Skip to content
Client access

Industry

Government

Digital citizen services, personal data and legacy systems. We help public entities protect them.

The context

More digital services for citizens, with limited resources and growing demands

The digital transformation of the Peruvian State has moved procedures, payments and records online. Public entities manage information on millions of citizens and run services that people and businesses depend on.

At the same time, many work with legacy systems, tight budgets and demanding procurement processes, while facing ransomware, data leaks and politically motivated attacks. An incident does not just interrupt a service: it damages citizens’ trust.

We help public entities understand their real exposure, comply with Peru’s digital security framework and respond in an orderly way when an incident occurs.

Key threats

The risks that matter most in the public sector

We prioritize the scenarios with the greatest impact on service continuity and citizens’ information.

Citizen data leaks

Databases with personal information exposed through application flaws, insecure configurations or improper access.

Ransomware in critical services

Server encryption that halts procedures, citizen services and internal processes for days or weeks.

Hacktivism and defacement

Politically motivated attacks that alter institutional portals or overload services to damage the entity’s image.

Legacy systems

Unsupported applications and servers still in production because replacing them depends on budget and procurement.

Phishing aimed at officials

Emails targeting those who manage systems, approve payments or handle classified information.

Impersonation of public services

Fake sites and messages that mimic public services to defraud citizens and steal their data.

Regulation and frameworks

The framework that guides digital security in the Peruvian State

Legislative Decree No. 1412

Peru’s Digital Government Law: the framework for digital transformation and digital security in public administration.

Emergency Decree No. 007-2020

Peru’s Digital Trust Framework, which strengthens digital security and incident management in the country.

NTP-ISO/IEC 27001

The Peruvian technical standard for implementing an information security management system in public entities.

Law No. 29733

Protection of the personal data public entities collect from citizens.

Law No. 30096

Peru’s Cybercrime Law, relevant for investigating and reporting incidents.

NIST CSF 2.0

An international framework useful for setting priorities and measuring cybersecurity maturity.

How we help

Services built for public entities

We assess, strengthen and support your entity with a practical approach aligned with Peruvian regulation.

Penetration Testing

Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.

Compliance & Risk Management

We prepare your organization for ISO 27001, SBS Resolution No. 504-2021, PCI DSS and Law No. 29733, with controls that work in practice.

Social Engineering & Awareness

Controlled phishing, vishing and malicious QR campaigns that measure the human factor and turn it into a line of defense.

CISO as a Service

Outsourced security leadership: strategy, roadmap and board reporting, without the cost of a full-time executive.

Red Team & Ethical Hacking

Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.

Frequently asked questions

What public entities usually ask us

Can you take part in public procurement processes?

Yes. We are registered with Peru’s National Registry of Suppliers (RNP) and have worked directly with State entities, such as the Universidad Nacional de Ingeniería (UNI).

Do you help implement an ISMS under NTP-ISO/IEC 27001?

Yes. We perform the assessment, support the implementation of the management system and prepare the entity for audits.

What should we do in a digital security incident?

Contain the threat, preserve the evidence and report it according to the current digital security framework. Our team supports the technical response and the information needed to report to the competent authorities.

Do you work with regional and local governments?

Yes. We tailor the scope to each entity’s reality, prioritizing the highest-impact actions within the available budget.

How do you protect the entity’s classified information?

We work under non-disclosure agreements, with formal authorization, information handling rules and secure deletion of data at the end of the project.

Other industries

We also protect

Mining

Remote operations, critical OT assets and extended supply chains. We protect production continuity.

Banking & Fintech

SBS and PCI DSS requirements, digital fraud and exposed APIs. We assess your risk through an attacker’s eyes.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)