Criminal defence throughout Spain · offices in Madrid and Alicante
Ransomware, CEO fraud, data exfiltration, internal sabotage. When a company suffers a cyberattack, the first 72 hours concentrate criminal, regulatory and technical decisions that admit no error: report, notify, preserve, negotiate.
In brief. The response to a cyberattack runs on three simultaneous fronts: criminal (complaint and prosecution of the attackers), regulatory (notification to the Spanish Data Protection Agency within 72 hours, to INCIBE-CERT and to sectoral supervisors under NIS2 and DORA) and technical (containment and forensics without destroying the evidence).
The response to a cyberattack has three simultaneous fronts. Criminal: a complaint and prosecution against the perpetrators, with preservation of the evidence needed to pursue them. Regulatory: notification to the Spanish Data Protection Agency (AEPD) within 72 hours where personal data are compromised, to INCIBE-CERT and, in regulated sectors, to the relevant supervisor (NIS2, DORA). Technical: containment of the incident and forensic analysis without destroying the evidence.
The decisions taken on each front condition the other two. For that reason we offer an integrated response: criminal legal direction, regulatory management and our own forensic laboratory under a single incident command.
| Moment | Front | Action | Typical error |
|---|---|---|---|
| Hour 0 (detection) | Technical | Activate the plan and contain | Switching off equipment and destroying volatile evidence |
| Hours 0-12 | Forensic | Preservation with chain of custody | Restoring systems without a forensic copy |
| Hours 12-24 | Criminal | Complaint and tracing of funds | Delaying the complaint and losing traceability |
| Hours 24-48 | Banking | Recall of transfers | Failing to activate SWIFT/SEPA protocols |
| Hour 72 | AEPD | Notification of the breach | Notifying late, or over-notifying |
| Week 1 | Data subjects | Communication where high risk | Statements that aggravate liability |
| Weeks 2+ | Recovery | Criminal action and claims | Failing to capitalise on the evidence obtained |
| Legal person | 31 bis | Fine · suspension · dissolution | Absence of a compliance programme |
The timeline is indicative and describes the ordinary sequence of a corporate incident; the applicable obligations depend on the sector, the data affected and the specific circumstances of each case.
Our advantage is structural: our own forensic laboratory under legal direction, so that evidence is acquired from the first minute with the trial and the regulatory file in mind. On that foundation we apply LIWARD, Legal Intelligence Warfare for Defense, our own methodology, which integrates legal intelligence, case-law analytics, financial and accounting analysis and e-forensics into a single procedural strategy. That is what distinguishes us from conventional criminal defence.
Companies under attack: end-to-end direction of the incident; containment, forensics, complaint, AEPD and claims.
Directors and data protection officers: protection against personal liability arising from the management of the incident.
Companies and employees identified as the origin of the attack: criminal defence with technical counter-expertise.
Insurers and advisers: independent expert examination and legal direction of complex cyber claims.
Speak to a criminal lawyer
Criminal defence in English before the courts of Alicante and the rest of Spain, for residents and for visitors who have flown home.