Architecture · Governance · Assurance · Santiago, Chile

Security that is designed, measured and sustained.

PIMX ArcSec is an architecture and security practice. We work with organisations of any size and sector to understand their real exposure, design the controls that fit and keep them working over time — across digital infrastructure and the physical perimeter alike.

Arc — Architecture

Architecture and control design

Defining how security should end up: which controls exist, where they sit within the network and the systems, and who operates them. Design based on the organisation's real infrastructure, not on a textbook model.

Sec — Security

Assurance and operation

Independent assessment of the real state of play —maturity, legal obligations, technical exposure and physical protection— plus ongoing administration of the security platforms already in operation.

We work with Financial services· Healthcare· Retail and consumer· Industry and logistics· Education· Public sector· Professional services· Growing companies

Ways of working

Three ways to work with PIMX ArcSec

They can be engaged separately or combined. All of them are scoped to the size of the organisation and the technical capability it already has in house.

02 — Service lines

Eight service lines, one delivery standard

They can be engaged individually or as an annual programme. Where no baseline exists yet, the first line is the recommended entry point.

01

Maturity Assessment

What is the organisation's real level of security?

+

An assessment of the current state against recognised frameworks, compared with what is expected of an organisation of the same size, sector and risk profile. It is the baseline everything else is built on.

No intrusive testing required. The focus is on how the organisation actually operates: processes, responsibilities, existing controls and available evidence.

Specific deliverables
  • Current maturity level and a target reachable within 12 months
  • Gaps identified and ranked by risk
  • A prioritised portfolio of initiatives with estimated effort
  • Executive material for the board or the committee
NIST CSF 2.0ISO 27001CIS Controls v8.1Ley 21.66312/24-month roadmap
02

Architecture and Control Design

How should the control be designed, rather than just the finding patched?

+

This is the axis the brand is named after. We define how security should end up: which controls must exist, where they sit within the network and the systems, who operates them and how their effectiveness is verified. It applies both to designing a new platform and to redesigning one already in production.

The approach is practical. We work with the infrastructure the organisation actually has —the network, the systems and the existing processes— and not with a reference model that nobody can implement afterwards.

Typical scope
  • Target architecture and a control model by domain
  • Network segmentation and security zone design
  • Internal technical guidelines and standards
  • Integration architecture and service exposure
  • Security review of new projects and initiatives
  • Technology lifecycle: obsolescence and technical debt
  • Security requirements for third-party integration
Target architectureNetwork segmentationSecurity zonesTechnical guidelines
03

Ley 21.663 · ANCI Readiness

Does the organisation comply with the Cybersecurity Framework Act?

+

A structured review of every duty set by the Act and by the ANCI instructions, establishing the compliance status and the evidence behind it. If the organisation could be designated an Operator of Vital Importance, the reinforced standard applying to that group is assessed as well.

Matters assessed
  • Governance, roles and formal assignment of responsibilities
  • Asset inventory and the risk management process
  • Access control, segmentation and vulnerability management
  • Monitoring, detection and incident handling
  • Backups, operational continuity and supplier management
  • Procedure for notifying incidents to the ANCI
ANCIOVIISMSContinuityIncident reporting
04

Ley 21.719 · Personal Data Readiness

Will the organisation be ready by December 2026?

+

The scope goes far beyond the privacy policy. The work starts by establishing what personal data the organisation processes, where it lives, for what purpose it is used and on what legal basis. That record is usually the first gap, because in most cases it does not exist.

Next comes the operational side: consent that can be proven, and a real workflow —with owners and deadlines— for handling data subject requests.

Matters assessed
  • Personal data inventory and record of processing activities
  • Purpose and lawful basis for each processing activity
  • Provable consent, cookies and a consent management platform (CMP)
  • Data subject rights: workflows, owners and deadline control
  • Retention, processors and international transfers
  • Impact assessment (DPIA) where required
RoPAConsentData subject rightsDPIABreach notification
05

Compliance and Consent Platform

The day it gets requested, what proves the consent?

+

Readiness work defines what must be complied with. This line delivers the where it gets recorded: an in-house platform, customisable for each organisation, that carries the day-to-day operation of Ley 21.719 and leaves dated evidence of every decision.

The point is not having a cookie banner. It is that, when the regulator, a client or an audit asks, there is a record of what each individual accepted, when, against which wording, and what was done with every request received.

Modules
  • Cookie management and preference centre: site scanning and classification by purpose, type, lifetime and provider
  • Consent record: what was accepted, when and against which version of the wording, with a change history
  • Data subject rights: intake of requests, owner assignment, deadline control and full traceability of each case
  • Record of processing activities kept as a living inventory, not as a stray spreadsheet
  • Impact assessment (DPIA) with a guided workflow and evidence attached to the processing assessed
  • Evidence export and reporting for an audit or a regulator request
Customisation and operation

It adapts to the organisation's visual identity, to its real processing purposes and to its structure of accountable owners. After go-live it can be run by the internal team or kept as a managed service, deadline tracking of requests included.

CMPCookiesProvable consentData subject rightsRoPADPIAAuditable evidence

A platform does not replace the groundwork. If purposes, lawful bases and accountable owners are undefined, the tool merely automates an incomplete record. That is why it is implemented on top of service line 04, or on equivalent work already done.

06

Security Platforms and Consoles

Are the tools already purchased properly configured and operated?

+

Most organisations have already invested in security tooling. The problem is rarely that it is missing: it is that it was left misconfigured, out of date, carrying inherited rules nobody ever revisited, or with no one accountable for running it day to day.

This line covers both fronts: the technical review of each platform and, where needed, permanent administration of the consoles. The aim is for the tooling to actually deliver the level of protection being paid for.

Platforms covered
  • Perimeter and internal firewall: rules, policies and clean-up
  • WAF and protection of published applications
  • IPS/IDS and network threat detection
  • Web filtering and content control
  • Email security and anti-phishing
  • Antivirus and protection of workstations and servers
  • VPN, remote access and privileged access control
  • Ongoing console administration and rule change management
Virtual SOC

On that foundation a virtual SOC sized to each business can be built: monitoring of the events that matter, periodic alert review and an agreed response, without the cost or the structure of an in-house operations centre. Scope, hours and priorities are set by the organisation.

FirewallWAFIPS/IDSWeb filteringEndpointConsole administrationVirtual SOC
07

Ethical Hacking and API Security

Can the systems actually be compromised?

+

Controlled offensive testing, run under express authorisation and documented rules of engagement. The aim is to reproduce the path a real attacker would take and to record the full exploitation chain.

The difference is in the report. Raw tool output is not delivered: every finding goes through false-positive triage, is ordered by business impact and comes with concrete remediation. The report reads at two levels, executive and technical.

Scopes that can be engaged separately
  • Internet-facing attack surface
  • Web applications
  • APIs and integrations
  • Internal network
  • Internal infrastructure and services
OWASP Top 10OWASP API Top 10False-positive triageTwo-level reportRetesting
08

Converged Physical and Electronic Security

And the perimeter that is not digital?

+

An organisation's security does not stop at the firewall. Physical access to premises, equipment rooms and warehouses is as real a risk vector as the digital one, and both statutes in force treat it as part of the protective measures required.

This line integrates the design and assessment of electronic security with the rest of the architecture: same risk criteria, same deliverable format, and controls that talk to each other instead of operating as isolated systems.

Scope
  • CCTV with video analytics: people and vehicle detection
  • Licence plate reading cameras and facial recognition
  • Access control for buildings, floors and restricted areas
  • Vehicle barriers, intercom and video door entry
  • Fire detection systems, conventional and addressable
  • Convergence with digital identity and risk assessment of the physical perimeter
CCTV · AI analyticsLicence plate readingAccess controlFire detectionPhysical-digital convergence

Implementation and installation of the electronic systems is carried out together with specialised, certified partners. PIMX ArcSec owns the design, the security requirements, the integration with the architecture and the validation of the result.

04 — Method

Four phases, each with a defined deliverable

The same process across every service line. Each phase closes with a verifiable output, so progress is measurable rather than a matter of impression.

PHASE 01

Scope

Definition of the objective, the assets in scope, the operating constraints and the rules of work. It closes with a formally accepted scope document.

PHASE 02

Assessment

Fieldwork, analysis and testing according to the line engaged. Critical findings are reported during execution, not at the end of the report.

PHASE 03

Report and presentation

Delivery of the two-level report and presentation of results to both the technical and the executive teams, with room to discuss prioritisation.

PHASE 04

Follow-through

Support during remediation and retesting of closed findings, so the improvement is formally on record for an audit or a regulator.

05 — The deliverable

One format, whatever the service engaged

Every assessment is delivered in the same structure. That makes one year comparable with the next and lets the improvement be shown with evidence.

01

Security score

An objective measure of the current state, reproducible in later assessments to evidence progress.

02

Risk map

A visual view of risk by domain, ready for a committee or board presentation.

03

Prioritised findings

Every finding with its business impact and false-positive triage applied. Not a flat list.

04

Target architecture

The design the control should converge towards, not just a diagnosis of what is wrong.

05

Treatment plan

Initiatives with sequence, owners and estimated effort, in a format ready for budgeting.

06

Closure record

A formal document with scope, method and result. It stands as evidence in an audit.

Entry-level
assessmentThe recommended starting point

We recommend starting with a narrow scope. It shows how we work, it is short, and it leaves a deliverable with value of its own, whether or not the relationship continues.

Each proposal is sized against the real scope: size of the organisation, systems included and depth required. Later engagements are sized on that first baseline, by then familiar to both sides.

The first conversation is free of charge and it always ends with a concrete recommendation in writing.

06 — Profile

Marco García

Network and communications engineer, security architect. My day job is designing controls inside one of Chile's largest insurers: a regulated environment, with sensitive data and formal audit processes. PIMX ArcSec is the practice through which I bring that same judgement to other organisations.

A background in networks and communications shapes how I approach security: from the infrastructure upwards. Understanding how traffic moves, where the control points are and what each platform actually does is what separates a useful assessment from a list of generic recommendations.

I have sat on both sides of the table: building the controls and also putting them through external audit. That experience shapes how I write a report, because it tells apart a finding that changes the risk profile from one that only adds volume to the document.

What I offer is what I practise daily: architecture and control design, technology obsolescence governance, technical security guidelines, vulnerability management and Ley 21.719 implementation, including consent and data subject rights in a large-scale organisation.

For delivery I work with a network of certified professionals across different specialities and technical profiles. That makes it possible to staff each engagement with the skills it actually needs, without carrying a fixed structure or inflating the cost of small pieces of work.

The assessment and the presentation of results always stay with the same professional. What scales is the supporting team, not the distance from the client.

Certifications and roles
ISO 27001Information security management
ISO 27032Cybersecurity
GDPR — DPOData Protection Officer
CC — ISC2Certified in Cybersecurity
NIST CSFCybersecurity framework
Education
Network and Communications EngineeringProfessional degree
Postgraduate diploma in CybersecurityUniversidad de Chile
Postgraduate diploma in Software ArchitectureUniversidad Autónoma de Chile · in progress
CIS Controls v8.1Technical controls
Audit experience
Internal auditPreparation, evidence and remediation
External auditSupport and response to findings
Regulatory auditRequirements from supervisory bodies
Third-party auditSuppliers and client requirements
SOXControls over financial reporting
PCI DSSCard production · payment means
Supporting team
Certified professionalsBrought in according to the scope of the engagement
Diverse technical profilesNetworks, infrastructure, development and compliance
Professional collaborationFlexibility without a fixed structure
Chilean regulation
Ley 21.663Cybersecurity framework · ANCI
Ley 21.719Personal data protection

07 — Contact

Let us talk about your case

A reply within 24 business hours, straight from the professional in charge.

Whether it is an incident under way, a regulatory deadline or the need to set a baseline, the first conversation carries no cost and no commitment.

Direct email
loading…
Location
Santiago, Chile
Remote, and on site across the Santiago Metropolitan Region
Priority handling. If the organisation is going through an incident right now, say so in the subject line. Those cases are looked at before the rest.

Add your name so the reply can be addressed.

Check the email format.

Pick a subject so the reply can be focused.

Add at least a couple of lines of context.

Sending happens on this page. The data travels encrypted and is not shared with third parties.