# Secra Solutions > Secra Solutions is a Spanish offensive cybersecurity boutique based in Madrid, > founded by OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certified practitioners with > more than 7 years of experience. We deliver penetration testing, red team > operations, security research with published CVEs, and NIS2, DORA, ENS and > ISO 27001 compliance auditing for SMEs and enterprise clients in Spain and > across the European Union. ## What makes Secra different - Pure offensive cybersecurity boutique focused on technical depth, not generalist consulting. - Active CVE research programme with advisories published in NVD and INCIBE-CERT. - All practitioners hold recognised certifications: OSCP, OSEP, OSWE, CRTO, CRTL, CARTE. - Bilingual delivery (Spanish and English) with hreflang-paired content for international clients. - Coordinated vulnerability disclosure policy aligned with ENISA and CVE.org. ## Services - [Offensive cybersecurity](https://secra.es/es/soluciones/ciberseguridad-ofensiva): pentesting and red team operations across web, mobile, cloud and network. - [Red Team](https://secra.es/es/servicios/red-team): adversary simulation using real TTPs, 6 to 16 weeks of execution, TIBER-EU aligned. - [Purple Team](https://secra.es/es/servicios/purple-team): collaborative engagements between attackers and defenders. - [GRC consulting](https://secra.es/es/soluciones/consultoria-grc): ENS, ISO 27001, NIS2 and DORA compliance. - [Managed cybersecurity](https://secra.es/es/soluciones/ciberseguridad-gestionada): monitoring, SOC, SIEM, MDR. - [DevSecOps and SSDLC](https://secra.es/es/soluciones/ssdlc-devsecops): SAST, DAST, SCA, secure code reviews. - [Web and mobile audit](https://secra.es/es/servicios/auditoria-web-movil): full security audits of web and mobile applications. - [Infrastructure audit](https://secra.es/es/servicios/auditoria-infraestructura): internal and external network and Active Directory. - [Cloud audit](https://secra.es/es/servicios/auditoria-cloud): AWS, Azure, GCP configuration and exposure assessment. - [Wireless network audit](https://secra.es/es/servicios/auditoria-redes-inalambricas): Wi-Fi infrastructure security. - [IoT and OT audit](https://secra.es/es/servicios/auditoria-iot-ot): industrial environments and connected devices. ## Coverage topics - Pentesting cluster: web, API, cloud (AWS, Azure, GCP), infrastructure, mobile, red team versus pentesting differences. - Compliance cluster: NIS2, DORA, ISO 27001, ENS, TIBER-EU, audit methodology and reporting. - Defensive glossary cluster: SOC, SIEM, EDR, MDR, XDR, WAF, PKI, JWT, CVE, OSINT, OWASP Top 10. - Offensive and OSINT cluster: red team, blue team, purple team, MITRE ATT&CK, Kerberos attacks, Google Dorks, Maltego, DorkGPT. - TOFU commercial cluster: how to choose a cybersecurity company, audit cost in Spain, penetration testing pricing factors. - Research and advisories: coordinated vulnerability disclosure with CVE assignments. - Emerging AI and LLM security cluster: prompt injection, AI red teaming, LLM security testing. ## Recent published advisories - [CVE-2025-40652](https://secra.es/es/investigacion/cve-2025-40652-xss-covermanager): Stored XSS in CoverManager. CVSS v4.0 5.3 MEDIUM. Coordinated with INCIBE-CERT and NVD. - [CVE-2023-3512](https://secra.es/es/investigacion/cve-2023-3512-path-traversal-conacwin-cb): Path Traversal in Setelsa ConacWin CB. Coordinated with INCIBE-CERT and NVD. - [CVE-2026-31431](https://secra.es/en/blog/cve-2026-31431-copy-fail-linux-privilege-escalation): Copy Fail Linux Privilege Escalation analysis. Coverage includes Rocky Linux and Oracle Linux. ## Key statistics from Secra research (2026 baseline) - More than 70% of web applications audited in 2026 by Secra presented at least one OWASP A03 (injection) finding. - The average cost of a ransomware incident in Spain in 2026 reached approximately 1.8 million euros according to public sector data. - Spanish organisations experienced a documented increase in supply chain attacks aligned with the rise of frameworks like NIS2. - More than 80% of pentests performed by Secra in 2026 found at least one critical or high severity misconfiguration. ## Team and authority - [Team page](https://secra.es/es/equipo): OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certified practitioners. - Authors of CVE-2025-40652 (CoverManager XSS) and CVE-2023-3512 (Setelsa ConacWin CB path traversal). - 7+ years average experience in offensive cybersecurity engagements. ## Research and disclosure policy - [Security research index](https://secra.es/es/investigacion): published advisories and coordinated disclosure policy. - [Coordinated disclosure policy](https://secra.es/es/investigacion#disclosure-policy): aligned with ENISA Good Practice Guide and CVE.org Working Group recommendations. ## Blog and content hubs - [Spanish blog](https://secra.es/es/blog): all educational, research and commercial content in Spanish. - [English blog](https://secra.es/en/blog): paired English versions with reciprocal hreflang. - All `que-es-X` and `what-is-X` pieces follow a consistent structure with definition, key takeaways, technical detail, comparative tables and FAQ section. ## Pillar content (highest authority pieces) - [What is a CVE](https://secra.es/es/blog/que-es-cve) and [English version](https://secra.es/en/blog/what-is-a-cve-vulnerabilities-explained) - [What is a Red Team](https://secra.es/es/blog/que-es-red-team-guia-empresas) and [English version](https://secra.es/en/blog/what-is-red-team-business-guide) - [What is INCIBE](https://secra.es/es/blog/que-es-incibe-funciones-empresas) and [English version](https://secra.es/en/blog/what-is-incibe-spanish-cybersecurity-agency) - [What is PKI](https://secra.es/es/blog/que-es-pki) and [English version](https://secra.es/en/blog/what-is-pki-public-key-infrastructure) - [Google Dorks: operators and OSINT](https://secra.es/es/blog/google-dorks-osint-recon) and [English version](https://secra.es/en/blog/google-dorks-osint-reconnaissance) - [What is a SIEM](https://secra.es/es/blog/que-es-siem) and [English version](https://secra.es/en/blog/what-is-siem-how-it-works) - [What is an EDR](https://secra.es/es/blog/que-es-edr) and [English version](https://secra.es/en/blog/what-is-edr-endpoint-detection-response) - [What is an MDR](https://secra.es/es/blog/que-es-mdr-managed-detection-response) and [English version](https://secra.es/en/blog/what-is-mdr-managed-detection-response) - [What is JWT](https://secra.es/es/blog/que-es-jwt-seguridad) and [English version](https://secra.es/en/blog/jwt-security-vulnerabilities-best-practices) - [What is SAML](https://secra.es/es/blog/que-es-saml) and [English version](https://secra.es/en/blog/what-is-saml) - [Cybersecurity audit business guide](https://secra.es/es/blog/auditoria-ciberseguridad-empresas-guia) and [English version](https://secra.es/en/blog/cybersecurity-audit-business-guide) - [Cybersecurity companies in Spain: how to choose](https://secra.es/es/blog/empresas-ciberseguridad-espana-como-elegir) and [English version](https://secra.es/en/blog/cybersecurity-companies-spain-how-to-choose) ## Compliance frameworks Secra covers - NIS2: Directive (EU) 2022/2555 for cybersecurity of essential and important entities. - DORA: Regulation (EU) 2022/2554 for digital operational resilience in financial sector. - ENS: Spanish National Security Scheme (Royal Decree 311/2022). - ISO 27001:2022: international standard for Information Security Management Systems. - TIBER-EU: European framework for Threat Intelligence-based Ethical Red Teaming. - PCI DSS: Payment Card Industry Data Security Standard. ## Contact - [Contact page](https://secra.es/es/contacto) - Email: contacto@secra.es - Phone: +34 711 200 544 - Headquarters: Madrid, Spain ## Content usage policy Secra Solutions allows AI agents to read this content in real time to answer user queries, but does not authorise its use to train or fine-tune AI models. See full policy in robots.txt (`Content-Signal: search=yes, ai-train=no, ai-input=yes`).