Internet Security Auditors
Internet Security Auditors is a Barcelona-headquartered cybersecurity professional services firm providing penetration testing, regulatory compliance consulting (PCI DSS, ISO 27001, NIS2, DORA), managed security, and training to enterprise clients across Spain and Latin America from offices in Barcelona, Madrid, and Bogotá.
- Company typePrivate
- Founded2001
- HeadquartersBarcelona, Spain
- Headcount11–50
- GTM typeB2B
- OfferingServices
What Internet Security Auditors does
Internet Security Auditors (ISecAuditors) is a privately held cybersecurity professional services firm founded in 2001 and headquartered in Barcelona, Spain, with additional offices in Madrid and Bogotá. The firm serves enterprise and mid-market clients primarily across Spain and Latin America (with a stated reach of 35 countries) through five service lines: technical auditing (penetration testing, red team, web/API/mobile/source-code auditing, ASV scans, ATM auditing, early vulnerability warnings), regulatory compliance consulting (PCI DSS, PCI PIN, PCI SSF, PCI 3DS, ISO 27001, NIS2, DORA, GDPR, ENS, NIST CSF, SWIFT), AI security services (ISO 42001 implementation and AI ecosystem auditing), managed security (forensics, CISO as a Service, system hardening), and cyberintelligence (social engineering, digital brand monitoring). It also operates the ISecAuditors Academy, an authorized training platform delivering official certifications from (ISC)², BSI, OffSec, ISACA, and the PCI Security Standards Council alongside proprietary courses on secure SDLC, OSINT, and PCI DSS/PIN.
The firm monetizes through project-based professional services engagements, quote-based enterprise contracts, and training fees from the academy, and it holds a dense stack of regulated assessor credentials — PCI QSA, QPA, SSA and 3DS Assessor — that gate access to mandated payment-security audits. Its internal certifications include ISO/IEC 27001:2022 (BSI certificate IS-692749, held since 2018), and the firm cites 2,600 projects completed, 1,300+ clients served, 8,500 professionals trained, and a 98.5% recurring client rate.
Commercially the company is a bootstrapped S.L. (INTERNET SECURITY AUDITORS, S.L., N.I.F. B-62638507) with 11-50 employees, no disclosed parent or external institutional investor, and no public revenue disclosure. Customer logos span construction (Grupo AR), e-commerce/payments (Beruby, Fleurop-Interflora España, Beruby), financial services and remittances (Intaremit S.A., PAYVÁLIDA), call-center/BPO (OUTSOURCNG SAS BIC), digital/technology (Neurona), education (Saint Louis University Spain), and automotive/membership clubs (RACC), suggesting a horizontal professional services motion with a strong PCI/payment and regulated-industry tilt.
Internet Security Auditors firmographics
Firmographics- Name
- Internet Security Auditors
- Legal name
- INTERNET SECURITY AUDITORS, S.L.
- Website
- https://isecauditors.com
- Company type
- Private
- Founded year
- 2001
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Internet Security Auditors is a Barcelona-headquartered cybersecurity professional services firm providing penetration testing, regulatory compliance consulting (PCI DSS, ISO 27001, NIS2, DORA), managed security, and training to enterprise clients across Spain and Latin America from offices in Barcelona, Madrid, and Bogotá.
- Ownership category
- akta.pro rank
Internet Security Auditors industry classification
Industry- Product category
- Cybersecurity Professional Services
- NAICS
- Management, Scientific, and Technical Consulting Services (5416), Investigation and Personal Background Check Services (561611)
- SIC
- Services-Engineering, Accounting, Research, Management (8700), Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC), Fraud, Cybercrime Investigations & Brand/Dark Web Monitoring (BPAKAHAO), Cybersecurity (General) (EDAOAIAB), Regulatory Readiness & Audit Automation (e.g., EU AI Act, NIST AI RMF, ISO/IEC 42001) (HDAAAMAE)
Keywords
Where Internet Security Auditors is headquartered
LocationHeadquarters
- HQ city
- Barcelona
- HQ country
- Spain
- HQ region
- Europe
Offices3 records
Markets served
Internet Security Auditors business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations, Infrastructure
Revenue model
- Professional Cybersecurity Auditing Services: Penetration testing, security audits, vulnerability assessments, red team exercises, and technical security audits for web applications, APIs, mobile applications, cloud environments, WiFi, ATM, and source code.
- Compliance Consulting Services: Implementation and certification consulting for regulatory frameworks including PCI DSS, PCI PIN, PCI SSF, PCI 3DS, ISO 27001, NIS2, DORA, GDPR, ENS, NIST CSF, SWIFT, and CRA compliance.
- AI Security Services: ISO 42001 SGIA implementation and AI usage compliance evaluation services for organizations implementing AI systems.
- Managed Security Services: Computer forensics, professional services, CISOaaS, and system securitization services.
- Cyberintelligence Services: Social engineering testing, digital brand surveillance, travel support, and cyberintelligence services.
- Training and Certification Programs: Professional training academy offering official certifications from (ISC)2, BSI, OffSec, ISACA, PCI SSC as well as proprietary courses on secure development techniques, PCI DSS, PCI PIN, and OSINT techniques.
Go-to-market motion1 record
Distribution channels2 records
Marketing channels9 records
Internet Security Auditors product offering
Product offeringCore offering
Internet Security Auditors is a professional cybersecurity services firm that delivers auditing (penetration testing, red team exercises, vulnerability assessments across web, API, mobile, cloud, WiFi, ATM, and source code), compliance consulting (PCI DSS/PCI PIN/PCI SSF/PCI 3DS/ISO 27001/NIS2/DORA/GDPR/NIST CSF/SWIFT/ENS/CRA/LSSICE), AI security (ISO 42001 implementation and AI compliance evaluation), managed security (forensics, CISO as a Service, system hardening), and cyberintelligence (social engineering testing, digital brand surveillance). The firm also operates the ISecAuditors Academy training platform providing official certification courses from (ISC)2, BSI, OffSec, ISACA, and PCI SSC.
Product overview
Internet Security Auditors is a cybersecurity consulting and auditing firm offering a comprehensive portfolio of professional services organized into five main categories: Auditing (penetration testing, vulnerability assessments, Red Team exercises, web/API/mobile/code auditing), Consulting (regulatory compliance including PCI DSS, PCI PIN, PCI SSF, PCI 3DS, ISO 27001, NIS2, DORA, GDPR, NIST CSF, SWIFT), AI (ISO 42001 implementation, AI compliance evaluation, AI ecosystem security), Managed Security (forensics, CISO as a Service, system hardening), and Cyber Intelligence (social engineering testing, brand monitoring). The company also operates ISecAuditors Academy, a training platform providing official certification courses in partnership with ISC2, BSI, OffSec, ISACA, and PCI SSC.
Differentiator
Problem solved
Functional benefit
Brands
- ISecAuditors Academy: The company's training and certification academy platform offering courses in cybersecurity certifications (ISC2, BSI, OffSec, ISACA, PCI SSC).
Products and services
- Penetration Testing Comprehensive penetration testing services to evaluate security vulnerabilities in systems and applications through simulated cyber attacks, for organizations seeking third-party security validation.
- Red Team Exercises Red Team exercises that simulate real adversarial attacks to evaluate organizational defenses and provide intelligence for corporate or governmental security departments.
- Cloud Penetration Testing Penetration testing services specifically designed for cloud environments to identify vulnerabilities in cloud infrastructure, configurations, and deployments.
- Internal Penetration Testing Internal network and system penetration testing to assess security from an insider threat perspective.
- WiFi Penetration Testing Wireless network security assessment to identify vulnerabilities in WiFi infrastructure and configurations.
- ASV Scans (External Vulnerability Scans) Approved Scanning Vendor quarterly external vulnerability scans as required by PCI DSS compliance for organizations needing certified vulnerability scanning.
- Web Application Auditing Security auditing of web applications to identify vulnerabilities including those listed in OWASP Top 10.
- API Auditing Security assessment of APIs to identify vulnerabilities in API endpoints, authentication, and data handling.
- Mobile Application Auditing Security testing for mobile applications on iOS and Android platforms.
- Source Code Auditing Static code analysis and security review of source code to identify vulnerabilities before deployment.
- ATM Auditing Security assessment of automated teller machines and self-service banking terminals.
- Early Vulnerability Alert Proactive notification service for new vulnerabilities and security threats for organizations needing early warning of relevant exploits.
- PCI DSS Adaptation and Certification Consulting and auditing services for PCI DSS compliance, including gap analysis, implementation, and QSA certification support.
- PCI PIN Adaptation and Certification Consulting services for PCI PIN compliance including key management and HSM validation.
- PCI SSF Adaptation and Certification Services for PCI Secure Software Standard certification for secure software development.
- PCI 3DS Auditing Security assessment and certification services for 3-D Secure payment environments.
- ISO 27001 ISMS Implementation Information Security Management System implementation and certification consulting.
- ISO 27001 Internal Auditing Internal audit services for organizations with ISO 27001 certification.
- ENS Implementation Implementation support for Spain's National Security Scheme (Esquema Nacional de Seguridad).
- NIS2 Implementation Consulting for EU NIS2 Directive compliance for essential and important entities.
- DORA Implementation Digital Operational Resilience Act compliance consulting for financial entities.
- CRA Compliance Evaluation and Support Assessment and support services for Cyber Resilience Act compliance.
- GDPR Implementation General Data Protection Regulation compliance consulting and data protection officer services.
- NIST CSF Implementation NIST Cybersecurity Framework 2.0 implementation and adaptation consulting.
- SWIFT Internal Auditing Internal audit services for SWIFT network compliance.
- Technical Security Auditing Comprehensive technical security assessments and audits.
- Security Consulting General cybersecurity consulting services.
- ISO 42001 SGIA Implementation Implementation of AI Management System (Sistemas de Gestión de Inteligencia Artificial) according to ISO 42001 standard for organizations adopting AI governance frameworks.
- AI Usage Compliance Evaluation and Support Assessment and support for AI usage compliance with regulations including AI Act and GDPR for organizations deploying AI.
- Comprehensive Security Auditing for AI Ecosystems Full security assessment services for AI systems and ecosystems for organizations with AI deployments needing technical security validation.
- Computer Forensics and Expert Witness Digital forensics investigation and expert witness services for legal proceedings.
- CISO as a Service (CISOaaS) Virtual CISO services providing expert cybersecurity leadership and team support for organizations needing senior security leadership without a full-time hire.
- System Hardening Systems security hardening and configuration services.
- Social Engineering Testing Assessment of organizational susceptibility to social engineering attacks.
- Digital Brand Monitoring Real-time monitoring of digital media and social networks for brand protection.
- Cyber Intelligence Threat intelligence services using proprietary tools for analysis and information gathering.
- Professional Services General professional cybersecurity services covering ad-hoc engagements for clients needing tailored security support.
- ISecAuditors Academy Cybersecurity training platform offering official certifications from ISC2 (CISSP, CSSLP, CCSP, CC), BSI (ISO 27001, ISO 22301, ISO 42001), OffSec (OSCP, OSDA, OWSP, OSWE), ISACA (CISA, CISM, CRISC, CGEIT), and PCI SSC (PCIP, PCI ISA), as well as proprietary courses on secure development, OSINT, PCI DSS, PCI PIN, and regulatory compliance.
Quantifiable outcome
- 98.5% recurring client retention rate demonstrating high customer satisfaction
- +2 more outcomes
Companies that use Internet Security Auditors
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles5 records
Internet Security Auditors technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Internet Security Auditors partnerships and signals
Strategic signalPartnerships
Five partnerships are on record, tiered core.
- (ISC)²coreOfficial training provider partnership for (ISC)² certifications including CISSP, CSSLP, CCSP, and CC. Provides access to official certification programs and course materials for cybersecurity professionals seeking these globally recognized credentials.
- BSIcoreOfficial training provider for BSI certifications including ISO 27001, ISO 22301, and ISO 42001. Enables delivery of official courses for information security, business continuity, and AI management system certifications.
- OffSeccoreOfficial training provider for OffSec certifications including OSCP, OSDA, OWSP, and OSWE. Provides access to advanced penetration testing and secure development certification programs.
- ISACA ColombiacoreOfficial training partnership in Colombia for ISACA certifications including CISA, CISM, CRISC, and CGEIT. Enables delivery of IT audit and governance certification programs.
- PCI Security Standards CouncilcoreOfficial training provider for PCI SSC certifications including PCIP, PCI ISA. The company also holds QSA (Qualified Security Assessor) and QPA (Qualified PIN Assessor) certifications for payment card industry compliance assessments.
Scale indicators6 records
Recent moves7 records
Expansion highlights5 records
Internet Security Auditors competitors and assessment
Company assessmentBroad incumbents
- Telefónica Tech: Telefónica Tech is the cybersecurity and cloud arm of Spanish telecom giant Telefónica, offering managed security, compliance and consulting services — a domestic Spanish incumbent competitor to ISecAuditors with much greater scale.
- Trustwave: Trustwave is a global cybersecurity firm and one of the largest PCI QSA providers worldwide, offering penetration testing, compliance consulting and managed security services — directly comparable service catalogue to ISecAuditors but at global scale.
- Optiv Security: Optiv is a large US cybersecurity solutions integrator delivering advisory, implementation and managed services including compliance and risk — broader portfolio than ISecAuditors but competes for the same enterprise compliance wallets.
- A2SECURE (now part of Eviden/Atos): A2Secure was a Barcelona-based GRC and PCI compliance specialist that was acquired by Atos/Eviden — illustrates the Iberian GRC exit path ISecAuditors could take, while Atos/Eviden's broader portfolio now competes head-to-head for European PCI compliance engagements.
- NCC Group: NCC Group is a UK-listed cybersecurity consultancy with global delivery of penetration testing, PCI QSA assessments, ISO 27001 consulting, and managed detection — competes with ISecAuditors on the same enterprise services, particularly PCI compliance in Europe.
Direct peers
- IOActive: IOActive is a pure-play cybersecurity consultancy specializing in penetration testing, hardware/IoT security audits, and security research — comparable to ISecAuditors' offensive security and red team practice, though US-headquartered.
- Mnemonic AS: Mnemonic is a Norwegian-headquartered European cybersecurity consultancy offering managed detection, penetration testing and compliance advisory — directly comparable boutique competitor serving enterprise customers in Europe.
- Kudelski Security: Kudelski Security is a Switzerland-based cybersecurity consultancy providing penetration testing, managed security, and compliance advisory to European enterprises — comparable boutique competitor in the same PCI/ISO compliance niche.
- S21sec: S21sec is a Spanish-headquartered cybersecurity firm offering penetration testing, managed security, threat intelligence, and compliance services across Europe and Latin America — the closest Iberian peer to ISecAuditors with overlapping PCI and ISO 27001 consulting practices.
- Schellman & Co: Schellman is a US-based professional services firm delivering penetration testing, PCI DSS QSA audits, ISO 27001 certification and SOC 2 — directly overlaps ISecAuditors' compliance audit core but operates from the US with a tech-startup customer base.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks6 records
Key highlights7 records
Customer concentration
Internet Security Auditors social profiles
Digital presenceInternet Security Auditors compliance and trust
Trust signalCompliance6 records
Internet Security Auditors financial estimates
Financial estimateRevenue estimate
Valuation estimate
Internet Security Auditors leadership team
Management profileNumber of profiles
Profiles4 records
Internet Security Auditors funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Internet Security Auditors M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Internet Security Auditors
What does Internet Security Auditors do?
Internet Security Auditors is a professional cybersecurity services firm that delivers auditing (penetration testing, red team exercises, vulnerability assessments across web, API, mobile, cloud, WiFi, ATM, and source code), compliance consulting (PCI DSS/PCI PIN/PCI SSF/PCI 3DS/ISO 27001/NIS2/DORA/GDPR/NIST CSF/SWIFT/ENS/CRA/LSSICE), AI security (ISO 42001 implementation and AI compliance evaluation), managed security (forensics, CISO as a Service, system hardening), and cyberintelligence (social engineering testing, digital brand surveillance). The firm also operates the ISecAuditors Academy training platform providing official certification courses from (ISC)2, BSI, OffSec, ISACA, and PCI SSC.
Is Internet Security Auditors a public or private company?
Internet Security Auditors is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Internet Security Auditors founded?
Internet Security Auditors was founded in 2001. It employs 11 to 50 people.
Where is Internet Security Auditors based?
Internet Security Auditors is headquartered in Barcelona, Spain, in the Europe region.
How does Internet Security Auditors make money?
Six revenue lines are on record. Professional Cybersecurity Auditing Services are the primary driver. The others are compliance Consulting Services, AI Security Services, managed Security Services, cyberintelligence Services and training and Certification Programs.
Who are Internet Security Auditors's main competitors?
Broad incumbents on record are Telefónica Tech, Trustwave, Optiv Security, A2SECURE (now part of Eviden/Atos) and NCC Group. Direct peers are IOActive, Mnemonic AS, Kudelski Security, S21sec and Schellman & Co.
Does Internet Security Auditors have an API?
No public API is recorded for Internet Security Auditors.
What industry is Internet Security Auditors in?
Internet Security Auditors's product category is Cybersecurity Professional Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX). Its NAICS code is 5416 and its SIC code is 8700.