More of me 👉 here

Free penetration test evaluation: what we find before an attacker does
Table of Contents
We spend a good part of our working time finding the way into systems someone was confident were locked down: a login form that trusts the wrong header, a staging subdomain nobody remembered to take offline, an API that hands back more than the page in front of it ever asks for. Always under a signed authorisation, for a client who asked us to, before somebody without one gets there first.
This is an invitation to do that for you. It starts with a free evaluation, and the whole engagement runs digitally — from Spain, wherever you are.
Almost nobody gets tested until it is too late
INCIBE , Spain’s national cybersecurity institute, managed 122,223 cybersecurity incidents in 2025 — up 26% on 2024’s 97,348, and the highest figure the organisation has recorded. Of those: 55,411 involved malware, 45,445 were online fraud (itself up 19% on the year before), 25,133 were phishing, and 3,849 were unauthorised access or data theft. Separately, INCIBE’s own scanning identified 237,028 vulnerable systems exposed on Spanish networks over the year.
Those are managed incidents, not a census of every attack — INCIBE itself is clear that the real number is necessarily higher. What the trend line shows is not ambiguous: exposure is going up, not down, and most of it is found by the attacker first, not the owner.
What it costs when nobody tested
British Airways, 2018–2020. Attackers redirected traffic on ba.com to a fake site and skimmed the payment details of roughly 400,000 customers. The UK’s Information Commissioner’s Office investigated and, in its penalty notice, was specific about what BA had failed to do: it had not carried out rigorous testing — “in the form of simulating a cyber-attack” — on its own systems, and had no file integrity monitoring that would have caught the attacker’s changes. The ICO’s original proposed fine was £183 million; after representations, it was reduced to £20 million — still one of the largest data protection fines in UK history, for a failure that a testing programme exists specifically to catch.
Computer Weekly’s own headline on the case put the asymmetry sharply: "£4,000 bug bounty could have saved BA from record ICO fine." We would not promise you a number that specific about your own systems — nobody honest can, before looking — but the shape of the trade is the right one to have in mind.
AI didn’t create this threat — it industrialised it
INCIBE’s own 2025 figures already carry the signature: phishing and smishing fraud cases in Spain grew 25% that year, concentrated in banking, logistics and healthcare. The old advice about spotting bad grammar or a clumsy greeting is losing its usefulness for a specific, documented reason.
The UK’s National Cyber Security Centre assessed in January 2024, and has reaffirmed since , that AI “will almost certainly increase the volume and heighten the impact of cyber attacks” — precisely because it removes the skill and effort that used to gate who could run a competent attack. The EU’s own cybersecurity agency, ENISA, put a number on one slice of that in its Threat Landscape 2025 report : of the phishing emails it identified between September 2024 and February 2025, over 80% showed some use of AI.
It is not only email. In January 2024, a finance employee at the engineering firm Arup joined what looked like a routine video call with the company’s CFO and several colleagues, and authorised fifteen wire transfers totalling HK$200 million — about $25.6 million — over the course of that single call. Every person on the call except him was a deepfake, built from video and audio the real executives had already appeared in during ordinary company meetings. Nobody caught it until he rang Arup’s head office afterwards to double-check.
And it is not only criminals experimenting. In February 2024, Microsoft and OpenAI disclosed that they had identified and shut down accounts used by five state-linked hacking groups — tied to Russia, Iran, North Korea and China — using OpenAI’s models for reconnaissance, translation and basic coding help. Nothing novel yet, by their own account: the same reconnaissance and scripting these groups always did, just faster.
None of this changes what a penetration test is for. It changes how quickly the gap you haven’t tested for gets found, and by whom.
Why “consent” is not a courtesy — it is the law
Everything a penetration test does — getting into a system its owner did not build a door for you to use — is, without permission, a crime in Spain. Article 197 bis.1 of the Criminal Code , in force since the 2015 reform (Ley Orgánica 1/2015), punishes anyone who, “vulnerando las medidas de seguridad establecidas para impedirlo, y sin estar debidamente autorizado” — circumventing the security measures put in place to prevent it, and without being duly authorised — accesses or helps someone else access a computer system, with six months to two years in prison. The one thing that turns that same act into a legitimate security service is the phrase in the middle: debidamente autorizado.
That is why every engagement we run starts before a single request is sent against your systems: a signed authorisation naming exactly what is in scope, the time window, the specific assets covered, and a contact on your side who can vouch for us if your own monitoring lights up. It is not paperwork for its own sake. It is the specific fact that keeps the same technical work on the right side of the law.
What the law increasingly expects anyway
Even where nobody is asking yet, the direction of travel is consistent:
- GDPR, article 32(1)(d) requires "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing." This applies to essentially any company handling personal data in the EU — not a niche obligation for regulated sectors.
- NIS2 (Directive (EU) 2022/2555) lists security testing among the risk-management measures its “essential” and “important” entities must implement. Spain missed the 17 October 2024 transposition deadline, and on 8 July 2026 the European Commission referred Spain to the Court of Justice of the EU for still not having notified full transposition — nearly two years late. The substance of the obligation does not wait for Spain’s own paperwork to catch up.
- DORA (Regulation (EU) 2022/2554), in force since 17 January 2025, requires financial entities that their regulator designates as significant enough to carry out Threat-Led Penetration Testing at least every three years , under the TIBER-EU methodology.
- ENS, Spain’s Esquema Nacional de Seguridad (Real Decreto 311/2022 ), requires a formal security audit at least every two years for systems in its MEDIA or ALTA categories, or sooner after any significant change — a self-assessment on the same two-year cycle applies even at the lowest, BÁSICA category. Anyone selling software or services to Spanish public administration is very likely inside this scope.
What the free evaluation actually is
An external, non-intrusive first look at what you are actually exposing to the internet: mapping it, checking it against known misconfigurations and unpatched software, and a manual review of the areas most likely to matter for a business like yours. You get a plain-language summary of what we found and an honest answer to the only question that matters — whether a full audit is worth your money right now. If it isn’t, that is what we will tell you.
What the full audit adds
The full engagement is manual-led, not a scanner report with our logo on it. Methodology follows the OWASP Testing Guide and the Penetration Testing Execution Standard; scope and rules of engagement are agreed and signed before testing starts, exactly as above; findings are written up in plain language, ranked by the risk they actually represent rather than by a generic severity score; and once you have fixed what we found, we retest it. Price is quoted after the evaluation, scoped to what you actually run — pretending two companies’ attack surfaces cost the same to test properly would be the first dishonest thing we told you.
Delivered digitally, from Spain
The testing itself runs remotely against your externally reachable, agreed-scope systems, so distance was never really the constraint it looks like. A company anywhere can be scoped, evaluated and tested without anyone booking a flight. Running the practice from Spain means the engagement sits under EU jurisdiction, and anything we touch during testing is handled under the same GDPR-aligned discipline as everything else we build.
If you want to know where you actually stand
Tell us what you would like evaluated, and where to send the results.
This article describes our own testing practice in general terms; the exact scope, methodology and legal obligations that apply to you depend on your systems, your sector and your jurisdiction. It is general information, not legal or compliance advice — if you operate in a regulated sector, confirm your specific testing obligations with your own compliance advisors.
