I help businesses close security gaps before they become a problem, with audits, pentesting and incident response backed by documented methodology.
65% of serious incidents in Spanish SMEs happen on systems with already-known, avoidable vulnerabilities.
Forms, admin panels or APIs without proper protection, open to anyone.
Customer information accessible due to a simple server misconfiguration.
Fines of up to €20 million for lack of adequate technical measures.
Malicious code installed on your site, stealing data without anyone noticing.
A public incident can destroy customer trust within days.
Reused or previously breached credentials, the most common entry point.
Competitive, transparent pricing, without the overhead of a large consultancy. Fixed quote before starting, always. Prices excl. VAT.
Manual analysis of OWASP Top 10 vulnerabilities: SQL injection, XSS, CSRF, IDOR, CORS. Technical report plus executive summary for management.
Full pentesting with controlled manual exploitation, APIs and authentication included. Report + 30-min call with management.
Technical investigation after an incident: what happened, how attackers got in and which systems were affected, following ISO 27037 methodology.
Continuous review of your exposed attack surface, early alerts on new vulnerabilities and direct email support.
Cybersecurity and GDPR/LOPDGDD compliance report covering the technical requirements demanded in public tender processes.
Expert reports with legal standing for judicial or extrajudicial proceedings: digital evidence extraction and analysis.
Every business and situation is different. Tell me about yours in a free consultation and we'll design the exact scope together.
Tell me about your situation by email or video call. I assess feasibility at no cost.
You receive a proposal with a fixed price, scope and timeline. No surprises later.
Manual analysis using professional tools and internationally recognized methodology.
Delivered within the agreed timeline. Technical and executive versions. Post-delivery support included.
Offensive security specialist based in La Línea de la Concepción, available remotely across Spain.
Active vulnerability hunter on HackerOne and Bugcrowd — the same technical rigor I apply to every audit.
See my full background →Practical cybersecurity articles, without unnecessary jargon.
What cybersecurity, GDPR and ENS clauses actually appear in Spanish municipal tenders, with real examples.
Read article →The steps that make the difference between containing an incident and letting it become a crisis.
Read article →The warning signs that your website has vulnerabilities you don't know about — and what to do before an attacker finds them.
Read article →The logs, screenshots and access records that disappear in the first hours — and why acting fast changes everything.
Read article →No sales layers or middle management: you talk to me from the first email through report delivery, which means a tighter price without losing technical rigor.
We sign an NDA before any work begins. All findings and evidence are handled under GDPR and deleted at project close if you request it.
You still receive a report with the methodology applied and scope covered — useful as evidence of due diligence for clients, insurers or compliance audits.
Typically 50% when confirming the engagement and 50% on report delivery. For smaller projects, a single payment on delivery. No surprises: the price is fixed before starting.
100% remote across Spain. The initial consultation and results presentation are done by video call, no travel required.
The service covers detecting, documenting and prioritizing. Your technical team implements the fix, but I can support the process and validate that the fix closes the issue.
First consultation free, by video call or email, no obligation. Tell me about your situation and I'll tell you exactly what I can do and how much it would cost.