Madrid · Domestic and International Service info@imts.es
ES / EN / PT
Catalog · 9 services

Cybersecurity Services
IT Compliance and Risk Management

Strategic services define the framework: governance, risk, compliance, and auditing. Operational services support companies’ day-to-day cybersecurity: access, systems, vendors, support, and ICT equipment.

How We Organize Our Offerings

Nine cybersecurity services, two levels of depth.

Our cybersecurity service offering is structured around five strategic services—which define what needs to be done, to what standard, and within what timeframes—and four operational services that ensure this actually happens on a day-to-day basis.

We do not sell individual services. We sell a coherent management system. That is why it is common for a client who starts with an internal audit to end up implementing a comprehensive GRC framework, or for an ISO 27001 implementation to lead to the structured management of their IT vendors.

Capa A · Operations 4
Four services that ensure that what is designed is delivered.
SO / 01

Logical Security

Access, identities, endpoints, the cloud, and vulnerability management. The operational layer that enforces the controls defined by security governance.

CloudEndpointsNowVulnerabilities
Recommended for
Organizations with their own or hybrid IT infrastructure and regulatory requirements. View service details →
SO / 02

IT Technical Support and Maintenance

Continuous operation in accordance with safety standards. Preventive and corrective maintenance, change management, and documentation for the ISMS.

ChangesCorrectiveEstimateSGSI Evidence
Recommended for
Organizations with certified systems that need their operations to be aligned with their management system. View service details →
SO / 03

ICT Supplier Management

Contracts, SLAs, and third-party risk in accordance with NIS2 and DORA. The supply chain as an extension of your security perimeter.

ContractsNIS2 · DORASLAThird-Party Risk
Recommended for
Organizations with multiple critical IT vendors and regulatory obligations. View service details →
SO / 04

ICT Equipment

Equipment sales, leasing, and managed supply. Assets tracked from acquisition through decommissioning, integrated into the security inventory.

AssetsFor SaleManaged SupplyRenting
Recommended for
Organizations that want to free themselves from managing their technology infrastructure without losing the View service details →
Capa B · Strategic 5
Five services that define the framework: governance, risk, compliance, and audit.
SS / 01

Dirección de Seguridad Externa · CSO Virtual

Accredited, external, and flexible security management. Risk analysis, security plan, and oversight of physical and technological measures in accordance with Article 36 of Law 5/2014.

Access PointsCCTVFCSELaw 5/2014Risk AnalysisSecurity Plan
Recommended for
SMEs, retail, logistics, manufacturing, homeowners' associations, events, and companies with multiple View service details →
SS / 02

Open-Source Intelligence and OSINT Analysis

There is a wealth of public information, but very little useful intelligence. We transform scattered data into actionable insights: due diligence, digital monitoring, and geopolitical and reputational analysis.

Competitive IntelligenceDigital SurveillanceDue diligenceGDPRGeopolitical
Recommended for
Executive management, security and compliance departments, law firms, companies with international operations, and organizations exposed to reputational risks. View service details →
SS / 03

GRC · Governance, Risk, and Compliance

An integrated framework for governance, risk management, and regulatory compliance. Modular, scalable, and designed for organizations that need a rigorous approach without having their own dedicated department.

ComplianceGovernmentPoliciesReportsRisks
Recommended for
Organizations with multiple regulatory obligations that need consistency without maintaining their own department. View service details →
SS / 04

ICT Framework Consulting and Implementation

ISO 27001, ENS, TISAX, ISO 22301, and ISO 20000. From the initial assessment to certification and its maintenance, with realistic timelines: 12 to 18 months for a job well done.

ENSISO 20000ISO 22301ISO 27001TISAX
Recommended for
ICT companies, MSPs, automotive industry suppliers, financial institutions, government agencies, and any organization that needs to obtain certification. View service details →
SS / 05

Independent Internal Audit

The mechanism that allows you to determine whether your management system is actually working or exists only on paper. ICT and physical security system audits in accordance with ISO 19011. A fundamental principle: we do not audit systems that we have helped implement.

ENSISO 19011ISO 27001Physical SecurityTISAX
Recommended for
Certified organizations subject to periodic internal audits and companies in the process of certification. View service details →
Frequently Asked Questions

IMTS: Cybersecurity Company in Madrid

Cybersecurity services for businesses include risk analysis, defining controls, protecting systems and identities, vulnerability management, logical security, internal auditing, regulatory compliance, and evidence generation.

At IMTS, cybersecurity is addressed in an integrated manner, linking governance, risk, compliance, and day-to-day technical operations.

Cybersecurity focuses on protecting systems, data, applications, users, and infrastructure from threats, unauthorized access, and incidents.

IT compliance focuses on demonstrating that these controls exist, are documented, and comply with standards or frameworks such as ISO 27001, ENS, TISAX, ISO 20000, NIS2, DORA, or GDPR.

Both areas must work together: without technical controls, there is no real security, and without evidence, there is no demonstrable compliance.

GRC stands for Governance, Risk, and Compliance.

In cybersecurity, a GRC model helps organize an organization’s policies, risks, controls, regulatory obligations, responsible parties, evidence, and reports.

Its goal is to ensure that security does not depend on isolated actions, but rather on a managed, measurable system that is aligned with senior management.

Logical security is the technical layer that protects information systems, applications, data, and digital identities.

It includes controls such as access management, multi-factor authentication, identity management, endpoint protection, cloud security, hardening, vulnerability management, monitoring, logging, and incident response.

It is an essential component for cybersecurity and compliance frameworks to function effectively in practice.

The National Security Framework establishes measures to protect systems, services, and data, particularly within public administrations and the providers that work with them.

Compliance with the ENS requires analyzing the system’s category, implementing security measures, documenting controls, generating evidence, and conducting periodic monitoring.

Yes. IMTS provides cybersecurity, IT compliance, and risk management services to organizations in Madrid and throughout Spain.

Depending on the type of service, work can be performed in person, remotely, or in a hybrid format, particularly for projects involving consulting, internal auditing, GRC, ISO 27001, ENS, logical security, and ICT risk management.

Not sure where to start?

Tell us about your situation. We'll let you know which services are right for you.

First meeting is free and with no obligation. No empty promises, no one-size-fits-all solutions.

EMAIL info@imts.es
WEB www.imts.es/en
Seats Madrid · Domestic and International Service
Request a meeting →