Logo ECIJA

    Which sectors are most vulnerable to cyber-attack in Spain and how to strengthen their security

    Cipher and ECIJA offer a turnkey solution from technical implementation to legal and compliance coverage, including compliance with the DORA Regulation and the National Security Scheme (ENS).

    Although any company can be the victim of an attack, essential sectors are particularly vulnerable: transport, financial, tax and ICT were the most affected, with 341 incidents altogether.

    Faced with this scenario of growing threat, Cipher-cybersecurity division of the Prosegur Group-has strengthened its offer through a strategic alliance with ECIJA, a firm specialising in digital law, privacy and compliance. Together, both companies combine technical capabilities and legal advice to meet the requirements of the NIS2 Directive, whose deadline for transposition into Spanish law expired on 17 October 2024, although the corresponding national regulation has not yet been approved.

    Essential sectors, such as transport, the financial and tax system, and ICTs, were the most affected, with 341 incidents that demonstrate the vulnerability of critical areas for the economy and society. The NIS2 obliges all entities to increase caution in data management, improve their security systems, adopt adequate organisational and technical measures, and promptly report any incident. Although Spain has not formally completed transposition, many regulators already require information on the state of information security maturity, prompting organisations to anticipate regulatory requirements.

    Cipher brings more than two decades of experience in critical infrastructure protection and has proprietary technology solutions such as xMDR (Extended Detection and Response) and Security Observatory for advanced threat detection and continuous monitoring. In addition, its SPIP (Security Posture Improvement Plan) combines the work of cybersecurity architects and ethical hackers to detect vulnerabilities and generate security plans that optimise time and costs. With international certifications such as PCI QSA, ISO 27001 and ISO 20000, Cipher offers a tailored approach according to the criticality of each client's assets.

    For its part, ECIJA assumes legal and compliance responsibilities, performing compliance gap analysis, developing internal policies and procedures, adapting contracts and training senior management. It also prepares organisations for audits and manages possible sanctioning procedures. Thanks to this collaboration, companies have a "turnkey" service that covers everything from technical implementation to legal coverage for NIS2, DORA and the National Security Scheme, allowing them to efficiently face one of the greatest regulatory challenges of the last decade in terms of cybersecurity.

    Related professionals

    LATEST FROM #ECIJA

    Articles
    29 July 2026
    Michael Jackson and Pepsi: the contract that changed the commercial exploitation of image rights forever

    The historic agreement between Michael Jackson and Pepsi marked a turning point in the commercial exploitation of image rights, laying the foundations for modern sponsorship contracts. Today, in a world dominated by social media and artificial intelligence, these agreements are more complex and strategic than ever.

    Read more
    Articles
    28 July 2026
    Prodhab’s guidelines on debt recovery procedures

    It sets out new rules for the processing of personal data in debt collection procedures and communications with third parties.

    Read more
    Reports
    28 July 2026
    The European Parliament and the Council approve the Digital Omnibus Package on AI

    ECIJA’s TMT department analyses the ‘Digital Omnibus’, the reform approved by the European Union that streamlines the Artificial Intelligence Regulation (AIR). It extends deadlines, reduces the burden on SMEs and strengthens the powers of the European AI Office, without compromising the level of protection of rights and security.

    Read more
    Reports
    28 July 2026
    Data Protection Officer (DPO): Chile and Spain

    A comparative analysis of the regulation, functions and requirements of the Data Protection Officer (DPO) in Chile and Spain, highlighting their strategic role in governance and compliance in the field of personal data protection.

    Read more
    Articles
    24 July 2026
    Alfredo Moreno publishes a letter to the editor on the challenges posed by the new Data Protection Act

    The Managing Partner of ECIJA Chile has published a letter to the editor in *Diario Constitucional* in which he analyses the main challenges posed by the implementation of the new Personal Data Protection Act in Chile.

    Read more
    23 July 2026
    ECIJA is advising NOSTROMO PICTURES and BETA FICTION on the film “CRONOS”

    ECIJA has advised NOSTROMO PICTURES and BETA FICTION on the film “CRONOS”, which is based on the real-life accounts of those involved and recounts the unfolding of Operation Cronos, the operation launched following the terrorist attack carried out on Las Ramblas (Barcelona) on 17 August 2017.

    Read more
    Reports
    22 July 2026
    Joint guidelines on the ASEAN and RIPD model contractual clauses for international transfers of personal data

    ECIJA Ecuador analyses the Joint ASEAN–RIPD Guidelines on international data transfers.

    Read more
    Articles
    20 July 2026
    Félix Jáquez chairs a panel at the 2026 Trust Services and Digital Certification Conference

    Félix Jáquez, a partner at ECIJA DOMINICAN REPUBLIC, is taking part as a moderator at the 2026 Trust Services and Digital Certification Congress

    Read more