Central government
Autonomous bodies, agencies and public sector entities subject to the ENS framework and to National Cryptologic Centre oversight.
Managed cybersecurity · Government and large enterprise
We support public administrations, critical infrastructure operators and large enterprises with compliance under the Spanish National Security Framework, continuous monitoring and incident response. Backed by the technical capacity, contracting track record and data centres of the Datarecover group.
Frameworks
Organisations whose disruption reaches beyond the balance sheet: a public service that stops being delivered, a plant that halts, a supply chain that breaks.
Autonomous bodies, agencies and public sector entities subject to the ENS framework and to National Cryptologic Centre oversight.
Provincial councils, municipalities and consortia, with particular focus on entities without a fully staffed in-house IT team.
Health services, hospitals and affiliated centres, where system availability and the high classification of clinical data drive the design.
Water, energy, transport and waste management. IT/OT convergence and obligations arising from Spanish Law 8/2011 and NIS2.
Corporate groups and multinationals with subsidiaries, heterogeneous environments and compliance demands from their own customers.
Distributed campuses, very large user populations and intellectual property as the primary asset to protect.
Available as separate lots or as a single managed service. Either way the same team responds, through one point of contact and one reporting dashboard.
Define the framework before buying technology: where the risk actually is, what the regulation demands and in which order the budget should be spent.
Verify whether what is assumed to be protected actually is. Demonstrated through controlled exploitation and evidence, not a tool-generated list.
Deploy, configure and maintain the defences. Without single-vendor dependency and without licences that never get configured.
Continuous monitoring with analysts on duty. An alert nobody interprets is not detection: it is noise accumulating in a console.
Public procurement of cybersecurity follows its own rules. We know the procedure and prepare technical documentation in the format the file requires.
We cover the full cycle of Royal Decree 311/2022: system categorisation as BASIC, MEDIUM or HIGH, risk analysis, statement of applicability, compliance plan and preparation for the conformity audit — required every two years at MEDIUM and HIGH categories — or self-assessment at BASIC. Where the category requires it, we deploy products and services listed in the National Cryptologic Centre catalogue (CCN-STIC 105).
We work within the National Cryptologic Centre ecosystem: risk analysis with PILAR, security posture reporting through INES, federated incident management in LUCÍA and monitoring with CCN solutions where the organisation has already deployed them. Incident notifications are prepared in the format and within the deadlines the receiving body requires.
Directive (EU) 2022/2555 has been partially transposed in Spain through Royal Decree-Law 7/2025, while the Cybersecurity Coordination and Governance Act remains in parliamentary process. The substantive Article 21 obligations — risk management, notification, continuity, supply chain — derive from the directive itself, so we work on them without waiting for national publication.
We participate as prime contractor, within a temporary business consortium or as subcontractor to an awarded bidder. We prepare the technical proposal, work plan, assigned team and evidence of technical and financial standing to the level of detail the tender specification demands, and support contracting bodies in drafting technical requirements when preliminary market consultation is requested.
In an incident, the indicator that determines the impact is the time between intrusion and containment. Our method is a countdown on that number.
We examine the organisation as an attacker would: published attack surface, corporate credentials leaked in breaches, supplier exposure and inherited remote access. Reducing the number of doors is cheaper than watching all of them.
The difference between a managed service and a licence with a logo is not the technology. It is how the relationship is governed.
A named technical lead plus a designated deputy, both familiar with the customer architecture and present at the review committee.
Committed times to detect, first respond and contain by severity level, measured and published in the monthly report.
Executive report for management and technical detail for the IT team, with risk prioritised by impact on the service delivered.
Technology is chosen to fit the environment. Licences are held in the customer's name and operational documentation is handed over with the service.
Sec5Zero is the cybersecurity division of Datarecover, a managed services provider in cloud, systems and security since 2006. Behind every contract there are owned data centres, a team already operating production infrastructure, and the financial and administrative capacity that public procurement requires.
Cloud, Security & Systems. Headquarters in Majadahonda, Madrid.
Almost twenty years running customer systems in production, with a contractual record that can be evidenced in tender files.
Owned facilities in Norias, Pozuelo and Arévalo, with cross-site recovery capability and data held on Spanish territory.
Infrastructure, backup and contingency managed by the group, with no dependency on third parties at the moment of restoring a service.
Security, systems and cloud within the same group. No handover of responsibility between suppliers during an incident.
Active incident
Direct incident response line answered by analysts. We also attend to organisations that are not yet customers, under an immediate service agreement.
We send the external exposure assessment and review it with you in a thirty-minute session. No commitment, no installation and no access to any of your systems.