Blog, news and current events

Cybersecurity, real attacks, data theft, BOE and policies.

News explained for companies: what has happened, why it matters and what controls should be reviewed to reduce risk.

Data theftRansomwareBOE and EU regulations

Cybersecurity news and real cases

Attacks, data theft, ransomware and trends explained in clear language, always with a reference source and practical measures.

Research · INCIBE

What a company can learn from the INCIBE blog: risks and priority actions

Practical selection on risk management, monitoring, fraud, incident response and AI governance, with official sources linked.

Read INCIBE research →
Real news · INCIBE-CERT

INCIBE publishes CVE-2026-7787 in IBM Langflow: what to check if you use internal AI

Real news based on INCIBE-CERT about CVE-2026-7787 in IBM Langflow OSS and practical measures for companies that use AI tools.

Read real news →
Real EU regulations NIS2

NIS2: Implementing Regulation (EU) 2024/2690 specifies technical requirements for digital entities

Practical summary of Implementing Regulation (EU) 2024/2690 and its impact on cybersecurity measures and significant incidents under NIS2.

Read real news →
Real BOE · Network security

BOE: Royal Decree 43/2021 develops the security of networks and information systems

Royal regulatory news from the BOE on Royal Decree 43/2021 and its relationship with continuity, incidents and operators of essential services.

Read real news →
Real BOE · Data protection

BOE: Organic Law 7/2021 and data protection in criminal investigations and infractions

Business summary of Organic Law 7/2021 published in the BOE and its importance for personal data processed in the prevention, detection and investigation of criminal infractions.

Read real news →
Real case / data theft

MOVEit case: how a vulnerability ended in massive data theft

Lessons on vendors, external exposure, patching, and incident response.

Read news →
Ransomware/double extortion

Ransomware and double extortion: when the attack threatens to publish data

What it means for a company that ransomware includes information exfiltration.

Read news →
Report/data breaches

Data breaches due to stolen credentials: a recurring threat

What to prioritize: MFA, privileged access, phishing and account control.

Read news →
Trends / ENISA

Ransomware, data leaks and supply chain attacks

How to convert threat trends into business controls and decisions.

Read news →

Regulations, BOE and directives

Separate topics to rank searches on NIS2, ENS, DORA, CRA, GDPR and ISO 27001.

Practical guide

NIS2: which companies are obliged and how to prepare

Main guide to understand scope, obligations, relationship with ISO 27001 and ENS, and initial steps.

Read guide →
EU Directive

NIS2 Directive: the European text that changes cybersecurity obligations

Practical summary of Directive (EU) 2022/2555, its scope and how to follow its application in Spain from official sources.

Read topic →
BOE/ENS

Royal Decree 311/2022: what the National Security Scheme requires

Keys to the ENS published in the BOE for companies that work with the Public Administration or want to prepare for tenders.

Read topic →
EU Regulation

DORA: digital operational resilience for the financial sector

What DORA requires and why it affects financial entities, ICT providers and technological supply chains.

Read topic →
EU Regulation

Cyber ​​Resilience Act: cybersecurity requirements for digital products

A new European reference for manufacturers and suppliers of products with digital elements.

Read topic →
BOE / Data protection

LOPDGDD and RGPD: data protection as part of security compliance

Why privacy, security measures and breach management must be worked on in a coordinated manner.

Read topic →
News · ENISA

Cyber ​​Resilience Maturity Model for SMEs: How to Use It

How to turn a cyber resilience self-assessment into scope, evidence, priorities, and a verifiable technical backlog.

Read the analysis →