Service · Cybersecurity

VPN and encryption

Encryption answers two separate questions that are best kept apart. The first is what happens to data in transit: between the Zaragoza office and the Huesca warehouse, between a remote employee's home and the server, between your company and the accountancy firm that receives payroll. The second is what happens to data when a laptop is left behind on the AVE high-speed train or someone walks off with a NAS drive. A badly configured VPN or an unencrypted laptop can turn a minor incident into a breach that may have to be reported to the AEPD; handled properly, a stolen laptop is just a stolen laptop. We design and configure both sides remotely: connections between sites and for people working away from the office, disk encryption with properly safeguarded recovery keys, and a sound way to send sensitive documents to third parties.

WireGuard, IPsec
current, well-audited protocols
BitLocker, FileVault
on every laptop
Recovery keys
in the directory, not on a sticky note
Site to site
and person to site, with MFA

What falls within the scope of this service

We use the firewall or router you already have if it is up to the job. If a site needs new hardware, your staff or installer connects it and we configure it remotely.

Pin down the details with one of our engineers

Site-to-site links

IPsec or WireGuard tunnels between offices, warehouses and shops, with rules defining what may pass from one site to another. Also useful for a branch in the Canary or Balearic Islands that relies on servers on the mainland.

Remote access

A user VPN with MFA, or zero-trust access that publishes only the applications needed rather than the whole network. Every connection is logged with user, time and device.

Disk encryption

BitLocker on Windows and FileVault on Mac, enabled through Intune or Jamf, with the recovery key held in Entra ID. External drives used for backups are included.

Certificates

TLS certificates on websites and internal services, automatic renewal and an expiry inventory, so no service goes down on a Sunday because its certificate lapsed.

Sending sensitive documents

Microsoft 365 message encryption, links with an expiry date and password, or AES-encrypted archives. For regular exchanges with advisers or insurers, a fixed channel rather than loose attachments.

Key custody

Where encryption and recovery keys are stored, who can look them up and what happens if the person in charge is away. Without that, encryption becomes a risk of losing your own data.

How the engagement unfolds, one stage at a time

Encryption is switched on in batches of devices, always with the recovery key verified first. An encrypted disk without its key is a lost disk.

01

Inventory

Sites, links, devices that leave the office, current encryption status and how sensitive documents are sent today.

02

Design

Connection topology, remote access method and encryption policy, with a timetable of changes.

03

Implementation

Tunnels and VPN configured out of hours, disks encrypted in batches and keys checked in the directory.

04

Recovery test

We simulate a lost laptop and unlock an encrypted machine with its key to confirm the procedure works.

A lost encrypted laptop rarely turns into a data protection problem; an unencrypted one probably will. If the disk was encrypted and the key was not compromised, the risk to individuals is low and the assessment of the incident changes completely. Few measures have such a direct effect on what you would need to explain to the AEPD.

Common questions

That depends on which one. Several older VPNs, particularly the SSL products from some vendors, have had serious vulnerabilities exploited on a massive scale. If yours is patched and uses MFA, it may still be fine. If not, a modern protocol such as WireGuard or zero-trust access that does not expose the whole network is the better route.

On machines from the last few years, you will not notice, because the processor handles encryption in hardware. What matters is that the recovery key is stored before encryption starts, so a BIOS update cannot leave the machine locked.

Ideally through a fixed channel: a folder shared with the firm with named access, or the portal the firm already provides. If it has to be email, use Microsoft 365 encryption or an encrypted file with the password sent by another channel. What you want to avoid is an unprotected attachment to a generic address.

Yes. WireGuard and IPsec handle patchy links well, and a second 4G or 5G line can be set up as automatic backup. If the site's connection is very limited, we look at which services would be better in the cloud rather than on the mainland server.

Encrypt what travels and what could go missing

Tell us how many sites you have, how staff connect from outside and whether laptops are encrypted. We will propose a design and a timetable.

Hours
Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings
Video calls via Google Meet or Teams

This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.