Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
Anyone looking for a cybersecurity company in Spain is hardly ever looking for a list of names: they are about to sign a contract and want to know what to ask so they do not get it wrong. The names take five minutes to find. What you cannot find is the criteria, and the criteria are the only thing separating a security audit that changes something from an expensive report nobody opens again. This guide is those criteria, in the order you need them, and it explains the Spanish rules rather than assuming you already live under them.
"Cybersecurity company" is a label covering three businesses that have little in common, and confusing them is the mistake that costs most.
All three are necessary and none replaces the others. A SOC does not tell you whether your application has an authorisation vulnerability, and a certificate does not tell you whether a hacker would get in today. Before asking for a quote it pays to know which of the three you need, because the same brochure sells all three and the price does not tell them apart.
Asperis does the first one: offensive security, with compliance as a consequence rather than as a separate product. If you want a provider on the ground in Spain, the Barcelona page explains how we work from there.
The scope comes first because it decides everything else: the price, the duration, what gets found and what does not. A fixed price on an open scope is not a commercial advantage, it is a postponed argument.
What has to be in writing, at this level of detail:
All of that together has a name in the industry, the rules of engagement, and it is the document that turns an attack into a lawful service. If a provider does not bring it as standard, that is not a paperwork detail: it means they are going to improvise.
Before discussing the scope it helps to know what you have exposed, which is usually more than what is in the inventory. That is your attack surface, and measuring it is a job in itself.
Ask which methodology they follow and ask them to name it. This is not a formality: a public methodology is a list of things that have to be tested, so naming it is committing to a verifiable minimum. Without one, coverage depends on the memory and the mood of whoever you get.
For web applications the usual reference is the OWASP testing guide, and the OWASP Top 10 is its best known summary. Be careful with that last point, because it is a frequent and expensive confusion: the Top 10 is a list of risk categories, not a test plan. A provider offering "we cover the OWASP Top 10" is offering less than it sounds.
And there is one question that separates manual work from automated work better than any other: which part of the finding is found by a tool and which part is found by a person. A scanner finds old versions and default configurations. It does not find that customer A’s invoice identifier works inside customer B’s session, because that requires understanding what your business does. If the answer is vague, the answer is that there is no manual work.
When what you want tested is not an application but the ability to detect and respond, the format is different: a red team, which pursues a specific objective without warning the defending team, or an assumed breach exercise, which starts from the assumption that the attacker is already inside and measures how far they get.
In this industry the result depends on the person assigned more than on almost anything else. So the useful question is not how many people the company has, but who is going to be on your project.
We say who we are on our team page, and that is exactly the level of detail worth demanding from anyone, ourselves included.
Ask for a sample report before you sign, anonymised. It is the request that yields the most information and the one fewest providers expect. What to look for in it:
And a practical question that saves weeks: in what format do they deliver. A PDF is a document; findings inside your own issue tracker are work already started. In our case findings live on the platform from the moment they are found, not at the end.
A pentest without a retest is a photograph. Somebody tells you what is wrong, your team fixes it, and nobody checks that what was fixed is actually fixed. It is surprisingly common for the fix to close the path that was tested and leave the one next to it open.
What has to be closed off in the contract:
And a recommendation that costs nothing: agree beforehand who fixes, within what deadline by severity, and who decides whether a risk is accepted instead of corrected. Reports almost always get stuck there, not on the technical side.
Often the search for a cybersecurity company does not come from a scare but from a requirement. It pays to know which one applies to you before asking for a quote, because it changes the deliverable.
The question to ask a provider is not whether they "work with" these rules, but what specific evidence their work produces that you can put in front of an auditor. And if what you need is personal data protection, that is a different conversation and it goes through GDPR, the European regulation Spanish texts call the RGPD.
None of these signs is conclusive on its own. Two or three together are.
The short list, to take into the meeting: a written and itemised scope; a named methodology; what is manual and what is automated; the names of the assigned team; an anonymised sample report; business impact as well as severity; a retest with closed conditions; insurance; contactable references; and what evidence it produces for the rule that applies to you.
If it helps as a comparison, this is how we answer those ten: the catalogue is at services, ethical hacking is the usual way in, and at contact you can ask for the sample report with no commitment. And if you want the ground under all of it first, what a penetration test actually is and what it produces is set out in this guide, and if you would rather start from the basics and in order, the guide to cybersecurity for companies comes before all of this.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.