Skip to main content
BilgeQor
Back to industries

Founder, CTO

Founder-led Startups & Digital Products

Verified cybersecurity incident and help-line context · Spain / INCIBE-CERT

INCIBE-CERT managed incidents and 017 consultations — Spain 2025

Market context — not industry-specific evidence

INCIBE-CERT managed 122,223 cybersecurity incidents in calendar year 2025, a 26% year-on-year increase, and proactively detected and notified 237,028 relevant vulnerable systems. Of the total incidents, 401 were attended among essential and important operators aligned with NIS2 terminology; within that operator subset, banking accounted for 34%, transport 14%, energy 8%, financial-market infrastructure 7%, and insurers and pension funds 6%. Across all managed incidents, malware accounted for 55,411 cases (including 392 ransomware attacks), online fraud for 45,445 cases, phishing for 25,133 cases, and information theft for 3,849 cases. 4,600 potentially fraudulent .es domains were closed in collaboration with Red.es. The INCIBE 017 help-line handled 142,767 consultations, a 44.9% year-on-year increase, of which 49% were preventive and 51% reactive. These figures are Spain INCIBE-CERT 2025 reporting context; they are not total Spanish business incident prevalence and not industry-specific evidence.

Spain · INCIBE-CERT 2025 managed incident, vulnerable-system notification, essential/important-operator incident, incident-category, fraudulent-domain closure, and 017 consultation contextCalendar year 2025

Cybersecurity incidents managed by INCIBE-CERT — 2025

Cybersecurity incidents managed by INCIBE-CERT
122,223
Unit
cybersecurity incidents managed by INCIBE-CERT
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

INCIBE-CERT managed 122,223 cybersecurity incidents in calendar year 2025.

Spain INCIBE-CERT 2025 reporting context only. Not total Spanish business incident prevalence and not industry-specific evidence.

Year-on-year increase in INCIBE-CERT managed incidents — 2025

Year-on-year increase in managed incidents
26%
Unit
percent year-on-year increase in managed incidents
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

INCIBE-CERT managed incidents increased 26% year-on-year in calendar year 2025.

Spain INCIBE-CERT 2025 reporting context only. The 26% is a year-on-year change in managed incident counts and does not measure a per-business incident rate. Not total Spanish business incident prevalence and not industry-specific evidence.

Relevant vulnerable systems proactively detected and notified — 2025

Relevant vulnerable systems proactively detected and notified
237,028
Unit
relevant vulnerable systems proactively detected and notified by INCIBE-CERT
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

INCIBE-CERT proactively detected and notified 237,028 relevant vulnerable systems in calendar year 2025.

Spain INCIBE-CERT 2025 reporting context only. Not total Spanish business incident prevalence and not industry-specific evidence.

Incidents attended among essential and important operators — Spain 2025

Incidents attended among essential and important operators (NIS2-aligned)
401
Unit
incidents attended among essential and important operators (NIS2-aligned, 2025)
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

401 incidents were attended among essential and important operators aligned with NIS2 terminology in 2025; a distinct subset of the 122,223 total managed incidents.

NIS2-aligned essential/important-operator incident subset only. This is not a count of all-Spain business incidents and not industry-specific evidence.

Key sectors affected within the 401 essential/important-operator incident subset — 2025

Banking — 34%
34%
Unit
percent — banking share within the 401 essential/important-operator incident subset
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Transport — 14%
14%
Unit
percent — transport share within the 401 essential/important-operator incident subset
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Energy — 8%
8%
Unit
percent — energy share within the 401 essential/important-operator incident subset
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Financial-market infrastructure — 7%
7%
Unit
percent — financial-market infrastructure share within the 401 essential/important-operator incident subset
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Insurers and pension funds — 6%
6%
Unit
percent — insurers and pension-funds share within the 401 essential/important-operator incident subset
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

These percentages describe key sectors affected within the 401 essential/important-operator incident subset aligned with NIS2 terminology only. They are not all-Spain sector incident prevalence rates, all-business sector rates, or industry-specific evidence for any sector shown on this page.

Selected managed incident categories — Spain 2025

Malware cases — 55,411
55,411
Unit
malware cases managed by INCIBE-CERT
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Ransomware attacks (within malware) — 392
392
Unit
ransomware attacks (subcategory within malware cases)
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Online fraud cases — 45,445
45,445
Unit
online fraud cases managed by INCIBE-CERT
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Phishing cases — 25,133
25,133
Unit
phishing cases managed by INCIBE-CERT
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context
Information-theft cases — 3,849
3,849
Unit
information-theft cases involving unauthorised access to or extraction of digital and/or confidential data
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

Source-defined incident categories within INCIBE-CERT 2025 managed incidents. The 392 ransomware figure is a subcategory within the 55,411 malware cases, not a separate peer count. These are not total Spanish business incident rates and not industry-specific evidence.

Potentially fraudulent .es domains closed — Spain 2025

Potentially fraudulent .es domains closed in collaboration with Red.es
4,600
Unit
potentially fraudulent .es domains closed in collaboration with Red.es
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

4,600 potentially fraudulent .es domains were closed in collaboration with Red.es in calendar year 2025.

Proactive domain closure action by INCIBE in collaboration with Red.es. This is not a count of Spanish business cyber incidents and not industry-specific evidence.

INCIBE 017 help-line consultations handled — 2025

INCIBE 017 consultations handled
142,767
Unit
INCIBE 017 help-line consultations handled
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

INCIBE 017 handled 142,767 consultations in calendar year 2025.

INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.

Year-on-year increase in INCIBE 017 consultations — 2025

Year-on-year increase in consultations
44.9%
Unit
percent year-on-year increase in INCIBE 017 consultations
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

INCIBE 017 consultations increased 44.9% year-on-year in calendar year 2025.

INCIBE 017 help-line context only. The 44.9% is a year-on-year change in consultation counts and does not measure a per-person victimisation rate. Not total Spanish business incident prevalence and not industry-specific evidence.

Preventive consultations share — INCIBE 017 2025

Preventive consultations
49%
Unit
percent of 017 consultations that were preventive
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

49% of INCIBE 017 consultations in calendar year 2025 were preventive.

INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.

Reactive consultations share — INCIBE 017 2025

Reactive consultations
51%
Unit
percent of 017 consultations that were reactive
Period
Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Scope
Spain INCIBE-CERT 2025 managed incident and 017 consultation context

51% of INCIBE 017 consultations in calendar year 2025 were reactive.

INCIBE 017 help-line context only. Not total Spanish business incident prevalence and not industry-specific evidence.

Source: INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026

Scope: INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026. The 122,223 managed incidents and 237,028 vulnerable-system notifications describe INCIBE-CERT 2025 reporting context. The 401 essential/important-operator incidents are a NIS2-aligned subset; the sector percentages (banking, transport, energy, financial-market infrastructure, insurers/pension funds) apply only to that 401-incident subset and must not be presented as all-Spain sector prevalence rates, all-business sector rates, or industry-specific evidence. The 392 ransomware attacks are a subcategory of the 55,411 malware cases. The 26% and 44.9% figures are year-on-year changes in counts and do not measure per-business or per-person incident rates. These figures do not measure total Spanish business incident prevalence, hidden incident prevalence, population-wide victimisation rates, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official INCIBE press release and Balance de Ciberseguridad 2025 INCIBE (supporting PDF). The 122,223 managed incidents, 237,028 vulnerable systems notified, and 401 essential/important-operator incidents describe INCIBE-CERT 2025 reporting context. The 26% increase is a YOY change in managed incident counts; it does not measure a per-business incident rate. The 401 essential/important-operator incidents are aligned with NIS2 terminology; the sector percentages (34% banking, 14% transport, 8% energy, 7% financial-market infrastructure, 6% insurers/pension funds) describe key sectors affected within the 401-incident subset only and must not be presented as all-Spain sector incident prevalence, all-business sector prevalence, or industry-specific evidence. The 392 ransomware attacks are a subcategory within the 55,411 malware cases. The 44.9% increase in 017 consultations is a YOY change and does not measure per-person victimisation. These figures are Spain INCIBE-CERT 2025 reporting context only; they are not total Spanish business incident prevalence, hidden incident prevalence, population-wide victimisation rate, industry-specific evidence, compliance achievement, certification, or proof of security.

Accessible data table
Verified Spain INCIBE-CERT 2025 cybersecurity incident and help-line context data from INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026, reporting period Calendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context.
MetricValueSourceScopeReporting period
Cybersecurity incidents managed by INCIBE-CERT122,223 cybersecurity incidents managed by INCIBE-CERTINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Year-on-year increase in managed incidents26% percent year-on-year increase in managed incidentsINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Relevant vulnerable systems proactively detected and notified237,028 relevant vulnerable systems proactively detected and notified by INCIBE-CERTINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Incidents attended among essential and important operators (NIS2-aligned)401 incidents attended among essential and important operators (NIS2-aligned, 2025)INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Banking — 34%34% percent — banking share within the 401 essential/important-operator incident subsetINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Transport — 14%14% percent — transport share within the 401 essential/important-operator incident subsetINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Energy — 8%8% percent — energy share within the 401 essential/important-operator incident subsetINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Financial-market infrastructure — 7%7% percent — financial-market infrastructure share within the 401 essential/important-operator incident subsetINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Insurers and pension funds — 6%6% percent — insurers and pension-funds share within the 401 essential/important-operator incident subsetINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Malware cases — 55,41155,411 malware cases managed by INCIBE-CERTINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Ransomware attacks (within malware) — 392392 ransomware attacks (subcategory within malware cases)INCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Online fraud cases — 45,44545,445 online fraud cases managed by INCIBE-CERTINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Phishing cases — 25,13325,133 phishing cases managed by INCIBE-CERTINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Information-theft cases — 3,8493,849 information-theft cases involving unauthorised access to or extraction of digital and/or confidential dataINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Potentially fraudulent .es domains closed in collaboration with Red.es4,600 potentially fraudulent .es domains closed in collaboration with Red.esINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
INCIBE 017 consultations handled142,767 INCIBE 017 help-line consultations handledINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Year-on-year increase in consultations44.9% percent year-on-year increase in INCIBE 017 consultationsINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Preventive consultations49% percent of 017 consultations that were preventiveINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context
Reactive consultations51% percent of 017 consultations that were reactiveINCIBE / INCIBE-CERT, Balance de Ciberseguridad 2025 INCIBE, 9 February 2026Spain INCIBE-CERT 2025 managed incident and 017 consultation contextCalendar year 2025 managed incident, vulnerable-system notification, essential/important-operator incident, online fraud, phishing, malware, information-theft, fraudulent-domain closure, and 017 help-line consultation context

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Configuration Errors
  • Authentication Flaws
  • Data Leakage

Digital surfaces in scope

Web AppsMobile AppsAPIs

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.