Secure&IT
Independent Spanish cybersecurity consultancy combining regulatory compliance advisory (ENS, GDPR, NIS2, DORA) with a managed SOC-CERT and industrial security practice.
Visit Website ↗ + Add to CompareOverview
Secure&IT is an independent Spanish cybersecurity consultancy, legally registered as Secure and IT Proyectos, S.L., organized around a "360-degree Security" model that spans five service lines: regulatory compliance, IT governance and process, systems and IT security, managed security, and industrial (OT) cybersecurity. Its compliance practice centers on the dense set of national and EU frameworks that apply to Spanish organizations, including the GDPR/RGPD, Spain’s Esquema Nacional de Seguridad (ENS), the NIS2 directive, and the EU’s DORA regulation for financial-sector digital operational resilience.
Headquartered in Las Rozas de Madrid with an additional office in Vitoria-Gasteiz, the company runs an Advanced SOC-CERT for 24/7 monitoring and incident response alongside its advisory work, and holds a Great Place to Work certification. The company markets itself as having more than a decade of experience in the Spanish cybersecurity and compliance market.
Secure&IT operates as a service-led consultancy and MSSP rather than a technology product vendor, giving it real regional regulatory depth but a narrower, more geographically bound footprint than pan-European or global GRC platforms. Independent evidence of its technical efficacy or client outcomes beyond its own marketing materials is limited in publicly available sources.
Innovation Matrix Assessment
No evidence of a proprietary software product roadmap was found; the company evolves primarily through service-line expansion, such as adding DORA and NIS2 compliance offerings, rather than software release cycles.
A multi-office operation (Madrid and Vitoria-Gasteiz) with an in-house 24/7 SOC-CERT and a Great Place to Work certification suggests a stable, functioning consultancy, though headcount and financials are not independently disclosed.
No independently verifiable funding, revenue, or customer-count growth data was found; the company markets 'more than a decade' of experience but no evidence of expansion beyond its two current offices was located.
Operates a fairly standard security-consultancy and MSSP service model (compliance advisory, SOC-CERT, industrial security) without a clearly differentiated proprietary technology or novel methodology found in available sources.
Great Place to Work certification and ISO 27001-aligned service claims are the main independently referenced credentials found; no named client case studies, breach outcomes, or third-party technical evaluations were located.
Deep focus on Spain-specific and EU-wide regulatory regimes (Esquema Nacional de Seguridad, GDPR/RGPD, NIS2, DORA) addresses a genuine and currently intensifying compliance burden for Spanish and EU organizations, particularly financial entities facing DORA.
Why CISOs Should Care
For CISOs and compliance leads at Spanish or EU organizations navigating overlapping mandates such as ENS, GDPR, NIS2, and DORA, Secure&IT offers a dedicated regional consultancy combining compliance advisory with a managed SOC rather than a pure-play technology product.
What Makes It Different
Distinguishes itself through deep specialization in Spanish national and EU regulatory frameworks (ENS, DORA, NIS2) bundled with managed detection and industrial/OT security, rather than a single point product.
The Matrix Verdict
43/100 — EMERGING / UNRANKED
A credible, independent Spanish cybersecurity consultancy with genuine regional regulatory depth, but its service-led model and lack of independently disclosed growth or technical validation place it as a solid regional player rather than a category disruptor.
Editorial Note: Claims vs. Verified Findings
Independently verifiable: the company's registration as Secure and IT Proyectos, S.L. and its Madrid/Vitoria-Gasteiz office locations (Empresite business registry, ASLAN association listing), and its Great Place to Work certification. Vendor-sourced and unverified: the 'more than a decade of experience' tenure claim, the '360-degree Security' model description, and any implied client outcomes, which come from the company's own marketing site rather than independent audits.
Sources
Alternatives to Secure&IT
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…