Normativa
DORA in force: the financial sector under new digital operational resilience regulation
The DORA Regulation (Digital Operational Resilience Act) has been fully applicable since 17 January 2025. It affects financial entities, insurers and critical ICT providers. It requires ICT risk management, resilience testing and notification of major incidents within 4 hours.
DORAFinancial sectorResilience
Sector
2nd GRC Forum Congress: 400 professionals debate European regulatory complexity
The Fundación Telefónica hosted the 2nd GRC Forum Congress, organised by the AEC. Around 400 governance, risk and compliance professionals debated the need to turn regulatory complexity (NIS2, DORA, AI Act, GDPR) into strategic advantage. The consensus: GRC is no longer a legal department task but a board-level responsibility.
GRCGRC ForumGovernance
Sector
ISACA Madrid: Audit & GRC Congress 2026 consolidates the strategic GRC profile
The Madrid chapter of ISACA held its annual Audit & GRC Congress on 26 March. The event focused on the convergence of internal audit, risk management and regulatory compliance in the context of the new European regulatory framework. Next major event: CiberTodos Congress, October 2026.
ISACAAuditGRCMadrid
Tendència
ISO 27001 covers 80% of the path to ENS and NIS2: where to start
An information security management system based on ISO/IEC 27001 covers approximately 80% of the controls required by the ENS and NIS2. For SMEs without prior certification, implementing ISO 27001 as a first step is the lowest-cost, highest-regulatory-coverage strategy.
ISO 27001ENSNIS2Strategy
Sector
C1b3rwall 2026: the largest cybersecurity congress in Spain, 2-4 June
The 6th C1b3rwall Congress takes place on 2, 3 and 4 June at the National Police Academy in Ávila, under the motto "Cybercrime 3.0". It is one of the reference events for cybersecurity professionals in Spain, with technical, operational and strategic sessions.
C1b3rwallCongressJune 2026
Tendència
GRC stops being a checkbox exercise and becomes operational resilience
The simultaneous entry into force of NIS2, DORA and the AI Act makes 2026 the year of regulatory convergence. Organisations that treated GRC as one-off compliance will need to move towards a continuous governance model. Independent consultants with a multi-framework vision and AI as a working tool have become a strategic resource for SMEs.
GRCNIS2DORAAI ActSMEs
Normativa
Spain under European infringement proceedings for failing to transpose NIS2
The European Commission sent a reasoned opinion to Spain and 18 other member states for failing to transpose the NIS2 Directive by the October 2024 deadline. The forthcoming Cybersecurity Coordination and Governance Act is still going through parliamentary procedure while public administrations adapt their procurement processes to the new requirements.
NIS2TranspositionEuropean CommissionSpain
Normativa
NIS2 draft law creates the National Cybersecurity Centre as new coordinating body
The draft Cybersecurity Coordination and Governance Act envisages the creation of the National Cybersecurity Centre (CNC), attached to the Office of the President of the Government. The body will lead national policy, set common criteria for sectoral authorities and act as the single point of contact with the EU and ENISA.
NIS2CNCGovernancePublic administration
Normativa
ENS certification will be able to demonstrate NIS2 compliance: the specific equivalence profile is taking shape
The NIS2 transposition draft provides for a Specific Compliance Profile that will allow Spanish entities to accredit compliance with the directive through the National Security Framework (ENS) certification. A strategic opportunity for public bodies and companies that have already started their ENS adaptation process.
ENSNIS2CertificationCompliance
Sector
Cyber Security World Madrid: 4-5 November at IFEMA, a key industry event
Cyber Security World Madrid takes place on 4 and 5 November 2026 in halls 3-5 at IFEMA Madrid. It is consolidating its position as the leading corporate cybersecurity trade fair in Spain, with exhibitors, solution demonstrations and strategic sessions for corporate and institutional security professionals.
EventsMadridIFEMANovember 2026
Sector
27th International Industrial Cybersecurity Congress: 23-24 September in Seville
The Centro de Ciberseguridad Industrial is organising the 27th edition of its international congress on 23 and 24 September 2026 in Seville. The programme focuses on critical infrastructure protection, IT/OT risk management in hybrid industrial environments and emerging threats in the OT ecosystem, with success stories and expert panels.
OTCritical infrastructureCongressSeptember 2026
Sector
ENISE celebrates its 20th edition: two decades as a cybersecurity reference in León
The International Information Security Meeting (ENISE), organised by INCIBE, celebrates its 20th edition this year at the Palacio de Exposiciones in León. The event brings together companies, experts, entrepreneurs and investors to share the latest trends and opportunities in the cybersecurity sector at national and European level.
ENISEINCIBELeón20th edition
Tendència
Gartner identifies six trends that will redefine cybersecurity in 2026
Gartner has published the six trends that will shape cybersecurity in 2026: identity as the new perimeter (centralised IAM and anti-phishing MFA), AI in SOCs for autonomous detection, convergence of European regulations, continuous exposure management, supply chain security and cybersecurity as a board-level topic.
GartnerIAMSOCStrategy
Tendència
Google Cloud Cybersecurity Forecast 2026: operational resilience and automation as central pillars
The Google Cloud 2026 report places operational resilience, incident response automation and risk management as strategic priorities. Cybersecurity is shifting from a technology cost to a corporate governance pillar that is decisive for business continuity and digital trust with customers and regulators.
Google CloudResilienceAutomationForecast
Tendència
The CISO loses the technical role: the board takes ownership of cybersecurity as a business risk
The convergence of NIS2, DORA and the AI Act confirms 2026 as the year in which cybersecurity moves out of the IT department and into the boardroom. Organisations that treat regulatory compliance as a formality are being pushed to transition towards continuous risk governance models, with the CISO as a strategic business partner.
CISOGovernanceBoardGRC
Incidents
Ransomware paralyses the Port of Vigo: Spain's first major industrial incident of 2026
The Port of Vigo suffered a ransomware attack in March 2026 that disrupted logistics and administrative operations, forcing a switch to manual processes to maintain port activity. The incident, covered by Recorded Future, highlights the vulnerability of port infrastructure to increasingly sophisticated ransomware threats.
RansomwareCritical infrastructureSpainOT
Incidents
Alert at Spain's Tax Agency: actor "HaciendaSec" claims access to data of 47 million citizens
The Spanish Ministry of Finance opened an investigation following statements by a malicious actor identified as "HaciendaSec" who claimed to have access to personal, banking and tax data of over 47 million citizens. Authorities activated verification protocols to determine the actual scope of the potential breach.
Data breachPublic administrationSpainGDPR
Incidents
Confirmed cyberattack on the European Commission: data extracted from public cloud services
The European Commission confirmed on 24 March a cyberattack targeting its Europa web infrastructure, exploiting vulnerabilities in external cloud services. The incident resulted in limited data extraction from public systems and has triggered a review of the attack surface of European institutional digital infrastructures.
EUEuropean CommissionCloudInfrastructure
IA
CrowdStrike: AI-powered attacks grow 89% in 2026 and spread in 29 minutes
According to CrowdStrike's Global Threat Report, AI-powered attacks have increased 89% between 2025 and 2026. The average propagation time has fallen to 29 minutes, 65% less than in 2024. 75% of recent attacks have used AI tools to automate breaches, generating hyper-personalised phishing campaigns and detecting vulnerabilities in minutes.
CrowdStrikeOffensive AIPhishingAutomation
IA
Google's chief analyst: "The era in which AI exploits vulnerabilities is already here"
Google's chief analyst warned on 11 May that AI is already being actively used to exploit vulnerabilities, not just to detect them. The warning comes as several ransomware families have incorporated AI modules to automatically identify weak points in corporate infrastructure and adapt the attack in real time without human intervention.
GoogleOffensive AIZero-dayRansomware
IA
AI moves from support to centre stage in SOCs: anomaly detection and response in under 30 seconds
In 2026, artificial intelligence is consolidating its role in Security Operations Centres (SOCs), moving from a support tool to the engine of detection and response. Current systems achieve over 96% accuracy in anomaly identification and initiate countermeasures in under 30 seconds, drastically reducing the exposure window to active incidents.
SOCDefensive AIDetectionAutomation