The selection reflects the articles visible in the consultation of August 4, 2026. The dates and titles belong to INCIBE; business analysis is from Blue Moon.
What is repeated in the contents of INCIBE
The revised selection connects five business needs: understand risk, monitor security even if management is non-technical, reduce fraud through social engineering, know how to respond to an incident, and govern new technologies such as artificial intelligence.
These issues do not prove that a specific company has a gap or that a standard is applicable to it. They serve to ask better questions before deciding on an investment or plan.
1. Risk management: decide before accumulating controls
INCIBE includes Risk management: a practical guide to making better cybersecurity decisions, updated on February 5, 2026. The useful reading for a company is to convert risks into responsible parties, priorities, controls and evidence, instead of starting with a tool.
- What assets, processes and data are in scope.
- What scenarios can disrupt operations or expose information.
- What controls really exist and what evidence demonstrates their operation.
- What residual risk management accepts and when it will be reviewed.
2. Supervise without relying on technical jargon
The article How to monitor your company's digital security without being a technical expert, published on May 14, 2026, fits a common need: management must be able to ask about priorities, those responsible, and results without pretending to do the technical work.
A responsible business conversation starts with context: size, critical processes, suppliers, known incidents, contractual obligations and internal capacity. Not by selling a standard package.
3. Fraud, spoofing and BEC: verifiable processes
INCIBE published pieces on telephone spoofing, BEC y fraudulent account changes in HR. The common denominator is not that training solves everything, but that sensitive decisions need independent and traceable verification.
- Confirm payment changes through a known channel.
- Separate request, approval and execution when possible.
- Train people with examples and reporting procedures.
- Preserve evidence without storing unnecessary data.
4. Respond when the incident has already occurred
Digital first aid: what to do after a cyber attack, published on December 4, 2025, allows the conversation to be prepared: who decides, what is isolated, how evidence is preserved, how it is recovered and when it is communicated.
The preparation must be tested. A procedure does not demonstrate capability until the people responsible know about it and a controlled test reveals which part is failing.
5. AI Governance: a related line, not an equivalence
The INCIBE article on UNE-ISO/IEC 42001, published July 2, 2026, opens a conversation about responsible decisions and trust in organizations that use AI.
It is a line adjacent to information security: it is not equivalent to ISO 27001, it does not demonstrate certification and it does not allow us to conclude by itself that a company must implement a specific system. It does justify reviewing uses, responsible parties, data, suppliers, risks and evidence.
Relationship with Blue Moon services
These topics can connect with a risk diagnosis, preparation of evidence for an ISMS, ENS or NIS2 adequacy when applicable, secure development, AppSec, training and review of digital processes. The scope should be decided after knowing the real situation, not from the title of an article.
Do you want to turn these questions into priorities?
We can review the context of your company, separate real risks from hypotheses and define maintainable next steps.
Request diagnosis