Distinct regulatory framework per sector
A bank lives under DORA and EBA; a hospital under ENS and NIS2; a SaaS SMB under ISO 27001 and GDPR. Sectoral pages explain the regulation that applies to each client — not the entire catalog list.
Service pages explain what we do. Sector pages explain who we do it for and why the approach changes when the client changes.
Why a sectoral approach
The same service (SOC/MDR, vulnerability management, audit) runs differently if the client is a bank under DORA or a hospital under ENS. Sectoral pages capture that difference.
A bank lives under DORA and EBA; a hospital under ENS and NIS2; a SaaS SMB under ISO 27001 and GDPR. Sectoral pages explain the regulation that applies to each client — not the entire catalog list.
The financial sector fears fraud, BEC and operational resilience. The health sector fears ransomware with clinical impact and special-category data leakage. Services apply differently.
What a banking Risk Committee expects is not the same as what a Clinical Security Committee expects. Each sector has its own language and its own way of measuring success.
An entity that crosses several sectors (e.g., a health mutual under DORA by scale) reuses evidence across frameworks. Sectoral pages show those crossovers explicitly.
Available sectors
Banking, insurance, servicing, payments, asset management and critical tech providers to the financial sector. DORA, EBA, BCBS 239, NIS2, Solvency II, PCI-DSS and ECB/EBA/CNMV/Banco de España/DGSFP supervision.
Public and private hospitals, clinics, primary care, mutuas, healthtech, telemedicine, pharma and health-sector tech providers. ENS, NIS2 (essential sector), reinforced GDPR for special-category data, ISO 27001/27799 and medical devices regulation.
Autonomous communities, city councils, provincial councils, autonomous bodies, state agencies, public foundations, defense, judiciary and tech providers serving Spanish public administration. ENS mandatory, NIS2 essential sector, CCN-STIC as operational reference.
OEMs, Tier-1/2/3 manufacturers, discrete and process manufacturing, chemicals, food, metal, industrial distribution and industrial IT providers. NIS2 essential sector, ISO 27001, IEC 62443 over OT/ICS and TISAX for automotive.
Public and private universities, business schools, university research centres, learning platforms and IT suppliers to the higher-education sector. Real focus on infrastructure security (track record with university clients), ENS for public-sector ties, GDPR special research regime (Article 89) and external exposure.
Power generation, transmission and distribution, retailers, gas, oil and refining, water, renewables and IT/OT suppliers to the energy sector. HIGHLY critical sector under NIS2, common PIC designation, IT/OT boundary with IEC 62443 judgement and ENS for public-sector ties.
Large grocery distribution, specialty retail, e-commerce, marketplaces, foodservice, wholesale distribution, retail logistics and IT suppliers to the sector. PCI DSS v4.0, GDPR reinforced by scale, anti-Magecart at checkout and operations ready for Black Friday.
Horizontal and vertical B2B SaaS, PaaS/IaaS platforms, embedded software, AI/ML SaaS, B2B marketplaces, MSPs and cybersecurity vendors. ISO 27001 as the certifiable foundation, ENS for selling to the Spanish public sector, DORA/NIS2 if critical supplier, AI Act and CRA where they apply.
Let's talk
The eight sectors with public pages are the ones with the highest demand, but we also work in other domains (logistics, transport, telecommunications, media, NGOs and more). If your organisation does not fit an existing page, we can prepare a proposal and direct conversation tailored to your regulatory and operational framework.
Antes de irte…
Te damos un diagnóstico rápido de 15 min y te decimos qué priorizar primero: M365, pentesting, vulnerabilidades, SOC y/o DORA, NIS2, ENS o ISO 27001.
Sin spam. Respuesta en 24h.