Choosing a cybersecurity company in Spain has become a strategic decision any mid-sized or large organisation has to make at least once a year, and the difference between getting it right or wrong is measured in incidents avoided, regulatory fines under NIS2 or DORA, and internal team hours burned fixing problems the provider should have caught. The Spanish market runs from specialised boutiques with own research and signed advisories to cyber divisions inside Big Four firms selling audits and compliance bundled into enterprise projects. Each has its place, none works for everything, and the choice should start from the concrete problem you want to solve, not from the size of the provider's logo.
This guide explains what a cybersecurity company does and doesn't do, the provider types that coexist in Spain (boutique, Big Four, MSSP, vendor), the service areas that make up the standard catalogue, how to evaluate a proposal before signing, what red flags to spot and how the choice shifts based on buyer maturity and regulated sector.
Key takeaways on choosing a cybersecurity company
- The Spanish market has four types: specialised boutiques, Big Four cyber divisions, MSSPs (managed services), and vendors with own services.
- The choice starts from the problem (offensive audit, compliance, managed SOC, incident response), not the size of the provider.
- Quality signals: own published research (signed CVEs), technical certifications (OSCP/OSEP/OSWE/CRTO), verifiable references in your sector.
- Red flags: opaque hourly pricing, automation without human validation, lack of documented methodology.
- For regulated companies (NIS2, DORA, ENS) prefer a provider delivering auditable evidence, not only executive reports.
What a cybersecurity company does
A cybersecurity company groups technical and consulting services aimed at assessing, defending and responding to risks on the digital assets of another organisation. What gets contracted varies with the product:
- Offensive technical audit (pentesting, red team): authorised simulation of an attacker to find vulnerabilities before they do.
- Defence and monitoring (SOC, SIEM, EDR, MDR): real-time detection and response to incidents, usually under a managed contract.
- GRC consulting (NIS2, DORA, ENS, ISO 27001): implementation of compliance frameworks, risk management, certification audits.
- Incident response (DFIR): containment, forensic analysis and recovery after a breach.
- Threat intelligence: feeds, monitoring of actors and campaigns, context for the defensive team.
- Training and awareness: phishing simulations, technical training, exec tabletop exercises.
What a pure cybersecurity company normally doesn't do, even if the market blurs the line:
- Sell product without service (that's a vendor, not a cybersecurity company).
- Cover "all of IT" (helpdesk, networks, generic infrastructure). That's a generalist consultancy or an MSP.
- Sell "fast" compliance certificates without a real audit. That's a regulatory risk, not a service.
Identifying the concrete problem before requesting a quote is what prevents buying capacity you don't need or falling short on what matters.
Types of cybersecurity company in Spain
The Spanish market has four well-differentiated profiles. None is better in the abstract.
Specialised boutiques
Teams of 10 to 100 people focused exclusively on offensive, GRC, DFIR or threat intelligence. Own research, conference talks, advisories, open source contribution. Examples in Spain: Tarlogic, Hispasec, BlackArrow, Internet Security Auditors, Securízame and a group of mid-sized boutiques (Secra among them).
Where they fit: organisations that value technical depth and direct contact with whoever does the work. Year-over-year continuity is common because the team learns the context.
Big Four and large consultancies
PwC, Deloitte, KPMG, EY run cyber divisions inside their risk advisory practice. They fit when the buying decision sits with the executive committee and the reputational badge matters, or when the audit is contracted as part of a broader compliance project (ENS, NIS2, ISO 27001) the same provider is already leading.
Common limitation: offensive technical profile inside the firm rotates a lot and report depth often falls below a boutique's. The best version of a Big Four in pentesting is when they subcontract to a boutique and sign on top, which is public and accepted across the industry.
MSSP and MDR (managed services)
Telefónica Tech, S2 Grupo, Innotec (Accenture), Indra, GMV, Entelgy offer managed cybersecurity as one piece within a broader programme (24/7 SOC, MDR, EDR, GRC, platform management). Clear fit when you already consume their SOC and want to consolidate vendors.
Limitation: ad-hoc pentesting is not their core product, so deliverable quality depends heavily on the specific team assigned. Continuous managed defence is where they perform best.
Vendors with professional services
Some vendors (Microsoft, AWS, Cloudflare, CrowdStrike, Palo Alto, Datadog, SentinelOne) offer professional services that include pentesting or red team of their own platform. Useful when the asset sits inside their ecosystem and you want the test run by whoever knows the internals.
Limitation: they tend to focus on their own ecosystem. If your surface is heterogeneous (multi-cloud, multiple SaaS, on-prem infra), they don't cover the full map.
Service areas in the standard catalogue
When you compare companies, most organise the catalogue in some combination of these families:
| Family | Typical services | When it applies |
|---|---|---|
| Offensive | Pentesting web, mobile, API, infrastructure, cloud, IoT/OT, Red Team, Purple Team | Validate the technical posture annually or after changes |
| Defence | SOC, SIEM, EDR, MDR, NDR | Continuous monitoring and response |
| GRC | NIS2, DORA, ENS, ISO 27001, PCI DSS, GDPR, risk | Regulatory compliance and certification |
| DFIR | Incident response, forensics, recovery | During or after an incident |
| Threat intelligence | Feeds, threat hunting, OSINT | Advanced defensive maturity |
| Training | Phishing simulation, technical training, tabletops | Reducing human risk |
A mature company usually covers 3-4 of these families well and partners for the rest. Few do all six with the same depth.
How to evaluate a proposal by service type
Evaluation criteria change with the service family. Those that apply to offensive audits (named team, methodology traceable to OWASP or NIST, sample report, retest included, sector fit) are developed in how to choose a penetration testing company and are not repeated here. For the rest of the catalogue, what to look at:
- SOC, MDR and managed services. Detection and response metrics committed by contract (time to notification and time to containment, per severity), the analyst team's real coverage (24/7 in shifts or 8/5 with on-call), telemetry sources that are actually integrated (EDR, identity, cloud, network) and who owns the logs and detection rules when the contract ends. A provider that cannot show a response playbook or a sample monthly report is selling licences with a service on top.
- GRC consulting. Concrete rather than generic deliverables: risk analysis with the stated methodology, statement of applicability, remediation plan with owners and deadlines, evidence prepared for the audit. Independence between the implementer and the certifier: the certification body (ISO 27001 or ENS) cannot be the same consultant. Demonstrable experience with the specific framework, with references you can call.
- Incident response (DFIR). Retainer contract with committed response time, forensic team experienced in your technology (Microsoft 365, Kubernetes, OT environments), chain-of-custody procedure and the ability to coordinate regulatory notification (72 hours under GDPR, 24-hour early warning under NIS2).
- Training and awareness. Baseline and progress metrics (click rate, phishing report rate) and content adapted to the sector, not a generic catalogue.
In every case the cross-cutting criterion is the same: ask for the name of the team that will deliver the service and a sample of the real deliverable.
Red flags in managed services and consulting
The red flags specific to a pentest proposal (quote closed before technical scoping, automated scanner disguised as an audit, cascading subcontracting, templated report without proofs of concept) are detailed in red flags when contracting a pentest. In the rest of the catalogue, others show up:
- SLA without metrics. "24/7 monitoring" with no notification or containment time per severity, or with token penalties the provider absorbs as a cost of sale.
- Product packaged as a service. The proposal is really an EDR or SIEM licence with support hours, without dedicated analysts or in-house detection engineering.
- The same provider implements and certifies. A consultancy promising "guaranteed certification" or presenting the certification auditor as part of its team is selling a conflict of interest.
- Express compliance. Policy templates with no risk analysis, or NIS2 or ENS adequacy in weeks with no asset inventory or supplier assessment.
- Lock-in with no exit. Multi-year contracts with no reversion clause, no export of logs and rules at the end and no documented transition to another provider.
Sector specialisation in Spain
Some verticals carry specific requirements worth keeping in mind:
- Banking and financial services: DORA in application since January 2026, TLPT under TIBER-EU for significant entities, supervision by Banco de España and CNMV. Companies with documented TIBER-EU experience are scarce (publicly: S21sec/Innotec, Telefónica Tech, Mnemo and a small group of boutiques have executed TLPT projects).
- Healthcare: reinforced GDPR, essential NIS2 sector, aggravated sanction regime for health data. Mobile pentests of patient apps and audits of electronic health records are common.
- Public sector: mandatory ENS (Royal Decree 311/2022), medium and high categories demand biennial/annual documented audits, certification by an ENAC-accredited entity.
- Industry and OT: IoT/OT pentesting handled cautiously (don't audit production without a replica), familiarity with Modbus, S7, OPC UA, IEC 62443. Few providers with dedicated profiles; ask for specific industrial references.
- Retail and e-commerce: PCI DSS if payment is processed directly, mandatory annual pentest, focus on business logic and APIs.
- Telecommunications: essential NIS2, supervision by the Secretaría de Estado de Telecomunicaciones, sector-specific frameworks.
Compliance: which provider fits each framework
Not every framework accepts the same type of provider, and in several of them the separation of roles is mandatory. What to check before contracting:
- NIS2. Requires effective technical and organisational measures (article 21) and incident notification with a 24-hour early warning and a 72-hour notification (article 23). A GRC consultancy fits for risk analysis and governance, and an offensive or managed provider for verifying and sustaining the measures. In Spain, INCIBE-CERT is the reference CSIRT for the private sector. Full guide in NIS2 in Spain: a compliance guide for 2026.
- DORA. Annual digital operational resilience testing and, for the financial entities designated by the supervisor, threat-led penetration testing (TLPT) at least every three years under the TIBER-EU framework. Article 27 sets requirements for external testers (demonstrated technical capability, independence, professional indemnity insurance). Few providers in Spain can evidence TLPT projects; ask for concrete references. More in DORA compliance guide for financial entities 2026.
- ENS (Royal Decree 311/2022). Medium and high category systems require a security audit at least every two years, and the certificate of conformity is issued by a certification body accredited by ENAC; basic category only needs a self-assessment. The consultant that implements and the body that certifies must be different.
- ISO 27001:2022. Same separation: implementing consultancy on one side and accredited certification body on the other. Control 8.29 (security testing in development and acceptance) is covered by a documented technical audit with retest.
- PCI DSS v4.0. The formal assessment is performed by a QSA (Qualified Security Assessor) recognised by the PCI SSC; the requirement 11.4 pentest can be run by a qualified third party independent from the asset owner. Official documentation in the PCI SSC document library.
What concrete evidence an offensive audit report must provide for each of these frameworks is developed in pentesting and compliance: NIS2, DORA, ISO 27001 and PCI DSS.
How the choice shifts depending on the moment
Contracting your first audit is not the same as the seventh.
- First audit of the organisation. Accept that the first report will be loaded, plan 2-3 consecutive cycles to close the initial debt, choose a provider that helps prioritise (not one that delivers a flat list of 200 findings).
- Recurring audit with stable provider. Year-over-year continuity speeds things up because the team knows the context. Consider switching every 2-3 years to refresh the critical eye, without making it rigid policy.
- Audit after incident. Combine DFIR with external technical audit. Ideally different providers so the audit isn't done by whoever responded to the incident.
- Urgent compliance (DORA, NIS2 with closed deadline). Look for a provider with documented experience in the specific framework. Ask for references.
- Mature programme with in-house SOC. Fits to contract one-off pentesting with a specialised boutique and leave daily operations to the internal team plus a backup MSSP.
What we see in our engagements
What clients ask from us as company-level accreditation is, in the public sector, our own ENS certification or equivalent; elsewhere, what counts are the certifications of the people who will execute the work (OSCP, OSEP, OSWE, CRTO), not a corporate seal.
Frequently asked questions
How do I tell a serious cybersecurity company from one that just sells?
Three quick signals that filter well: (1) the provider's team publishes research, talks or signed advisories with name and surname; (2) the proposal closes after real technical scoping with concrete questions, not before; (3) the anonymised sample report has reproducible proof of concept, not abstract risks. If all three fail, drop it.
Is a small boutique or a large company better?
Depends on the asset and the buying organisation. The boutique brings technical depth, direct contact and continuity. The large company brings geographic coverage, integration with other services and reputational badge. What matters is not size but the profile of the specific team that executes. Ask for it by name.
How much does a cybersecurity project cost in Spain?
Varies a lot by service type, scope and target compliance. A mid-sized web pentest can run from several thousand to tens of thousands of euros; a full NIS2 implementation project, in the order of several tens of thousands. The factors that move an offensive audit budget and the ranges per asset type are in penetration testing pricing in Spain. For managed services, compare the monthly cost against the number of dedicated analysts and integrated sources, not against the promised alert volume.
Is a single provider better or several specialised ones?
Mature programmes usually combine: one company for technical audit (offensive boutique), another for managed services (MSSP) and GRC consulting with a third provider (consulting boutique or Big Four). Concentrating everything with a single provider creates dependence and limits external perspective. Concentrating across too many raises governance overhead.
Do I need a Spanish company or will an international one do?
For pure technical services (pentesting, red team, DFIR), an international company can work if it has the profile. For ENS compliance, Spanish NIS2, GDPR and projects with public administrations, a provider with presence and documented experience in Spain is preferable: they know the regulator, the timelines and the formats better. For sectors with state-level regulation (banking with Banco de España, telco with SETID), local presence is practically mandatory.
How do I verify the assigned team is really the one that signed the proposal?
Ask for it in the contract as an explicit clause: the named team in the proposal is who executes. Any substitution requires prior notice and client acceptance. Most serious providers accept it; those who resist usually have internal rotation issues they don't want to acknowledge.
Related resources
- How to choose a penetration testing company: specific criteria for offensive audit.
- What is a penetration test: the technical pillar of the offensive cluster.
- Penetration testing pricing in Spain: how engagement budgets really get scoped.
- Web security audit complete guide: what a concrete web audit includes and how to evaluate the proposal.
- NIS2 in Spain: compliance guide for 2026: the main regulatory framework in essential sectors.
Need to assess your cybersecurity before choosing a provider?
We reserve 30 minutes to understand your situation, review the scope you need and give you a concrete proposal with no commitment. No sales reps in between, you speak directly with a senior consultant.
How we work at Secra
Secra is a boutique offensive cybersecurity company based in Spain. We cover web, mobile, API, internal and external infrastructure, cloud, IoT/OT pentesting and red team with OWASP WSTG/MASVS, API Top 10, PTES and MITRE ATT&CK methodologies. We run an internal research programme that has published advisories on NVD and INCIBE-CERT (including CVE-2025-40652 in CoverManager and CVE-2023-3512 in Setelsa ConacWin CB). Every report includes reproducible proof of concept, justified CVSS severity, retest at no extra cost and mapping to NIS2, DORA, ENS, ISO 27001 or PCI DSS as applicable. If you want a concrete proposal for your organisation, get in touch through contact or explore the services and managed cybersecurity catalogue.
Sources
About the author
Javier Paradelo Rodríguez, CEO and co-founder
Ethical hackers with OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certifications, 7+ years of experience in offensive cybersecurity, and authors of CVE-2025-40652 and CVE-2023-3512.

