Barcelona · Security operations · Compliance
We watch your systems so your team can do its job.
Detection, incident response and the evidence NIS2, DORA and ISO 27001 audits ask for. For mid-sized companies, on the tools you already run.
Check your domain's email security
# Free check of your company's email security. # Reads public DNS only: nameservers, mail servers, # SPF, DMARC and DNSSEC. Nothing is installed. # Type your domain below and press Enter.
Full exposure review
Leave your details and we will send a scope and quote.
Services
Three levels. Each one includes the one below.
Scope and price are agreed per client after a scoping call. We work with the SIEM, EDR and cloud platforms you already have; if you have none, we recommend and deploy what fits.
L3Operations
Incident response, threat intelligence, a monthly report, and help with regulatory incident notifications.
Fits ifYou fall under NIS2 or DORA and need detection, response and reporting covered.
L2Detection
Monitoring of endpoints, identity and cloud logs. Detection rules mapped to MITRE ATT&CK, documented and version-controlled. Alerts triaged by our analysts and escalated to your team.
Fits ifNobody in your company watches security alerts today.
L1Exposure
What an attacker sees from outside: domains, email authentication, exposed services and known vulnerabilities. A written report ranked by risk, and a call to go through it.
Fits ifYou want a first view of your risk, or a client has sent you a security questionnaire.
Also on their own: incident response engagements, cloud hardening on AWS, Azure and Google Cloud, and compliance advisory (gap analysis, risk register, supplier assessments, ISMS documentation).
When an alert fires
What happens in the first 72 hours.
Under NIS2 an essential or important entity must send an early warning within 24 hours of becoming aware of a significant incident, and a fuller notification within 72. We run the technical side and draft the reports with you.
alert --> triage --> contain --> root cause | | | | +-- false positive: close, tune the rule | | v v T+0 T+24h early warning T+72h incident notification T+1mo final report
Regulations
What we help you prove.
- NIS2
- Art. 21 · Art. 23Risk management measures, and incident reporting at 24 hours, 72 hours and one month.
- DORA
- Ch. II · Ch. IIIICT risk management, classification and reporting of major ICT-related incidents, resilience testing.
- GDPR
- Art. 32 · Art. 33Security of processing, and breach notification to the authority within 72 hours.
- ISO 27001
- 2022 · Annex AGap analysis, ISMS documentation and preparation for the certification audit.
- Also
- on requestNIST CSF 2.0, the Cyber Resilience Act, PCI DSS 4.0 and SOC 2, when your clients or sector require them.
We help you meet these requirements. Valtisec is not a certification body and does not certify compliance.
Contact
Tell us what you need to cover, and by when.
We start with a call about your environment, the rules that apply to you and your deadlines. Then a written scope and price. Work starts once you approve it.
- hello (at) valtisec.com
- Office
- Carrer de Lepant 270, 08013 Barcelona
- Languages
- English, Spanish