Distinct regulatory framework per sector
A bank lives under DORA and EBA; a hospital under ENS and NIS2; a SaaS SMB under ISO 27001 and GDPR. Sectoral pages explain the regulation that applies to each client — not the entire catalog list.
Service pages explain what we do. Sector pages explain who we do it for and why the approach changes when the client changes.
Why a sectoral approach
The same service (SOC/MDR, vulnerability management, audit) runs differently if the client is a bank under DORA or a hospital under ENS. Sectoral pages capture that difference.
A bank lives under DORA and EBA; a hospital under ENS and NIS2; a SaaS SMB under ISO 27001 and GDPR. Sectoral pages explain the regulation that applies to each client — not the entire catalog list.
The financial sector fears fraud, BEC and operational resilience. The health sector fears ransomware with clinical impact and special-category data leakage. Services apply differently.
What a banking Risk Committee expects is not the same as what a Clinical Security Committee expects. Each sector has its own language and its own way of measuring success.
An entity that crosses several sectors (e.g., a health mutual under DORA by scale) reuses evidence across frameworks. Sectoral pages show those crossovers explicitly.
Available sectors
Banking, insurance, servicing, payments, asset management and critical tech providers to the financial sector. DORA, EBA, BCBS 239, NIS2, Solvency II, PCI-DSS and ECB/EBA/CNMV/Banco de España/DGSFP supervision.
Public and private hospitals, clinics, primary care, mutuas, healthtech, telemedicine, pharma and health-sector tech providers. ENS, NIS2 (essential sector), reinforced GDPR for special-category data, ISO 27001/27799 and medical devices regulation.
Autonomous communities, city councils, provincial councils, autonomous bodies, state agencies, public foundations, defense, judiciary and tech providers serving Spanish public administration. ENS mandatory, NIS2 essential sector, CCN-STIC as operational reference.
OEMs, Tier-1/2/3 manufacturers, discrete and process manufacturing, chemicals, food, metal, industrial distribution and industrial IT providers. NIS2 essential sector, ISO 27001, IEC 62443 over OT/ICS and TISAX for automotive.
Public and private universities, business schools, university research centres, learning platforms and IT suppliers to the higher-education sector. Real focus on infrastructure security (track record with university clients), ENS for public-sector ties, GDPR special research regime (Article 89) and external exposure.
Roadmap
The following sectors are on the roadmap. If your sector isn't yet published but we're already working with you in it, we can prepare a proposal directly without waiting for the public page.
Generation, transmission and distribution of electricity, gas, water. NIS2 essential sector and operational resilience.
Retail chains, e-commerce, marketplaces. PCI-DSS, GDPR, identity management and external exposure.
B2B SaaS providers, tech platforms with regulated clients. ISO 27001, ENS if selling to public sector, NIS2 if critical provider.
Let's talk
Not all our sectors have a public page yet. If you work in regulated industries, public administration, energy, education, retail, B2B SaaS or technology, we can prepare a proposal and direct conversation without waiting for the landing page to publish.
Antes de irte…
Te damos un diagnóstico rápido de 15 min y te decimos qué priorizar primero: M365, pentesting, vulnerabilidades, SOC y/o DORA, NIS2, ENS o ISO 27001.
Sin spam. Respuesta en 24h.