Saltar al contenido
Catálogo completo · 7 áreas de práctica · 70+ servicios · Atención Global 24×7 Full catalogue · 7 practice areas · 70+ services · Global 24×7

Nuestros Servicios Our Services

Desde el diagnóstico estratégico hasta la respuesta a incidentes 24×7. Siete categorías de servicio, con cotización a medida de cada caso. From strategic assessment to 24×7 incident response. Seven service categories, with a quote tailored to each case.

Explorar servicios Explore services

01 · Consultoría01 · Consulting

Estrategia · Cumplimiento · ContinuidadStrategy · Compliance · Continuity

1.1 · Consultoría Estratégica de Seguridad1.1 · Strategic Security Consulting

Plan Director de SeguridadSecurity Master Plan

Estrategia a 1, 2 y 3 años alineada con el negocio.One, two and three year strategy aligned with the business.

Roadmap + matriz RACIRoadmap and RACI matrix
Ver fichaView details

Gestión de Riesgos TIIT Risk Management

ISO 27005, MAGERIT o FAIR. Activos, amenazas, impactos.ISO 27005, MAGERIT or FAIR. Assets, threats and impacts.

Mapa de riesgos + plan de tratamientoRisk map and treatment plan
Ver fichaView details

1.2 · Consultoría Normativa y de Cumplimiento1.2 · Regulatory and Compliance Consulting

RGPD / LOPDGDDGDPR / LOPDGDD

Registro de tratamientos, análisis de riesgos, EIPD.Record of processing activities, risk analysis and DPIA.

RGPD · LOPDGDDGDPR · LOPDGDD
Ver fichaView details

PCI-DSSPCI-DSS

Preparación para certificación de datos de tarjetas.Readiness for cardholder data certification.

PCI-DSS v4.0.1PCI-DSS v4.0.1
Ver fichaView details

ISO 27001ISO 27001

Implementación completa del SGSI.End-to-end ISMS implementation.

ISO/IEC 27001:2022ISO/IEC 27001:2022
Ver fichaView details

DORADORA

Entidades financieras: gestión de riesgos TIC, reporte de incidentes.Financial entities: ICT risk management and incident reporting.

Reglamento UE 2022/2554EU Regulation 2022/2554
Ver fichaView details

NIS2NIS2

Directiva de seguridad de redes y sistemas de información.Directive on the security of network and information systems.

Directiva UE 2022/2555EU Directive 2022/2555
Ver fichaView details

SWIFT CSPSWIFT CSP

Cumplimiento del programa de seguridad del cliente de SWIFT.Compliance with the SWIFT Customer Security Programme.

SWIFT CSPSWIFT CSP
Ver fichaView details

SOC 2 (Type I / Type II)SOC 2 (Type I / Type II)

Informe de controles que piden los clientes de EE. UU.Controls report commonly required by clients in the United States.

AICPA Trust Services CriteriaAICPA Trust Services Criteria
Ver fichaView details

HIPAAHIPAA

Salvaguardas de seguridad y privacidad de información de salud de EE. UU.Security and privacy safeguards for US health information.

HIPAA Security RuleHIPAA Security Rule
Ver fichaView details

ISO 22301ISO 22301

Sistema de gestión de continuidad del negocio, certificable.Certifiable business continuity management system.

ISO 22301:2019ISO 22301:2019
Ver fichaView details

ISO 27701ISO 27701

Extensión de privacidad sobre el SGSI.Privacy extension to the ISMS.

ISO/IEC 27701ISO/IEC 27701
Ver fichaView details

NIST CSF 2.0NIST CSF 2.0

Adopción del marco del NIST, incluida la función Gobernar.Adoption of the NIST framework, including the Govern function.

NIST CSF 2.0NIST CSF 2.0
Ver fichaView details

EU AI ActEU AI Act

Clasificación por nivel de riesgo de los sistemas de IA y plan de adecuación.Risk-tier classification of AI systems and remediation plan.

Reglamento UE 2024/1689EU Regulation 2024/1689
Ver fichaView details

Cyber Resilience Act (CRA)Cyber Resilience Act (CRA)

Requisitos de ciberseguridad para productos con elementos digitales.Cybersecurity requirements for products with digital elements.

Reglamento UE 2024/2847EU Regulation 2024/2847
Ver fichaView details

CMMCCMMC

Madurez de ciberseguridad para la cadena de suministro de defensa de EE. UU.Cybersecurity maturity for the US defence supply chain.

CMMC 2.0CMMC 2.0
Ver fichaView details

TISAXTISAX

Evaluación de seguridad de la información para la industria automotriz.Information security assessment for the automotive industry.

TISAX · VDA ISATISAX · VDA ISA
Ver fichaView details

Readiness de CiberseguroCyber Insurance Readiness

Evidencia y controles que exige la aseguradora para suscribir la póliza.Evidence and controls the insurer requires to underwrite the policy.

Cuestionario de suscripciónUnderwriting questionnaire
Ver fichaView details

1.3 · Consultoría de Continuidad de Negocio1.3 · Business Continuity Consulting

1.4 · Cumplimiento Costa Rica1.4 · Costa Rica Compliance

Perfil Tecnológico SICVECASICVECA Technology Profile

Elaboración y remisión del perfil tecnológico y del histórico de incidentes.Preparation and filing of the technology profile and incident history.

Clases de datos 24 y 56Data classes 24 and 56
Ver fichaView details

Cumplimiento Ley 8968 (PRODHAB)Ley 8968 Compliance (PRODHAB)

Protección de datos personales en Costa Rica: registro, consentimiento y medidas.Personal data protection in Costa Rica: registration, consent and safeguards.

Ley 8968 · PRODHABLey 8968 · PRODHAB
Ver fichaView details

Servicios de Consultoría Consulting services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

02 · Auditoría02 · Auditing

Hacking Ético · Código · OrganizacionalEthical Hacking · Code · Organisational

2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

Ejercicio de Red TeamRed Team Exercise

Ataque realista prolongado basado en objetivos concretos.Prolonged, realistic attack driven by specific objectives.

TIBER-EU · MITRE ATT&CKTIBER-EU · MITRE ATT&CK
Ver fichaView details

Purple TeamPurple Team

Ejercicio colaborativo Red Team + Blue Team en tiempo real.Collaborative Red Team and Blue Team exercise in real time.

MITRE ATT&CKMITRE ATT&CK
Ver fichaView details

Assumed BreachAssumed Breach

Se parte de un equipo ya comprometido para medir detección y contención.Starts from an already compromised host to measure detection and containment.

MITRE ATT&CKMITRE ATT&CK
Ver fichaView details

Auditoría de SAP y ERPSAP and ERP Audit

Roles, segregación de funciones y configuraciones críticas del ERP.Roles, segregation of duties and critical ERP configurations.

SAP · Oracle · DynamicsSAP · Oracle · Dynamics
Ver fichaView details

Red Teaming de IA y LLMAI and LLM Red Teaming

Inyección de prompt, fuga de datos y abuso de agentes con herramientas.Prompt injection, data leakage and abuse of tool-enabled agents.

OWASP Top 10 para LLMOWASP Top 10 for LLM
Ver fichaView details

2.2 · Auditorías de Código y Configuración2.2 · Code and Configuration Audits

Modelado de AmenazasThreat Modelling

Se identifican los ataques posibles en la fase de diseño, antes de escribir código.Identifies feasible attacks at the design stage, before any code is written.

STRIDE · PASTASTRIDE · PASTA
Ver fichaView details

2.3 · Auditorías Organizacionales2.3 · Organisational Audits

Auditoría ENSENS Audit

Cumplimiento del Esquema Nacional de Seguridad.Compliance with the Esquema Nacional de Seguridad.

RD 311/2022RD 311/2022
Ver fichaView details

Auditoría de Protección de DatosData Protection Audit

Medidas técnicas y organizativas, registro de tratamientos.Technical and organisational measures and the register of processing activities.

RGPD · LOPDGDDRGPD · LOPDGDD
Ver fichaView details

Auditoría de PCI-DSSPCI-DSS Audit

Evaluación de cumplimiento del estándar de tarjetas.Compliance assessment against the payment card standard.

PCI-DSS v4.0.1PCI-DSS v4.0.1
Ver fichaView details

2.4 · Auditorías Especializadas2.4 · Specialised Audits

Ingeniería SocialSocial Engineering

Campañas de phishing, vishing, smishing y pretexting.Phishing, vishing, smishing and pretexting campaigns.

Informes por departamentoReporting by department
Ver fichaView details

Compromise AssessmentCompromise Assessment

Búsqueda de evidencia de compromiso activo o pasado en el entorno.Search for evidence of active or past compromise across the environment.

IOC · IOAIOC · IOA
Ver fichaView details

Servicios de Auditoría Auditing services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

03 · SOC Gestionado03 · Managed SOC

SOCaaS 24×7 · Incidentes · PlataformasSOCaaS 24×7 · Incidents · Platforms

3.1 · SOC como Servicio (SOCaaS)3.1 · SOC as a Service (SOCaaS)

Monitorización 24×724×7 Monitoring

Vigilancia continua desde SIEM, EDR, firewalls, IDS/IPS.Continuous surveillance across SIEM, EDR, firewalls and IDS/IPS.

L1 · L2 · L3L1 · L2 · L3
Ver fichaView details

Threat IntelligenceThreat Intelligence

Integración de inteligencia de amenazas en detección.Integration of threat intelligence into detection.

OSINT + comercialOSINT and commercial
Ver fichaView details

Detection EngineeringDetection Engineering

Casos de uso, reglas Sigma y cobertura medida contra MITRE ATT&CK.Use cases, Sigma rules and coverage measured against MITRE ATT&CK.

Sigma · MITRE ATT&CKSigma · MITRE ATT&CK
Ver fichaView details

3.2 · Gestión de Incidentes3.2 · Incident Management

Análisis Forense DigitalDigital Forensics

Adquisición, preservación, análisis e informe pericial.Acquisition, preservation, analysis and expert witness reporting.

ForenseForensics
Ver fichaView details

Malware AnalysisMalware Analysis

Análisis estático y dinámico de muestras de malware.Static and dynamic analysis of malware samples.

Reverse engineeringReverse engineering
Ver fichaView details

3.3 · Servicios Gestionados de Plataformas3.3 · Managed Platform Services

Gestión de SIEMSIEM Management

Splunk, QRadar, Sentinel, Elastic.Splunk, QRadar, Sentinel and Elastic.

SIEMSIEM
Ver fichaView details

Gestión de FirewallFirewall Management

Reglas, revisión periódica, hardening, actualizaciones.Rule sets, periodic review, hardening and updates.

NGFWNGFW
Ver fichaView details

Gestión de ParchesPatch Management

Ciclo de identificación, prueba y despliegue de parches con métricas.Identification, testing and deployment cycle with metrics.

Patch managementPatch management
Ver fichaView details

Deception y HoneypotsDeception and Honeypots

Señuelos y credenciales trampa para detección temprana de intrusos.Decoys and trap credentials for early intruder detection.

DeceptionDeception
Ver fichaView details

Gestión de NDRNDR Management

Detección y respuesta sobre el tráfico de red, incluido el que no pasa por un agente.Detection and response across network traffic, including traffic no agent sees.

NDRNDR
Ver fichaView details

Servicios de SOC Gestionado Managed SOC services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

04 · Formación04 · Training

Concienciación · Técnica · DirectivaAwareness · Technical · Executive

Programas de formación y concienciaciónTraining and awareness programmes

Formación para EmpleadosEmployee Training

Presencial u online para todos los niveles.Classroom or online delivery for every level of the organisation.

MultinivelMulti-level
Ver fichaView details

Workshops EjecutivosExecutive Workshops

Sesiones cortas sobre riesgos, inversión y ciber-resiliencia.Short sessions on risk, investment and cyber resilience.

C-LevelC-Level
Ver fichaView details

Servicios de Formación Training services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

05 · Arquitectura05 · Architecture

Diseño · Implementación · HardeningDesign · Implementation · Hardening

Diseño y despliegue de tecnología de seguridadDesign and deployment of security technology

Implementación de SIEMSIEM Implementation

Arquitectura, instalación, fuentes, casos de uso.Architecture, installation, log sources and use cases.

DespliegueDeployment
Ver fichaView details

Implementación de DLPDLP Implementation

Clasificación, políticas, endpoint, red, cloud.Classification, policies, endpoint, network and cloud coverage.

Prevención fugasLeak prevention
Ver fichaView details

MicrosegmentaciónMicrosegmentation

VMware NSX, Cisco ACI, Guardicore, Zero Networks.VMware NSX, Cisco ACI, Guardicore and Zero Networks.

SegmentaciónSegmentation
Ver fichaView details

Hardening de SistemasSystems Hardening

Servidores, endpoints, bases de datos, cloud.Servers, endpoints, databases and cloud workloads.

SecurizaciónHardening
Ver fichaView details

SASE / SSESASE / SSE

Acceso seguro convergente para usuarios remotos y sucursales.Converged secure access for remote users and branch offices.

SASE · SSE · ZTNASASE · SSE · ZTNA
Ver fichaView details

Diseño de Seguridad OT / ICSOT / ICS Security Design

Segmentación y arquitectura defensiva para entornos industriales.Segmentation and defensive architecture for industrial environments.

IEC 62443 · Modelo PurdueIEC 62443 · Purdue Model
Ver fichaView details

DNS ProtectorDNS Protector

Bloqueo de dominios maliciosos en la resolución, antes de que exista la conexión.Malicious domains are blocked at resolution, before any connection exists.

DNS filteringDNS filtering
Ver fichaView details

Protección Anti-DDoSAnti-DDoS Protection

Absorción y filtrado de ataques de denegación de servicio antes de que lleguen.Absorption and filtering of denial of service attacks before they land.

Mitigación DDoSDDoS mitigation
Ver fichaView details

CDN y Protección de BordeCDN and Edge Protection

Distribución de contenido con filtrado, gestión de bots y caché en el borde.Content delivery with filtering, bot management and caching at the edge.

CDN · Edge · BotsCDN · Edge · Bots
Ver fichaView details

Gestión de SecretosSecrets Management

Bóveda central para credenciales y claves, con rotación automática y auditoría de uso.Central vault for credentials and keys, with automatic rotation and usage auditing.

Vault · RotaciónVault · Rotation
Ver fichaView details

Servicios de Arquitectura Architecture services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

06 · Especializados06 · Specialised

IA · Forense · DevSecOps · BrandAI · Forensics · DevSecOps · Brand

Servicios verticales para riesgos específicosVertical services for specific risks

Criptografía y PKICryptography and PKI

Infraestructura de clave pública, certificados, firma electrónica.Public key infrastructure, certificates and electronic signature.

PKIPKI
Ver fichaView details

Bug Bounty ProgramBug Bounty Programme

Alcance, reglas, plataforma, triage y recompensas.Scope, rules, platform, triage and rewards.

Bug BountyBug Bounty
Ver fichaView details

Servicio Anti-RansomwareAnti-Ransomware Service

Exposición, hardening, simulacro y plan de respuesta.Exposure review, hardening, simulation exercise and response plan.

Anti-RansomwareAnti-Ransomware
Ver fichaView details

Seguridad de IA / LLMAI / LLM Security

Prompt injection, data poisoning, model inversion.Prompt injection, data poisoning and model inversion.

AI SecurityAI Security
Ver fichaView details

Servicios de Especializados Specialised services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.

07 · Soluciones07 · Solutions

Desarrollo · Soporte · ImplementacionesDevelopment · Support · Implementations

7.1 · Desarrollo y automatización7.1 · Development and automation

Desarrollo de AplicacionesApplication Development

Aplicaciones web, móviles y de escritorio bajo metodologías ágiles y revisión continua de seguridad.Web, mobile and desktop applications built with agile methodologies and continuous security review.

Web · Móvil · DesktopWeb · Mobile · Desktop
Ver fichaView details

Desarrollo de Sistemas y APIsSystems and API Development

Backends robustos, APIs REST/GraphQL, microservicios y integraciones empresariales.Robust backends, REST/GraphQL APIs, microservices and enterprise integrations.

Backend · APIsBackend · APIs
Ver fichaView details

Desarrollo de Páginas WebWebsite Development

Sitios corporativos, landing pages, plataformas e-commerce, portales privados.Corporate sites, landing pages, e-commerce platforms and private portals.

Sites · PortalesSites · Portals
Ver fichaView details

7.2 · Soporte y operación7.2 · Support and operations

Soporte TI GeneralGeneral IT Support

Mesa de ayuda, soporte L1/L2/L3, gestión de incidencias y solicitudes.Help desk, L1/L2/L3 support, incident and service request management.

Help desk + L1/L2/L3Help desk + L1/L2/L3
Ver fichaView details

Soporte de ServidoresServer Support

Administración, mantenimiento, monitorización y hardening de servidores físicos y virtuales.Administration, maintenance, monitoring and hardening of physical and virtual servers.

Linux · Windows · VMwareLinux · Windows · VMware
Ver fichaView details

Soporte de RedesNetwork Support

Diseño, operación y soporte de redes LAN/WAN, switching, routing, WiFi y VPN.Design, operation and support of LAN/WAN networks, switching, routing, WiFi and VPN.

LAN · WAN · WiFi · VPNLAN · WAN · WiFi · VPN
Ver fichaView details

Soporte CloudCloud Support

Operación y optimización de entornos AWS, Azure, GCP, OCI. Gestión de costos y seguridad.Operation and optimisation of AWS, Azure, GCP and OCI environments, including cost and security management.

AWS · Azure · GCPAWS · Azure · GCP
Ver fichaView details

Soporte a AplicacionesApplication Support

Mantenimiento evolutivo y correctivo de aplicaciones existentes con SLA definido.Evolutionary and corrective maintenance of existing applications under a defined SLA.

AMS · MantenimientoAMS · Maintenance
Ver fichaView details

7.3 · Implementaciones y migraciones7.3 · Implementations and migrations

ImplementacionesImplementations

Despliegue de plataformas, sistemas e infraestructura nueva con plan de pruebas y go-live.Deployment of new platforms, systems and infrastructure with a test plan and go-live.

Plataformas + sistemasPlatforms + systems
Ver fichaView details

MigracionesMigrations

Migración on-premise a cloud, entre clouds, entre plataformas y entre versiones, sin pérdida de datos.On-premise to cloud, cloud to cloud, cross-platform and version migrations, with no data loss.

On-prem ↔ Cloud · Cross-cloudOn-prem ↔ Cloud · Cross-cloud
Ver fichaView details

7.4 · Proyectos de tecnología7.4 · Technology projects

Diseño de ProyectosProject Design

Levantamiento de requisitos, arquitectura, planificación, presupuesto y plan de riesgos.Requirements gathering, architecture, planning, budgeting and risk plan.

Discovery + DiseñoDiscovery + Design
Ver fichaView details

Desarrollo de ProyectosProject Delivery

Ejecución end-to-end de proyectos de desarrollo, sistemas, aplicaciones, web, ciberseguridad y gobernanza.End-to-end execution of development, systems, application, web, cybersecurity and governance projects.

End-to-endEnd-to-end
Ver fichaView details

Seguimiento y Soporte a ProyectosProject Tracking and Support

PMO externalizada, control de hitos, gestión de cambios, reporting ejecutivo y soporte post go-live.Outsourced PMO, milestone control, change management, executive reporting and post go-live support.

PMO + Post go-livePMO + Post go-live
Ver fichaView details

Servicios de Soluciones Solutions services

El formulario abre una propuesta a medida, sin compromiso. The form opens a tailored proposal, with no commitment.