Cybersecurity with purpose

Your strategic partner in cybersecurity, resilience and digital trust.

We govern, protect, operate, assure and evolve the cybersecurity of organisations that cannot afford to fail.

  • From exposure to resilience.
  • From compliance to control.
  • From technology to trust.
One group, five capabilities

Track record

More than two decades protecting organisations that cannot afford to fail.

0+
años de trayectoria
0+
clientes atendidos
0+
proyectos de ciberseguridad
0+
incidencias resueltas
Samsung SDS EMM Resell Partner Certified · Bomontec

Certified partnership

Certified Samsung SDS EMM Resell Partner.

Bomontec is a partner certified by Samsung SDS for the resale, deployment and support of its Enterprise Mobility Management platform in Spain: the technology foundation of Blindium and of our On-Prem secure mobility offering.

On-Prem and air-gapNIAP Common Criteria MDM-PP v4.0DISA STIGSamsung KnoxMigration from Omnissa

The certifications and recognitions cited correspond to the Samsung SDS EMM product according to their issuing source. Samsung, Samsung SDS and Knox are trademarks of their respective owners.

Immediate trust

Cybersecurity that builds trust. Technology that drives your business.

Trust

We act with integrity, transparency and ongoing support.

Experience

A track record in critical, regulated and highly demanding environments.

Specialisation

Technical, regulatory and operational teams focused on results.

Results

Visibility, control, continuity and measurable improvement.

The problem we solve

Organisations no longer just have to avoid incidents. They have to withstand, demonstrate and respond.

Digital risk is no longer an isolated technical matter: it affects continuity, reputation, contracts, regulators, third parties and management.

How we approach it
  • Exposed critical infrastructure, cloud and connectivity.
  • Dependence on third parties, technology providers and legacy systems.
  • Regulatory pressure: ENS, NIS2, DORA, ISO 27001, ISO 22301, ISO/IEC 42001, CRA and AI Act.
  • Overstretched internal teams and no executive visibility of risk.
  • The need to demonstrate compliance to customers, regulators, committees and boards.
  • Reputational risk for executives, CEOs, CFOs, influencers, celebrities and institutions.

Why Grupo Bomontec

What sets us apart from a consultancy or a generic MSSP.

01

The whole lifecycle, one point of contact

Governance, compliance, operations, resilience, product and people within a single group. No bouncing from one vendor to the next.

02

Our own technology, data in the EU

Neo products designed and operated by us, with infrastructure in the European Union and control over where your data lives.

03

Defence-grade secure mobility

Certified Resell Partner for Samsung SDS EMM and Blindium, serving armed forces, police, intelligence and critical entities.

04

Presence in four regions

Spain, the European Union, LATAM and Africa, with a team in Madrid and local partners in every market.

05

Evidence, not promises

Every service ends in verifiable deliverables: reports, records, plans and dashboards that stand up to an audit.

06

Protection for people too

Private Shield: personal exposure, digital identity, impersonation and confidential response for executives and their families.

Brand ecosystem

One group. Multiple specialisms. A single outcome: digital trust.

Complementary capabilities covering the entire cybersecurity lifecycle: strategy, operations, compliance, secure mobility and our own products.

Governance / vCISO

Bomonsis Cybersecurity

Cybersecurity strategy, governance and leadership that turns technical and regulatory risks into executive decisions.

vCISOCISO OfficeRisk governanceAI GovernanceTPRMSecurity Committee
CyberOps

Bomontec Tecnologías

Operations, monitoring, response and technological resilience to protect critical assets 24/7.

SOCSIEMMDREDR/XDRThreat HuntingIncident Response
In-house products

Neo

Our own products for identity, resilience, perimeter, compliance and digital trust.

NeoFenseNeoHoleNeoFrontHANeoConsentGuardNeoVPNNeoWardenNeoSafe
Defence-grade EMM

Blindium

Management and hardening of mobile devices for armed forces, police, intelligence and critical entities.

Samsung SDS EMM on-premAir-gapped networksKnoxVPNDualDAR encryption
Enterprise mobility

Samsung SDS EMM by Bomontec

Certified Resell Partner for Samsung SDS EMM On-Prem in Spain, serving public administrations, banking, utilities and large enterprises.

On-PremAir-gap readyNIAP Common CriteriaMulti-OSMigration from Omnissa

What we do for you

From strategy to operations. From compliance to trust.

Six capabilities around your critical assets. Scroll down: each step lights up its layer.

Capas de protección del grupo alrededor de los activos críticos Activos críticos Gobierno Cumplimiento Operación Resiliencia Producto Personas
01

Govern

We define priorities, risks, policies, committees, roadmap and executive reporting.

02

Protect

We harden assets, cloud, networks, identities, endpoints, applications and critical environments.

03

Detect

We monitor threats, vulnerabilities, exposure and signs of compromise.

04

Respond

We act on incidents, reduce impact and coordinate recovery.

05

Assure

We review evidence, compliance, third parties, continuity, AI and digital products.

06

Evolve

We automate, measure and continuously improve your security maturity.

Services by need

Choose the entry point that best fits your situation.

You don't need to buy a tool. You need to know which risk to reduce, which capability to build and how to prove it.

In-house products and secure mobility

Our own technology to accelerate digital trust.

Identity, resilience, perimeter, compliance and secure mobility in a modular portfolio, with a dedicated website for each product.

Executives and high profile

Digital protection for people who cannot afford to be exposed.

CEOs, CFOs, board members, public figures, business families, influencers and trusted teams need a different kind of protection: discreet, continuous and focused on real risk.

  • Personal exposure assessment
  • Digital identity protection
  • Leak monitoring
  • Device and account security
  • Protection against impersonation
  • Reputational crisis response

Sectors

Specialists in environments where trust is critical.

We adapt strategy, operations and compliance to the demands of each sector.

Public administration

Protection of essential services, ENS, NIS2, continuity, operational sovereignty and institutional response.

  • ENS adaptation and certification
  • NIS2 transposition and essential services
  • Continuity and operational sovereignty

Finance and insurance

DORA, technology risk, third parties, continuity, fraud, sensitive data and operational resilience.

  • End-to-end DORA programme
  • Third-party risk management (TPRM)
  • Resilience testing and TLPT

Industry and OT/ICS

Segmentation, monitoring, production continuity, IT/OT defence and advanced response.

  • OT network segmentation and visibility
  • Monitoring and detection in industrial environments
  • Production continuity and recovery

Energy and utilities

Critical infrastructure, availability, compliance, resilience and operational continuity.

  • Critical infrastructure protection
  • High availability and resilience
  • NIS2, ENS and sector regulation compliance

Healthcare

Data protection, clinical systems, continuity of care and connected devices.

  • Health data protection (GDPR)
  • Security of clinical systems and connected devices
  • Continuity of care against ransomware

Technology, SaaS and digital products

CRA, Product Security, SBOM, PSIRT, AppSec, DevSecOps and commercial trust.

  • Cyber Resilience Act (CRA) compliance
  • Product security programme and PSIRT
  • SBOM and component vulnerability management

Retail and distribution

Omnichannel protection, customer data, continuity, fraud and distributed operations.

  • E-commerce and payment protection (PCI DSS)
  • Network security in stores and warehouses
  • Continuity of distributed operations

Senior executives and exposed individuals

Privacy, reputation, personal exposure, digital identity and discreet protection.

  • Personal and family exposure assessment
  • Identity and digital footprint protection
  • Monitoring of leaks and impersonation

Methodology

A clear methodology for turning uncertainty into control.

  1. 01

    Discover

    We get to know your business, environment, risks and priorities.

  2. 02

    Analyse

    We assess maturity, exposure, compliance and real capabilities.

  3. 03

    Design

    We define strategy, roadmap, architecture and action plan.

  4. 04

    Implement

    We deliver controls, processes, technology and evidence.

  5. 05

    Operate

    We monitor, respond and support continuous improvement.

  6. 06

    Optimise

    We measure results, reduce risk and evolve capabilities.

Commercial proposals

Flexible, modular and scalable packages.

We select the right delivery model according to your maturity, criticality, exposure, regulation and business goals. Each proposal can be contracted as a monthly service, fixed-scope project, institutional programme or executive retainer.

My situation:
Secure start

Essential

Basic protection and control

From an initial assessment

Organisations that want to start with managed, prioritised and well-ordered security.

  • Initial assessment
  • Basic monitoring
  • Priority hardening
  • Incident management
  • Basic executive reporting
  • Specialist service desk
Critical operations

Premium

Resilience and continuity

Project + service

Organisations with critical operations, high technology dependence and continuity objectives.

  • Everything in Advanced
  • Threat Hunting
  • Backup / Disaster Recovery
  • ISO 22301
  • Advanced response
  • Operational continuity
  • Premium support
Large accounts

Enterprise

Tailored cybersecurity

Custom proposal

Business groups and multinational environments that need coordinated governance, operations and compliance.

  • vCISO / CISO Office
  • SOC / MDR
  • DORA / NIS2 / ENS / ISO
  • AI Governance
  • Product Security / CRA
  • TPRM
  • Dedicated architecture and team
Public sector

Institutional Program

Institutional programme

Scope-based programme

Ministries, public administrations, agencies, critical infrastructure and national or regional programmes.

  • Institutional assessment
  • Governance and roadmap
  • ENS / NIS2 / continuity
  • Coordinated operations and response
  • Controlled, measurable pilot
  • Knowledge transfer
  • Executive dashboard
Discreet and confidential

Executive Protection / Private Shield

High-profile private protection

Executive retainer

CEOs, CFOs, board members, business families, public figures, celebrities and exposed individuals.

  • Personal and family exposure
  • Identity and digital footprint
  • Reputation monitoring
  • Account and device security
  • Confidential response
  • Private executive report

Delivery models are indicative. The final scope is defined according to criticality, countries, assets, regulatory requirements, continuity needs and the required service level.

Frameworks and standards

The frameworks that structure our work.

We do not present them as our own certifications unless contractually applicable; they are reference frameworks for designing, implementing, reviewing and evidencing.

ISO 27001ISO 22301ENSNIS2DORANIST CSFISO/IEC 42001CRAAI ActGDPRCIS ControlsPCI DSSOWASPMITRE ATT&CK

International presence

International presence, local commitment.

We support organisations in Spain, the European Union, LATAM and Africa, with a global outlook and the ability to adapt locally. Activity and partnerships in Morocco, Tunisia, Cape Verde, Benin and other African markets.

Map of Grupo Bomontec's presence in Spain, the European Union, LATAM and AfricaEuropeLATAMAfricaMadrid · HQMadrid · HQSpainHead office, team, SOC and support. All of the group's services and products.BrusselsBrusselsEuropean UnionRegulated projects under NIS2, DORA, GDPR, CRA and the AI Act. Neo product infrastructure in the EU.RabatRabatMoroccoActivity and collaboration with local partners: governance, operations and secure mobility.TunisTunisTunisiaActivity and collaboration: compliance, SOC and infrastructure protection.PraiaPraiaCabo VerdeInstitutional programmes and resilience of essential services.CotonouCotonouBeninCollaboration on cybersecurity programmes and knowledge transfer.Mexico CityMexico CityLATAMSupport for business groups and institutions across the region.BogotáBogotáLATAMGovernance, compliance and operations for financial institutions and services.LimaLimaLATAMResilience, continuity and infrastructure protection.SantiagoSantiagoLATAMProduct security and compliance for technology and SaaS.Buenos AiresBuenos AiresLATAMProtection of executives and business groups.
  • SpainHeadquarters in Boadilla del Monte (Madrid). Local team, operations and support.
  • European UnionRegulated projects under NIS2, DORA, GDPR, CRA and the AI Act.
  • LATAMSupport for business groups and institutions across the region.
  • AfricaMorocco, Tunisia, Cape Verde, Benin and other markets.

Leadership

Leadership that builds trust.

Cybersecurity is not just technology. It is strategy, trust and a vision for the future.

Executive guidance translates technical complexity, regulatory pressure and digital exposure into prioritised decisions, executable plans and confidence for management.

Experience. Vision. Commitment.

  • A track record in technology, digital transformation, cybersecurity and resilience.
  • A multi-sector view of critical, regulated and international environments.
  • The ability to connect business, technology, compliance and operations.
Meet the leadership
Team reviewing a security investigation on screen

Resources

Guides, checklists and templates to help you decide with confidence.

Practical material produced by our teams. Delivered on request so we can tailor it to your situation and add a short briefing.

NIS2 checklist for essential and important entities

The Article 21 measures, notification deadlines and management obligations, in a single checklist.

NIS2Compliance
RequestOn request

DORA guide: from regulation to work plan

ICT risk framework, incidents, resilience testing and the register of providers, explained step by step.

DORAFinance
RequestOn request

ENS roadmap: from categorisation to certification

Phases, owners, evidence and common mistakes when adapting to the Spanish National Security Framework (ENS).

ENSPublic sector
RequestOn request

Cyber Resilience Act for software manufacturers

Which products are in scope, essential requirements, SBOM, PSIRT and the application timeline.

CRAProduct
RequestOn request

Free self-assessment

Where does your organisation stand?

Eight questions, two minutes. You will get a view of your maturity level and the proposal that fits best. No data is sent until you decide.

  • No sign-up or email: the result is calculated in your browser.
  • Guidance on the proposal that fits you best.
  • If you wish, send the result with your request in one click.

Indicative only. It does not replace a professional assessment and is not an audit or certification.

Common questions

Frequently asked questions

If you can't find your answer, write to us and we'll reply during business hours.

What is Grupo Bomontec?

A Spanish cybersecurity group with more than 20 years of track record that brings together governance and leadership (Bomonsis Cybersecurity), operations and defence (Bomontec Tecnologías), regulatory compliance, secure mobility (Blindium and Samsung SDS EMM) and in-house products (Neo).

Do you work with organisations of any size?

Yes. Proposals range from Essential, for organisations starting out with managed security, to Enterprise and the Institutional Program for large accounts and public administrations, plus private high-profile protection.

Which regulations do you cover?

ENS, NIS2, DORA, ISO 27001, ISO 22301, ISO/IEC 42001, CRA, AI Act and GDPR, as well as reference frameworks such as NIST CSF, CIS Controls, PCI DSS, OWASP and MITRE ATT&CK.

Where do you operate?

In Spain, the European Union, LATAM and Africa, with headquarters in Boadilla del Monte (Madrid) and activity in Morocco, Tunisia, Cabo Verde, Benin and other African markets.

How do we get started?

With an assessment request. A specialist reviews your situation, risks and priorities and gives you an initial commercial and technical view with no obligation.

Let's talk

Ready to take the first step?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.

Request an assessment

Tell us your area of interest and we'll reply with an initial commercial and technical view.

Enter your name.
Enter your company or organisation.
Enter a valid email address.
Enter a valid phone number or leave the field empty.
Briefly describe what you need (at least 10 characters).
Image with a 5-character verification code
The verification code is incorrect.
Do not send credentials, keys or classified information through this form. If your request is urgent, say so and leave a contact phone number.

Initial commercial response normally during business hours. For critical incidents, state the urgency and a contact phone number. Data controller: BOMONTE TECNOLOGIAS, S.L. · Privacy channel: gdpr@bomontec.net.