Cybersecurity audit and protection infrastructure
Cybersecurity

ACCEM

IT Security Audit, Data Protection & Ongoing Cyber Resilience

Third Sector / Non-profit

|Ongoing — continuous consulting

95,000+

Records Protected

100%

Critical Findings Remediated

34%→7%

Phishing Click Rate

The Challenge

ACCEM is one of Spain's leading social inclusion organizations, with 3,800+ employees across 15 autonomous communities serving 95,000+ people annually — including refugees, migrants, trafficking victims, and unaccompanied minors. Their systems handle highly sensitive personal data across distributed offices and accommodation centers. After years of organic growth, the IT infrastructure had accumulated technical debt and lacked a consolidated security posture: no centralized monitoring, no formal incident response plan, and uneven practices across sites. A breach could expose vulnerable populations to real harm and put the organization at serious regulatory risk under GDPR.

Our Approach

We started with a full-scope IT security audit across network infrastructure, web applications, access management, and data handling workflows — covering both headquarters and distributed regional offices. We ran vulnerability scans and penetration tests against external and internal assets, audited user privilege levels and credential policies, and reviewed data flows to map where sensitive information was stored, transmitted, and exposed. From the findings, we built a prioritized remediation roadmap organized by risk severity. We then moved into implementation: firewall hardening, endpoint protection rollout, network segmentation, access policy enforcement, and deployment of centralized log monitoring. We wrote incident response playbooks tailored to their operational reality, ran a phishing simulation campaign as a baseline, and delivered security awareness training across all staff levels. The engagement continues with quarterly reassessments and ongoing advisory.

Key Deliverables

Full-scope IT security audit report with risk classification
Prioritized remediation roadmap by severity
Penetration testing report (external and internal)
Network segmentation and firewall hardening
Centralized log monitoring and alerting setup
Endpoint protection deployment across all offices
Incident response playbooks and escalation procedures
Phishing simulation campaign and baseline report
Security awareness training for 3,800+ staff
GDPR compliance assessment and gap analysis
Quarterly reassessment and ongoing security advisory

Tech Stack

NessusBurp SuiteWiresharkOWASP ZAPSplunkCrowdStrikepfSenseWazuh

Impact

The audit identified the critical findings across ACCEM's distributed infrastructure, and every one of them was remediated following the risk-prioritized roadmap. Full GDPR compliance was achieved for the data handling of 95,000+ beneficiary records, with verified data residency and sovereignty over all sensitive information. The phishing simulation baseline showed a 34% click rate — after targeted training across all 3,800+ staff, follow-up simulations dropped that to under 7%. Centralized monitoring now covers all regional offices with real-time alerting. All systems hardened using open-source tools to ensure vendor independence and full auditability. We remain as their permanent security consultants, running quarterly reassessments and adapting the security posture as the organization and threat landscape evolve.

Interested in similar results?

Let's talk about your project and how we can help.