Cybersecurity
Cybersecurity audits, hardening and AI security
ISO 27001 and NIST CSF 2.0 audits, OWASP and MITRE ATT&CK assessments, security for LLM-based tools (ChatGPT Enterprise, Copilot, Gemini). For companies in Argentina and clients abroad. Free 30-minute initial diagnosis.
NIST CSF 2.0 audit
Full assessment of the six pillars (Govern, Identify, Protect, Detect, Respond, Recover). Executive report + risk-prioritised remediation plan.
ISO/IEC 27001:2022 implementation
From gap analysis to external certification: policy, SOA, risk assessment, Annex A controls.
AI security (OWASP LLM Top 10 + NIST AI RMF)
Risk assessment of ChatGPT Enterprise, Microsoft Copilot, Gemini adoption. Prompt injection, data leakage, bias, governance, acceptable use policy.
Pentest and red team
OWASP, MITRE ATT&CK methodology. External, authenticated and scenario-based testing with CVSS-scored findings and remediation plan.
Frequently asked questions
What is NIST Cybersecurity Framework 2.0 and when should we adopt it?
NIST CSF 2.0 is an international reference framework to manage cybersecurity risk. Version 2.0 (2024) adds the Govern pillar to the five originals (Identify, Protect, Detect, Respond, Recover). It is worth adopting when you want a clear map of your security posture and a risk-prioritised improvement plan, regardless of whether you intend to formally certify or not.
When does ISO/IEC 27001 certification make sense?
ISO 27001 makes sense when a client, a tender, an insurer or sector regulation requires it, or when you want to professionalise security management as a differentiator. A typical SME implementation takes 4 to 9 months from gap analysis to external audit, depending on initial maturity and ISMS scope.
What risks do ChatGPT Enterprise, Copilot and Gemini add to my company?
Four main ones: (1) confidential data leakage when the team pastes sensitive info into chats, (2) prompt injection altering model behaviour, (3) hallucinations taken as facts, and (4) weak governance (who can use it, for what, with which data?). We work with OWASP LLM Top 10 and NIST AI RMF to evaluate and mitigate each.
Do you perform penetration tests and red team simulations?
Yes. External pentests (no credentials, attacker perspective), authenticated pentests (with regular user credentials), and red team with MITRE ATT&CK scenarios. Deliverable includes executive and technical reports with CVSS severity and a prioritised remediation plan.
Do you cover operational technology (OT/ICS/SCADA) beyond IT?
Yes. For industries like oil & gas, salmon farming, fisheries and the Argentine electronics regime. We evaluate IT/OT segmentation, PLC and HMI exposure, industrial ransomware risk and operational continuity.
Do you work with companies outside Argentina?
Yes. We have delivered projects in Argentina, Ireland and the European Union, and operate in time zones compatible with Argentina, Chile, Spain and Ireland.
Free cybersecurity diagnosis
30 minutes, no commitment. We map your risks and propose a tailored scope before any quote.