Workspace GDPR-compliant? The Data Processing Amendment (DPA), EU data regions, DLP rules and Vault retention — checked step by step. Using Google Workspace doesn't exempt you from complying with the GDPR: your company remains the data controller for the personal data handled in Gmail, Drive or Meet. Google acts as a data processor, but the configuration, access and control of the data are your responsibility. This guide explains what you need so that your use of Workspace is GDPR-compliant. Frequently asked questions answered by the QuantumSec team: Q: Does Google Workspace comply with the GDPR for me? A: No. Google, as a processor, provides the tools and guarantees (DPA, SCC, data regions, encryption), but GDPR compliance is your company's responsibility: legal bases, informing data subjects, secure configuration, access control and breach management. Q: Can I store data only in the European Union? A: In certain Workspace editions you can configure data regions to store data at rest in the EU. It doesn't cover 100% of metadata or every service, so it's advisable to document transfers and rely on Google's DPA and SCC. Q: Where is Google Workspace's official data processing agreement? A: Google publishes the official document at cloud.google.com/terms/data-processing-addendum. It's now called the Cloud Data Processing Addendum (CDPA) — the successor to the former Data Processing Amendment (DPA) — governing how Google handles your data as a processor. Review it, accept it from the Admin console and keep that acceptance as evidence of GDPR compliance. --- ## Google Workspace and NIS2: requirements and how to comply URL: https://www.quantumsec.es/en/resources/google-workspace-nis2/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How Google Workspace fits NIS2 requirements: access control and MFA, event logging, incident management and supply chain security (third-party apps). If your company is subject to the NIS2 directive, your email and collaboration environment falls within scope. NIS2 doesn't mention Google Workspace by name, but it requires technical and organizational security measures that apply directly to how you configure and operate your Workspace. This guide translates those requirements into concrete actions on your Google environment. Frequently asked questions answered by the QuantumSec team: Q: Does NIS2 literally require me to audit my Google Workspace? A: The directive doesn't explicitly mention Workspace audits, but it requires measures (access control, MFA, logging, incident management, third-party risk) that in practice require reviewing and hardening your environment. An audit is the most effective way to demonstrate that those measures are in place. Q: How do I know if my company is subject to NIS2? A: It depends on the sector and the size of the organization. We cover this in our NIS2 adaptation guide; if you have doubts, in an initial call we help you determine whether you're in scope and what it means for your Workspace. --- ## OAuth consent phishing in Google Workspace URL: https://www.quantumsec.es/en/resources/oauth-consent-phishing-workspace/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Consent phishing tricks users into authorizing malicious OAuth apps with access to Gmail and Drive. How it works, why MFA doesn't stop it and how to protect your Workspace. Consent phishing is an attack that doesn't steal passwords: it steals permissions. Instead of tricking you into revealing your credential, it tricks you into authorizing a malicious application that gains access to your Gmail and Drive. It's one of the most effective vectors against Google Workspace because it bypasses MFA and persists over time. Frequently asked questions answered by the QuantumSec team: Q: If I change the password, is it solved? A: No. The attacker's access depends on the granted OAuth token, not on the password. To cut it you must revoke the app's authorization (its token) from the admin console, in addition to reviewing forwarding rules and active sessions. Q: How do I block this attack at the organization level? A: By configuring API access control in restricted mode: third-party apps are blocked except those you approve in an allowlist, and unverified apps are blocked. This way, even if an employee clicks Allow, the organization policy prevents access. --- ## Domain-Wide Delegation: the critical and least-audited risk in Google Workspace URL: https://www.quantumsec.es/en/resources/domain-wide-delegation-workspace/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Domain-wide delegation (DWD) allows impersonating any Google Workspace user. What DeleFriend is, why it's critical and how to audit your service accounts. Domain-wide delegation (DWD) is one of the most powerful —and most dangerous— features of Google Workspace. It allows a service account to act on behalf of any user in the domain. Used well, it enables legitimate integrations; poorly controlled, it's a direct path to full takeover of the environment. The DeleFriend research highlighted how easy it is to abuse. Frequently asked questions answered by the QuantumSec team: Q: Is DeleFriend still exploitable? A: Abuse of domain-wide delegation depends on the design of the feature and the configuration of each organization, not on a one-off patch. Mitigation is on your side: inventory of service accounts with DWD, least privilege of scopes, control of who generates keys in GCP and monitoring. Q: How do I know if I have domain-wide delegation active? A: It's reviewed in the Google admin console (domain-wide delegation management) cross-referenced with the GCP service accounts and their IAM permissions. It's precisely one of the points we cover in a Google Workspace audit. --- ## 2FA in Google Workspace: 2-step verification and security keys URL: https://www.quantumsec.es/en/resources/google-workspace-2fa/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to configure 2-step verification (2SV) and security keys or passkeys in Google Workspace, and why SMS isn't enough to protect your business. 2-step verification is the single measure that stops the most attacks in Google Workspace, but not all methods protect equally. This guide explains how to roll out 2SV across the organization and why security keys and passkeys are far superior to SMS. Frequently asked questions answered by the QuantumSec team: Q: Can I force all employees to use 2FA? A: Yes. From the admin console you can apply mandatory 2SV at the organization or organizational unit level, with an enrollment period. It's the recommended configuration for any company. Q: What happens if an employee loses their key or phone? A: It's handled with backup codes generated in advance and an admin-controlled recovery process. It's worth having that procedure defined before making 2SV mandatory. --- ## Super admins in Google Workspace: security best practices URL: https://www.quantumsec.es/en/resources/google-workspace-super-admins/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How many Google Workspace super admins should your company have? The CIS Benchmark answer, least-privilege roles and hardened account protection. The super admin account is the master key to your Google Workspace: it accesses everything, changes any setting and creates or deletes users. It's also the most coveted target for an attacker. Managing it well is one of the most important security decisions in your environment. Frequently asked questions answered by the QuantumSec team: Q: Why not use a single super admin account for everything? A: For two reasons: if that account is lost or locked, you're left without admin access; and if it's compromised, the attacker controls everything. The recommendation is two protected accounts and delegated roles for the rest of the team. Q: How do I detect if new admins are created without authorization? A: By configuring alerts in the admin console for privilege changes and reviewing the audit logs. The creation of a new super admin is one of the events that should always trigger an alert. --- ## Google Drive security for businesses: prevent data leaks URL: https://www.quantumsec.es/en/resources/google-drive-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to prevent data leaks in Google Drive: external sharing control, public links, permissions, shared drives and DLP. A guide for businesses. Google Drive is where your company's information lives: contracts, customer data, intellectual property. A misconfigured share can expose all of that to anyone with a link. This guide explains how to control sharing and reduce the risk of a data leak. Frequently asked questions answered by the QuantumSec team: Q: How do I find publicly shared files? A: With the investigation tool and the Drive reports in the admin console. In a Workspace audit we specifically review external sharing and public links containing sensitive data. Q: What happens to a departing employee's files? A: If they're in My Drive, they can be lost or orphaned when the account is deleted. That's why it's advisable to use shared drives for company information and to transfer data ownership as part of offboarding. --- ## Malicious Gmail forwarding rules: the persistence that survives a password change URL: https://www.quantumsec.es/en/resources/gmail-forwarding-rules-persistence/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Malicious forwarding rules and filters in Gmail are a persistence mechanism after a compromise. How to detect and prevent them in your company. When an attacker compromises a Gmail account, one of their first actions is to create a forwarding rule or a filter that sends them a copy of the email and hides the alerts. These rules persist even if you change the password, and they're one of the most overlooked indicators of compromise. Frequently asked questions answered by the QuantumSec team: Q: Can I prevent automatic forwarding to external addresses? A: Yes. From the admin console you can disable or restrict automatic email forwarding to external addresses at the organization level. It's one of the most effective measures to cut this persistence vector. Q: After an incident, what should I review in Gmail? A: Forwarding rules, filters, mailbox delegation, app passwords and active sessions. Any of them can keep the attacker's access even after you've changed the password. --- ## Secure offboarding in Google Workspace: a checklist for employee departures URL: https://www.quantumsec.es/en/resources/google-workspace-offboarding/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Secure offboarding checklist for Google Workspace: suspend the account, revoke sessions and tokens, transfer data and review rules, delegations and devices. Poorly managed former-employee accounts are a silent attack surface: access that stays active, data that's lost and tokens that are never revoked. This checklist covers the secure offboarding of an employee in Google Workspace, step by step. Frequently asked questions answered by the QuantumSec team: Q: Should I delete the account immediately? A: No. It's advisable to suspend it first, transfer the data and only then delete or archive it according to your retention policy. Deleting it outright can cause the loss of information and evidence. Q: If the account was compromised, is suspending it enough? A: Suspending it cuts the sign-in, but you must also review OAuth tokens, forwarding rules and delegations, because they can keep the attacker's access independently of the password. --- ## From Workspace to GCP: how an attacker escalates in the Google ecosystem URL: https://www.quantumsec.es/en/resources/google-workspace-to-gcp-escalation/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Google Workspace and Google Cloud are intertwined. How an attacker pivots from Workspace to GCP (and back) via identities and delegation, and how to audit it. Google Workspace is rarely isolated: it shares identities with Google Cloud (GCP) and with dozens of SaaS apps through SSO. That integration is convenient, but it creates escalation paths an attacker uses to move from email to infrastructure. This guide explains that boundary and how to audit it. Frequently asked questions answered by the QuantumSec team: Q: Is auditing only the Workspace enough? A: No, if you also use Google Cloud. The escalation leverages precisely the integration between the two: you must audit GCP IAM, service accounts and domain-wide delegations in addition to the Workspace configuration. Q: Who should worry about this? A: Any company using Google Workspace and Google Cloud together, especially if it has service accounts with domain-wide delegation or automated integrations between the two environments. --- ## Microsoft 365 security for businesses: the complete guide URL: https://www.quantumsec.es/en/resources/microsoft-365-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Microsoft 365 security guide for businesses: real risks, Entra ID, conditional access, OAuth apps, Exchange and compliance. Written by ethical hackers. Microsoft 365 concentrates your company's email, documents and identities in Entra ID, Exchange Online, SharePoint and Teams. That centralization makes it a priority target: compromising a misconfigured tenant can grant access to the whole business. This guide explains the real risks and how to protect your environment beyond the default settings. Frequently asked questions answered by the QuantumSec team: Q: Is Microsoft 365 secure by default? A: It has a solid baseline, but the default configuration isn't the most secure. For a business environment it must be hardened (phishing-resistant MFA, conditional access, OAuth consent control, restricted external sharing) following a framework such as the CIS Benchmark. Q: How often should I review my Microsoft 365 security? A: At least once a year, and always after major changes (migration, growth, new integrations) or any suspicion of unauthorized access, phishing or CEO fraud. --- ## Microsoft 365 hardening: a security checklist for businesses URL: https://www.quantumsec.es/en/resources/microsoft-365-hardening/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Checklist to harden Microsoft 365 based on the CIS Benchmark: admins, MFA, conditional access, OAuth apps, Exchange, SharePoint and logging. Microsoft 365's default configuration prioritizes ease of use. This checklist, aligned with the CIS Microsoft 365 Benchmark, walks through the settings that most reduce your attack surface, ordered by impact. Start with identity: Entra ID is where an attacker looks first. Frequently asked questions answered by the QuantumSec team: Q: Is the Secure Score and the CIS Benchmark enough? A: They're an excellent configuration baseline, but they don't replace an offensive audit: they review settings one by one, but they don't chain vectors or reproduce what a real attacker would do (illicit consent, AiTM, token theft). Q: What should I harden first? A: Identity: phishing-resistant MFA, conditional access without gaps (including blocking legacy authentication) and protecting global admins with PIM. That's where an attacker looks first. --- ## How attackers hack Microsoft 365 URL: https://www.quantumsec.es/en/resources/how-attackers-hack-microsoft-365/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The real vectors used to compromise Microsoft 365: AiTM phishing and token theft, illicit app consent, Exchange persistence and Entra ID abuse. Understanding how Microsoft 365 is attacked is the first step to defending it. Most compromises don't exploit a Microsoft flaw, but the organization's configuration and behavior. These are the vectors we see again and again in audits and incident response. Frequently asked questions answered by the QuantumSec team: Q: If I change the password, do I lock the attacker out? A: Not necessarily. Stolen session tokens, OAuth app consents, forwarding rules and credentials added to app registrations can keep access. After an incident you must revoke tokens and sessions, review consents and rules, and audit Entra ID. Q: Does MFA protect me from everything? A: Phishing-resistant MFA is essential, but AiTM phishing can steal the session and illicit consent doesn't require the password. That's why you need to harden conditional access, control apps and audit the environment. --- ## Google Workspace vs Microsoft 365 audit: what changes and what stays the same URL: https://www.quantumsec.es/en/resources/workspace-vs-microsoft-365-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Differences between auditing Google Workspace and Microsoft 365: identity, OAuth apps, delegation, logging and attack vectors. What changes and what stays the same. Google Workspace and Microsoft 365 solve the same problem —email, identity and collaboration in the cloud— but with different architectures. Auditing one or the other shares principles, but the specific vectors and tools change. This guide explains the differences so you know what to expect from each audit. Frequently asked questions answered by the QuantumSec team: Q: Is Microsoft 365 or Google Workspace more secure? A: Neither is inherently more secure: both have a solid baseline and incidents almost always come from the customer's configuration, not the platform. What makes the difference is how well your tenant is hardened and audited. Q: Can you audit both environments at once? A: Yes. We apply the same offensive methodology to Google Workspace and Microsoft 365, and we pay special attention to the integrations between them and with the cloud (GCP/Azure) when they coexist. --- ## How much does cybersecurity cost for an SMB in Spain (real prices) URL: https://www.quantumsec.es/en/resources/cybersecurity-cost-for-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Real cybersecurity pricing guide for SMBs in Spain: vulnerability assessment, pentesting, managed security and NIS2 compliance. One of the questions we get most from managers and IT leads at small and medium businesses is: "how much is this going to cost me?". The honest answer is that it depends on scope, but in this guide we break down the real price ranges for the cybersecurity services most in demand among Spanish SMBs, so you can plan your budget with concrete numbers instead of vague promises. Frequently asked questions answered by the QuantumSec team: Q: Are there grants or subsidies for cybersecurity for SMBs in Spain? A: Yes. Spain's Kit Digital (a government digitalization program for SMBs and freelancers) includes a "Cybersecurity" category with vouchers of up to €6,000 for companies with 3 to 50 employees. Some regional governments also run their own digital security grant programs. INCIBE also offers free resources and tools for SMBs. Q: Can I make a single investment and be permanently protected? A: No. Security is an ongoing process: new vulnerabilities appear, infrastructure changes and attack techniques evolve. We recommend an annual vulnerability assessment, a pentest every 1-2 years (or after major changes) and a periodic policy review. A managed service covers the continuous monitoring piece. Q: Do these prices include tax? A: The ranges in this guide are reference prices before tax. Final prices depend on your company's specific scope. Request a free, no-obligation quote: we'll send it within 24 hours. --- ## What is TLPT (Threat-Led Penetration Testing) and why DORA requires it URL: https://www.quantumsec.es/en/resources/what-is-tlpt/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. TLPT (Threat-Led Penetration Testing): what it is, which DORA-regulated entities must run it, and how it differs from standard pentesting. Technical guide. TLPT (Threat-Led Penetration Testing) is a red team exercise based on real threat intelligence that the DORA Regulation requires from the most critical financial entities in the EU. It isn't a more thorough pentest: it's a full adversary simulation — red team, not a scoped vulnerability assessment — designed to measure whether your organization detects and responds to a targeted attack, not just whether it has patchable vulnerabilities. Frequently asked questions answered by the QuantumSec team: Q: Is my company required to run TLPT if I already comply with DORA? A: Not necessarily. DORA applies broadly to a wide range of financial entities, but TLPT is only mandatory for those designated as critical by the competent authority, at a minimum cadence of every 3 years. Most entities subject to DORA are not required to run TLPT, but are subject to less demanding operational resilience tests. Q: Can QuantumSec run a full TLPT? A: A TIBER-EU-compliant TLPT requires providers specifically accredited for the threat intelligence and red team phases, coordination with the supervisor, and a concrete regulatory scope. We can help you prepare your organization before a TLPT (prior red team, hardening, gap analysis against the framework) and interpret your obligations under DORA; for the formal TLPT exercise, we guide you through the accreditation process and the right provider for your profile. --- ## Pentesting and cyber insurance: what insurers require in Spain URL: https://www.quantumsec.es/en/resources/pentesting-cyber-insurance/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What pentesting evidence insurers require before issuing a cyber risk policy in Spain, how it lowers your premium, and what happens if you claim without ever testing. Getting a cyber risk policy without having tested your security is getting harder: insurers have tightened requirements after years of high ransomware and CEO-fraud loss ratios, and now ask for concrete technical evidence before issuing a policy or offering better terms. A recent pentest isn't a paperwork formality for the insurer — it's the proof the underwriter uses to estimate how much risk they're actually taking on. Frequently asked questions answered by the QuantumSec team: Q: How recent does a pentest report need to be for an insurer? A: It depends on the insurer and the policy size, but the usual requirement is a report from the last 12 months. For higher-coverage policies or regulated sectors, some require mandatory annual cadence as a renewal condition. Q: Can the same pentest be used for multiple insurers or brokers? A: Yes — a technical pentest report following a recognized methodology (OWASP, PTES) with clear evidence is valid to present to different insurers or brokers while comparing policies. You don't need to repeat the audit for every quote. --- ## GraphQL pentesting: common vulnerabilities in GraphQL APIs URL: https://www.quantumsec.es/en/resources/graphql-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The most common GraphQL API vulnerabilities: exposed introspection, batching attacks, BOLA in resolvers and resource exhaustion. How they're tested in a pentest. GraphQL solves real problems with REST APIs — over-fetching, under-fetching, versioning — but introduces a different attack surface that REST-oriented tests don't cover well. A single endpoint, a strongly-typed schema and client-defined nested queries completely change what needs testing and how. Frequently asked questions answered by the QuantumSec team: Q: Is disabling introspection in production enough to be secure? A: No. Disabling introspection reduces easy reconnaissance surface, but doesn't fix access-control or resource-exhaustion issues — an attacker with partial schema knowledge (e.g. from client-side code) can still exploit vulnerable resolvers without introspection. Q: Does an automated scanner detect these GraphQL vulnerabilities? A: It partially detects exposed introspection and some known patterns, but BOLA in specific resolvers and query complexity limits require understanding the business logic of each mutation and relation — that's manual pentesting territory, not automated scanning. --- ## Power Platform and Power Automate security: shadow IT in Microsoft 365 URL: https://www.quantumsec.es/en/resources/power-platform-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why Power Automate and Power Platform are a shadow IT and data leakage vector in Microsoft 365, and how to audit connectors, flows and DLP policies. Power Platform — Power Automate, Power Apps, Power BI — lets any employee with a Microsoft 365 account build automation flows and apps without going through IT. That accessibility is also its biggest risk: hundreds of flows built by non-technical users, connected to corporate data, with no security review or centralized inventory. Frequently asked questions answered by the QuantumSec team: Q: Is disabling Power Platform entirely a realistic option? A: It's possible but rarely advisable: Power Platform delivers real, legitimate automation value. The more practical alternative is governing it — DLP policies, managed environments, periodic flow reviews — rather than blocking it outright, except in organizations with very strict isolation requirements. Q: Does this risk show up in a standard Microsoft 365 audit? A: Not always. Many M365 audits focus on identities, email and Drive/SharePoint, leaving Power Platform out as a less-known surface. It's worth explicitly requesting it as part of the scope if your organization actively uses it. --- ## Red Team vs Pentesting: key differences and how to choose URL: https://www.quantumsec.es/en/resources/red-team-vs-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Red Team and pentesting aren't the same: scope, objective, whether the defensive team knows, and what each one measures. How to decide which your company needs. Red Team and pentesting share tools and an offensive mindset, but they answer different questions and aren't interchangeable. Confusing them leads to hiring the wrong service: asking for a Red Team when what you need is a thorough pentest of one application, or asking for a pentest when the real question is whether your SOC would detect a real attack. Frequently asked questions answered by the QuantumSec team: Q: Does a Red Team replace periodic pentesting? A: No. They're complementary, not substitutes. A Red Team doesn't aim to maximize vulnerability coverage — it may not even touch certain systems if they're not on the path to the objective — so it doesn't replace the continuous technical hygiene that recurring pentesting provides. Q: How long does a Red Team exercise take compared to a pentest? A: A pentest usually takes 1 to 3 weeks depending on scope. A Red Team typically spans several weeks or even months, because it prioritizes stealth over speed: moving slowly and avoiding detection is part of the exercise's objective. --- ## Purple Team: when to combine Red Team and Blue Team URL: https://www.quantumsec.es/en/resources/purple-team-red-blue-team/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What Purple Teaming is, how it differs from a covert Red Team, and when it makes more sense to work live and collaboratively with your detection team. Purple Team isn't a third team: it's a way of working where the red team (attacker) and the blue team (defender) collaborate in real time, instead of operating covertly and separately as in a classic Red Team. The goal shifts from "measure whether you'd catch us" to "improve your detection together, as fast as possible". Frequently asked questions answered by the QuantumSec team: Q: Does Purple Team take as long as a Red Team? A: Usually less, and more predictably: being collaborative and focused on specific techniques (rather than a free-roaming objective to discover), a Purple Team session can be scoped to days rather than weeks, covering a specific set of MITRE ATT&CK TTPs. Q: Can we do a Red Team first and then a Purple Team? A: That's the most common and recommended sequence: the Red Team reveals which techniques you failed to detect; the follow-up Purple Team works specifically on those techniques collaboratively until the gap is closed, with immediate validation that the fix works. --- ## Phases of a Red Team exercise: how it works from start to finish URL: https://www.quantumsec.es/en/resources/red-team-exercise-phases/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The 5 phases of a real Red Team exercise: objective definition, threat intelligence, initial intrusion, post-exploitation and closure with the blue team. A Red Team exercise isn't a longer pentest: it's a process structured into distinct phases, each with its own objectives and risks, that can span several weeks or months. Understanding each phase helps set realistic expectations before hiring one. Frequently asked questions answered by the QuantumSec team: Q: How long does a full Red Team exercise take, start to finish? A: Typically between 4 and 12 weeks, depending on the complexity of the objective, the size of the organization and the required level of stealth. The post-exploitation phase is usually the longest because it prioritizes staying undetected over speed. Q: What happens if phase 3 doesn't gain any initial foothold? A: That's a legitimate outcome that still provides valuable information: it means the exposed perimeter and phishing awareness are solid. In that case, an assisted starting point (assumed breach) is usually agreed with the client to still be able to assess the later phases. --- ## Microsoft Teams security: external access, guest sharing and federation URL: https://www.quantumsec.es/en/resources/microsoft-teams-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Security risks in Microsoft Teams: external access, guest sharing, federation policies and unmanaged communication. How to audit and harden them. Teams is no longer just corporate chat: it concentrates meetings, files, channels and automations connected to SharePoint and Entra ID. Its default configuration favors external collaboration, which turns external access, guests and federation into one of the least audited surfaces of Microsoft 365. Frequently asked questions answered by the QuantumSec team: Q: Should I disable external access in Teams entirely? A: That's usually not realistic if your company collaborates with clients or vendors. It's better to replace "all domains" with an explicit list of allowed domains and review it periodically, rather than leaving federation open to any organization. Q: Do Teams guests count as Microsoft 365 licenses? A: No, guests don't consume a license, which reduces the friction to add them — and explains why they accumulate uncontrolled. That's exactly why they need a review and expiration policy independent of the employee onboarding/offboarding cycle. --- ## SharePoint Online security: external sharing risks URL: https://www.quantumsec.es/en/resources/sharepoint-online-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. SharePoint Online external sharing risks: "anyone with the link" links, permission inheritance breaks and data leakage. How to audit them. SharePoint Online is where most of a Microsoft 365 tenant's corporate documents live, and its sharing model is designed to make sharing as easy as possible. That ease is also its main risk: "anyone with the link" links and inherited permissions no one reviews end up exposing sensitive information outside the organization. Frequently asked questions answered by the QuantumSec team: Q: Is it ever safe to use "anyone with the link" links? A: Only for genuinely public content, with expiration configured. For any document with business information, sharing with specific people or groups (authenticated) is preferable, since it leaves a clear record of who has access and allows granular revocation. Q: How do I know if a site has "broken" permissions? A: The SharePoint admin center and tools like the file access report let you identify items with unique permissions (broken relative to the site). It's one of the first checks in any SharePoint audit, because it often reveals access no one remembers granting. --- ## Entra ID: privileged roles and Privileged Identity Management (PIM) URL: https://www.quantumsec.es/en/resources/entra-id-pim-privileged-roles/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to manage privileged roles in Entra ID with Privileged Identity Management (PIM): just-in-time access, access reviews and common mistakes. A permanent Entra ID global administrator is one of the most valuable targets for an attacker: compromising that account opens the door to the entire tenant. Privileged Identity Management (PIM) exists to eliminate exactly that risk, turning privileged roles from permanent into temporary and activated on demand — but only if configured correctly. Frequently asked questions answered by the QuantumSec team: Q: Is PIM included in all Microsoft 365 licenses? A: No. PIM requires Entra ID P2 licenses (included in Microsoft 365 E5 or as an add-on). It's an investment that's easily justified against the cost of a global administrator compromise, but license coverage should be verified before planning the rollout. Q: How many global administrators should my organization have? A: Microsoft recommends between 2 and 4, never fewer than 2 (to avoid lockout if one loses access) or many more than 4. Any double-digit figure is a sign that roles were assigned for convenience rather than actual need, and should be reviewed. --- ## Conditional Access: the most common configuration mistakes URL: https://www.quantumsec.es/en/resources/conditional-access-common-mistakes/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The most frequent mistakes when configuring Conditional Access in Entra ID: coverage gaps, forgotten exclusions and untested policies. How to avoid them. Conditional Access is Entra ID's most powerful access control, but also one of the easiest to silently misconfigure: a policy that looks correct can have a gap that renders it ineffective for a subset of users or scenarios, and that gap isn't discovered until someone exploits it. Frequently asked questions answered by the QuantumSec team: Q: Is a single MFA policy for all users enough? A: No. A single broad MFA policy doesn't cover legacy authentication, doesn't differentiate by session risk or device, and doesn't protect against token theft. A robust design combines several specific policies: legacy auth blocking, phishing-resistant MFA on critical accounts, and risk-based policies (Identity Protection). Q: How do I test a policy without risking locking out legitimate users? A: Deploy it first in "report-only" mode on a small pilot group, review sign-in logs for at least one or two weeks, and use Entra ID's "What If" tool to simulate its effect before enforcing it in production for all users. --- ## Azure AD Connect: hybrid sync attacks from on-premises to the cloud URL: https://www.quantumsec.es/en/resources/azure-ad-connect-hybrid-attacks/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How an attacker abuses Azure AD Connect to escalate from on-premises to the cloud: MSOL account, AD FS attacks and hybrid sync compromise. Azure AD Connect is the bridge that syncs your on-premises Active Directory with Entra ID, and like any bridge between two environments, it's also the path an attacker takes to escalate from one to the other. Compromising the sync server or its service account can grant full Entra ID access from an on-premises machine. Frequently asked questions answered by the QuantumSec team: Q: Does migrating to Azure AD Cloud Sync eliminate this risk? A: It significantly reduces it, but doesn't eliminate it entirely: Cloud Sync uses lightweight agents with fewer permissions than the classic Azure AD Connect install, but there's still a bridge between on-premises and the cloud that requires the same level of isolation and monitoring. Q: Does this risk apply if my company is 100% cloud, with no local Active Directory? A: No. If you don't have an on-premises Active Directory or hybrid sync, this specific vector doesn't affect you. It's a risk specific to organizations in transition or in a permanent hybrid model, which are still the majority among Spanish businesses. --- ## Microsoft 365 Copilot security risks: what actually changes in your tenant URL: https://www.quantumsec.es/en/resources/microsoft-copilot-security/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Microsoft 365 Copilot security risks: permission inheritance, pre-existing oversharing and Copilot Studio agent governance, and how to audit for them. Microsoft 365 Copilot doesn't create new vulnerabilities on its own: it inherits and surfaces the permissions that already existed in your tenant. The problem is that it does so at a speed and with a search capability that turns any pre-existing permission flaw — a forgotten link, a misconfigured folder — into a far more visible and easily exploitable risk for any user with Copilot access. Frequently asked questions answered by the QuantumSec team: Q: Can Copilot leak information a user shouldn't have access to? A: It shouldn't, because it respects existing Microsoft Graph permissions. The real risk isn't that Copilot grants new access, but that it makes trivially visible content that was already technically accessible due to a pre-existing permission flaw no one had detected. Q: Should I audit my tenant before enabling Copilot company-wide? A: Yes, it's the standard recommendation. Enabling Copilot without a prior oversharing cleanup in SharePoint, OneDrive and Teams multiplies the impact of any misconfigured permission that already existed, rather than creating the problem from scratch. --- ## Secure offboarding in Microsoft 365: a checklist for employee departures URL: https://www.quantumsec.es/en/resources/microsoft-365-offboarding/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Secure offboarding checklist for Microsoft 365: revoke sessions and tokens, transfer mailbox and OneDrive, review rules, delegations and devices. A poorly managed former-employee account in Microsoft 365 keeps access to email, files and federated applications long after the person has left, if the offboarding process is limited to disabling sign-in. This checklist covers the secure offboarding of an employee in Microsoft 365, step by step. Frequently asked questions answered by the QuantumSec team: Q: Is disabling the account in Entra ID on the departure date enough? A: It's not sufficient on its own. Disabling the account blocks new sign-ins, but doesn't revoke already-active sessions and tokens, and doesn't remove forwarding rules, delegations or OAuth app consents that can keep access independent of the password or account state. Q: What if the employee had a Conditional Access exclusion of their own? A: You need to review and remove any Conditional Access exclusion associated with the account as part of offboarding, because a forgotten exclusion can leave that identity without the MFA or managed-device protections that apply to the rest of the organization. --- ## Malicious Exchange Online forwarding rules: the foundation of CEO fraud URL: https://www.quantumsec.es/en/resources/exchange-forwarding-rules-bec/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How forwarding rules in Exchange Online are used for CEO fraud (BEC): persistence after compromise, concealment and how to detect them. Almost every case of CEO fraud (Business Email Compromise) we investigate shares the same technical element: a forwarding or inbox rule created by the attacker after compromising an Exchange Online account, letting them monitor billing conversations for weeks before stepping in at the right moment. Frequently asked questions answered by the QuantumSec team: Q: Does MFA protect me from CEO fraud based on forwarding rules? A: It helps prevent the initial account compromise, but it isn't foolproof: AiTM phishing can steal the session while bypassing MFA, and illicit OAuth consent doesn't even require the password. That's why detecting anomalous forwarding rules is an independent and necessary defense layer. Q: How do I tell a legitimate forwarding rule from a malicious one? A: Legitimate rules usually forward to known corporate addresses for a documented reason (temporary leave, delegation). Any rule forwarding to an unknown external domain, that hides or auto-deletes alert emails, or that was created without the user's knowledge, should be treated as suspicious and reviewed immediately. --- ## OT/ICS security: why IT pentesting isn't enough for industrial environments URL: https://www.quantumsec.es/en/resources/ot-ics-security-vs-it-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why industrial OT/ICS environments need a different security approach than conventional IT pentesting: availability, protocols and physical risk. Applying the same IT pentesting methodology to an OT/ICS environment is, at best, ineffective, and at worst, dangerous. Industrial networks prioritize continuous availability and physical safety over confidentiality, use protocols an IT scanner doesn't understand, and a failure in a control system can have physical consequences, not just a data breach. Frequently asked questions answered by the QuantumSec team: Q: Can I request the same pentest I run on my IT network for my industrial plant? A: It's not advisable. A scan or pentest designed for IT can cause availability outages on fragile OT devices, and ignores protocols and specific risks (Modbus, PLCs, physical safety) an IT approach doesn't cover. You need an adapted methodology focused on not interrupting production. Q: Does this service replace IoT pentesting? A: No, they're complementary: IoT and hardware pentesting assesses the security of individual connected devices (firmware, communications, physical hardware), while an OT/ICS assessment analyzes the full industrial environment — segmentation, protocols, remote access — in which those devices operate. --- ## CI/CD pipeline pentesting: what needs to be audited URL: https://www.quantumsec.es/en/resources/cicd-pipeline-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What's audited in a CI/CD pipeline pentest: exposed secrets, runner permissions, dependencies and software supply chain integrity. A compromised CI/CD pipeline doesn't grant access to a single application: it grants access to the factory that builds and deploys every application. It's one of the highest-impact surfaces in any software development organization, yet it's rarely audited with the same rigor as the application it produces. Frequently asked questions answered by the QuantumSec team: Q: Does CI/CD pipeline pentesting replace a source code audit? A: No, they're complementary. A source code audit reviews the application itself (SAST, manual logic and vulnerability review); pipeline pentesting reviews the infrastructure that builds and deploys that application — secrets, permissions, dependency integrity. Both surfaces matter because an attacker can choose whichever is weaker. Q: Which CI/CD platforms does this type of assessment cover? A: The methodology applies to any platform — GitHub Actions, GitLab CI, Jenkins, CircleCI, Azure DevOps — because the risks (exposed secrets, runner permissions, dependency integrity) are conceptually the same, even though configuration details differ between platforms. --- ## DevSecOps: how to integrate offensive security without slowing releases URL: https://www.quantumsec.es/en/resources/devsecops-offensive-security-sdlc/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to integrate pentesting and offensive security into a DevSecOps cycle without slowing releases: pipeline SAST/DAST, continuous pentesting and security gates. The most common objection to integrating offensive security into a DevSecOps cycle is that it "slows down releases". That's true if it's integrated badly: a multi-week full pentest can't live inside a pipeline that deploys several times a day. But the alternative isn't choosing between speed and security — it's distributing offensive security across different layers with different cadences. Frequently asked questions answered by the QuantumSec team: Q: Do I need to stop deployments to run a pentest? A: Not necessarily. A manual pentest can run against a staging environment equivalent to production, in parallel with normal development, and only block the deployment of the specific feature if a critical finding appears — not the entire organization's pipeline. Q: How often should an application with continuous releases be audited? A: It depends on the pace of change, but a common combination is: SAST/DAST on every commit, on-demand review of high-risk features before launch, and a full manual pentest at least once a year or after major architectural changes. --- ## What is OSINT and how it is used in corporate cyber threat intelligence URL: https://www.quantumsec.es/en/resources/what-is-osint/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. OSINT (Open Source Intelligence): what it is, which sources it uses and how it's applied in corporate cyber threat intelligence. Differences with CTI and legal limits. OSINT (Open Source Intelligence) is the discipline of collecting and analyzing publicly available information — social media, public records, metadata, source code, specialized search engines — to reach useful conclusions about a person, company or infrastructure. In cybersecurity it's the foundation cyber threat intelligence (CTI) is built on: before you can get ahead of a threat, you need to know what information about your organization is already visible to an attacker. Frequently asked questions answered by the QuantumSec team: Q: Is OSINT legal? A: Yes, as long as it's limited to genuinely public information and doesn't require bypassing any access barrier (login, authentication, exploits). Subsequent use of that information — especially if it includes personal data — must comply with applicable data protection regulation. Q: What's the difference between OSINT and hacking? A: Hacking involves accessing protected systems or data, typically without authorization if malicious. OSINT never crosses that line: it works exclusively with information already publicly accessible. They are different phases of the same offensive security exercise: OSINT is reconnaissance, not exploitation. Q: Do I need special tools to do OSINT? A: There are specialized tools and search engines (Shodan, Censys, theHarvester, metadata search tools) that speed up the process a lot, but the starting point — general search engines, social media, WHOIS — is freely accessible. The real value is in the skill to correlate information, not just the tool. --- ## Internal and perimeter network penetration testing: what it covers and when your company needs it URL: https://www.quantumsec.es/en/resources/internal-and-perimeter-network-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an internal and perimeter network pentest covers, what vulnerabilities it detects, and when your company needs one. A technical, practical guide. A network pentest assesses the security of your network infrastructure — perimeter (what faces the Internet) and internal (what sits behind the firewall) — by simulating what a real attacker would do once inside. Unlike an automated scan, it manually confirms which misconfigurations are exploitable, how far an attacker could move laterally, and which critical assets would be exposed if the perimeter fell. Frequently asked questions answered by the QuantumSec team: Q: Does an internal network pentest require physical access to my offices? A: Not necessarily. It can be run remotely via a device or VPN deployed on your network, or on-site if preferred. Both approaches are common; it is agreed based on your network architecture and preferences. Q: How often should a network pentest be repeated? A: At least once a year, and whenever there are significant infrastructure changes (new office, merger, network provider migration). If you are subject to NIS2 or the ENS, the regulation may require a specific cadence depending on your categorization. Q: Does an internal network pentest interfere with daily operations? A: The goal is that it doesn't. An execution window is agreed, and if something poses an immediate risk to availability, it is communicated before proceeding. Most tests are passive or have low operational impact. --- ## iOS vs Android penetration testing: key differences and what your app needs URL: https://www.quantumsec.es/en/resources/ios-vs-android-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Differences between iOS and Android app pentesting: attack vectors, methodology and how to scope your budget if your app is on both platforms. iOS and Android share the same audit standard — OWASP MASVS/MASTG — but have different architectures, permission models and attack vectors. Auditing an app on both platforms isn't repeating the same work twice: each operating system exposes different attack surfaces that require specific methodology and tooling. Frequently asked questions answered by the QuantumSec team: Q: Does auditing iOS cost the same as Android? A: Effort is usually similar when both apps have comparable complexity, though it can vary depending on each binary's exposed surface: an Android app with many exported components or an iOS app with complex obfuscation mechanisms may require more time on their respective platform. Q: If my app is hybrid (React Native, Flutter), do I still need to audit both platforms? A: Yes. Even though the business code is shared in a cross-platform framework, each native build (IPA for iOS, APK/AAB for Android) packages that code differently and uses its own OS-native storage and communication mechanisms, which can introduce platform-specific vulnerabilities despite sharing the same codebase. Q: Does mobile pentesting include the backend/API the app consumes? A: Mobile pentesting focuses on the client (the app installed on the device), but since the app always communicates with an API, it's common and advisable to also include a pentest of that API in the same scope to cover the full data flow. --- ## Cybersecurity for SMBs in the Valencian Region: sectors, risks and what the regulation requires URL: https://www.quantumsec.es/en/resources/cybersecurity-smbs-valencian-region/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Cybersecurity for SMBs in the Valencian Community: most exposed sectors, common risks and what the regulation actually requires (NIS2, ENS). A practical guide. The Valencian Region (Comunitat Valenciana) has a dense fabric of industrial, agri-food and logistics SMBs — from ceramics in Castellón to footwear around Elche-Alicante, alongside the logistics hub around the Port of Valencia. That profile, with many companies interconnected as suppliers to one another, means a security incident at one SMB can spread through its supply chain. This guide covers which risks are most relevant to the Valencian business fabric and what the current regulation actually requires, regardless of company size. Frequently asked questions answered by the QuantumSec team: Q: Are SMBs also bound by NIS2? A: NIS2 mainly applies to medium and large companies (more than 50 employees or over €10M in turnover) in regulated sectors. However, an SMB can still be included if it acts as a critical supplier to an essential or important entity, regardless of its own individual size. Q: Are there digitalization and cybersecurity grants available for companies in the Valencian Region? A: There are national-level digitalization grant programs (such as Kit Digital) and, occasionally, region-specific calls. Conditions and availability change frequently, so the most reliable approach is to check the calls in force at the time they're needed, rather than assuming a specific grant applies. Q: Does it matter whether my company is in Valencia city or another part of the region (Castellón, Alicante)? A: No, not for service delivery. A pentest, audit or threat intelligence program is delivered mostly remotely, with in-person or video-call meetings as convenient, regardless of which province of the Valencian Region the company is located in. --- ## MSSP vs in-house security team: when to outsource cybersecurity URL: https://www.quantumsec.es/en/resources/mssp-vs-in-house-security-team/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. MSSP vs in-house security team: what each model covers, when outsourcing makes sense and when to build your own team. A decision guide. A Managed Security Service Provider (MSSP) delivers continuous security functions — monitoring, vulnerability management, incident response — as an outsourced service, functions that would otherwise require building an in-house team with a CISO, analysts and dedicated tooling. Neither model is objectively better: the right choice depends on your company's size, budget and how much direct control you need over the security function. Frequently asked questions answered by the QuantumSec team: Q: Can I start with an MSSP and move to an in-house team later? A: Yes, it's a common transition as the company grows. A well-run MSSP leaves clear documentation and processes that make it easier, when the time comes, to build an in-house team on an already mature foundation instead of starting from scratch. Q: Does an MSSP fully replace a CISO? A: It can cover the function through a virtual CISO — strategic advisory and oversight of the security program —, but it does not remove the need for someone inside the company to hold ultimate responsibility and the authority to make decisions that affect the business. Q: What if I already have a security analyst but no 24/7 coverage? A: That's exactly the typical hybrid-model scenario: your in-house analyst handles day-to-day work and business decisions, and the MSSP covers monitoring outside business hours and first response to incidents that occur when your team isn't available. --- ## Most common vulnerabilities in SAP systems: a technical guide URL: https://www.quantumsec.es/en/resources/common-sap-vulnerabilities/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. The most common vulnerabilities in SAP environments: default accounts, RFC/Gateway interface, broken segregation of duties, ABAP code and patching. Most SAP compromises don't exploit an exotic flaw: they exploit well-known configurations that nobody thoroughly reviewed for years. This guide covers the most common vulnerabilities we find when auditing production SAP environments, from the easiest to fix to the one that usually carries the highest business impact. Frequently asked questions answered by the QuantumSec team: Q: Is an SoD review the same as a SAP pentest? A: No. An SoD review confirms, on paper, which permission combinations users hold. A SAP pentest confirms whether those combinations — and other technical vulnerabilities like the Gateway, ABAP code or patch status — are actually exploitable, and demonstrates the real impact of a compromise. Q: Is the RECON vulnerability (CVE-2020-6287) still relevant? A: The flaw itself has been patched since 2020, but it remains relevant as a reference case: months after disclosure there were still unpatched systems being actively scanned by attackers, illustrating the real risk of letting SAP Security Notes pile up unapplied. Q: How often should a SAP system be audited? A: At least once a year, and always after relevant changes: an S/4HANA migration, a significant expansion of modules or roles, or an incident that raises suspicion of a compromise or internal fraud. --- ## Cybersecurity awareness training for employees: a practical guide URL: https://www.quantumsec.es/en/resources/cybersecurity-awareness-training-for-employees/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a cybersecurity awareness and training program for employees should include, how often to run it, and how to measure whether it actually works. A company's weakest security link is almost never the technology: it's the person who clicks the wrong link on an ordinary day. The IT team's technical training doesn't reach the accounting employee who receives an email from "the CEO" requesting an urgent transfer. A well-designed awareness program isn't an online course taken once a year to tick a box: it's a continuous process that changes real behavior. Frequently asked questions answered by the QuantumSec team: Q: Is a once-a-year online course enough? A: No. It produces a temporary improvement that fades within weeks. Combining periodic training sessions with recurring phishing simulations delivers much stronger, more sustained results over time. Q: What's the difference between technical training and security awareness? A: Technical training teaches skills (how to configure a firewall, how to review a log). Awareness aims to change behavior in non-technical people: recognizing a phishing attempt, verifying an unusual payment request, not reusing passwords. They complement each other but are designed and measured differently. Q: How do you measure the ROI of investing in an awareness program? A: The most direct indicator is how the report rate and click rate on phishing simulations evolve over time. Indirectly, it also shows up in the reduction of real incidents handled by the security team that originated from human error. --- ## Microsoft Exchange Online security audit URL: https://www.quantumsec.es/en/resources/microsoft-exchange-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a Microsoft Exchange Online security audit covers: delegated permissions, connectors, transport rules, SPF/DKIM/DMARC and audit logging. Corporate email is both the company's most-used communication channel and one of the attackers' favorite targets: CEO fraud, targeted phishing and much of the lateral movement after an account compromise all pass through it. An Exchange Online audit goes beyond checking whether MFA is enabled: it analyzes delegated permissions, transport rules, connectors and audit logs to confirm what an attacker could actually do with access to a mailbox. Frequently asked questions answered by the QuantumSec team: Q: Do you need Global Administrator access to audit Exchange? A: No. A read-only Exchange administrator role or a delegated role with audit permissions is enough. The scope for any specific active tests is agreed in advance. Q: Does this audit replace the general Microsoft 365 audit? A: No, it complements it. If you've never audited the tenant, we recommend starting with the general Microsoft 365 audit. This Exchange-focused audit makes sense as a standalone piece when email is especially critical or after a mail-related incident. Q: Can it detect if a malicious forwarding rule is already active? A: Yes. Reviewing transport and mailbox rules is part of the standard scope, precisely because it's one of the most common persistence techniques after an account compromise. --- ## ENS certification: what the auditor checks and how to arrive prepared URL: https://www.quantumsec.es/en/resources/ens-security-audit-spain/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What the certification audit for Spain's National Security Framework (ENS) requires: categories, frequency and how to prepare. Based on RD 311/2022. Spain's National Security Framework (Esquema Nacional de Seguridad, ENS) regulates the security of information systems used by Spanish public administrations and the companies that provide services to them. Unlike NIS2 or DORA, the ENS has been in force since 2010, and its current version (Royal Decree 311/2022) requires a periodic, formal audit process — not just a statement of intent. This guide explains what that audit involves and how to prepare your organization before going through it. If you already know you need help getting there, our ENS audit and compliance service handles the whole process, from classification to certification. Frequently asked questions answered by the QuantumSec team: Q: Can a private company need to comply with the ENS even if it is not a public administration? A: Yes. Any private company providing services to a Spanish public administration that involve handling its information or using its systems may be required to demonstrate ENS compliance, usually as a tender or contract requirement. Q: How often does the ENS audit or self-assessment need to be repeated? A: At least every two years, both for the basic-category self-assessment and for the formal certification audit of medium and high categories. Q: Do I need to run a pentest to get ENS certified? A: It isn't a mandatory documentary requirement in itself, but it's strongly recommended as preparation: it helps confirm that the technical measures you'll declare in the certification audit actually hold up against a real attack, not just on paper. --- ## What investors ask for in your startup's security due diligence URL: https://www.quantumsec.es/en/resources/investor-security-due-diligence/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a Series A/B investor checks in your startup's security due diligence: what the pentest, policies and documentation they will ask you for actually cover. When a startup raises a serious funding round, technical due diligence no longer stops at code or architecture review: Series A investors and beyond almost always include a security posture review. Showing up unprepared rarely kills the deal, but it does create friction, slows the close and opens the door to less favorable terms. This guide explains exactly what you'll be asked for and how to prepare each piece in advance. Frequently asked questions answered by the QuantumSec team: Q: Do I need SOC 2 or ISO 27001 for a Series A? A: Usually not. Those certifications are typically requested by enterprise clients or investors at later stages (Series B onward). For a Series A, a recent pentest plus basic security documentation is usually enough. Q: How far ahead of closing should I start? A: At least 6-8 weeks, since a quality product pentest usually takes 1 to 3 weeks to run, plus scheduling time with the provider. Q: What if the pentest finds critical vulnerabilities right before closing? A: Better that you find them than the investor's due diligence team. A report showing findings already fixed with re-test evidence builds more confidence than having no report at all. --- ## Cybersecurity audit before selling your company URL: https://www.quantumsec.es/en/resources/cybersecurity-audit-before-selling-your-company/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why a pre-sale cybersecurity audit (M&A) stops a buyer from cutting the price or pausing the deal entirely. What it covers and when to run it. In any sale or merger process (M&A), the buyer will run their own technical due diligence, and if they're the first to find a security problem, that vulnerability becomes their negotiating leverage. A cybersecurity audit run on your side before taking the company to market lets you enter the process with your homework done: no surprises for the buyer, and no room for a technical finding to become an excuse to lower the price. Frequently asked questions answered by the QuantumSec team: Q: Does this replace the due diligence the buyer will run? A: No, it complements it. The buyer will run their own review (or demand access to yours), but arriving with a recent, independent report drastically reduces what they find on their own and speeds up the process. Q: What if the audit finds something serious? A: Better to find it yourself with months of runway than to have the buyer find it during negotiation. A finding remediated before taking the company to market doesn't affect valuation; one discovered by the buyer does. Q: Can the same report be used for multiple potential buyers? A: Yes, as long as it stays reasonably current (no more than 6-12 months old) and is backed by evidence that findings remain remediated at the time of the process. Q: What if the buyer wants the audit next week, not months ahead? A: Scope can be narrowed to the systems that actually underpin the business's value, prioritizing kickoff and dedicated team to compress the timeline. What shouldn't be skipped is manual verification and re-testing remediated findings: our express pentesting and audits guide explains exactly what can be sped up and what shouldn't. --- ## Virtual CISO for SMBs: what it is and when it makes sense URL: https://www.quantumsec.es/en/resources/virtual-ciso-for-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a virtual CISO (vCISO) is, what they actually do, the cost versus an in-house CISO, and when an SMB genuinely needs one instead of hiring. A senior CISO in Spain costs between €80,000 and €130,000 a year, a figure most SMBs can neither afford nor need full-time. The virtual CISO (vCISO) is the alternative: an external professional or team that takes on strategic security responsibilities part-time, without the cost or commitment of an in-house hire. This guide explains exactly what they do, what they don't replace, and how to tell if your company needs one now. Frequently asked questions answered by the QuantumSec team: Q: Can a vCISO sign the NIS2 or ENS declaration of conformity? A: They can prepare it and coordinate the whole process, but final legal responsibility rests with company leadership, not the external provider. Q: How many hours a month does a vCISO dedicate to a typical SMB? A: Usually 8 to 20 hours a month, adjusted by phase: more intensive in the first months (assessment and plan) and lighter during maintenance and follow-up. Q: Can I start with a vCISO and move to an in-house CISO later? A: Yes, that path is common. Many companies use the vCISO to build the security program and, once volume justifies it, hire someone in-house with the criteria and documentation already in place. --- ## ISO 27001 for SMBs: a practical guide to certifying without an endless project URL: https://www.quantumsec.es/en/resources/iso-27001-for-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Why your enterprise client demands ISO 27001 certification, what getting it actually involves for an SMB, and how to do it without a two-year project. More and more SMBs run into the same requirement: an enterprise client demands ISO 27001 as a contract condition, or a public tender requires it outright. The good news is ISO 27001 doesn't demand the same documentation structure for a 15-person company as for a 5,000-person corporation: the standard scales to the organization's real size and complexity. This guide explains what certifying actually involves as an SMB and how to avoid it becoming a two-year project. Frequently asked questions answered by the QuantumSec team: Q: How much does ISO 27001 certification cost for an SMB? A: Implementation consulting typically runs €3,000 to €12,000 depending on the starting point, plus the cost of the external certification audit (varies by certifying body and company size). Q: Can I reuse ISO 27001 work to also comply with NIS2 or ENS? A: Largely yes. The three frameworks share fundamental controls (access management, incident management, business continuity), so implementing one significantly reduces the effort for the others. Q: Does the certification expire? A: Yes, it lasts three years with annual surveillance audits to keep it active. --- ## Cyber insurance for SMBs: what insurers require before covering you URL: https://www.quantumsec.es/en/resources/cyber-insurance-for-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Which security controls insurers now require to issue or renew a cyber insurance policy, and how to avoid being denied cover or paying more for it. It's increasingly common for an insurer to reject a cyber insurance claim, or refuse to issue the policy at all, because the company hadn't implemented the minimum controls it declared on the application questionnaire. Cyber insurance is no longer a blank check: it's a contract with concrete technical conditions that must be met before, during and at the moment of the incident. This guide explains what controls are required today and how to avoid surprises. Frequently asked questions answered by the QuantumSec team: Q: Does cyber insurance replace having security measures? A: No, it's complementary. It covers part of the financial impact of an incident (forensics, notification, potential fines, business loss), but it doesn't prevent the incident or exempt you from basic controls. Q: What if I don't have any of the required controls? A: You can often still get coverage, but at a much higher premium or with specific exclusions for scenarios tied to the missing control. It pays off to implement them before contracting, not after. Q: Do I need a vulnerability assessment before buying the insurance? A: It's not mandatory, but it's the fastest way to know whether what you're about to declare on the questionnaire is actually true, and to catch gaps before the insurer finds them during a claim. --- ## ENS for SMBs supplying Spain's Public Administration URL: https://www.quantumsec.es/en/resources/ens-for-smb-public-sector-suppliers/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to comply with Spain's National Security Framework (ENS) as an SMB supplying the public sector, without a big consultancy's budget or team. If your company provides a technology service to a city council, a regional department, or any public body, at some point you'll be asked to prove compliance with Spain's National Security Framework (ENS). Many SMBs assume the ENS is only for large public-sector suppliers, but Royal Decree 311/2022 applies to any private company providing technology services to the public sector, regardless of size. This guide explains how to approach it as a small company. Frequently asked questions answered by the QuantumSec team: Q: Do I need an external certification audit if I'm BASIC category? A: Not necessarily. For BASIC category, conformity can be certified through a properly documented internal self-assessment, without needing an ENAC-accredited certification body. Q: What happens if I don't comply with the ENS and a tender requires it? A: You won't be able to bid for the contract or tender, and if you already have an active contract, the public body can require adequacy as a condition to keep or renew it. Q: Does ENS work help with anything else? A: Yes. It shares important controls with ISO 27001 and NIS2, so the effort of ENS adequacy reduces the work if you need to comply with those frameworks in the future. --- ## SOC 2 for startups: when you need it and how to approach it URL: https://www.quantumsec.es/en/resources/soc2-for-startups/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. When your startup actually needs SOC 2, which type (Type I or Type II) enterprise clients will ask for, and the real time and cost to get certified. SOC 2 is, by far, the security requirement most likely to stall an enterprise deal for a SaaS startup. It isn't a law or a regulatory obligation: it's an audit standard that your large clients demand as proof you handle their data responsibly. This guide explains when to start, which report type you'll be asked for, and what to expect from the actual process. Frequently asked questions answered by the QuantumSec team: Q: Is SOC 2 legally required? A: No. It's a voluntary audit standard (AICPA) that your clients require contractually, not a regulatory obligation like GDPR or NIS2. Q: Can I show a pentest instead of SOC 2? A: A recent pentest often helps and sometimes suffices for less demanding clients, but most mature enterprise buyers specifically ask for the SOC 2 report, not a substitute. Q: What happens if I fail the surveillance audit? A: SOC 2 isn't a permanent certification: each report covers a specific period. You need to repeat the audit cycle periodically (usually every 12 months) to keep reports current. --- ## Security checklist before a funding round URL: https://www.quantumsec.es/en/resources/security-checklist-before-funding-round/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. A security checklist to run through before raising a funding round: what to prepare so technical due diligence doesn't stall or delay the closing. Preparing for security due diligence isn't about improvising documents the week before closing: it's a short, concrete list of things to do 2 months ahead of time. This checklist summarizes, in priority order, what needs to be ready before you sit down with the investor's due diligence team. Frequently asked questions answered by the QuantumSec team: Q: Do I need to hire someone external for this checklist? A: The pentest does require a specialized provider. Policy and process documentation can be drafted internally, though external support usually speeds up the process and avoids formatting mistakes that due diligence analysts already recognize. Q: Does this checklist also work for a Series B or C? A: This is the minimum baseline. At later stages, investors usually add requirements like SOC 2 or ISO 27001, which are larger-scope projects beyond this initial checklist. Q: What if my startup is very early and has none of this? A: That's common at pre-seed or seed stage. Start with the pentest and the security policy: they're the two pieces asked about first and give the best maturity signal for the least effort. Q: What if the investor is closing in two weeks, not 6-8? A: The pentest is still the critical piece and the one with the least slack, but a project narrowed to the core product with a dedicated team can start within days. Our express pentesting and audits guide explains what can genuinely be sped up and what shouldn't be compressed. --- ## Cyber due diligence in M&A: what buyers actually check URL: https://www.quantumsec.es/en/resources/cyber-due-diligence-in-ma/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a buyer actually reviews in the technical due diligence of an acquisition: active vulnerabilities, past incidents and hidden security debt. If you're on the buying side of an acquisition, technical cybersecurity due diligence is where problems surface that even the seller didn't know they had: active vulnerabilities, former employee accounts that still have access, or a security incident never formally reported. This guide explains what a well-run cyber due diligence should cover and how to translate findings into business decisions — price, terms, or walking away. Frequently asked questions answered by the QuantumSec team: Q: How long does a cyber due diligence take in an M&A deal? A: It depends on scope and the access the seller provides, but a reasonably complete analysis typically takes 1 to 3 weeks. Q: Can I request one even if the seller already presents their own report? A: Yes, and it's advisable. The seller's report is a good starting point, but as a buyer it's worth validating findings independently, especially when there's a lot at stake in the deal. Q: What if I find something serious mid-negotiation? A: It becomes a negotiation point: price adjustment, part of the payment held in escrow conditional on remediation, or specific warranty clauses in the purchase agreement. --- ## AI Act for freelancers and SMBs: what actually applies to you URL: https://www.quantumsec.es/en/resources/ai-act-for-freelancers-and-smbs/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. If you use ChatGPT, a chatbot or AI tools in your business, the AI Act may apply even if you're a freelancer. What it actually requires, and since when. When people talk about the AI Act, most think of large tech companies developing AI models. But the regulation also applies to anyone who simply uses third-party AI tools in their business: a customer service chatbot, a hiring screening tool, or an AI assistant for managing clients. If you're a freelancer or SMB using any of these tools, this guide explains what genuinely applies to you. Frequently asked questions answered by the QuantumSec team: Q: How does the AI Act relate to GDPR? Does complying with one cover the other? A: No: they are separate obligations that stack. GDPR governs the processing of personal data; the AI Act governs the AI system itself, even when no personal data is involved. A chatbot that only answers product questions may fall outside GDPR and still carry a transparency duty under the AI Act. And the other way round: using AI to screen CVs triggers both at once — high risk under the AI Act, and automated decision-making about people under GDPR Article 22. In practice they are documented together, but complying with one does not exempt you from the other. Q: Do I need to register anything if I use ChatGPT in my business? A: If you use it as an internal productivity assistant, usually not. Obligations kick in when the system makes or supports decisions about external people (customers, candidates), not from the mere internal use of a generative AI tool. Q: Does the AI Act require me to hire a DPO like GDPR does? A: There's no mandatory equivalent role for small SMBs. The more demanding governance obligations (like an AI compliance officer) are mainly aimed at providers of high-risk systems, not small-scale deployers. Q: What happens if I don't comply and I'm a freelancer? A: Penalties are proportional to company size: the regulation provides that for SMBs and startups, fines are calculated using whichever is lower between the set percentages and the absolute figures, to avoid disproportionate penalties relative to their turnover. --- ## WiFi security audit: what vulnerabilities a pentester looks for URL: https://www.quantumsec.es/en/resources/wifi-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a professional WiFi audit actually tests: WPA2/WPA3, Evil Twin, rogue APs and network segmentation. The OWISAM methodology, explained in full. A misconfigured corporate WiFi network is a direct route into the internal network that needs neither a cable nor physical access to a building: being within signal range is enough. Yet it's one of the surfaces fewest companies formally audit. This guide explains what a WiFi security audit actually tests and why it differs from a conventional network audit. Frequently asked questions answered by the QuantumSec team: Q: Do you need to be physically on-site to run this audit? A: Yes, for the full assessment. Unlike a web or network pentest that can run remotely, wireless network analysis requires physical presence within signal range. We schedule the visit at a time that minimizes disruption to your operations. Q: Can a WiFi audit affect connectivity during business hours? A: The more aggressive tests (like deauthentication attacks) are agreed in advance and, if there is a risk of disruption, run outside business hours or during a maintenance window. Most of the assessment (inventory, configuration review) does not affect the service. Q: How long does a WiFi security audit take? A: Between 1 and 3 days depending on the number of sites, access points and segmentation complexity. The report is usually delivered 2-3 days after fieldwork ends. --- ## Artificial Intelligence and LLM pentesting: what vulnerabilities it looks for URL: https://www.quantumsec.es/en/resources/ai-llm-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an AI pentest actually tests: prompt injection, jailbreaking and data exfiltration. OWASP Top 10 for LLMs and MITRE ATLAS explained clearly. An LLM integrated into a product isn't just "more software to audit": it introduces attack vectors that didn't exist before, like prompt injection or system prompt exfiltration, which traditional pentesting tools aren't built to detect. This guide explains what AI system pentesting actually involves and why it needs its own methodology. Frequently asked questions answered by the QuantumSec team: Q: Does an automated vulnerability scanner detect these issues? A: No. Traditional scanners look for CVEs and misconfigurations in deterministic software. Prompt injection, jailbreaking or context exfiltration require an expert actively interacting with the model and testing variants, the same way manual pentesting differs from a plain vulnerability scan. Q: Does this only apply to chatbots, or also to copilots and AI agents? A: It applies to any system using an LLM: customer-facing chatbots, code copilots, agents with function calling, or RAG pipelines with access to corporate data. Each type has its own vectors that get tailored during the project scope. Q: How long does an AI system security assessment take? A: It depends on pipeline complexity: 5 to 10 business days for a standard chatbot or assistant, more if it includes function calling, multiple integrations or a complex RAG pipeline. --- ## AI-powered pentesting: how the methodology changes (and what doesn't) URL: https://www.quantumsec.es/en/resources/ai-powered-pentesting/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How AI improves traditional pentesting: faster recon, smarter finding prioritization and wider coverage. What still requires a human expert. Here AI isn't the target of the assessment, it's the tool: it speeds up reconnaissance, generates adaptive payloads and prioritizes thousands of findings, while the human expert focuses on business-logic exploitation and attack chaining, which is where real impact actually gets demonstrated. This guide explains exactly what AI does in a modern pentest and why it doesn't replace the pentester. Frequently asked questions answered by the QuantumSec team: Q: Is this the same as an automated AI scan? A: No. An automated scan, with or without AI, doesn't manually exploit findings or understand business context. Here AI speeds up specific tasks within an assessment directed by a human expert who exploits, validates and prioritizes every finding. Q: Is it cheaper than a traditional pentest? A: It usually delivers a better coverage-to-cost ratio because reconnaissance and prioritization are accelerated, freeing up the expert's time for exploitation. Final pricing depends on scope, same as any pentest. Q: What kind of projects benefit most from this approach? A: Large, complex applications with tight deadlines, pre-launch security reviews, code audits on large repositories, and bug bounty programs that need a systematic initial sweep before opening scope to external researchers. --- ## External ethical hacking: what an attacker can see and exploit from the internet URL: https://www.quantumsec.es/en/resources/external-ethical-hacking/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an attacker can see and exploit from the internet with zero prior access: OSINT, forgotten subdomains, exposed panels and email spoofing. An attacker targeting your company from the internet doesn't start with access or information: they start with a domain name and a search engine. External ethical hacking simulates exactly that starting point to answer the question that actually matters: what can someone achieve with zero prior advantage? This guide explains what it involves and how it differs from a conventional network pentest. Frequently asked questions answered by the QuantumSec team: Q: What's the difference between external ethical hacking and a network pentest? A: External ethical hacking focuses exclusively on what is visible from the internet, starting from zero with no credentials or prior access, and includes a full OSINT phase. A network pentest can cover both the external perimeter and the internal network, but usually starts from an already-defined scope. Q: Does it include OSINT on my employees? A: Yes, within the agreed scope. We identify what employee data is exposed in breaches, LinkedIn and other open sources that a real attacker would use for targeted phishing or credential stuffing attacks. Q: Can this assessment take down my production systems? A: By default we avoid any action carrying real risk to availability (denial-of-service attacks, data deletion). If any test carries potential risk, it is agreed with you before running it. --- ## Internal ethical hacking: how far an attacker can get inside your network URL: https://www.quantumsec.es/en/resources/internal-ethical-hacking/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an attacker can do once inside your network: lateral movement, Kerberoasting and escalation to Domain Admin. PTES + MITRE ATT&CK methodology. Most companies invest in protecting the perimeter, but once an attacker gets in — through phishing, a leaked account, a malicious insider — few really know how far they could get. Internal ethical hacking simulates exactly that scenario: an attacker who already has a foothold inside the network. This guide explains what it assesses and why Active Directory is almost always the final target. Frequently asked questions answered by the QuantumSec team: Q: What starting point is used for internal ethical hacking? A: We typically simulate a standard domain user with no special privileges — the most realistic scenario (an employee compromised by phishing, or an attacker with initial access). It's also possible to start from physical network access or an unprivileged account on a specific machine, depending on the agreed scope. Q: Can the test affect production systems? A: We coordinate every test with your IT team. The more invasive techniques, like modifying Active Directory objects, are run only with explicit authorization and during agreed windows. The goal is to demonstrate risk, not cause disruption. Q: How often should this assessment be repeated? A: At least once a year, and always after significant changes to Active Directory or network structure (mergers, new offices, migrations). If you are subject to NIS2 or ISO 27001, the regulation may require a specific cadence. --- ## ISO 27001 vs ENS: key differences and which one you need URL: https://www.quantumsec.es/en/resources/iso-27001-vs-ens/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ISO 27001 and Spain's National Security Framework (ENS) aren't interchangeable: scope, obligation and certification. How to know which one your company needs. ISO 27001 and Spain's National Security Framework (ENS) share more than it seems — both require a risk assessment, a statement of applicability and an audit before certification — but they answer different obligations and aren't always interchangeable. Confusing them leads to badly scoped projects: pursuing ISO 27001 certification when a public contract explicitly requires ENS, or the other way around. Frequently asked questions answered by the QuantumSec team: Q: Does ISO 27001 certification count as ENS compliance? A: Not automatically. They are independent certifications issued under different accreditation schemes, although they share a common technical base. Having ISO 27001 makes the ENS compliance project much easier (much of the documentation and controls already exist), but it doesn't replace formal ENS certification if a public contract explicitly requires it. Q: Which one is faster to get? A: It depends on the system category (ENS) or the scope (ISO 27001), but as a rough reference, an ENS BASIC-category project or an ISO 27001 with a narrow scope usually takes 3 to 6 months to the certification audit; MEDIUM/HIGH categories or wider ISO 27001 scopes can extend to 6-12 months. Q: What if my company already has NIS2 or DORA underway? A: Both share controls with the ENS and ISO 27001 (risk management, business continuity, incident notification), so it pays to map the common requirements from the start to avoid duplicating work across different compliance projects. --- ## What is MAGERIT and how is it used for risk analysis URL: https://www.quantumsec.es/en/resources/what-is-magerit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. MAGERIT explained: what it is, how it works, the PILAR tool, and why Spain's ENS requires it for information systems risk analysis. Full guide. MAGERIT (Risk Analysis and Management Methodology for Information Systems) is the reference methodology used by Spain's public sector to assess information system risk. It was developed by the Higher Council for e-Government and is now maintained by the Ministry of Finance; Spain's National Security Framework (ENS) explicitly cites it as the recommended risk analysis framework. Frequently asked questions answered by the QuantumSec team: Q: Is MAGERIT mandatory to certify under the ENS? A: The ENS requires a risk analysis, and MAGERIT is the methodology it cites as the reference, but it doesn't rule out an equivalent methodology if justified. In practice, the vast majority of ENS projects in Spain use MAGERIT because it's the recognized standard and because PILAR greatly simplifies documenting evidence. Q: Do I need to buy or install PILAR myself? A: PILAR is a tool with controlled distribution managed by the CCN, available to public administrations and authorized entities. In a consulting project, it's normally the consultant who has access to the tool and runs the analysis, delivering the generated reports as part of the project. Q: How long does a MAGERIT risk analysis take? A: It depends on the size of the asset inventory, but for a BASIC or MEDIUM category system it usually takes 2-4 weeks within the overall ENS compliance project. --- ## Statement of Applicability (SoA): what it is and how to build it in ISO 27001 URL: https://www.quantumsec.es/en/resources/statement-of-applicability-iso-27001/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What ISO 27001's Statement of Applicability (SoA) is, what it must include, and how to build it from your risk assessment and the 93 Annex A controls. The Statement of Applicability — SoA — is, along with the security policy, the document most scrutinized by any ISO 27001 auditor. It's the written proof that your company has reviewed all 93 Annex A controls one by one and decided, with reasoning, which apply and which don't. An SoA copied from a generic template is the fastest signal that the rest of the ISMS isn't real either. Frequently asked questions answered by the QuantumSec team: Q: Is the SoA reviewed once, or does it need updating? A: It's reviewed whenever something relevant changes: a new asset, a newly identified risk, a change in ISMS scope, or at minimum during each annual system review. An SoA that's out of sync with the current risk assessment is a typical finding in surveillance audits. Q: Can we use an SoA template as a starting point? A: As a structure, yes. As content, no: every justification must reflect your organization's real risk assessment. A template with generic, copied justifications is exactly what an experienced auditor spots and questions in the first review. Q: Who must sign off or approve the Statement of Applicability? A: Top management, as part of their accountability for the ISMS (ISO 27001 clause 5.1). It's not a purely technical document: it involves a business decision about which risks are accepted and which are mitigated. --- ## ISO 27001 internal audit: checklist and how to prepare it URL: https://www.quantumsec.es/en/resources/iso-27001-internal-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. How to prepare ISO 27001's mandatory internal audit: what clause 9.2 requires, who can run it, and a checklist before the external certification audit. Before an external auditor reviews your ISMS, the standard itself requires you to audit it yourself. ISO 27001's internal audit isn't a bureaucratic formality: it's the filter meant to catch deviations before the certification body finds them, when fixing them already costs time and credibility. Frequently asked questions answered by the QuantumSec team: Q: How often does the internal audit need to happen? A: At least once a year, and always before each external certification or surveillance audit. Many organizations audit in blocks throughout the year (for example, technical controls in one quarter, organizational processes in another) instead of doing it all at once. Q: Does the internal audit replace the certification audit? A: No. Both are complementary and mandatory: the internal one is a requirement of the standard you must fulfil yourself; the certification audit is run by an accredited external body and is the one that issues (or maintains) the certificate. Q: What happens if the internal audit finds a serious nonconformity? A: It gets documented, a corrective action is opened with a deadline and owner, and it's tracked until closed. Finding and fixing a nonconformity during the internal audit is exactly what the system is meant to do: it's worse if the certification auditor finds it first. --- ## ISO 27001 and ENS certification bodies in Spain: how to choose URL: https://www.quantumsec.es/en/resources/iso-27001-ens-certification-bodies/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an ENAC-accredited certification body is, how to choose between AENOR, Bureau Veritas, DNV and others, and what to ask before hiring the audit. Consulting prepares your ISMS; certification is issued by an independent third party. In Spain, that certification audit — for both ISO 27001 and the ENS — is only valid if carried out by a body accredited by ENAC (Spain's National Accreditation Body). Choosing among the available certification bodies — AENOR, Bureau Veritas, DNV, SGS and others — has more practical implications than it seems. Frequently asked questions answered by the QuantumSec team: Q: Can I switch certification bodies at renewal? A: Yes. At the end of the certification cycle (3 years for ISO 27001, 2 for the ENS) you can choose a different accredited body. It is common to compare price and availability at that point, although switching means the new auditor starts with no history of your organization. Q: Do all certification bodies cost the same? A: No. Price depends on the number of audit days (calculated using standards like IAF MD 5 based on employee count and scope complexity) and each body's day rate, which does vary between certifiers. It's worth requesting quotes from 2-3 accredited bodies before deciding. Q: Can a certification body refuse the certificate even after I've paid for the audit? A: Yes, and that is exactly what gives the certificate its value: if the audit reveals unresolved major nonconformities, the body won't issue the certificate until they're fixed. Paying for the audit buys the process, not the outcome. --- ## How much does ISO 27001 certification cost: a real cost breakdown URL: https://www.quantumsec.es/en/resources/how-much-does-iso-27001-certification-cost/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ISO 27001 cost breakdown: implementation consulting, certification audit and annual maintenance. Rough ranges by company size, no hidden line items. The cost of ISO 27001 certification is not a single figure: it's three separate line items — implementation consulting, certification audit and annual maintenance — that many companies only half-budget because they only ask about the first one. This guide breaks down each line item so the budget has no surprises halfway through the project. Frequently asked questions answered by the QuantumSec team: Q: Is the certification audit cost negotiable? A: The number of audit days is calculated using standardized criteria and shouldn't be negotiated downward without real justification — doing so compromises the validity of the certification. What does vary between bodies is the day rate, and that's where comparing quotes makes sense. Q: Is it cheaper to do ENS and ISO 27001 together rather than separately? A: Usually yes, because they share a significant part of the risk assessment, policies and controls. Approaching them as a single consulting project, even if certified separately, reduces total effort compared to doing them at different times. Q: Are there public grants to help fund ISO 27001 certification? A: There are sometimes digitalization or cybersecurity grant programs (national or regional) that can cover part of the cost. Programs change frequently, so it is worth checking what is currently available when starting the project rather than assuming a specific grant applies. --- ## Do you need a penetration test to get ISO 27001 certified? URL: https://www.quantumsec.es/en/resources/do-i-need-a-pentest-for-iso-27001/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ISO 27001 doesn't require a pentest by name, but Annex A and its risk-based approach make one nearly unavoidable in practice. When an auditor asks for one. The short answer: the standard doesn't literally require it, but in practice it's very hard to pass a certification audit without one if your organization has internet-facing systems or sensitive data. The reason lies in how ISO 27001 is built: it doesn't mandate specific tools, it requires you to prove you manage risk effectively — and for many technical risks, a penetration test is the only credible way to prove that. Frequently asked questions answered by the QuantumSec team: Q: Is an automated vulnerability scan enough? A: For low or medium severity risks, it may be. For assets your own risk assessment classifies as critical, an experienced auditor expects evidence of manual testing confirming real exploitability, not just an unverified list of CVEs. Q: Does the full pentest report have to be handed over to the auditor? A: Usually the executive report and confirmation that critical vulnerabilities were remediated (or an in-progress remediation plan) are presented as evidence, not necessarily the full technical detail with PoC, which can be treated as sensitive information. Q: What if the pentest finds critical vulnerabilities right before the audit? A: It's better for your own pentest to find them than for the auditor to find them some other way. What's being assessed isn't "zero vulnerabilities" but that a risk management process exists that detects and remediates them with a reasonable plan and timeline. --- ## ISO 31000 vs MAGERIT: which risk analysis methodology to choose URL: https://www.quantumsec.es/en/resources/iso-31000-vs-magerit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. ISO 31000 is a generic risk management framework; MAGERIT is Spain's public-sector-specific methodology. Which one to choose based on your compliance needs. Both ISO 27001 and the ENS require a risk assessment, but neither mandates a single methodology. In Spain, the choice almost always comes down to two options: ISO 31000, the generic international framework, or MAGERIT, Spain's public-sector-specific methodology. Choosing well avoids redoing the work if you need the other compliance framework later. Frequently asked questions answered by the QuantumSec team: Q: Can I use MAGERIT for an ISO 27001 project unrelated to the public sector? A: Yes. ISO 27001 doesn't require a specific methodology, only a coherent and repeatable risk assessment process. MAGERIT satisfies that perfectly, although in purely private contexts it's less common than ISO 31000/27005 since it's less known outside Spain. Q: Is ISO 27005 mandatory if you choose ISO 31000? A: No, but it's highly recommended: ISO 31000 is deliberately generic and doesn't go into information-security-specific detail, while ISO 27005 does, which makes practical application within an ISMS much easier. Q: Is switching methodology mid-project a problem? A: It's avoidable with a good upfront decision, but not catastrophic: what an auditor reviews is the outcome (assets identified, risks valued, treatment decided), not the methodology itself. Switching methodology means redoing part of the exercise, not losing the validity of the whole project. --- ## Express penetration testing: what can (and can't) be sped up URL: https://www.quantumsec.es/en/resources/express-penetration-testing/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Need an urgent pentest or security audit for a funding round, an acquisition or a compliance deadline. What can genuinely be sped up, and what shouldn't. The investor is closing in two weeks. The buyer wants security evidence next week. The tender with an ENS or ISO 27001 requirement has a deadline and there's no room left. In all three cases the question is the same: can a penetration test or security audit genuinely be done fast, without turning into an automated scan dressed up as a serious assessment? The honest answer is that part of the process can be compressed significantly, and another part shouldn't be touched if the report needs to hold up as real evidence for an investor, a buyer or an auditor. Frequently asked questions answered by the QuantumSec team: Q: Can you start this week? A: It depends on team availability at that moment, but we prioritize projects with a known business deadline (funding close, deal signing, tender deadline) over projects with no urgency. The initial scoping call can usually happen within 24-48 hours. Q: Is an express pentest less reliable than a normal one? A: Not if it's done by narrowing scope rather than cutting rigor. The difference between a serious express pentest and a low-quality one isn't speed, it's whether each finding's real exploitability is still manually verified or replaced with an automated scan. We speed things up by narrowing scope to what's critical and dedicating more team, not by skipping steps. Q: How much can the timeline realistically be compressed? A: For a scope narrowed to one specific critical asset (an application, a system), it's common to cut a standard project's timeline in half by prioritizing kickoff and team dedication. What doesn't compress is the minimum manual testing time and the post-remediation re-test, because that's where the report's real value lies. Q: What if the deadline is for a formal certification (ENS, ISO 27001), not just a technical report? A: There the room to accelerate is smaller: the certification audit itself is run by an external accredited body on its own schedule. What we can compress is the preparation phase beforehand — gap analysis, implementing critical controls, documentation — so you reach that audit as soon as possible with confidence it will pass on the first attempt. --- ## What is a web security audit and what does it include? URL: https://www.quantumsec.es/en/resources/what-is-a-web-security-audit/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What a web security audit covers, how it differs from an automated scan or a full penetration test, and what a serious final report should include. "Web security audit" is the term most companies search for when they want to know whether their site or application has exploitable vulnerabilities — and also the term many agencies use to sell a 20-minute automated scan dressed up as a serious assessment. This guide explains what a real web security audit should include, how it differs from a simple scan and from penetration testing, and what to demand before paying for one. Frequently asked questions answered by the QuantumSec team: Q: What is the difference between a web security audit and web penetration testing? A: When both are done rigorously, none: manual testing, controlled exploitation and verified real impact. The difference is usually marketing — some companies use "audit" for reviews more focused on configuration and "pentest" for the active intrusion exercise — but what you should demand is the same in both cases. Q: Does an automated scanner like Qualys or Nessus count as a web security audit? A: It works as a first filter, not as a full audit. It detects vulnerabilities known by signature or version, but doesn't understand your application's business logic: it won't see that two combined permissions allow privilege escalation, or that a checkout flow can be manipulated. A real audit uses automated scanning as a starting point and adds manual verification. Q: What should I demand to make sure the audit is real and not a scan in disguise? A: Ask for a previous audit report (anonymized) before hiring: if it only contains findings with a known CVE and no original proof of concept, it's a scan with a template on top. A real report includes business-logic findings specific to your application, backed by reproducible evidence (screenshots, requests/responses) and CVSS classification. Q: How long does a typical web security audit take? A: Between one and three weeks for a medium-sized application, depending on the number of roles, flows and endpoints in scope. Very large applications or those with multiple integrations may need more time; narrowly scoped engagements (a single critical flow) can be completed in a few days. Q: Do you need access to the application source code? A: Not for a black-box or grey-box audit, which are the most common: in black box we work without credentials, like an external attacker; in grey box we use standard user credentials to assess access control. Code access (white box) is optional and allows a more exhaustive analysis, but it's not a requirement for the audit to be real. --- ## AI usage policy: what it must cover and how to write it URL: https://www.quantumsec.es/en/resources/ai-usage-policy-for-companies/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What an AI usage policy should cover in an SMB: approved tools, data that must never be pasted into a chatbot, and who signs off each new use case. Most companies discover they need an AI usage policy the day someone pastes an entire contract into a public chatbot. By then the data is already out. An AI usage policy is not a defensive legal document: it is the set of rules that lets your team use these tools —which they will use anyway— without turning every prompt into a data leak. This guide covers what it must contain, which decisions to make before writing it, and why blanket bans do not work. Frequently asked questions answered by the QuantumSec team: Q: Does a 10-person company need an AI usage policy? A: Yes, and it is probably easier than in a large one. In a small team one page is enough: the list of approved tools, three rules on which data never leaves, and who to ask when in doubt. Size does not change the risk of someone pasting a contract into a chatbot; it only changes how much paperwork it takes to prevent it. Q: Is using the paid version of ChatGPT or Copilot enough? A: It helps, but it does not replace the policy. Enterprise plans typically do not train on your data and let you disable retention, which covers part of the contractual risk. They do not cover who decides what may be pasted, who reviews the output before it reaches a client, or what happens with regulated data. The tool is one piece; the policy is the frame. Q: How often should the policy be reviewed? A: At least every six months, and whenever a new tool is approved or an existing one changes its processing terms. AI vendors revise their terms frequently, and a policy that authorises a tool under conditions that no longer apply is worse than having none, because it creates a false sense of control. Q: Who should sign off the policy? A: Leadership, because it means accepting a level of risk, with input from whoever leads IT or security and from at least one owner of the areas that will use it most. If only legal signs it, the usual result is a correct document that nobody applies. --- ## Shadow AI: the AI your team already uses and you cannot see URL: https://www.quantumsec.es/en/resources/shadow-ai-at-work/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. What shadow AI is, why your employees already use ChatGPT without telling you, and how to find which AI tools are in play before banning anything. Shadow IT has been a known problem for years: applications entering the company without going through IT. Shadow AI is its accelerated version, and it spreads faster for two reasons: it requires installing nothing, and it produces an immediate, visible benefit for whoever uses it. A browser and a personal account are enough for corporate information to start leaving the organisation with no record at all. Frequently asked questions answered by the QuantumSec team: Q: How do I know whether there is shadow AI if nobody admits it? A: Start with the OAuth applications connected to your Google Workspace or Microsoft 365 tenant, and with DNS or proxy logs pointing at AI vendor domains. Those two sources usually produce an initial inventory within hours. Complete it with an anonymous survey: usage from personal devices appears in no corporate log and is only discovered by asking without consequences. Q: Is an employee using ChatGPT on their personal phone shadow AI? A: If they use it with company information, yes, and it is the hardest variant to control because it leaves no trace in corporate infrastructure. That is why purely technical control has a low ceiling: the combination that works is a convenient approved alternative, a clear policy on which data never leaves, and training with real examples. Q: What is the difference between shadow IT and shadow AI? A: Classic shadow IT usually involves installing software or contracting a service, which leaves a trace in spend or on devices. Shadow AI needs only a browser and a personal account, spreads faster, and additionally appears passively when a vendor switches on AI features in a tool you had already approved, without anyone making a decision. Q: Does blocking AI vendor domains solve the problem? A: It reduces usage on the corporate network and works as a temporary measure, but it pushes usage to personal devices, where you lose all visibility. As a standalone measure it usually makes the real situation worse: the same volume of information leaves the organisation, now with no record at all. --- ## How to use AI safely at work URL: https://www.quantumsec.es/en/resources/how-to-use-ai-safely-at-work/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Practical rules for using ChatGPT, Copilot or Gemini at work without leaking client data, contracts or source code. With examples and a checklist. Almost every guide on safe AI use is written for the security team. This one is written for the person using the tool every day: whoever has to decide, in ten seconds, whether they can paste that email, that contract or that snippet of code into a chat. These are the practical rules that settle most of those decisions, with concrete examples of what goes wrong. Frequently asked questions answered by the QuantumSec team: Q: Can I use ChatGPT for work if my company has no AI policy? A: You can, carefully, applying the rules in this guide: corporate account where one exists, anonymise first, never credentials or regulated data, and review the output. That said, the absence of a policy is an organisational problem, not yours: it is worth raising the need for one, because without it every person improvises a different standard and the company has visibility into nothing. Q: Is it safe to paste my company code into an AI assistant? A: It depends on the account and the code. On a corporate account that does not train on your data, to debug an isolated function, the risk is low. On a personal account, or with code containing proprietary business logic, credentials or connection strings, no. As a practical rule: share the minimum snippet that reproduces the problem, never the whole file or the repository. Q: Is Microsoft 365 or Google Workspace AI safer than ChatGPT? A: When deployed in the corporate tenant, yes, in one specific respect: the data stays inside the contracted environment and under the processing agreement you already hold with the vendor. But it introduces a different risk: these assistants access everything your user can see, so if your file permissions are wrong, the AI suddenly surfaces information that had been badly shared for years but buried. Q: Do I have to disclose that content was generated by AI? A: For content that is published or delivered to a third party, it is the recommended practice, and in certain scenarios involving interaction with people the AI Act requires explicit transparency. Internally it usually need not be declared, but it should be clear who reviewed the content, since that is the part carrying the responsibility. --- ## Who does DORA apply to: how to tell if your entity is in scope and what it must deliver URL: https://www.quantumsec.es/en/resources/who-does-dora-apply-to/ Source: QuantumSec (https://www.quantumsec.es) — Spanish offensive security company, OSCP-certified team, backed by INCIBE Ventures. Which financial entities are covered by DORA, what each one must deliver and how to check whether your organisation falls within the scope of the regulation. DORA has applied since January 2025 and its scope is far broader than many entities assume. It does not cover banks alone: it reaches insurers, fund managers, crypto-asset service providers, payment institutions and, through the supply chain, the ICT providers serving them. This guide answers the question any security lead asks first — whether it applies and what has to be delivered — before getting into the technical detail of the regulation. Frequently asked questions answered by the QuantumSec team: Q: DORA aplica solo a bancos A: No. El ámbito cubre unas veinte categorías de entidad financiera, entre ellas aseguradoras, gestoras de fondos, empresas de servicios de inversión, entidades de pago y dinero electrónico, proveedores de servicios de criptoactivos e infraestructuras de mercado. Los bancos son una parte del ámbito, no el ámbito completo. Q: Mi empresa es pequeña, queda fuera de DORA A: El tamaño no exime con carácter general: activa el principio de proporcionalidad. Las microempresas y ciertas entidades pequeñas pueden acogerse a un marco simplificado de gestión del riesgo TIC, pero siguen obligadas a gestionar el riesgo, notificar incidentes graves y probar sus sistemas. Existen exclusiones concretas, pero son tasadas. Q: Somos proveedor de software de un banco, nos aplica DORA A: No de forma directa, salvo que seáis designados proveedor TIC crítico, en cuyo caso pasáis a supervisión europea directa. Lo que sí ocurre siempre es que vuestros clientes financieros os trasladarán por contrato las cláusulas mínimas que DORA les exige: derechos de auditoría, niveles de servicio, notificación de incidentes y estrategia de salida. Q: Estamos obligados a hacer un TLPT A: Solo si vuestra autoridad competente os designa para pruebas avanzadas, atendiendo a tamaño, perfil de riesgo y relevancia. En España esa autoridad es el Banco de España, la CNMV o la DGSFP según el tipo de entidad, y el marco aplicable es TIBER-ES. El resto de entidades del ámbito debe mantener un programa de pruebas de resiliencia, pero no necesariamente un TLPT. Q: Qué pasa si nos aplican DORA y NIS2 a la vez A: Para las entidades financieras cubiertas, DORA actúa como norma especial y prevalece sobre NIS2 en gestión del riesgo TIC y notificación de incidentes. En grupos con filiales de varios sectores pueden convivir ambos marcos, y conviene mapear los controles comunes una sola vez en lugar de duplicar programas. Q: Desde cuándo es exigible DORA A: El reglamento es de aplicación desde el 17 de enero de 2025. No hay periodo transitorio adicional: las obligaciones son exigibles y las autoridades competentes ya pueden requerir evidencia del marco de gestión del riesgo TIC y del programa de pruebas.