Cybersecurity
Picture a fifteen-person accountancy practice in Valencia. On Monday its biggest client sends over a security questionnaire, on Tuesday the insurer wants confirmation that every account uses MFA, and on Thursday an employee clicks a fake Correos delivery notice. Three separate events, one underlying issue: you have to be able to prove what you do, and what you do has to work. This area brings GDPR, ENS and NIS2 compliance together with the technical safeguards behind it, and every part of it is delivered remotely over video calls and secure access.
Regulation and requirements
Each framework asks much the same things in different words. The GDPR talks about appropriate measures, Spain's National Security Framework (ENS) about measures set by system category, NIS2 about risk management owned by the board. One solid foundation answers all three. We work to the principles of ISO 27001, with INCIBE and CCN-CERT guidance as our reference points.
GDPR and personal data protection
The technical half of compliance: an inventory that feeds your record of processing activities, role-based permissions, access auditing, support for data subject requests and a one-page sheet for the first hours of a breach.
Security policies and documentation
Texts built from interviews with your team rather than from a template: the policy, a MAGERIT-based risk analysis, the ENS statement of applicability and procedures that can be followed on an ordinary working day.
Technical protection
Nine services, each working on its own layer: identities, devices, network, applications, data and the web. You will rarely need all of them. The risk analysis shows which come first and which can wait a year.
Security tooling deployment
For anyone sitting on unused Microsoft 365 Business Premium features or an EDR still stuck in observe mode. A pilot, department-by-department expansion and a calm switch to blocking.
Infrastructure security
Port 3389 shut, cameras and guest Wi-Fi moved into their own zone, and the ERP supplier connecting through a named account protected by MFA.
Application security
Who is allowed to change a supplier's IBAN in a3ERP, which account PrestaShop syncs under, and where the Redsys payment key is actually stored.
Data leak prevention (DLP)
Files containing ID numbers, IBANs or health details spotted automatically, a prompt before anyone forwards them to Gmail, and hard blocks kept for serious cases, in line with Article 87 of the LOPDGDD.
Database security
The “sa” login retired, encryption at rest on SQL Server or MySQL, auditing on patient and customer tables, and forgotten exports tracked down and deleted.
Web application firewall (WAF)
Cloudflare or your cloud's own WAF tuned weeks ahead of Black Friday, so that at peak trading it halts mass card testing rather than your real shoppers.
Access control and endpoint security
A stolen password is no longer enough: MFA with no exceptions, only Intune-enrolled devices can open company data, and nobody is an administrator on their own laptop.
VPN and encryption
WireGuard or IPsec linking office and warehouse, BitLocker on every laptop with its key held in Entra ID, and a fixed channel for sending payroll to your accountants.
Vulnerability scanning
Monthly internal and external scans, ranked using INCIBE-CERT advisories and the KEV catalogue. Fewer report pages, more patches genuinely applied.
Monitoring and upkeep
Settings made in January no longer fit the business by September: people join and leave, new software arrives, attack methods shift. These four services keep working after the project itself is finished.
Where to begin
On a tight budget, sequence matters more than brand. For SMEs of 10 to 250 staff we propose the following order, which tackles the most common ways in first.
Who is asking for what
A video call to gather what is already being demanded of you: client clauses, tender terms, the cyber insurance policy, the GDPR. From that we know which evidence you need and which systems hold the most delicate data.
Identities and email
MFA, removal of former employees' accounts and rules against fake change-of-IBAN requests. This is where most SME incidents start, and it is the cheapest door to close.
Devices, network and backups
EDR with blocking on, basic hardening, remote desktop taken off the internet and backups that have been restored at least once. This is the stage that stops ransomware or limits how far it spreads.
Paperwork and monitoring
With the technical groundwork running, the documents describe facts rather than wishes. After that comes whatever the risk warrants: a WAF, DLP, finer segmentation or a SOC.
Put a price on a week without systems before you put one on security. An online shop taking €4,000 a day, or a warehouse unable to issue delivery notes, loses more in a few days offline than years of sensible protection would cost. That figure, rather than fear of a fine, is what helps you decide how much to spend and in which order.
Common questions
The directive and its Spanish transposition set out sectors, size thresholds and exemptions, and the precise fit should be confirmed by a lawyer. What we see all the time is the knock-on effect: small firms outside its scope receiving questionnaires from clients inside it. We prepare that technical side with you.
The system you use to deliver the service must meet the ENS measures for its category, backed by certification from an accredited body or, for some basic-category systems, a self-assessment-based statement if the tender accepts one. We help you get ready for certification: risk analysis, statement of applicability, technical measures and evidence.
Yes. The questions tend to repeat: MFA, offline backups, EDR, patching, training. We go through which ones you can honestly answer yes to, what is missing and what it would take to close the gaps before renewal. Ticking yes to something that does not exist could leave you uncovered at the very moment you need the policy.
Do not switch machines off, as evidence is lost; unplug them from the network instead. From a clean device, change the passwords of admin accounts and email support@apply.es, or helpme@apply.es if you have a contract. If personal data is involved, the 72-hour clock for the AEPD has started. INCIBE also runs a free, confidential cybersecurity helpline.
Yes. Interviews run on Teams or Google Meet and configuration takes place over secure remote access, with every session logged. If a device ever needs handling, a member of your team or your installer does it while we guide them live. The timetable is agreed after the initial review and set out in the contract.
Related areas
Tell us what is being asked of you and what you have today
A client questionnaire, a tender requiring the ENS, an insurance renewal or a specific worry. After a remote review we will tell you what is missing, the order to tackle it in and what can wait.
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Video calls via Google Meet or Teams
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
- We clarify the brief. If a detail is missing before we can price the work, we email you or suggest a quick Google Meet or Teams session.
- We draft a proposal. The scope of work, a price in euros with VAT shown separately and a realistic start date, with no small print.
- The choice is yours. The proposal arrives by email. Read it at leisure, query any line you like and only then decide.