All services

Service · Security

Cybersecurity for the public sector

Practical security for public services: correct headers and policies, tested access rules, backups that have actually been restored and an architecture that limits the damage when something fails.

Who it is for

Administrations that run their own digital services and need to comply with Spain's National Security Framework (ENS) with real measures, not just documents.

What we deliver

  • 01

    Audit of headers, CSP, TLS, dependencies and cloud configuration.

  • 02

    Service hardening: rate limiting, App Check, managed secrets, data encryption.

  • 03

    Data access rules with automated tests against the emulator.

  • 04

    Backups with point-in-time recovery and restoration drills.

  • 05

    Monitoring, alerts and deployments with rollback.

  • 06

    Report of the measures applied and how they map to the ENS.

How we work

  1. 01

    Assessment

    We review the exposed surface and prioritise by real risk.

  2. 02

    Remediation

    We apply the measures in order of impact, with tests.

  3. 03

    Verification

    We check with independent tools and document the results.

  4. 04

    Monitoring

    Alerts and periodic reviews so nothing degrades.

Cybersecurity capabilities

Beyond building public platforms, we have worked on cybersecurity teams at private companies. This is what we apply in our projects today and what we can put at your administration's service.

Application security

  • OWASP Top 10 and ASVS
  • Header, CSP and TLS audits
  • OWASP ZAP and Burp Suite
  • Nmap and reconnaissance
  • Code and dependency review (SCA)
  • Trivy and npm audit
  • Input sanitisation and validation
  • Authentication and session testing

Cloud security

  • Least-privilege Google Cloud IAM
  • Security Command Center
  • Cloud Armor (WAF and rate limiting)
  • Secret Manager and key rotation
  • Cloud Audit Logs
  • Encryption at rest and in transit
  • Tested Firestore and Storage rules
  • Cloudflare (DNS, WAF, Turnstile)

Identity and access

  • OAuth 2.0 and OpenID Connect
  • MFA and passkeys
  • Firebase Auth and Google Workspace
  • Role and claim management
  • Secure sessions (httpOnly, SameSite)
  • Signed JWTs with expiry
  • App Check and reCAPTCHA Enterprise

Detection and monitoring

  • Cloud Logging and alerting
  • Security telemetry in BigQuery
  • Anomaly and abuse detection
  • Error Reporting
  • Uptime and monitoring
  • AI-assisted event correlation
  • Response runbooks

Resilience and recovery

  • PITR backups and scheduled exports
  • Restore drills
  • Zero-downtime deployments and rollback
  • Continuity plan
  • Incident management and postmortems
  • Periodic reviews

Regulation and compliance

  • Spain's National Security Framework (ENS)
  • GDPR and data minimisation
  • NIS2
  • ISO 27001 (control mapping)
  • CIS Benchmarks
  • MITRE ATT&CK
  • Reports for audits and procurement

People and processes

  • Training and awareness
  • Phishing simulations
  • Password and access policies
  • security.txt and responsible disclosure
  • Supplier review