info@societejuridique.com
Madrid: Paseo de la Castellana 216 8 ª Planta
Alicante: Av. Ansaldo Nº31, local 16
24h emergencies: 669 30 21 13

Social media:

Cyberattacks · incident response

Cyberattacks on companies: legal incident response

Criminal defence throughout Spain · offices in Madrid and Alicante

Ransomware, CEO fraud, data exfiltration, internal sabotage. When a company suffers a cyberattack, the first 72 hours concentrate criminal, regulatory and technical decisions that admit no error: report, notify, preserve, negotiate.

In brief. The response to a cyberattack runs on three simultaneous fronts: criminal (complaint and prosecution of the attackers), regulatory (notification to the Spanish Data Protection Agency within 72 hours, to INCIBE-CERT and to sectoral supervisors under NIS2 and DORA) and technical (containment and forensics without destroying the evidence).

Why it is different

72h
72 hours: the deadline for notifying the Data Protection Agency sets the pace of the entire response.
2
Offices in Madrid and Alicante; assistance anywhere in Spain.
LIWARD
Our own methodology of legal intelligence and forensic analysis.

A cyber incident admits no improvised management

The response to a cyberattack has three simultaneous fronts. Criminal: a complaint and prosecution against the perpetrators, with preservation of the evidence needed to pursue them. Regulatory: notification to the Spanish Data Protection Agency (AEPD) within 72 hours where personal data are compromised, to INCIBE-CERT and, in regulated sectors, to the relevant supervisor (NIS2, DORA). Technical: containment of the incident and forensic analysis without destroying the evidence.

The decisions taken on each front condition the other two. For that reason we offer an integrated response: criminal legal direction, regulatory management and our own forensic laboratory under a single incident command.

Scenarios we handle

The legal fronts of a corporate cyber incident

Art. 264 CP

Ransomware and sabotage

Computer damage, denial of service and extortionate encryption of systems: criminal pursuit of the attackers. Penalty: up to eight years in aggravated cases.
Arts. 248–250 CP

CEO fraud · BEC

Transfers diverted through impersonation: urgent tracing, bank recall and criminal proceedings.
Arts. 278–280 CP

Exfiltration and espionage

Theft of trade secrets by employees or third parties: internal investigation, forensics and criminal actions. Penalty: two to four years; disclosure, three to five.
Art. 197 bis CP

Intrusions and unlawful access

Unauthorised access to corporate systems: technical proof of the access and of its authorship. Penalty: six months to two years.
GDPR Art. 33

Notification to the AEPD

Assessment of the breach and notification within 72 hours: content, risks and communication to those affected. Deadline: 72 hours from knowledge.
NIS2 · DORA

Sectoral compliance

Notification and incident-management obligations for essential sectors and financial entities. Framework: NIS2, DORA and sectoral regulation.
Forensics

Forensic analysis of the incident

Acquisition of evidence with chain of custody, analysis of attack vectors and an expert report fit for court.
Negotiation

Handling the extortion

Legal advice in ransom scenarios: criminal implications, international sanctions and communications. Risk: payments to sanctioned entities.
Art. 31 bis CP

Defence of the accused company

Where the incident reveals internal offences or the company itself is investigated: corporate and director defence. Coverage: entity, directors and employees.
The response timeline

The first hours decide the case

MomentFrontActionTypical error
Hour 0 (detection)TechnicalActivate the plan and containSwitching off equipment and destroying volatile evidence
Hours 0-12ForensicPreservation with chain of custodyRestoring systems without a forensic copy
Hours 12-24CriminalComplaint and tracing of fundsDelaying the complaint and losing traceability
Hours 24-48BankingRecall of transfersFailing to activate SWIFT/SEPA protocols
Hour 72AEPDNotification of the breachNotifying late, or over-notifying
Week 1Data subjectsCommunication where high riskStatements that aggravate liability
Weeks 2+RecoveryCriminal action and claimsFailing to capitalise on the evidence obtained
Legal person31 bisFine · suspension · dissolutionAbsence of a compliance programme

The timeline is indicative and describes the ordinary sequence of a corporate incident; the applicable obligations depend on the sector, the data affected and the specific circumstances of each case.

Our differentiator

Where cybersecurity meets forensic analysis

Our advantage is structural: our own forensic laboratory under legal direction, so that evidence is acquired from the first minute with the trial and the regulatory file in mind. On that foundation we apply LIWARD, Legal Intelligence Warfare for Defense, our own methodology, which integrates legal intelligence, case-law analytics, financial and accounting analysis and e-forensics into a single procedural strategy. That is what distinguishes us from conventional criminal defence.

01

Legal intelligence

02

Financial and accounting analysis

03

Digital evidence · e-forensic

04

Procedural strategy

How we work

From detection to recovery

Phase 01

Containment and preservation

Phase 02

Forensic analysis

Phase 03

Complaint and notifications

Phase 04

Recovery and claims

Who we represent

Each profile demands a distinct defence

C

Companies

Companies under attack: end-to-end direction of the incident; containment, forensics, complaint, AEPD and claims.

D

Directors and DPOs

Directors and data protection officers: protection against personal liability arising from the management of the incident.

I

Persons under investigation

Companies and employees identified as the origin of the attack: criminal defence with technical counter-expertise.

V

Insurers and advisers

Insurers and advisers: independent expert examination and legal direction of complex cyber claims.

FAQ

Frequently asked questions

We have suffered a ransomware attack. What are the first three calls?
Technical response, legal direction and the cyber insurer: contain, preserve forensic evidence and start the legal clocks (AEPD 72 hours, INCIBE, criminal complaint). We assume the legal and forensic direction of the incident and coordinate all parties under professional privilege.
Is it lawful to pay the ransom?
It is not prohibited as a general rule, but it may be where the recipient is subject to international sanctions, and it never guarantees recovery. It also conditions the regulatory file. We advise on the decision while documenting the diligence of the governing body.
Do we always have to notify the AEPD?
Only where the breach affects personal data with a risk to the rights of those concerned, and within 72 hours. Under-notifying exposes the company to sanction; over-notifying, to unnecessary reputational damage. The technical and legal assessment of the risk is the key to that decision.
Can we recover the money from a CEO fraud?
Sometimes, if action is taken at once: SEPA/SWIFT recall, freezing of intermediate accounts and criminal proceedings with interim measures. Traceability goes cold within days. Our team activates the banking, police and judicial routes simultaneously.
Do you handle cases outside Alicante?
Yes. We operate from Madrid and Alicante and provide assistance anywhere in Spain, including urgent assistance to detainees and proceedings with an international dimension.
What is the LIWARD methodology?
It is our own methodology, Legal Intelligence Warfare for Defense, which integrates legal intelligence, financial and accounting analysis and digital forensic evidence into a single procedural strategy. It allows us to anticipate the weaknesses of the opposing case and to build on technical evidence, not on legal argument alone.

Speak to a criminal lawyer

In a fast-track case, the days you have are the case.

Criminal defence in English before the courts of Alicante and the rest of Spain, for residents and for visitors who have flown home.

Logotipos-abogacia-scje
Paseo De La Castellana 216 8º 28046 Madrid
Alicante – Playa de San Juan Av. Ansaldo 31, local 16, 03540 Alicante
Londres: 20 Wenlock Road, N1 7GU, Reino Unido
París: 72 Faubourg St Honoré, 75008, Francia
info@societejuridique.com

Société de Conseil Juridique et Expert es un despacho de abogados con sedes en Madrid, Alicante, Londres y París, especializado en defensa y acusación penal, delitos económicos y corporativos y derecho tecnológico. Trabajamos con orientación estratégica en procedimientos penales complejos, propiedad intelectual y análisis forense avanzado, y prestamos consultoría jurídica, compliance y escudos de protección a particulares y empresas. Atendemos desde Alicante y Madrid, con consulta online en toda España y asistencia al detenido 24 horas. Resuelva sus dudas en las preguntas frecuentes o solicite una primera consulta.

Copyright © 2026 Société de Conseil Juridique et Expert S.L.

EspanolEnglishFrancaisРусскийItalianoDeutsch
WhatsApp · Urgencias 24h