Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
If you are reading this because it is happening right now, start with the first hours and come back to the rest afterwards. What follows is what an organisation operating in Spain has to do, including the number most guides leave out: if personal data is involved you have 72 hours to notify, and the clock started when you found out, not when you finish investigating.
Order matters more than speed. These are the steps that keep a containable incident from turning into one that is not.
A playbook written in advance turns these six steps into something you execute instead of something you argue about. And any indicators of compromise that come out are what you search the rest of the network with: if it was on one machine, the question is how many more it is on.
This is the number people arrive looking for, so it goes first.
If the incident affects personal data and poses a risk to individuals, it has to be notified to the supervisory authority without undue delay and, at the latest, within 72 hours of becoming aware of the breach. That obligation is the GDPR, the EU regulation that Spanish texts call the RGPD. In Spain the supervisory authority is the AEPD, the Agencia Española de Protección de Datos. And if the risk to individuals is high, the affected people have to be told as well. On top of the GDPR sits the LOPDGDD, which has no equivalent in other countries because it is the Spanish act that adapts the GDPR into national law.
Two misunderstandings that cost dearly:
The procedure and the form are on the AEPD’s own page on notifying data breaches, and the text of the Spanish act is in the BOE, the Spanish state gazette. Both of those sources are in Spanish. We are a security firm and not a law firm: here we say where the obligation sits and which clock is running, and the reading of your particular case is signed by your own adviser.
Many companies operating in Spain assume the data protection deadline is the only one running. There are two more, and one of them is shorter.
NIS2 is Directive (EU) 2022/2555, and its Article 23 sets three milestones for a significant incident: an early warning within 24 hours, an incident notification within 72 and a final report within one month. Twenty four hours is not enough time to organise anything that was not organised already. Being a directive, it reaches you through each member state’s own transposition, so which authority you report to depends on where you operate. And be careful about ruling yourself out of scope by intuition: the list of sectors includes manufacturing, food, waste, postal services and managed service providers, and an entity inside the scope also pushes obligations onto its suppliers by contract.
DORA is Regulation (EU) 2022/2554 and it applies to the financial sector and to its technology service providers. It requires incidents to be classified and the major ones to be reported to the competent authority on its own schedule of initial, intermediate and final reports. The exact deadlines live in the technical standards that develop the regulation and we do not reproduce them here: if DORA applies to you, your compliance team needs that table in writing, and before they need it.
The practical consequence of the three clocks together is the same one: a duty to notify is a duty to detect. You cannot meet a deadline that starts counting when you find out if you have no way of finding out.
Plainly, because this page is read by people with a problem on their hands and they deserve a straight answer: Asperis does not sell incident response, and does not act as a forensic expert witness. If the fire is burning right now, what you need is a response team and, depending on the case, a criminal complaint to law enforcement. We are not going to sell you something else because you happened to land here.
Our part is the before and the after, which is where the day of the incident is actually decided.
Almost everything that goes wrong during an incident does not go wrong for want of technology. It goes wrong because nobody had decided four things in advance.
Who decides. A name and a deputy, with the authority to stop production at three in the morning without asking permission.
How you talk to each other if email is unavailable. An agreed alternative channel, with the phone numbers somewhere that does not depend on the system that may be compromised. Coordinating an incident over the same mailbox the attacker is reading is more common than it sounds.
What backups you have and when a restore was last tested. Not when the backup was taken: when it was actually restored and how long that took. They are two different questions and only the second one is useful.
And who you call. With a name, a phone number and, if there is a contract, a contract number. Shopping for an incident response provider while the incident is happening is the worst negotiation there is.
None of this costs money. It costs a one hour meeting and writing it down somewhere that is not the intranet that might be down.
English edition adapted on 4 August 2026 from the Spanish original, first published on 23 January 2024 and last reviewed on 3 August 2026.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Talk to a senior pentesterPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.