José Palanco
Written by

José Palanco

José Ramón Palanco is the CEO/CTO of Plexicus, a pioneering company in ASPM (Application Security Posture Management) launched in 2024, offering AI-powered remediation capabilities. Previously, he founded Dinoflux in 2014, a Threat Intelligence startup that was acquired by Telefonica, and has been working with 11paths since 2018. His experience includes roles at Ericsson`s R&D department and Optenet (Allot). He holds a Telecommunications Engineering degree from the University of Alcala de Henares and a Master`s in IT Governance from the University of Deusto. As a recognized cybersecurity expert, he has been a speaker at various prestigious conferences including OWASP, ROOTEDCON, ROOTCON, MALCON, and FAQin. His contributions to the cybersecurity field include multiple CVE publications and the development of various open source tools such as nmap-scada, ProtocolDetector, escan, pma, EKanalyzer, SCADA IDS, and more.

Jev Doesn't Chat. It Decides. Why That Matters for Cybersecurity.
Application Security

Jev Doesn't Chat. It Decides. Why That Matters for Cybersecurity.

Jev is designed to return typed decisions instead of prose. That distinction could change where semantic judgment fits in security workflows, provided teams retain policy, fallbacks, verification, and human review.

José Palanco José Palanco ·
Top 15 AI Pentest Tools for 2026: Autonomous Agents Ranked & Compared
Review

Top 15 AI Pentest Tools for 2026: Autonomous Agents Ranked & Compared

The 2026 AI pentest market splits into three lanes: autonomous agents that exploit live systems, BAS platforms that emulate adversary techniques, and PTaaS vendors that wrap AI around human testers. We ranked 15 of them on signed-scope evidence, replay verification, and pricing transparency so you can pick the right one for your next pentest run.

José Palanco José Palanco ·
From Alert to Fix: Closing the Loop with Proof-Driven AppSec
Code Remediation

From Alert to Fix: Closing the Loop with Proof-Driven AppSec

Most security programs are a series of disconnected loops — alert, triage, fix, audit, fix again, audit again. Proof-Driven AppSec closes the loop once and makes every step provable. This is the canonical definition, the four-loop structure, and what it looks like in production.

José Palanco José Palanco ·
ترسانة DevSecOps: من مبتدئ إلى محترف
Learn

ترسانة DevSecOps: من مبتدئ إلى محترف

تشغيل `trivy image` ليس DevSecOps—إنه توليد ضوضاء. الهندسة الأمنية الحقيقية تتعلق بنسبة الإشارة إلى الضوضاء. يوفر هذا الدليل تكوينات جاهزة للإنتاج لـ 17 أداة قياسية في الصناعة لوقف الثغرات دون إيقاف الأعمال، منظمة في ثلاث مراحل: ما قبل الالتزام، حراس بوابة CI، وفحص وقت التشغيل.

José Palanco José Palanco ·
قلل الضوضاء: اجعل أدوات الأمان تعمل لصالحك
Learn

قلل الضوضاء: اجعل أدوات الأمان تعمل لصالحك

تثبيت أداة الأمان هو الجزء السهل. يبدأ الجزء الصعب في 'اليوم الثاني'، عندما تقوم تلك الأداة بالإبلاغ عن 5000 ثغرة جديدة. يركز هذا الدليل على إدارة الثغرات: كيفية تصفية التنبيهات المكررة، وإدارة الإيجابيات الكاذبة، وتتبع المقاييس التي تقيس النجاح فعليًا. تعلم كيفية الانتقال من 'العثور على الأخطاء' إلى 'إصلاح المخاطر' دون إرهاق فريقك.

José Palanco José Palanco ·
أفضل أدوات SCA في عام 2025: فحص التبعيات، تأمين سلسلة توريد البرمجيات الخاصة بك
Review

أفضل أدوات SCA في عام 2025: فحص التبعيات، تأمين سلسلة توريد البرمجيات الخاصة بك

تعتمد التطبيقات الحديثة بشكل كبير على المكتبات الخارجية والمفتوحة المصدر. هذا يسرع من عملية التطوير، ولكنه يزيد أيضًا من خطر الهجمات. كل تبعية يمكن أن تقدم مشاكل مثل الثغرات الأمنية غير المرقعة، التراخيص الخطرة، أو الحزم القديمة. تساعد أدوات تحليل تكوين البرمجيات (SCA) في معالجة هذه المشاكل.

José Palanco José Palanco ·
أمن تطبيقات الويب: أفضل الممارسات والاختبار والتقييم لعام 2026
Cybersecurity

أمن تطبيقات الويب: أفضل الممارسات والاختبار والتقييم لعام 2026

أمن تطبيقات الويب ضروري لحماية تطبيقاتك من الهجمات السيبرانية التي تستهدف البيانات الحساسة وتعرقل العمليات. يغطي هذا الدليل أهمية أمن تطبيقات الويب، الثغرات الشائعة، أفضل الممارسات وطرق الاختبار، مما يساعدك على تأمين تطبيقك، ضمان الامتثال والحفاظ على ثقة المستخدمين

José Palanco José Palanco ·
15 اتجاهًا في DevSecOps لتأمين عملك
Cybersecurity

15 اتجاهًا في DevSecOps لتأمين عملك

أصبح اختراق الأمان الكابوسي حقيقة للعديد من الشركات الأوروبية. تعرف على 15 اتجاهًا تحويليًا في DevSecOps يجب أن تعرفها لتبقى بعيدًا عن قائمة الاختراقات.

José Palanco José Palanco ·
الدليل الاستشاري النهائي لإدارة وضع أمان التطبيقات (ASPM)
Application Security

الدليل الاستشاري النهائي لإدارة وضع أمان التطبيقات (ASPM)

إذا كنت تقوم ببناء أو تشغيل برامج اليوم، فمن المحتمل أنك تتعامل مع الخدمات المصغرة، والوظائف الخالية من الخوادم، والحاويات، والحزم الخارجية، وكم هائل من مربعات الامتثال. كل جزء متحرك يولد نتائجه الخاصة، ولوحات المعلومات، والتنبيهات الحمراء الغاضبة. قبل فترة طويلة، يصبح وضوح المخاطر مثل القيادة في ضباب سان فرانسيسكو في الساعة 2 صباحًا - تعرف أن الخطر موجود، لكن لا يمكنك رؤيته بوضوح.

José Palanco José Palanco ·
بليكسيكوس تحصل على استثمار بقيمة 150 ألف دولار من مايكروسوفت
Investment

بليكسيكوس تحصل على استثمار بقيمة 150 ألف دولار من مايكروسوفت

حصلت بليكسيكوس على استثمار بقيمة 150,000 دولار من مايكروسوفت لتوسيع بنيتها التحتية السحابية. سيساهم هذا التمويل في تحسين أداء النظام وقابليته للتوسع والموثوقية، مما يمكن بليكسيكوس من دعم المزيد من الشركات بحلول مؤسسية مدعومة بالذكاء الاصطناعي.

José Palanco José Palanco ·
بليكيسوس وسيفيروس يعززان الأمن السيبراني في 19 دولة
Cybersecurity

بليكيسوس وسيفيروس يعززان الأمن السيبراني في 19 دولة

تعاون جديد بين بليكيسوس وسيفيروس يهدف إلى تعزيز أمن التطبيقات في 19 دولة في أمريكا اللاتينية وإيبيريا. يجلب هذا التعاون في مجال الأمن السيبراني حلول إدارة وضعية أمن التطبيقات المتقدمة (ASPM) إلى المنظمات التي تسعى للدفاع بشكل استباقي ضد التهديدات السيبرانية.

José Palanco José Palanco ·
Ready to validate what matters?

Ready to validate what matters?

Plexicus is Proof-Driven AppSec: validated findings, contextual understanding, and reviewed remediation — anchored in evidence, scoped with you.

Qualification

Check whether AI Swarm Pentest fits your environment.

Share the minimum context. We will review the scope and tell you the next commercial step.

Before submitting — verify you fit

Teams with fewer than 50 developers: start a 14-day Trial instead of booking a demo. Start a 14-day Trial →

0 / 280

No commitment. If you don't fit, we'll tell you.

SAMPLE HANDOVER · ILLUSTRATIVE

Sample evidence handover

A trimmed view of what your team receives at the end of an AI Swarm Pentest engagement. Real engagements include full technical evidence, executive narrative, and a remediation plan.

VALIDATED FINDING Evidence attached

Server-Side Request Forgery in webhooks/receiver

demo-project/sample-app · src/webhooks/receiver.py:42

SeverityHigh CVSS 3.18.6 Priority79 Confirmedvia replay

Untrusted caller-supplied URLs reach an internal egress without an allowlist. Replayed in a sandbox against a fresh authorised target — the same control was validated to fail twice.

REVIEWER-READY REMEDIATION Merge-ready PR

Validate the target URL against an allowlist of permitted hostnames. Reject private/internal IP ranges. Enforce HTTPS only.

plexicus/remediation/webhooks-ssrf 3 changed · 0 new files
42resp = requests.get(target_url)
42+if not is_allowed_host(target_url):
43+  raise WebhookRejected(target_url)
44+resp = requests.get(target_url, timeout=5)
Every engagement hands over:
  • Executive briefing
  • Validated findings list
  • Merge-ready PRs
  • Compliance mapping (NIS2 · DORA · CRA)