How we work
Methodology
Every project follows a structured five-stage process, backed by recognized international frameworks and with post-delivery support included.
Process
Five stages to guarantee measurable results and knowledge transfer.
Discovery
1-2 weeksWe understand your business, your systems, your team and your goals. We assess the current state and define the project scope.
Assessment
2-4 weeksWe analyze the situation using specialized tools and methodologies. We identify risks, opportunities and gaps.
Plan
1 weekWe design a prioritized roadmap with concrete actions, deadlines, owners and success metrics.
Implementation
Variable based on scopeWe execute the plan. Each deliverable comes with clear documentation and knowledge transfer.
Support
30 days includedFollow-up, adjustments and resolution of questions after delivery, at no additional cost.
Post-delivery support included
Every project includes 30 days of free support after delivery. Follow-up, adjustments and resolution of questions at no additional cost. After that, we offer maintenance plans with pre-agreed rates.
International reference frameworks
All our cybersecurity services are developed aligned with the leading international frameworks.
| Service | Applicable frameworks |
|---|---|
| Security audits | NIST CSF 2.0, ISO 27001, CIS Controls v8 |
| GRC / Compliance | ISO 27001, ISO 9001, COBIT 2019, local regulations |
| vCISO | NIST CSF 2.0, ISO 27001, NIST 800-53, CIS Controls |
| Awareness / Phishing | NIST SP 800-50, ISO 27001 Annex A |
| Pentesting | OWASP Top 10, OWASP Testing Guide, PTES, MITRE ATT&CK |
| AI Security | NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 |
| Infrastructure / Networks | CIS Benchmarks, NIST 800-171 |
Our risk assessments, audits and security plans follow globally recognized best practices, ensuring that every recommendation we deliver has solid methodological backing.
Ready to work with methodology?
Get in touch and we'll show you how we apply these frameworks to your company's reality.