{"id":6399,"date":"2021-03-10T09:49:53","date_gmt":"2021-03-10T08:49:53","guid":{"rendered":"https:\/\/edorteam.com\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/"},"modified":"2026-05-04T17:33:52","modified_gmt":"2026-05-04T15:33:52","slug":"cybersecurity-and-rd-43-2021-ciso-advisory-plan","status":"publish","type":"page","link":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/","title":{"rendered":"Cybersecurity and RD 43\/2021 &#8211; CISO Advisory Plan"},"content":{"rendered":"<div class=\"et_pb_section_0 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_0 et_pb_row et_pb_equal_columns et_block_row\"><div class=\"et_pb_column_0 et_pb_column et_pb_column_1_2 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_0 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>IT security and RD 43\/2021, how does it impact essential companies?<\/h2>\n<\/div><\/div><div class=\"et_pb_text_1 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><p>We help you reinforce and update your company in IT security matters with the CISO Advisor service. RD 43\/2021 marked a turning point <strong>for essential service companies<\/strong>. We explain its cybersecurity obligations and how to address them.<\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_0_wrapper\"><a class=\"et_pb_button_0 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"#obligaciones\">Companies obligated by RD 43\/2021<\/a><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_1_wrapper\"><a class=\"et_pb_button_1 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"#ciso\" data-icon=\"$\">How we help you at Edorteam<\/a><\/div><\/div><div class=\"et_pb_column_1 et_pb_column et_pb_column_1_2 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_0 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/plan-ciso-asesor-empresas-responsable-seguridad-informacion.png\" width=\"603\" height=\"1000\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/\/plan-ciso-asesor-empresas-responsable-seguridad-informacion.png 603w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/\/plan-ciso-asesor-empresas-responsable-seguridad-informacion-600x995.png 600w\" sizes=\"(max-width: 603px) 100vw, 603px\" class=\"wp-image-4645\" title=\"plan-ciso-advisor-companies-responsible-security-information\" alt=\"Cybersecurity and RD 43\/2021 &#8211; CISO Advisory Plan\" \/><\/span><\/div><\/div><\/div><\/div><div class=\"et_pb_section_1 et_pb_section et_section_regular et_block_section et_animated\"><div class=\"et_pb_row_1 et_pb_row et_pb_row_3-4_1-4 et_block_row et_block_row_3-4_1-4\"><div class=\"et_pb_column_2 et_pb_column et_pb_column_3_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_2 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>What is Royal Decree 43\/2021?<\/h2>\n<p>It is a Royal Decree approved on January 27, 2021, by which Royal Decree-Law 12\/2018, of September 7, on security of networks and information systems is developed.<\/p>\n<p>This Royal Decree wants to end the insufficient cybersecurity policies that many companies still present today, such as obsolete operating systems, unlicensed software and an absolute lack of access control and activity monitoring.<\/p>\n<p>This, added to the exponential growth of cyberattacks that have been taking place during the last year, motivated by the pandemic situation and the rise of teleworking, have led to the entry into force of this regulation and the adjusted time limits to apply it.<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_3 et_pb_column et_pb_column_1_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_3 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>It is considered that essential services companies such as energy, health, waste management or food, should reduce to the maximum their risks of suffering a cyber incident that paralyzes their work activity, hence the new law.<\/h3>\n<\/div><\/div><div class=\"et_pb_divider_0 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_2 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_2 et_pb_row et_block_row\"><div class=\"et_pb_column_4 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_4 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2 id=\"obligaciones\">What companies are required to comply with RD 43\/2021?<\/h2>\n<p>In accordance with the provisions of article 2 of RD 43\/2021, obligated organizations are divided into two large groups:<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_3 et_pb_row et_pb_row_3-5_1-5_1-5 et_block_row et_block_row_3-5_1-5_1-5\"><div class=\"et_pb_column_5 et_pb_column et_pb_column_3_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_5 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>Essential Service Operators<\/h4>\n<p>Companies that belong to sectors known as<strong> Critical Infrastructure<\/strong> by Directive (EU) 2016\/1148 of the European Parliament and of the Council, of July 6, 2016 (known as the NIS Directive).<\/p>\n<p>The Critical Infrastructure sectors provide the services necessary for the maintenance of the<strong> basic social functions<\/strong> : health, safety, social and economic well-being of citizens, or effective operation of State institutions and Public Administrations.<\/p>\n<p>In Law 8\/2011, of April 28, which establishes measures for the protection of critical infrastructures, these sectors of activity are established:<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_6 et_pb_column et_pb_column_1_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_0 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Administration<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_1 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Water<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_2 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Feeding<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_3 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Energy<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_4 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Outer space<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_5 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Nuclear Industry<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_6 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Chemical industry<\/h4><\/div><\/div><\/div><\/div><div class=\"et_pb_column_7 et_pb_column et_pb_column_1_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_7 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Research Industry<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_8 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Health<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_9 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Financial and Tax System<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_10 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Information and Communication Technologies (ICT)<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_11 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Transport<\/h4><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_row_4 et_pb_row et_block_row\"><div class=\"et_pb_column_8 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_divider_1 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><div class=\"et_pb_row_5 et_pb_row et_block_row\"><div class=\"et_pb_column_9 et_pb_column et_pb_column_3_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_6 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>Digital Service Providers<\/h4>\n<p>Within this second group, small or micro-enterprises (less than 50 workers or less than 10 million euros in annual turnover) are exempt.<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_10 et_pb_column et_pb_column_2_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_12 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Online markets<\/h4><div class=\"et_pb_blurb_description\"><p>Platforms for the sale of products and \/ or services of third parties.<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_13 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Online search engines<\/h4><\/div><\/div><\/div><div class=\"et_pb_blurb_14 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Cloud services<\/h4><\/div><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_3 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_6 et_pb_row et_block_row\"><div class=\"et_pb_column_11 et_pb_column et_pb_column_2_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_7 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2>What are the obligations of RD 43\/2021?<\/h2>\n<\/div><\/div><div class=\"et_pb_text_8 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>Appoint the Information Security Manager or CISO<em> (Chief Information Security Officer)<\/em><\/h4>\n<p>This figure can be a person, entity or collegiate body, and will be appointed before the corresponding Ministry (according to the sector of the company) at most the<strong> April 27, 2021<\/strong> . The professional figure of the CISO has several responsibilities within the company and therefore should be a profile with high capacities,<a href=\"https:\/\/nova.edorteam.com\/en\/what-are-the-functions-of-the-information-security-officer-or-ciso\/\"> Here we explain how the CISO of your company should be<\/a> .<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_12 et_pb_column et_pb_column_1_3 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_1 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/seguridad-informatica-empresas-real-decreto-43-2021.jpg\" width=\"626\" height=\"402\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/seguridad-informatica-empresas-real-decreto-43-2021.jpg 626w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/seguridad-informatica-empresas-real-decreto-43-2021-600x385.jpg 600w\" sizes=\"(max-width: 626px) 100vw, 626px\" class=\"wp-image-4639\" title=\"computer security-companies-royal-decree-43-2021\" alt=\"Royal Decree 43\/2021 obligations in cybersecurity\" \/><\/span><\/div><div class=\"et_pb_text_9 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>A CISO acts as a point of contact with the competent authority and supervises that the company complies with the established cybersecurity requirements.<\/h4>\n<\/div><\/div><div class=\"et_pb_divider_2 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><div class=\"et_pb_row_7 et_pb_row et_pb_equal_columns et_block_row\"><div class=\"et_pb_column_13 et_pb_column et_pb_column_1_2 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_10 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>Prepare the Statement of Applicability<\/h4>\n<p>In accordance with the provisions of article 6 of RD 43\/2021, the CISO must prepare a document called Declaration of Applicability of the<strong> security measures<\/strong> of the company. Broadly speaking, it should include:<\/p>\n<ul>\n<li>Analysis of<strong> Actual state<\/strong> cybersecurity of the company in order to identify gaps and risks.<\/li>\n<li>Reflect the<strong> deficiencies<\/strong> detected and how they are intended to be solved.<\/li>\n<li>Develop a monitoring plan to<strong> check<\/strong> that these deficiencies are eventually corrected.<\/li>\n<li>Set up<strong> plans<\/strong> for the detection, management, recovery and assurance of the continuity of operations in the event of a cyber-incident.<\/li>\n<\/ul>\n<\/div><\/div><\/div><div class=\"et_pb_column_14 et_pb_column et_pb_column_1_2 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_11 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h4>Sign and submit the Declaration of Applicability<\/h4>\n<p>The Statement of Applicability must be signed by the CISO and approved by the company. Finally, it will be presented to the competent authority no later than the<strong> July 27, 2021<\/strong> .<\/p>\n<p>In addition, the Statement of Applicability will be<strong> reviewable at least every 3 years<\/strong> .<\/p>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_4 et_pb_section et_section_regular et_block_section\"><div class=\"et_pb_row_8 et_pb_row et_block_row\"><div class=\"et_pb_column_15 et_pb_column et_pb_column_4_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_12 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h2 id=\"ciso\">Edorteam, a valuable support for your CISO<\/h2>\n<p>With our CISO Advisory Plan, we accompany your company in its adaptation to RD 43\/2021. The figure of the CISO requires high capacities and carries important responsibilities. Trust Edorteam to<strong> guide and accompany<\/strong> to your company's CISO:<\/p>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_row_9 et_pb_row et_block_row\"><div class=\"et_pb_column_16 et_pb_column et_pb_column_3_5 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_15 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">U<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Situation analysis<\/h4><div class=\"et_pb_blurb_description\"><ul>\n<li>We analyze the current state of the company's cybersecurity.<\/li>\n<li>We identify possible risks and threats.<\/li>\n<li>We advise the management to appoint the CISO of the company.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_16 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">\ue0f5<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Definition of objectives<\/h4><div class=\"et_pb_blurb_description\"><ul>\n<li>We work hand in hand with the CISO in the development of a Cybersecurity Plan for the company.<\/li>\n<li>We define the strategic objectives to be achieved in terms of cybersecurity and how to solve them.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_17 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">\ue038<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Improvement actions<\/h4><div class=\"et_pb_blurb_description\"><ul>\n<li>If you need software solutions to improve the cybersecurity of the company, we take care of their implementation on all computer equipment.<\/li>\n<li>We train your professionals in its use, promoting good practices in cybersecurity.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><div class=\"et_pb_blurb_18 et_pb_blurb et_pb_bg_layout_light et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">\ue02d<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h4 class=\"et_pb_module_header\">Support and follow-up<\/h4><div class=\"et_pb_blurb_description\"><ul>\n<li>We advise your CISO in the presentation of the Declaration of Applicability.<\/li>\n<li>We monitor the effectiveness of the measures applied.<\/li>\n<li>We will maintain direct contact to resolve technical or digital security incidents.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_17 et_pb_column et_pb_column_2_5 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_image_2 et_pb_image et_animated et_pb_module et_block_module\"><span class=\"et_pb_image_wrap\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/ciso-rd-43-2021-ciberseguridad.jpg\" width=\"1000\" height=\"750\" srcset=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/ciso-rd-43-2021-ciberseguridad.jpg 1000w, https:\/\/nova.edorteam.com\/wp-content\/uploads\/ciso-rd-43-2021-ciberseguridad-600x450.jpg 600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\" class=\"wp-image-4638\" title=\"ciso-rd-43-2021-cybersecurity\" alt=\"CISO Advisory Service for companies and RD 43\/2021\" \/><\/span><\/div><div class=\"et_pb_text_13 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>At Edorteam you have both a legal department and an IT department specialized in cybersecurity solutions.<\/h3>\n<\/div><\/div><div class=\"et_pb_divider_3 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><div class=\"et_pb_text_14 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>The service is comprehensive: we not only identify the improvements to be made, we also take care of their implementation in the company.<\/h3>\n<\/div><\/div><div class=\"et_pb_divider_4 et_pb_divider et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_section_5 et_pb_section et_section_regular et_block_section et_animated\"><div class=\"et_pb_row_10 et_pb_row et_pb_equal_columns et_block_row\"><div class=\"et_pb_column_18 et_pb_column et_pb_column_2_3 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_15 et_pb_text et_pb_bg_layout_dark et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><p id=\"kitconsulting\">We speak your language<\/p>\n<h2>\ud83d\udca1 Update your business's IT security<\/h2>\n<\/div><\/div><div class=\"et_pb_text_16 et_pb_text et_pb_bg_layout_dark et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><p>At Edorteam, we understand that adapting to <strong>cybersecurity regulations such as RD 43\/2021 can seem complex,<\/strong> full of technical requirements and complicated concepts. That's why we strive to explain everything in a simple and direct way, ensuring that you understand every step we take to protect your company.<\/p>\n<p data-start=\"1572\" data-end=\"1780\">With over 30 years of experience protecting companies, we are <strong>specialists in cybersecurity and regulatory compliance.<\/strong> Our team advises you so that your company complies with regulations without complications.<\/p>\n<\/div><\/div><\/div><div class=\"et_pb_column_19 et_pb_column et_pb_column_1_3 et-last-child et_block_column et_pb_column_empty et_pb_css_mix_blend_mode_passthrough\"><\/div><\/div><div class=\"et_pb_row_11 et_pb_row et_pb_equal_columns et_block_row\"><div class=\"et_pb_column_20 et_pb_column et_pb_column_1_2 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_blurb_19 et_pb_blurb et_pb_bg_layout_dark et_pb_blurb_position_left et_pb_module et_block_module\"><div class=\"et_pb_blurb_content\"><div class=\"et_pb_main_blurb_image\"><span class=\"et_pb_image_wrap\"><span class=\"et-pb-icon et_animated et_animated\">N<\/span><\/span><\/div><div class=\"et_pb_blurb_container\"><h3 class=\"et_pb_module_header\">IT security services for companies<\/h3><div class=\"et_pb_blurb_description\"><ul>\n<li>Audit and risk analysis.<\/li>\n<li>Implementation of security measures.<\/li>\n<li>Cybersecurity training for employees.<\/li>\n<li>Cyber incident management and notification.<\/li>\n<li>Preparation for ISO 27001 and ENS certifications.<\/li>\n<\/ul>\n<\/div><\/div><\/div><\/div><\/div><div class=\"et_pb_column_21 et_pb_column et_pb_column_1_2 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_2_wrapper\"><a class=\"et_pb_button_2 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"#contacto\" data-icon=\"$\">Contact our experts now<\/a><\/div><\/div><\/div><\/div><div class=\"et_pb_section_6 et_pb_section et_section_regular et_block_section et_animated\"><div class=\"et_pb_row_12 et_pb_row et_pb_row_4col et_pb_equal_columns et_pb_gutters1 et_block_row et_block_row_4col\"><div class=\"et_pb_column_22 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_17 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>The keys of RD 43\/2021 in e-book format<\/h3>\n<p>All about Royal Decree 43\/2021 on security of networks and information systems.<\/p>\n<p><strong>Download this e-book<\/strong> and find out which measures you should apply and if you are an obliged company.<\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_3_wrapper\"><a class=\"et_pb_button_3 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"\/wp-content\/uploads\/EDORTEAM-ciberseguridad-2021.pdf\" target=\"_blank\">Download e-book<\/a><\/div><\/div><div class=\"et_pb_column_23 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough et_clickable\"><div class=\"et_pb_divider_5 et_pb_divider_hidden et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><div class=\"et_pb_column_24 et_pb_column et_pb_column_1_4 et_block_column et_pb_css_mix_blend_mode_passthrough\"><div class=\"et_pb_text_18 et_pb_text et_pb_bg_layout_light et_pb_module et_block_module\"><div class=\"et_pb_text_inner\"><h3>What are the functions of the CISO?<\/h3>\n<p>Visit our blog to learn more about<strong> what kind of professional profile<\/strong> can perform the functions of the CISO.<\/p>\n<p>Can it be someone outside the company? Is it a temporary figure? Discover it here.<\/p>\n<\/div><\/div><div class=\"et_pb_module et_pb_button_module_wrapper et_pb_button_4_wrapper\"><a class=\"et_pb_button_4 et_pb_button et_pb_bg_layout_dark et_pb_module et_block_module\" href=\"https:\/\/nova.edorteam.com\/funciones-responsable-seguridad-de-la-informacion-ciso\/\">Read more<\/a><\/div><\/div><div class=\"et_pb_column_25 et_pb_column et_pb_column_1_4 et-last-child et_block_column et_pb_css_mix_blend_mode_passthrough et_clickable\"><div class=\"et_pb_divider_6 et_pb_divider_hidden et_pb_space et_pb_divider_position_top et_pb_module\"><div class=\"et_pb_divider_internal\"><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-6399","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cybersecurity and RD 43\/2021 - CISO Advisory Plan - Edorteam<\/title>\n<meta name=\"description\" content=\"We explain the obligations of RD 43\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.\" \/>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity and RD 43\/2021 - CISO Advisory Plan - Edorteam\" \/>\n<meta property=\"og:description\" content=\"We explain the obligations of RD 43\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/\" \/>\n<meta property=\"og:site_name\" content=\"Edorteam\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/edorteam\/\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-04T15:33:52+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cumplimiento-legal-empresas-abogado.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"598\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@edorteam\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\\\/\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\\\/\",\"name\":\"Cybersecurity and RD 43\\\/2021 - CISO Advisory Plan - Edorteam\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#website\"},\"datePublished\":\"2021-03-10T08:49:53+00:00\",\"dateModified\":\"2026-05-04T15:33:52+00:00\",\"description\":\"We explain the obligations of RD 43\\\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity and RD 43\\\/2021 &#8211; CISO Advisory Plan\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\",\"name\":\"Consultor\u00eda Compliance y protecci\u00f3n de datos\",\"description\":\"Empresa de Ciberseguridad y Protecci\u00f3n de Datos\",\"publisher\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#organization\"},\"alternateName\":\"Edorteam\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#organization\",\"name\":\"Edorteam | Cibersecurity services and data protection company\",\"alternateName\":\"Edorteam\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/cropped-favicon.png\",\"contentUrl\":\"https:\\\/\\\/nova.edorteam.com\\\/wp-content\\\/uploads\\\/cropped-favicon.png\",\"width\":512,\"height\":512,\"caption\":\"Edorteam | Cibersecurity services and data protection company\"},\"image\":{\"@id\":\"https:\\\/\\\/nova.edorteam.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/edorteam\\\/\",\"https:\\\/\\\/x.com\\\/edorteam\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/edorteam\\\/\",\"https:\\\/\\\/www.instagram.com\\\/edorteam\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybersecurity and RD 43\/2021 - CISO Advisory Plan - Edorteam","description":"We explain the obligations of RD 43\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Cybersecurity and RD 43\/2021 - CISO Advisory Plan - Edorteam","og_description":"We explain the obligations of RD 43\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.","og_url":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/","og_site_name":"Edorteam","article_publisher":"https:\/\/www.facebook.com\/edorteam\/","article_modified_time":"2026-05-04T15:33:52+00:00","og_image":[{"width":1000,"height":598,"url":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cumplimiento-legal-empresas-abogado.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@edorteam","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/","url":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/","name":"Cybersecurity and RD 43\/2021 - CISO Advisory Plan - Edorteam","isPartOf":{"@id":"https:\/\/nova.edorteam.com\/en\/#website"},"datePublished":"2021-03-10T08:49:53+00:00","dateModified":"2026-05-04T15:33:52+00:00","description":"We explain the obligations of RD 43\/2021 and which are the affected companies, a milestone for cybersecurity and company CISOs.","breadcrumb":{"@id":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/nova.edorteam.com\/en\/cybersecurity-and-rd-43-2021-ciso-advisory-plan\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/nova.edorteam.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity and RD 43\/2021 &#8211; CISO Advisory Plan"}]},{"@type":"WebSite","@id":"https:\/\/nova.edorteam.com\/en\/#website","url":"https:\/\/nova.edorteam.com\/en\/","name":"Consultor\u00eda Compliance y protecci\u00f3n de datos","description":"Empresa de Ciberseguridad y Protecci\u00f3n de Datos","publisher":{"@id":"https:\/\/nova.edorteam.com\/en\/#organization"},"alternateName":"Edorteam","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nova.edorteam.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/nova.edorteam.com\/en\/#organization","name":"Edorteam | Cibersecurity services and data protection company","alternateName":"Edorteam","url":"https:\/\/nova.edorteam.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/nova.edorteam.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cropped-favicon.png","contentUrl":"https:\/\/nova.edorteam.com\/wp-content\/uploads\/cropped-favicon.png","width":512,"height":512,"caption":"Edorteam | Cibersecurity services and data protection company"},"image":{"@id":"https:\/\/nova.edorteam.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/edorteam\/","https:\/\/x.com\/edorteam","https:\/\/www.linkedin.com\/company\/edorteam\/","https:\/\/www.instagram.com\/edorteam\/"]}]}},"_links":{"self":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/comments?post=6399"}],"version-history":[{"count":5,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6399\/revisions"}],"predecessor-version":[{"id":20463,"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/pages\/6399\/revisions\/20463"}],"wp:attachment":[{"href":"https:\/\/nova.edorteam.com\/en\/wp-json\/wp\/v2\/media?parent=6399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}