How we work
Step 1
Check-up and diagnosis.
A full Gap Analysis: your real picture and a prioritized plan — what the law demands, what your market expects and where to start.
Step 2
Getting you up to speed.
We execute the plan: technical, organizational and documentation. Your company ends up where it should be.
Step 3
Always up to date.
Annual subscription: ongoing advice, regulatory monitoring and living evidence — with an annual report for management and an annual drill. No surprises.
Plan Tria
Managed Cybersecurity Service
An annual fee with which we keep your company protected, organised and up to date.
Not a project that starts and ends: your cybersecurity covered, month after month.
When you need it, the specialist work
One-off projects with a fixed scope and budget, inside or outside your plan.
vCISO
Your external security officer, with a voice at board level: priorities, budget and technical liaison. A recurring fee, without hiring an in-house role.
More info →Technical pentest
A controlled attack on your systems to find the holes before the attackers do. Executive and technical report, with a remediation plan.
More info →ISO 27001 certification
Preparation, implementation and support all the way to the certificate. We guide you through the audit.
More info →National Security Framework (ENS)
Mandatory to work with the Spanish public administration. We take you to conformity, from category analysis to audit.
More info →Security awareness training & phishing simulation
Security awareness programme with simulated phishing and per-employee tracking. Cut human risk, the number-one way in.
More info →Full EU AI Act compliance
Inventory of your AI systems, risk classification, usage policies and the documentation the regulation demands.
More info →Data protection (GDPR) & outsourced DPO
A designated Data Protection Officer — for those who need one by law, or for peace of mind.
More info →Incident investigation and expert support
Forensics: what happened, how they got in and what they took. With specialist technical support in the heat of the moment, through our partner.
More info →Reputation crisis management
If the incident reaches the press or social media: messaging, spokesperson and a communication plan to protect your brand.
More info →Cybersecurity legal support
If the request leads to proceedings, legal defence with lawyers specialised in cybersecurity, coordinated with our technical side.
More info →OSINT and open-source intelligence
What information about you circulates out there: digital footprint, leaked credentials and brand impersonation. What an attacker sees, seen first by you.
More info →Compliance, alive.
The Tria platform, included in your plan, keeps your compliance running every day — not in a report that expires. Want to see it? Watch the demo →
Compliance documentation and proof, up to date, in one place, ready to show.
Your clients' questionnaires stop taking weeks: the information is already prepared.
Policies and procedures that update when the rules change — or your company does.
Start with the free check-up
In 2 minutes you'll know which regulations apply to you, what your obligations are and what to build your plan on — free, no strings attached.
Take the free check-up (Spanish) →Or write to us: hola@tria.consulting