Protect your company, the clear and approachable way.

I'm Antonio Cebreiro, an independent cybersecurity consultant. I help companies like yours comply with NIS2, ISO 27001 and ENS, get real value from the Microsoft 365 security they already pay for, and train their teams. You work directly with me, in plain language.

A personal reply within 24 business hours · No commitment

ISO/IEC 27001 Lead Auditor AZ-500 · Azure Security Engineer 5+ years leading security teams Speaker at AMTEGA, CIBERECO and CIBERGAL
Situations

Which of these sounds like you?

Pick the one closest to your day-to-day. If you recognise yourself in any of them, this is exactly the kind of work I do.

Situation 01 / 04

From legal text to a prioritised plan

The directive is already in force and nobody in the company knows exactly what it demands or where to start. I clear that up and we turn it into a prioritised plan.

  • A client or your parent company has already asked about NIS2
  • You're not sure whether you're an essential or important entity
  • Management wants timings and cost before deciding
Strategy and compliance
Situation 02 / 04

First we squeeze what you already pay for

Many Entra, Purview, Defender and Intune capabilities may already be included in the licences you pay for. Properly configured, they deliver more security than most of the new tools you're being sold.

  • You have E3 or E5 licences left half configured
  • Vendors keep offering you tools you already own
  • Nobody has reviewed Defender, Purview or Entra ID
Technical projects
Situation 03 / 04

Someone who sets priorities and answers to the board

IT puts out fires, but nobody sets priorities or answers to management. That's the gap I fill, a few hours a month.

  • Security depends on whoever has time that week
  • There's no written plan and no clear owner
  • A full-time CISO doesn't add up at your size
Outsourced CISO
Situation 04 / 04

Training the workforce, and the board too

One employee's click can cost more than any technical failure. I train your workforce and your executives so that click never happens.

  • You get emails impersonating clients or executives
  • The last training was a video nobody remembers
  • You've never run a phishing simulation
Training and awareness
Services

Cybersecurity consulting services

Most companies aren't short of technology: they're short of someone who will tell them plainly where to start and who to trust. That's what I do, freelance and remotely, for small and mid-sized companies.

01

Strategy and compliance consulting

Security master plans and roadmaps aligned with your business. Readiness for ISO 27001, ENS and NIS2, with compliance that is understandable and actionable —not a box-ticking exercise.

Master plans ISO 27001 ENS NIS2 Audit Roadmaps
02

Cybersecurity training and awareness

Training for technical teams, awareness for the whole workforce and cybersecurity for executives. Security culture programmes and talks that actually stick, backed by real social engineering experience.

Corporate training Awareness Security culture Social engineering Executive training
03

Technical projects

For when you need to get into the detail and leave the technology up and running. I specialise in DLP and data loss prevention, email security, Microsoft ecosystem security and Zero Trust architectures. We start by squeezing the security capabilities you already pay for in your licences and hardly ever use.

DLP Email Security Zero Trust Microsoft Purview Defender Entra ID Intune Architecture
04

Ongoing advisory · Outsourced CISO

If your company doesn't have —or doesn't yet need— a full-time security lead, I fill that gap from the outside: priorities, decisions and follow-up month by month. The industry calls it a vCISO, without the cost of a permanent hire.

Outsourced CISO vCISO Retained advisory Security committee Risk management
How I work

From the first call to a plan in motion

No blind commitments: every step has a known format and you decide with all the information in front of you.

  1. 01

    Diagnosis

    A free 30-minute call to understand your situation. You leave with an honest picture of where you stand, whether we end up working together or not.

  2. 02

    Plan

    If it makes sense to continue, you get a fixed proposal: scope, timeline and price. Priorities ordered by real risk, in a document your management can actually read.

  3. 03

    Ongoing support

    We execute the plan together, at your pace: a one-off project or monthly follow-up, with me at the other end whenever something comes up.

Free tools

From the community, for the community

Part of what I use with my clients is open to everyone: self-assessments and checklists you can use today, with no sign-up and without leaving your data anywhere.

About me

Approachable, clear, no smoke and mirrors

I'm a cybersecurity advisor, consultant and trainer. I help small and mid-sized companies protect what they've built: I define the strategy, sort out the priorities and train the people who keep it running.

I work freelance and remotely, with companies anywhere. That means dealing with me directly, with no middle layers and no product to sell you: my only interest is that you make the right decision.

I have built and led security teams from scratch, combining the technical and the strategic view. I'm an ISO 27001 lead auditor and AZ-500 certified in Azure security.

+5
Years in cybersecurity
6+
Industry talks
5
Certifications
Antonio Cebreiro Bernárdez speaking at a cybersecurity event Speaking · industry event
Certifications
AZ-500 · Azure Security Engineer Associate SC-900 · Microsoft Security, Compliance & Identity ISO/IEC 27001 Lead Auditor UNECE R/155 · Automotive cybersecurity — Cybentia CCI Industrial Cybersecurity · Green Level
Tools and expertise
Entra IDPurviewIntune DefenderCASBProofpoint ZscalerNessusSocial engineeringDLP Email SecurityZero Trust
Compliance
ISO 27001ENSTISAX CIS ControlsNIST CSFNIS2
Talks and media

Outreach that gets through

Talks at industry events and universities, plus appearances on Galician television. Cybersecurity only protects you if it's understood.

AMTEGACyberSecurity Next Gen Leaders
CIBERECOBasic Security Posture Management (BSPM)
CIBERGALThe human factor as the first line of defence
CECOCIBCybersecurity in industrial environments
CNTGIntroduction to cybersecurity for executives
ESEI · GDGCybersecurity 4.0: protecting tomorrow's industry
Galician television University lectures Industry events

Is your challenge about people rather than security? I am also a co-founder of Usoarit, a human resources consultancy for technology companies.

Discover Usoarit
Contact

Shall we talk?

If you're looking for someone approachable and trustworthy to protect your company, tell me where you stand right now. I'll reply personally within 24 business hours.

Maximum 2,000 characters.

By sending it you accept the privacy policy. Cloudflare protects the form against automated abuse and Microsoft 365 delivers the enquiry.