24/7 incident response · +34912820005 Public tenders ENES
Sec5ZeroDatarecover Group Request a meeting

Managed cybersecurity · Government and large enterprise

Cybersecurity for services that cannot be interrupted.

We support public administrations, critical infrastructure operators and large enterprises with compliance under the Spanish National Security Framework, continuous monitoring and incident response. Backed by the technical capacity, contracting track record and data centres of the Datarecover group.

  • ENS compliance and audit
  • 24/7 managed SOC
  • Incident response
  • Tender documentation

Frameworks

  • ENS · RD 311/2022
  • ISO/IEC 27001
  • NIS2
  • GDPR
  • CCN-STIC
  • NIST CSF 2.0
  • CIS Controls
Sectors

Where we work

Organisations whose disruption reaches beyond the balance sheet: a public service that stops being delivered, a plant that halts, a supply chain that breaks.

Central government

Autonomous bodies, agencies and public sector entities subject to the ENS framework and to National Cryptologic Centre oversight.

Local government

Provincial councils, municipalities and consortia, with particular focus on entities without a fully staffed in-house IT team.

Health and social care

Health services, hospitals and affiliated centres, where system availability and the high classification of clinical data drive the design.

Critical infrastructure

Water, energy, transport and waste management. IT/OT convergence and obligations arising from Spanish Law 8/2011 and NIS2.

Large enterprise

Corporate groups and multinationals with subsidiaries, heterogeneous environments and compliance demands from their own customers.

Universities and research

Distributed campuses, very large user populations and intellectual property as the primary asset to protect.

Services

Four areas covering the full cycle

Available as separate lots or as a single managed service. Either way the same team responds, through one point of contact and one reporting dashboard.

Strategy and governance

Define the framework before buying technology: where the risk actually is, what the regulation demands and in which order the budget should be spent.

  • ENS compliance: system categorisation, risk analysis and statement of applicability
  • Security master plan and multi-year roadmap
  • Preparation for ISO/IEC 27001 certification and ENS conformity audit
  • Virtual CISO with an agreed level of dedication
  • Supplier and supply chain risk management
  • Business continuity and disaster recovery planning

Technical assessment and hardening

Verify whether what is assumed to be protected actually is. Demonstrated through controlled exploitation and evidence, not a tool-generated list.

  • Penetration testing of infrastructure, web and mobile applications
  • Red Team exercises and adversary simulation
  • Continuous vulnerability management prioritised by exploitability
  • Configuration review and hardening against CIS and CCN-STIC guidance
  • Ransomware resilience assessment
  • Active Directory audit and attack path analysis

Protection and prevention

Deploy, configure and maintain the defences. Without single-vendor dependency and without licences that never get configured.

  • Endpoint and server security (EDR/XDR)
  • Perimeter security, segmentation and remote access (ZTNA)
  • Identity, MFA and privileged access management (PAM)
  • Email security and protection against fraud and impersonation
  • Cloud and Microsoft 365 security
  • Immutable backup with periodically verified recovery

Detection and response 24/7

Continuous monitoring with analysts on duty. An alert nobody interprets is not detection: it is noise accumulating in a console.

  • Managed 24/7 SOC with committed service levels
  • Proactive threat hunting across customer telemetry
  • Cyber intelligence and monitoring of brand, domains and credentials
  • Incident response and digital forensics (DFIR)
  • Remote containment of endpoints and identities
  • Support for notification to CCN-CERT, INCIBE-CERT and the data protection authority
Public sector

How we work with public administrations

Public procurement of cybersecurity follows its own rules. We know the procedure and prepare technical documentation in the format the file requires.

National Security Framework (ENS)

We cover the full cycle of Royal Decree 311/2022: system categorisation as BASIC, MEDIUM or HIGH, risk analysis, statement of applicability, compliance plan and preparation for the conformity audit — required every two years at MEDIUM and HIGH categories — or self-assessment at BASIC. Where the category requires it, we deploy products and services listed in the National Cryptologic Centre catalogue (CCN-STIC 105).

Tooling and coordination with CCN-CERT

We work within the National Cryptologic Centre ecosystem: risk analysis with PILAR, security posture reporting through INES, federated incident management in LUCÍA and monitoring with CCN solutions where the organisation has already deployed them. Incident notifications are prepared in the format and within the deadlines the receiving body requires.

NIS2 and pending legislation

Directive (EU) 2022/2555 has been partially transposed in Spain through Royal Decree-Law 7/2025, while the Cybersecurity Coordination and Governance Act remains in parliamentary process. The substantive Article 21 obligations — risk management, notification, continuity, supply chain — derive from the directive itself, so we work on them without waiting for national publication.

Procurement and tendering

We participate as prime contractor, within a temporary business consortium or as subcontractor to an awarded bidder. We prepare the technical proposal, work plan, assigned team and evidence of technical and financial standing to the level of detail the tender specification demands, and support contracting bodies in drafting technical requirements when preliminary market consultation is requested.

Method

From five to zero

In an incident, the indicator that determines the impact is the time between intrusion and containment. Our method is a countdown on that number.

Phase 5

Exposure

We examine the organisation as an attacker would: published attack surface, corporate credentials leaked in breaches, supplier exposure and inherited remote access. Reducing the number of doors is cheaper than watching all of them.

Service model

Service governance

The difference between a managed service and a licence with a logo is not the technology. It is how the relationship is governed.

01

Named service manager

A named technical lead plus a designated deputy, both familiar with the customer architecture and present at the review committee.

02

Contractual service levels

Committed times to detect, first respond and contain by severity level, measured and published in the monthly report.

03

Monthly committee and dashboard

Executive report for management and technical detail for the IT team, with risk prioritised by impact on the service delivered.

04

No vendor lock-in

Technology is chosen to fit the environment. Licences are held in the customer's name and operational documentation is handed over with the service.

Backing

Demonstrable standing, not a newly incorporated company

Sec5Zero is the cybersecurity division of Datarecover, a managed services provider in cloud, systems and security since 2006. Behind every contract there are owned data centres, a team already operating production infrastructure, and the financial and administrative capacity that public procurement requires.

Since 2006

Almost twenty years running customer systems in production, with a contractual record that can be evidenced in tender files.

3 data centres

Owned facilities in Norias, Pozuelo and Arévalo, with cross-site recovery capability and data held on Spanish territory.

Own cloud

Infrastructure, backup and contingency managed by the group, with no dependency on third parties at the moment of restoring a service.

One counterpart

Security, systems and cloud within the same group. No handover of responsibility between suppliers during an incident.

Active incident

If an incident is under way, do not use the form

Direct incident response line answered by analysts. We also attend to organisations that are not yet customers, under an immediate service agreement.

Contact

Start by knowing what your organisation looks like from the outside

We send the external exposure assessment and review it with you in a thirty-minute session. No commitment, no installation and no access to any of your systems.

Sales and projects
hola@sec5zero.com
24/7 incident response
+34 000 000 000
Head office
Calle Norias 92, 28221 Majadahonda, Madrid, Spain

We reply within 24 working hours.