End-to-end cybersecurity platform

Everything connected to your network. Seen and watched, 24/7.

Scud discovers every device on your network, across all your sites, detects its vulnerabilities and a team of analysts watches it around the clock as an extension of your security team. Built for large enterprises and public administrations; it also scales down to smaller organisations.

SCUD SENSOR · NETWORK MAP

13 DEVICES 2 EXPOSED CONTINUOUS SCAN 24/7

In plain words

Your building already has an alarm.
This is the alarm for your network.

SCUD SENSOR

The detectors

Like the motion detectors in your warehouse: a device that sees everything connected to your network. Including what nobody remembered was there.

SCUD SMART PLATFORM

The control room that analyses

Like the control room that receives the signals: it tells a false alarm from a real intruder, and only raises the alert when it truly matters.

SCUD MONITOR

The guards who respond

Like the guards at the monitoring centre: expert people, awake 24/7, who investigate every alert and act on your behalf.

The difference: this alarm also finds the open doors you didn’t know you had, and closes them before anyone gets in.

The problem

“It won’t happen to us.”
It happens every year to companies in every sector and public administrations.

What people tend to think: We have a firewall, EDR and an IT department.

What actually happens: They protect the perimeter and the machines they are installed on. They cannot see the cameras, POS terminals, printers, PLCs or machinery on the same network. And on a network of thousands of devices, what is not inventoried is not defended.

What people tend to think: Our team already watches the network.

What actually happens: Your team has projects, office hours and a volume of alerts nobody can review by hand. Attacks are automated, scan at any hour and move laterally in minutes. Someone needs to be awake at 3 a.m. who can tell the noise from the intruder.

What people tend to think: If something happens, we’ll fix it.

What actually happens: Ransomware stops production, invoicing and email for days, at every site at once. And the liability is no longer just technical: NIS2 directly binds large companies in 18 sectors, the ENS binds anyone working with Spain’s public sector, and both hold management accountable.

cybersecurity incidents in Spain, one every four minutes. While you read this, someone is trying a door.
330 / day
cybersecurity incidents in Spain, one every four minutes. While you read this, someone is trying a door.
SOURCE: INCIBE · 2025 REPORT
is all you get to report a serious incident. If you find out a week later, the deadline has already passed.
24 h
is all you get to report a serious incident. If you find out a week later, the deadline has already passed.
SOURCE: NIS2 DIRECTIVE
in maximum fines, and management is personally accountable. Cybersecurity is no longer an IT matter: it is a board matter.
€10M
in maximum fines, and management is personally accountable. Cybersecurity is no longer an IT matter: it is a board matter.
SOURCE: NIS2 DIRECTIVE

How it works

Three parts. One system that never blinks.

01 Scud Sensor

The Sensor connects to your network and maps it

A physical device, built by Scud, discovers everything that is connected: servers, IP cameras, printers, IoT, SCADA. Including what nobody remembered.

IN-HOUSE HARDWARE · ASSET DISCOVERY

02 Scud Smart Platform

The Smart Platform detects and prioritises threats

It compares your network traffic against known threats in real time, identifies vulnerabilities and ranks them by risk: first, whatever could bring your business to a halt.

MDR · REAL-TIME ANALYSIS

03 Scud Monitor

Our analysts watch and respond

People, not just alerts: an in-house SOC that investigates every warning, calls you when it matters and acts as an extension of your IT department.

IN-HOUSE SOC · CONTINUOUS MONITORING

The device that discovers what is really connected to your network.

A proactive cybersecurity tool that does more than identify vulnerabilities: it discovers every asset and the complete topology of your network: servers, IP cameras, printers, IoT, SCADA, fingerprint readers. Including the forgotten ones. The complete picture of your network’s security posture.

Specifications

Type
Physical network discovery and analysis device
Manufacturing
In-house software, developed in Europe
Installation
Without disrupting your operations
Coverage
IT, OT and IoT: from servers to industrial PLCs
Form factor
Compact appliance based on Linux and open-source software: plug it into a network port and it starts listening. Also available as a virtual machine for cloud environments
Traffic
Analyses all local network traffic in real time, passively: it never alters or slows down your communications

Capabilities

  • Discovers every connected asset and draws the real topology of your network.
  • Detects known vulnerabilities (CVE) on each device, including where no antivirus can be installed.
  • Identifies outdated firmware, default passwords and exposed services.
  • Finds forgotten devices: cameras, printers, fingerprint readers, SCADA equipment.
  • Feeds the Smart Platform with a live inventory of your network.

Capabilities and services

Everything that works while you’re not looking.

Know your network

Know what is connected, where, and in what state.

  • ASSET DISCOVERY
  • INTERNET OF FORGOTTEN THINGS
  • OT · SCADA
  • VULNERABILITY MANAGEMENT

Detect threats

See the attack as it happens, not in next month’s report.

  • NDR (NETWORK DETECTION AND RESPONSE)
  • XDR (EXTENDED DETECTION AND RESPONSE)
  • SIEM (SECURITY INFORMATION AND EVENT MANAGEMENT) · WAZUH
  • HONEYPOTS

Stay ahead of the attack

Find the open door before someone else uses it.

  • PENTEST 24/7
  • OSINT
  • DATA LOSS PREVENTION
  • POST-QUANTUM

Respond and sustain

People and infrastructure behind every alert, every day of the year.

  • IN-HOUSE SOC 24/7
  • CERS
  • ENS HIGH-LEVEL DATA CENTRE
  • CARRIER CONNECTION

Know what is connected, where, and in what state.

You can’t protect what you don’t know exists. These capabilities build the real inventory of your network, including industrial equipment and the devices nobody remembers, and rank their weaknesses by risk.

  • ASSET DISCOVERY Live inventory of devices, users and software connected to your network.
  • INTERNET OF FORGOTTEN THINGS Finds the old, forgotten devices nobody remembers connecting.
  • OT · SCADA Supervision of industrial devices according to MITRE ATT&CK® for ICS.
  • VULNERABILITY MANAGEMENT Continuous, risk-prioritised scanning with a concrete action plan.

Compliance

Comply, and prove it with continuous reports.

Regulation no longer asks for an annual snapshot: it asks for evidence that you watch your network. Scud generates continuous reports on vulnerabilities, devices and incident response: the documentation your auditor wants to see.

01 · NIS2 Directive (EU) 2022/2555

The European directive that turns cybersecurity into a legal obligation for 18 sectors.

NIS2 (Directive (EU) 2022/2555) significantly widens the number of companies required to meet strict cybersecurity requirements: energy, transport, health, water, manufacturing, food, digital services and public administration, among others. An annual audit is no longer enough: it demands continuous risk management, fast incident reporting and direct accountability of management.

The essentials

Who it applies to
Essential and important entities in 18 critical sectors, generally medium and large companies, and their suppliers.
Timeline
In force since January 2023; national transposition due October 2024, still in progress in Spain.
What it requires
Risk-management measures, supply-chain security, business continuity, vulnerability handling and management training.
Incidents
Early warning within 24 h, notification within 72 h and a final report within one month.
Penalties
Up to €10M or 2% of worldwide turnover (essential); up to €7M or 1.4% (important).

How Scud helps

  • The Sensor builds the real inventory of your network and its vulnerabilities: the basis of any risk analysis.
  • The Smart Platform monitors traffic in real time and documents the detection and response the directive asks you to prove.
  • The 24/7 SOC detects and reports incidents within the required deadlines.
  • Continuous compliance reports, not a yearly snapshot.

Pricing

One product, everything included. It fits any organisation.

Scud is not sold in pieces: every installation includes the Sensor, the Smart Platform and 24/7 monitoring by our analysts. It is built for large organisations with several sites, and the price scales with the number of sites and the size of the network, also if your company is smaller. Pay month to month or save with annual billing. Questions? Call us on +34 933 931 232.

Sensor · Smart Platform · Monitor 24/7

Scud Managed cybersecurity

from €990 / month

from €841 / month

per site · Billed monthly · VAT not included Billed annually · VAT not included

The final price depends on how many sites and devices we watch: we prepare a tailored proposal after the assessment.

Everything included in every installation

  • In-house hardware, installed in under a day
  • Asset discovery and network topology
  • Vulnerability detection (CVE)
  • Live device inventory
  • Real-time traffic analysis (NDR)
  • Threat intelligence: 300+ sources
  • Continuous pentesting
  • NIS2 · ISO 27001 compliance reports
  • In-house SOC 24/7 with human analysts
  • Every alert investigated; we call you when it matters
  • Emergency response (CERS)

The first step, at no cost

Free assessment

Free

No obligation. No card.

We connect a Sensor, map your network and show you what we find in a clear report. It is the starting point for your proposal.

  • Asset discovery and network topology
  • Vulnerability detection (CVE)
  • A clear report of what we found

Frequently asked questions

What management and IT leads ask us, with no technical runaround.

We already have an IT and security team. What does Scud add?

Eyes on the whole network, 24 hours a day. Our analysts act as an extension of your team: they watch every segment and every site, investigate the alerts and escalate only what needs a decision. Your team decides; we keep watch, outside office hours too.

Aren’t EDR and a firewall enough?

They protect the machines they are installed on and the perimeter. They don’t cover legacy servers, printers, IP cameras, IoT devices, industrial PLCs or lateral traffic between segments. Scud watches the whole network, including the devices where nothing can be installed.

I don’t want to get hit by ransomware. How do you prevent it?

We attack before the attacker does: continuous pentesting, detection of vulnerabilities and weak passwords, and monitoring of connections to known malicious infrastructure. If something tries to get in, the analysts receive the alert instantly.

I’ve already been hit by ransomware. Can you help?

Yes. Call us on +34 933 931 232 or write to info@scudsecurity.com. We investigate how they got in, contain the incident and harden your network so it doesn’t happen again.

I have old devices connected. Are they a risk?

We have found malware in security cameras, fingerprint readers, printers and SCADA equipment. Any connected, forgotten device is a door. The Sensor discovers them all and identifies their vulnerabilities.

If one device gets infected, can it spread to the rest?

Yes: a single compromised device can spread across the whole network in minutes. That’s why Scud monitors internal traffic, detects anomalous behaviour and blocks suspicious connections before they propagate.

I’m worried about a disgruntled employee with access to critical systems.

It is one of the most underestimated threats. Scud monitors connections in real time, alerts on unusual data extraction and detects unauthorised remote access, from the inside too.

I want to pass NIS2 or get ISO 27001 certified. Will Scud help?

An audit is a one-off assessment; regulation demands sustained monitoring. Scud gives you 24/7 monitoring and the continuous reports that document your compliance, and detects problems before the auditor flags them.

We are a public administration. Do you work with the public sector?

Yes. We work for public administrations and for the companies that serve them. The Smart Platform’s infrastructure is compatible with the ENS High level, and the reports document the operational measures the scheme requires: inventory, monitoring and incident handling.

We are a small company. Is Scud for us?

Scud is built for large networks: several sites, industrial environments, thousands of devices. But it is a single system sized to each network, so it also protects smaller organisations. The free assessment tells us what you need.

Free assessment

Find out what’s connected to your network. Today.

We connect a Sensor, map your network and show you what we find: every device, every vulnerability, in a clear report. No obligation.

Basic information on data protection

A summary of what we do with the data you send us through this form. The full details are in the privacy policy.

Controller
Scud Cybersecurity S.L. (VAT B21840079), Avda. Josep Fontcuberta, 145 2.º 2.ª, 08140 Caldes de Montbui (Barcelona), Spain. info@scudsecurity.com
Purpose
To handle your free assessment request and answer any questions you send us.
Legal basis
Your consent, given when you submit the form.
Recipients
We do not share your data with third parties, except where required by law.
Retention
For as long as needed to handle your request and manage the business relationship, and afterwards for the legally required limitation periods.
Your rights
Access, rectification, erasure, objection, restriction and portability, by writing to info@scudsecurity.com.

Blog

Threats, regulation and real cases.

All articles