Digital Transformation
Cybersecurity for companies: grants and obligations 2026
INCIBE handled 122,223 cybersecurity incidents in 2025, 26% more than the year before. Ransomware attacks jumped by 116% and the average cost of a cyberattack for an SME in Spain ranges between 35,000 and 80,000 euros (Secure&T, 2026). On top of that comes new European legislation, the NIS2 Directive, which extends cybersecurity obligations to companies in 18 sectors that were not regulated before. The good news: public grants are available that can fund a large part of the investment required.
How many cyberattacks do Spanish companies suffer?
The 2025 figures confirm an alarming trend. According to INCIBE (2026), the cybersecurity incidents handled in Spain broke down as follows:
- Malware: 55,411 cases, including 392 ransomware attacks that locked down entire systems and demanded a ransom
- Online fraud: 45,445 cases, led by phishing with 25,133 incidents of fake emails impersonating banks or suppliers
- Information theft: 3,849 cases of unauthorised access to confidential data
INCIBE also detected and reported 237,028 vulnerable systems in Spanish companies and organisations, all of them open to exploitation by cybercriminals.
The impact goes beyond the figures. During the second half of 2025 Spain recorded 605 significant incidents, the equivalent of three serious attacks a day. Manufacturing suffered intrusions that forced production lines to stop, while the frequency of cyber claims rose by 143% on the previous year (IT User, 2026).
Is your company ready for a cyberattack? At Tecnocim Innova we help you identify vulnerabilities and access grants to strengthen your digital security. Request a free assessment.
Legal cybersecurity obligations: NIS2 and the ENS
The NIS2 Directive (EU 2022/2555) is the new European legislation that extends cybersecurity obligations to 18 sectors, up from the 7 covered by the previous NIS1. In Spain, the Council of Ministers approved in January 2025 the Anteproyecto de Ley de Coordinación y Gobernanza de la Ciberseguridad (the Spanish cybersecurity governance bill) to transpose the directive; it is going through parliament now and is expected to enter into force during 2026.
Which companies does NIS2 affect?
The directive applies to medium-sized and large companies in critical sectors:
| Criterion | Threshold |
|---|---|
| Employees | 50 or more |
| Annual turnover | 10 million euros or more |
| Sectors | Energy, transport, banking, healthcare, water, food, industry, digital services and 10 more |
SMEs with fewer than 50 employees are exempt, unless they are the sole provider of an essential service or run critical infrastructure.
What obligations does it impose?
- Risk analysis that is documented and updated regularly
- Technical and organisational security measures proportionate to the risk
- Notification of serious incidents to the competent authority (INCIBE-CERT) within tight deadlines
- Supply chain security: assess your suppliers and require cybersecurity from them
- Mandatory cybersecurity training for management and employees, with follow-up metrics
- Senior management accountability: directors and executives are personally liable for breaches
Penalties
Companies that fail to comply with NIS2 face fines of up to 10 million euros or 2% of global turnover, whichever is higher. Directors can also be temporarily disqualified if negligence is proven.
Separately, the Esquema Nacional de Seguridad (ENS, Real Decreto 311/2022, the Spanish national security framework) is already mandatory for every public sector entity and its technology suppliers. If your company provides services to the Spanish public administration, you have to meet the ENS requirements.
What grants are available for corporate cybersecurity?
According to the Secure&T study (2026), only 44.2% of Spanish companies plan to increase their cybersecurity investment, largely because they do not know that public grants exist which can fund that investment in full or in part:
Kit Digital
The Kit Digital programme, funded with Next Generation EU money, includes the Servicio de Ciberseguridad Gestionada (managed cybersecurity service) and Puesto de Trabajo Seguro (secure workstation) categories. The amounts per company vary by segment:
| Segment | Employees | Maximum amount |
|---|---|---|
| III | 0–2 | €3,000 |
| II | 3–9 | €6,000 |
| I | 10–49 | €12,000 |
| IV | 50–99 | €25,000 |
| V | 100–249 | €29,000 |
In 2026 the programme runs until the funds are fully exhausted, with no rigid deadlines. More than 45% of small companies in Catalonia have already applied for this grant (Red.es, 2026).
The Activa Ciberseguridad programme
Run by the Escuela de Organización Industrial (EOI) with support from INCIBE, this programme offers free specialist advice worth 2,140 euros per company. It includes:
- A diagnosis of your current cybersecurity position
- Preparation of a cybersecurity plan tailored to your company
- A group workshop on building cybersecurity into business strategy
The programme has a budget of 9.63 million euros to serve 4,500 SMEs across Spain. Calls are published periodically.
Grants in Catalonia
The Generalitat de Catalunya has launched a cyber protection strategy backed by an investment of 18.6 million euros. ACCIÓ, the Catalan business competitiveness agency, channels part of these grants to Catalan companies. The RETECH Ciberseguridad project also builds up the cybersecurity ecosystem through INCIBE, with training, skills development and support for SMEs.
Do you need help applying for these grants? At Tecnocim Innova we manage the whole process, from identifying the right grant to the final justification. See our grants service.
Essential cybersecurity measures for your company
According to the World Economic Forum, 95% of cybersecurity problems can be traced to human error. A large technology investment is not always needed; the most effective measures are often organisational.
Basic measures every company should put in place:
- Team training: regular awareness programmes on phishing, social engineering and password management
- Backups: automated, encrypted and with regular restore tests (the 3-2-1 rule)
- Updates and patches: apply security updates within days, not weeks
- Multi-factor authentication (MFA): on all remote access and critical services
- Network segmentation: separate production systems from the corporate network
- Incident response plan: a documented procedure with defined roles and response times
- External audit: periodic vulnerability assessment by an independent third party
For industrial SMEs, INCIBE warns that it is common to find equipment running out-of-date operating systems, end-of-life software or connections on old protocols. A cybersecurity audit identifies these weak points before an attacker does.
The strategic consultancy service from Tecnocim Innova can help you design an action plan suited to your company's level of digital maturity.
Next step
Cybersecurity is no longer optional. With 122,223 incidents handled in 2025, the NIS2 Directive being transposed into Spanish law and public grants of up to 29,000 euros available, protecting your company is both a legal obligation and a funded investment opportunity.
At Tecnocim Innova we have spent more than 30 years helping companies access grants and optimise their investments. We support you throughout: from the initial cybersecurity assessment to managing the grants that fund the solution.
Contact us for a no-obligation review of your cybersecurity position and the grants you can access.
Related services
Digitalisation Grants
Kit Digital and Kit Consulting: up to €36,000 in digitalisation funding for SMEs. We manage the full application.
View service →Innovation Consultancy
We support your company through digital transformation, change management and innovation strategy.
View service →Free assessment for companies with revenue above €500,000
Get grant and tax deduction updates by email
Calls, deadlines and regulatory changes, once a month.
Related articles
Digital Transformation
Digital Transformation

