Site-to-site links
IPsec or WireGuard tunnels between offices, warehouses and shops, with rules defining what may pass from one site to another. Also useful for a branch in the Canary or Balearic Islands that relies on servers on the mainland.
Encryption answers two separate questions that are best kept apart. The first is what happens to data in transit: between the Zaragoza office and the Huesca warehouse, between a remote employee's home and the server, between your company and the accountancy firm that receives payroll. The second is what happens to data when a laptop is left behind on the AVE high-speed train or someone walks off with a NAS drive. A badly configured VPN or an unencrypted laptop can turn a minor incident into a breach that may have to be reported to the AEPD; handled properly, a stolen laptop is just a stolen laptop. We design and configure both sides remotely: connections between sites and for people working away from the office, disk encryption with properly safeguarded recovery keys, and a sound way to send sensitive documents to third parties.
We use the firewall or router you already have if it is up to the job. If a site needs new hardware, your staff or installer connects it and we configure it remotely.
IPsec or WireGuard tunnels between offices, warehouses and shops, with rules defining what may pass from one site to another. Also useful for a branch in the Canary or Balearic Islands that relies on servers on the mainland.
A user VPN with MFA, or zero-trust access that publishes only the applications needed rather than the whole network. Every connection is logged with user, time and device.
BitLocker on Windows and FileVault on Mac, enabled through Intune or Jamf, with the recovery key held in Entra ID. External drives used for backups are included.
TLS certificates on websites and internal services, automatic renewal and an expiry inventory, so no service goes down on a Sunday because its certificate lapsed.
Microsoft 365 message encryption, links with an expiry date and password, or AES-encrypted archives. For regular exchanges with advisers or insurers, a fixed channel rather than loose attachments.
Where encryption and recovery keys are stored, who can look them up and what happens if the person in charge is away. Without that, encryption becomes a risk of losing your own data.
Encryption is switched on in batches of devices, always with the recovery key verified first. An encrypted disk without its key is a lost disk.
Sites, links, devices that leave the office, current encryption status and how sensitive documents are sent today.
Connection topology, remote access method and encryption policy, with a timetable of changes.
Tunnels and VPN configured out of hours, disks encrypted in batches and keys checked in the directory.
We simulate a lost laptop and unlock an encrypted machine with its key to confirm the procedure works.
A lost encrypted laptop rarely turns into a data protection problem; an unencrypted one probably will. If the disk was encrypted and the key was not compromised, the risk to individuals is low and the assessment of the incident changes completely. Few measures have such a direct effect on what you would need to explain to the AEPD.
That depends on which one. Several older VPNs, particularly the SSL products from some vendors, have had serious vulnerabilities exploited on a massive scale. If yours is patched and uses MFA, it may still be fine. If not, a modern protocol such as WireGuard or zero-trust access that does not expose the whole network is the better route.
On machines from the last few years, you will not notice, because the processor handles encryption in hardware. What matters is that the recovery key is stored before encryption starts, so a BIOS update cannot leave the machine locked.
Ideally through a fixed channel: a folder shared with the firm with named access, or the portal the firm already provides. If it has to be email, use Microsoft 365 encryption or an encrypted file with the password sent by another channel. What you want to avoid is an unprotected attachment to a generic address.
Yes. WireGuard and IPsec handle patchy links well, and a second 4G or 5G line can be set up as automatic backup. If the site's connection is very limited, we look at which services would be better in the cloud rather than on the mainland server.
Tell us how many sites you have, how staff connect from outside and whether laptops are encrypted. We will propose a design and a timetable.
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.