About OCIRIA
Who we are
OCIRIA is a European cybersecurity boutique managed by defensive AI. We work in three steps: first we know your real risk with an audit —the part from outside and the part from within—, then you decide how to carry on, and —if it fits— we protect you continuously with an AI platform, calibrated with what we found. We serve mid-market European companies that want a clear technical counterpart, a realistic calendar and a signed report at the end. Our platform is ociria.com.
We were born out of fatigue. Fatigue of technical reports the board couldn't read, of audits that ended in a hundred slides without a single actionable data point, of products sold as solutions when they were loose parts, and of pitches talking about "global leaders" before showing a single finding. We decided to do it the other way around: a small, honest, technical service, with verifiable numbers and deadlines that are kept.
What sets us apart
We don't sell absolute protection. It doesn't exist. What we sell is judgement: seeing more, seeing earlier and understanding what we see. The report we sign describes what we saw, how we saw it, and what we still don't see. That last sentence is the one nobody wanted to put in writing. We put it.
AI that sees and that acts. In the audit, the AI handles triage, correlation and pattern detection that would take an analyst hours —to give your team its hours back and deliver judgement, not noise—. In the platform, that same AI goes from warning to acting: it detects, fixes and verifies continuously, with a kill-switch, human approval for anything sensitive and everything reversible. The machine does the repetitive part; the person keeps the final word.
Boutique speed. A single human chain of command and an always-on defensive AI, with no bureaucratic layers in between. Initial diagnosis in 10 business days, with a signed report and actionable next steps. And if we find something serious during the diagnosis, we tell you within 24 hours; we don't wait for the final report.
Senior team, dual jurisdiction. A Spanish-Romanian team, no franchise and no juniors, focused on the European mid-market. We know the real transposition of NIS2 isn't identical in every member state, and we work that nuance when it applies.
How we work · defensive AI with human oversight
We're a deliberately small operation: the owner supervises every case from start to finish. The technical capability comes from our own defensive AI stack —we triangulate every finding across several model families: mass scanning, correlation and critical analysis— and a human signs the verdict. We don't publish headcount figures: what matters is who supervises, how each finding is validated and what evidence is delivered.
How we work in practice
1. First contact. A 30-45 minute conversation to understand the context: size, sector, regulatory framework, recent incidents, internal team and suppliers.
2. Initial diagnosis. A week of work: exposed surface, brand OSINT, compliance assessment (NIS2, GDPR and ISO 27001 where relevant) and technical interviews.
3. Signed report. PDF within 10 business days of close. Findings with reproducible evidence, a prioritised plan and an effort estimate per block.
4. You decide how to carry on. With the report in hand, you choose with no pressure: you fix it yourself (you take the executable plan), we fix it with you (a closed project with a closing audit), or you turn on the platform to keep what we found in check —or monthly vCISO, if you prefer a human line—. It's never mandatory and everything is reversible. And if your diagnosis comes back clean, we'll tell you: you don't need the platform yet.
What we don't do
We don't replace a SIEM that already works. We don't ask for a rip-and-replace to "standardise". We don't sell fear. We don't publish client logos without their written consent. We don't sign reports with conclusions we haven't reached. And we don't promise certifications that depend on external bodies (ISO 27001, ISO 42001) as if we issued them ourselves: we prepare the road, and we say so honestly.
Legal framework
OCIRIA is operated by Ibida Black Level S.L. (tax ID B93643807), under Spanish commercial law and the applicable European regulation (AEPD, LSSI). We detail it in the legal notice and the privacy policy.
Next step
If you've made it this far and think a conversation would make sense, ask for one. No cost, no commitment, no sales script.
Email: [email protected] · Web: ociria.com