Security Policy
Information Security Policy
At OCIRIA, security is not an add-on: it is the core of what we do. As a cybersecurity company, we apply to our own systems the same rigour we offer our clients.
Our commitment
We protect the confidentiality, integrity and availability of the information we process, following best practices aligned with the Spanish National Security Framework, the ISO/IEC 27001 standard and the NIS2 directive.
Technical and organisational measures
- Encryption of communications (TLS) and of sensitive data at rest.
- Access control based on the principle of least privilege, with enhanced authentication (MFA) for administrative access.
- Continuous monitoring and logging of security events, with automatic threat detection and blocking.
- Vulnerability management: periodic analyses and patch application prioritised by risk level.
- Encrypted and verified backups, with a tested recovery plan.
- Supplier security: we evaluate third parties that have access to data or systems.
- Human oversight of processes assisted by artificial intelligence.
Incident management
We have an incident response procedure that prioritises containment, notification of affected individuals and authorities where appropriate, and subsequent learning. Where regulations require it (GDPR, NIS2), we notify within the legally established timeframes.
Responsible vulnerability disclosure
If you have detected a possible vulnerability in our systems, we appreciate you reporting it to us responsibly by writing to [email protected]. We commit to reviewing it, keeping you informed of its status, and not taking legal action against security research carried out in good faith.
Continuous improvement
We periodically review and update this policy and our security measures to adapt to new threats and regulatory requirements.
Last updated: 26 June 2026.