Service · Security
Cybersecurity for the public sector
Practical security for public services: correct headers and policies, tested access rules, backups that have actually been restored and an architecture that limits the damage when something fails.
Who it is for
Administrations that run their own digital services and need to comply with Spain's National Security Framework (ENS) with real measures, not just documents.
What we deliver
- 01
Audit of headers, CSP, TLS, dependencies and cloud configuration.
- 02
Service hardening: rate limiting, App Check, managed secrets, data encryption.
- 03
Data access rules with automated tests against the emulator.
- 04
Backups with point-in-time recovery and restoration drills.
- 05
Monitoring, alerts and deployments with rollback.
- 06
Report of the measures applied and how they map to the ENS.
How we work
- 01
Assessment
We review the exposed surface and prioritise by real risk.
- 02
Remediation
We apply the measures in order of impact, with tests.
- 03
Verification
We check with independent tools and document the results.
- 04
Monitoring
Alerts and periodic reviews so nothing degrades.
Cybersecurity capabilities
Beyond building public platforms, we have worked on cybersecurity teams at private companies. This is what we apply in our projects today and what we can put at your administration's service.
Application security
- OWASP Top 10 and ASVS
- Header, CSP and TLS audits
- OWASP ZAP and Burp Suite
- Nmap and reconnaissance
- Code and dependency review (SCA)
- Trivy and npm audit
- Input sanitisation and validation
- Authentication and session testing
Cloud security
- Least-privilege Google Cloud IAM
- Security Command Center
- Cloud Armor (WAF and rate limiting)
- Secret Manager and key rotation
- Cloud Audit Logs
- Encryption at rest and in transit
- Tested Firestore and Storage rules
- Cloudflare (DNS, WAF, Turnstile)
Identity and access
- OAuth 2.0 and OpenID Connect
- MFA and passkeys
- Firebase Auth and Google Workspace
- Role and claim management
- Secure sessions (httpOnly, SameSite)
- Signed JWTs with expiry
- App Check and reCAPTCHA Enterprise
Detection and monitoring
- Cloud Logging and alerting
- Security telemetry in BigQuery
- Anomaly and abuse detection
- Error Reporting
- Uptime and monitoring
- AI-assisted event correlation
- Response runbooks
Resilience and recovery
- PITR backups and scheduled exports
- Restore drills
- Zero-downtime deployments and rollback
- Continuity plan
- Incident management and postmortems
- Periodic reviews
Regulation and compliance
- Spain's National Security Framework (ENS)
- GDPR and data minimisation
- NIS2
- ISO 27001 (control mapping)
- CIS Benchmarks
- MITRE ATT&CK
- Reports for audits and procurement
People and processes
- Training and awareness
- Phishing simulations
- Password and access policies
- security.txt and responsible disclosure
- Supplier review
Related projects
Shall we talk?
Request a proposal