We protect your infrastructure, your data, and your users against attacks, human error, and disasters. We provide a documented recovery plan, immutable backups verified through actual restores, continuous monitoring, and staff training. We ensure compliance with the requirements of the LFPDPPP and the GDPR before an incident occurs—not after.

![[interface] screenshot of core features (for an AI legal tech company)](https://cdn.prod.website-files.com/6a0029a6f31182220001f475/6a318c6d5ce15fb85e88c8fe_6a318065570227777ccce860_Cybersecurity%2520by%2520Keptos.jpeg)


Reliable backups proven through actual restores—not just reports of successful backups
MFA phishing resistance and the principle of least privilege for all administrative access
RTO and RPO defined on an application-by-application basis, not as a single, operationally meaningless figure
Documented compliance with LFPDPPP and GDPR , with notification deadlines established in advance
Compliance with the requirements of your cyber risk policy: MFA, EDR , and immutable backups
The difference between being protected and believing you are protected becomes clear on the day of the incident.

Incident response plan with designated roles, a contact tree, and already identified legal notification obligations
Periodic restoration tests using real data, with a report of results and measured recovery time
Staff training through simulated phishing campaigns, with click-through rates tracked on a quarterly basis
A device being tested, not a list of installed tools.

Security failures are almost always caused by a person under pressure, not by improperly configured technology. We address both issues.
Most of the companies that were attacked had antivirus software, a firewall, and backups. What they didn't have was the certainty that all of those systems would work together on the day of the incident. Our job is to provide that certainty—and to prove it.
Before installing anything, we conduct an impact analysis: which applications would halt operations, how long they could be down, and how much data you could lose. That’s how we determine the RTO and RPO for each system. Without those values, any security plan is arbitrary: everything is protected equally, which is another way of saying nothing is protected.
No single solution can stop a modern attack. We focus on identity management with MFA and least privilege; email, since it remains the primary entry point; computers with EDR; network segmentation, so that a compromised computer does not expose the entire infrastructure; and backups as a last line of defense.
This is where most providers fall short. A “green” backup report says nothing about your ability to recover. We perform actual restores in an isolated environment, measure the time it takes to resume operations, and document the results. Backups are immutable: they cannot be deleted during their retention period—not even with administrator credentials—because modern ransomware targets backups first.
Most breaches start with a person: a well-written email, a call to the help desk, a fabricated emergency. We send out simulated phishing campaigns without warning and train those who fall for them, in their own language. We track click-through and report rates quarter by quarter. We’re not looking to assign blame; we want reporting to become second nature.
Every quarter, we conduct a drill based on a real-world scenario: ransomware, data loss, or prolonged downtime. We test our procedures, time the recovery process, and correct any failures. The response plan designates responsible parties, provides for the preservation of evidence prior to restoration, and addresses the reporting requirements of the LFPDPPP and, for European groups, the GDPR. Improvising in the midst of a crisis always comes at a high cost.
Backups, RTO, incident response, cyber risk insurance, and legal obligations in Mexico: What a management committee asks.
Comprehensive 360° service: impact analysis, DRP , automated backups, 24/7 monitoring, incident drills, and staff training. All managed by our SOC in Mexico City.
Typically 4 to 6 weeks, depending on the size of the company: 1 week of analysis, 2–3 weeks of implementation, and 1–2 weeks of drills and training.
We conduct quarterly drills based on real-world scenarios: ransomware, data loss, and DDoS attacks. We test our procedures, measure recovery times, and provide a report highlighting areas for improvement.
In most cases, no: we leverage your existing infrastructure using software tools (EDR, cloud-based SIEM). If specific hardware is required (NGFW firewall, IDS sensors), it is included in the quote.
Because we test them. A “backup successful” report only confirms that files were copied, not that you can recover them.
We conduct periodic recovery tests using real data in an isolated environment and measure the time it takes to resume operations. Each test generates a report detailing the results and any deviations detected. It’s the only honest way to answer the question that matters: How long will it take for us to get back to work?
In addition, backups are immutable: once created, they cannot be modified or deleted during the retention period, not even with administrator credentials. Modern ransomware targets backups first.
We don't provide a single figure, because not all of your applications are worth the same amount when they're down.
During the impact analysis, we define two values for each application: the RTO (how long the system can be down before the damage becomes unacceptable) and the RPO (how much data you can afford to lose). A production ERP and a historical file server do not have the same values, nor do they have the same protection costs.
These objectives are documented, tested in drills, and reviewed annually.
The response plan is activated with designated roles, not ad hoc ones: who decides to isolate a system, who informs management, who speaks with customers, and who contacts the insurer.
The first few hours follow a set sequence: containment, evidence preservation, assessment of the scope, and then restoration. Preserving the evidence before restoration is what allows you to understand what happened and respond to your insurer and the authorities.
Upon completion, we submit a post-incident report: timeline, root cause, affected data, and corrective actions.
Cyber risk insurers no longer provide coverage without conditions. Most now require MFA for remote and administrative access, EDR deployed on devices, immutable backups, and a documented response plan.
We ensure your device meets those requirements and provide you with the technical documentation the insurer requests, both when you purchase the policy and after a claim. A policy rejected due to noncompliance with a technical clause costs more than the premium.
We send simulated phishing campaigns to your staff without prior notice, followed by training for those who clicked on the links. We track the click-through rate and the reporting rate on a quarterly basis.
Our goal is not to point fingers, but to foster a culture of reporting. An employee who speaks up within two minutes is worth more than an employee who never makes a mistake.
The training is conducted in Spanish, English, or French, depending on each team's language.
The General Data Protection Regulation ( LFPDPPP ) requires the data controller to immediately notify the affected data subjects when a breach significantly impacts their economic or moral rights, so that they can take appropriate action.
If your group processes data belonging to European residents, the General Data Protection Regulation ( GDPR) also applies, with its 72-hour deadline for notifying the supervisory authority.
We prepare the decision-making framework in advance: what data is at stake, who assesses the severity, what is communicated, and to whom. Improvising this during a crisis is what turns a technical incident into a reputational and legal problem. This content is for informational purposes only and is not a substitute for advice from your legal department.
How Keptos Companies in Latin America with DRP, Continuous Monitoring, and Incident Response.
A situation we often see
A company had backups that were reported as “okay” every night. No one had ever tried to restore them. This is the most common—and most dangerous—situation: the green status report is reassuring without actually testing anything.
The standard approach: perform an actual restore test on real data in an isolated environment, measure the recovery time, and use that to document a response plan with designated roles, immutable backups, and quarterly drills.
The value isn't apparent on the day of installation, but rather on the day of an incident: when a ransomware attack or accidental data deletion occurs, the difference between a company that recovers within hours and one that negotiates a ransom was decided months earlier, during that first restore test.
Keptos our operations. Their team automated our workflows and kept us secure, all while making us feel truly supported.
With Keptos, we gained peace of mind. Their expertise in cybersecurity and AI helped us scale with confidence and focus on our customers.
Keptos more than just a provider—they're a partner. Their transparency and personalized attention make technology feel accessible and empowering.
Leave us your contact information, and a Keptos specialist will contact Keptos the same business day.
Thank you! We have received your request. We will be in touch soon.
An error occurred while submitting the form. Please try again.