What a company can learn from the INCIBE blog: risks and priority actions
Practical selection on risk management, monitoring, fraud, incident response and AI governance, with official sources linked.
Read INCIBE research →News explained for companies: what has happened, why it matters and what controls should be reviewed to reduce risk.
Attacks, data theft, ransomware and trends explained in clear language, always with a reference source and practical measures.
Practical selection on risk management, monitoring, fraud, incident response and AI governance, with official sources linked.
Read INCIBE research →Real news based on INCIBE-CERT about CVE-2026-7787 in IBM Langflow OSS and practical measures for companies that use AI tools.
Read real news →Practical summary of Implementing Regulation (EU) 2024/2690 and its impact on cybersecurity measures and significant incidents under NIS2.
Read real news →Royal regulatory news from the BOE on Royal Decree 43/2021 and its relationship with continuity, incidents and operators of essential services.
Read real news →Business summary of Organic Law 7/2021 published in the BOE and its importance for personal data processed in the prevention, detection and investigation of criminal infractions.
Read real news →Lessons on vendors, external exposure, patching, and incident response.
Read news →What it means for a company that ransomware includes information exfiltration.
Read news →What to prioritize: MFA, privileged access, phishing and account control.
Read news →How to convert threat trends into business controls and decisions.
Read news →Separate topics to rank searches on NIS2, ENS, DORA, CRA, GDPR and ISO 27001.
Main guide to understand scope, obligations, relationship with ISO 27001 and ENS, and initial steps.
Read guide →Practical summary of Directive (EU) 2022/2555, its scope and how to follow its application in Spain from official sources.
Read topic →Keys to the ENS published in the BOE for companies that work with the Public Administration or want to prepare for tenders.
Read topic →What DORA requires and why it affects financial entities, ICT providers and technological supply chains.
Read topic →A new European reference for manufacturers and suppliers of products with digital elements.
Read topic →Why privacy, security measures and breach management must be worked on in a coordinated manner.
Read topic →How to turn a cyber resilience self-assessment into scope, evidence, priorities, and a verifiable technical backlog.
Read the analysis →