Cybersecurity is no longer optional
Five years ago, cybersecurity for mid-sized companies was a topic that came up after the external audit, usually in a rush and with an improvised budget. Today it's a structural requirement: NIS2 may apply depending on sector, size and the cases defined by the directive and national transposition, insurers demand evidence, corporate clients require certifications, and ransomware attacks have moved from occasional headlines to everyday operational risk. The question isn't whether your business will be the target of an attempted breach — it already is, every organisation should assess its exposure — but whether your organisation is ready to detect, contain and recover from one without stopping the business.
At Impulso Tecnológico we design, deploy and operate enterprise cybersecurity programmes for mid-sized companies across Spain, Portugal and the other 24 countries where we have active clients. We don't sell isolated "security solutions" — we sell a coherent programme covering audit, prevention, detection, response and training, with leading technologies (Fortinet, Sophos, Microsoft Defender, Veeam) and a team selected for relevant experience. When an incident happens, we pick up the phone first, not fourth.

Security audit: start from where you actually are
Every security plan starts with an honest diagnosis. Our security audit combines technical analysis and organisational review to produce a complete map of the current attack surface, exploitable vulnerabilities, the policies that are missing and the ones that are excessive. We don't use generic templates — we tailor the scope to the client's sector, size and architecture.
The process covers, at minimum:
- Infrastructure analysis: network review, segmentation, switch and firewall configuration, WiFi access points and cloud architecture (Microsoft 365 / Azure / AWS where applicable).
- Critical-asset inventory: servers, databases, business applications, privileged identities. Anything worth protecting.
- Identity and access analysis: review of accounts with elevated permissions, real MFA usage, password policies, orphaned access.
- Vulnerability testing: automated internal + external scanning, manual validation of critical findings, prioritisation by real risk (not isolated CVSS scoring).
- Process review: incident response, backups, change management, user training. The human factor is responsible for more breaches than any technical failure.
- Regulatory compliance: fit with NIS2, Spain's National Security Framework (ENS), ISO 27001 and GDPR per client profile.
Deliverables: an executive report (for management) and a prioritised technical plan (for IT) with realistic timelines and commercial terms defined for each phase. No opacity.

NGFW firewalls and segmentation: the perimeter still matters
Despite the Zero-Trust paradigm and the fact that the office network is no longer the only frontier, the next-generation firewall (NGFW) remains a central piece of any enterprise security architecture. The difference now is that it does much more than filter ports: it inspects encrypted traffic (SSL/TLS), applies policies by application and user identity, integrates IPS/IDS, and communicates with the rest of the security stack.
- Fortinet FortiGate: our recommendation when the client prioritises performance, an integrated ecosystem (Security Fabric with FortiSwitch, FortiAP, FortiClient) and reasonable licensing cost at scale. Excellent for multi-site SD-WAN.
- Sophos XGS: our recommendation when Sophos Central is already deployed for endpoints, because the synchronised response between firewall and endpoint automatically detects anomalous behaviour and isolates the affected device before the threat spreads.
Deployment includes internal segmentation with VLANs by function (servers, users, IoT, guests, cameras), application policies per Active Directory / Entra ID group, SSL inspection where legislation and productivity allow, and centralised monitoring with alerts that reach an Impulso technician, not just an unread inbox.
Endpoint protection, EDR/XDR and synchronised response
Traditional antivirus stopped being enough a decade ago. Today, workstation protection is called EDR (Endpoint Detection and Response) or XDR (Extended Detection and Response) depending on whether it includes identity, email and network telemetry. We mainly deploy:
- Sophos Intercept X with XDR: for product maturity, firewall integration and the unified console in Sophos Central that lets us operate everything from a single pane.
- Microsoft Defender for Endpoint (Plan 2): when the client already has Microsoft 365 E5 or compatible licensing, leveraging native integration with Entra ID, Defender for Office 365 and Defender for Cloud Apps.
The policy includes anti-ransomware protection with automatic rollback, application control, disk encryption (managed BitLocker), USB device control and automated response to indicators of compromise.

Immutable backup and disaster-recovery plan
Backup is the last line of defence against ransomware — and paradoxically, it's where almost every SMB fails: copies accessible from the same network they're meant to protect, obsolete backup windows, short retention periods, restores that are never tested. Our minimum standard applies the 3-2-1-1-0 rule:
- 3 copies of the data (the production one + 2 backups)
- 2 different media (local disk + cloud or tape)
- 1 offsite copy geographically separated
- 1 immutable copy no operator can erase within the retention window
- 0 errors in periodic restore verification
We work with Veeam Backup & Replication and Acronis Cyber Protect for mixed environments (VMware, Hyper-V, Microsoft 365), with replication to immutable Azure Blob or S3 Object Lock. The recovery plan includes documented RTOs and RPOs, quarterly restore tests and annual full-incident simulations.
Regulatory compliance: NIS2, ENS, ISO 27001, GDPR
The regulatory burden on enterprise cybersecurity has grown substantially in the last three years. NIS2 (EU Directive 2022/2555) covers a much broader perimeter of companies than its predecessor, including medium enterprises in essential and important sectors. The National Security Framework (ENS) is mandatory for Spanish public-sector suppliers. ISO 27001 remains the reference standard for corporate clients that require certification from their providers. GDPR has been the common floor since 2018.
We accompany the client across the full journey: applicability analysis, gap analysis against the relevant standard, adequacy plan, implementation of technical and organisational controls, policy documentation, team training and, where required, support during the external certification audit.

Training and awareness: the human link
Many breaches begin with user action, so awareness and technical controls must work together. That's why any serious cybersecurity plan includes a continuous anti-phishing training and awareness programme:
- Monthly simulated phishing campaigns with per-department reports.
- 5-minute micro-trainings when a user fails — delivered in the moment.
- Annual in-person workshops for high-risk profiles (executives, finance, HR).
- Material tailored to the client: real sector examples, user's language (ES, EN, PT), tone that doesn't insult their intelligence.
How we work
Every client enters through the scoped security discovery → technical assessment and report with confirmed timing → prioritised security plan with defined commercial terms → phased implementation during agreed change windows → operation within the coverage window and SLA targets expressly included in the accepted scope → quarterly review of security posture against real KPIs.
If your company is breached right now, call +34 91 505 7575. Timing for the first assessment is confirmed according to scope, availability and urgency.