Blog
Guides

Cyber threats facing companies in Spain: the 2026 picture

This page is revised once a year and stays at the same address, so that each revision can be read against the one before it. It is not a list of headlines: it is what we are actually seeing arrive at companies in Spain, how it gets in, and what has changed in the part that is no longer optional because a regulation requires it.

A
Asperis Security
Offensive Security team
3 August 2026
9 min read
Share:
Five threats converging on a single point and entering the company through three gaps in the perimeter: a credential, an unpatched system and somebody who clicks.

What changed in this revision

This is the first English edition of a guide Asperis revises once a year in Spanish, and it is worth starting where the Spanish edition starts, because what changed is itself the diagnosis. The previous version of this page was written in early 2024 and described six threats: ransomware, phishing, attacks on critical infrastructure, data leakage, the supply chain and insecure IoT. That diagnosis was not wrong, but three things were missing from it and one of them was large.

  • It mentioned no regulation at all. It talked about critical infrastructure and about the Spanish regulatory framework without naming NIS2, DORA or the ENS, which are precisely what has turned security into a contractual requirement for a lot of companies that previously had none.
  • It treated identity as a password problem rather than as what it is today: the perimeter.
  • It closed by recommending firewalls and advanced antivirus. Both are still needed and neither is what decides the outcome any more.

What stays the same, because it is still true: ransomware leads, the most frequent way in is still a person, and the supply chain has stopped being a rare case.

Ransomware: the encryption is the least important part

If ransomware were only encryption, a good backup would solve it. It has not been only that for a long time.

The pattern we see has two levers: first they take the data, then they encrypt. The backup gives you back your operations, not your confidentiality, and the negotiation becomes a negotiation about publication. That is why the sites that name the victims who do not pay exist, and they double as a shop window for the next one.

The other change is structural: whoever gets in and whoever encrypts are usually no longer the same people. An initial access broker sells the way in, and ransomware as a service supplies the rest. That lowers the technical level needed to attack you and raises the number of people who can.

What actually changes the outcome, in order: backups the attacker cannot delete (an immutable backup, or one kept offline), a restore somebody has tested end to end, and segmentation so that one compromised machine does not reach all the others. All three are checked from the inside, which is what an internal network pentest does.

Email fraud, which is what moves the most money per incident

Ransomware makes the papers and email fraud takes the money quietly. It does not need malware: it needs a genuine invoice and a changed account number.

The three most repeated forms are CEO fraud, changing a supplier’s bank account inside a genuine email thread, and payroll diversion. All of them fit inside business email compromise, and none of them triggers a technical alert, because the email usually comes from a legitimate account.

What is new in the last period is that verifying by voice has stopped being worth anything: cloning a recognisable voice is now cheap. The control that still works is procedural rather than technological: no change of bank details is accepted through the same channel it arrived on, with no exception for seniority, which is exactly what this fraud exploits. It is worked through in the guide to identity theft and impersonation.

The supply chain: they no longer need to attack you

It is the most important underlying change since the previous version of this page, and it particularly affects the Spanish mid-sized company, which is usually a supplier to larger ones.

It happens along two different routes that are worth not confusing:

  • The software supplier. Somebody compromises a library, an update or a development tool, and gets into all of its customers at once. That is the software supply chain attack.
  • The service supplier. Somebody gets into your accountancy firm, your maintenance partner or your integrator, which has legitimate remote access to your systems. There is no vulnerability to patch here: there is a third party’s credential.

The practical consequence is that now they are going to ask you. Security clauses in contracts have stopped being an annex nobody read, and more and more companies ask their suppliers for concrete evidence: a test report, a certificate, or both.

Identity is the perimeter, and it is still handled as if it were passwords

Most of the intrusions we see do not start with an exploit, they start with a valid credential. And that changes where you have to look.

  • An infostealer on a personal machine takes passwords and, with them, session cookies. With the session stolen, the second factor is not asked for.
  • Phishing today does not steal the password, it puts itself in the middle: that is adversary in the middle, and it is why a second factor by SMS or by one-time code is no longer enough.
  • What does stop it is a factor that cannot be relayed, of the passkey kind, together with conditional access and the removal of legacy authentication, which is the door almost everybody leaves open.

In Microsoft 365 environments, where a great deal of Spanish business keeps its mail and its files, this is a specific and bounded configuration review: M365 hardening.

Generative AI: what actually changes and what does not

It is worth separating the noise from what is being seen.

What has really changed is the cost of the deception. A flawless email in Spanish, adapted to your sector and to the person receiving it, no longer takes time or language skills. Spelling mistakes as a warning sign are finished, and internal training has to stop teaching them that way.

What is new is surface of your own. Companies are connecting assistants to their data and to their tools, and that creates a kind of failure that did not exist before: inputs the model reads as instructions, agents with more permissions than they need, and data leaving through a channel nobody considered a channel. It gets tested, and that is what we do in AI pentesting.

What has not changed is the boring part: people still get in through a credential, through an unpatched system and through somebody who clicks.

It is worked through in cybersecurity and artificial intelligence, including why the prompt injection that makes the headlines is not the one that matters.

What is no longer optional: NIS2, DORA and the ENS

It is the block that was missing entirely from the previous version, and for a lot of companies it is the real reason they are reading this.

  • NIS2. A European directive that widens the number of entities under obligation in sectors such as energy, transport, health, water, banking and digital infrastructure. Two things make it different from what came before: it holds management directly accountable, and it requires significant incidents to be notified within short deadlines. It also reaches into the supply chain, so it can arrive as a clause from your customer even if your own sector is not on the list. Being a directive, what binds you is each member state’s transposition of it.
  • DORA. A European regulation for the financial sector and for its technology providers. It is the one that most affects what gets bought in offensive security, because for certain entities it requires threat-led testing, TLPT, which has its own requirements for how it is run and for who may run it, and is not an ordinary pentest.
  • ENS. The Esquema Nacional de Seguridad is Spain’s national security framework. It applies to the Spanish public sector and is passed on by contract to whoever sells to it, which is also how it reaches companies based outside Spain. It classifies systems by category and requires periodic audit. If your company bids for Spanish public tenders, this reaches you. We cover it in the ENS service, and the general certification route in ISO 27001.

The useful question is not which of them applies to you in the abstract, but what concrete evidence you are going to have to put in front of an auditor or a customer, and whether you have it today.

Where to look for the data, and where to start

This page gives criteria, not statistics. If you need figures for a board, go to the source and cite it with its date, rather than repeating a percentage with no year, which is exactly what the previous version of this same page did.

  • INCIBE, Spain’s national cybersecurity institute, publishes advisories, guides and material for businesses, mostly in Spanish, and runs a public helpline. It is the reference closest to the Spanish context.
  • ENISA, the European Union Agency for Cybersecurity, publishes a periodic threat landscape report with its methodology stated. It is what to cite in a European context.
  • CISA’s KEV catalogue lists vulnerabilities that are on record as actually exploited. It is not a list of what might happen, it is a list of what is happening, and that is why it is the best guide for deciding what gets patched first. Asperis is not affiliated with or endorsed by CISA.

And where to start, if you have to choose: identity and a second factor that cannot be relayed, patching what faces the internet after first finding out what faces the internet, backups the attacker cannot delete and that somebody has restored, and then checking all of it by attacking it. The full order is in the guide to cybersecurity for companies, how to choose who you give the work to is in the guide to cybersecurity companies in Spain, and a specific case can be put to us through contact.

A
Asperis Security
Offensive Security team
Share:

If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.

Talk to a senior pentester