A starting point, so you know where we speak from: protecting your company's data is neither optional nor "a big-company thing". The GDPR already requires every company handling data to have security measures in place (art. 32). That is already cybersecurity. NIS2, ENS or DORA are layers added on top depending on your sector and size — but the floor is the same for everyone.
1.A record year: 122,223 incidents (+26%)
INCIBE handled 122,223 cybersecurity incidents in 2025, 26% more than in 2024 and the highest figure on record. This is not a bad patch: it is a trend that rises every year.
2.60% hit SMEs and the self-employed
Most incidents did not target large corporations: 60% affected SMEs and the self-employed. Hardest hit: retail, hospitality, professional firms, and clinics.
3.NIS2 is no longer theory: 401 incidents at essential operators
INCIBE handled 401 incidents at essential and important entities —exactly the companies the NIS2 directive requires to strengthen their posture—. Most affected: banking (34%), transport (14%) and energy (8%).
4.Fraud remains entry door #1
45,445 online fraud cases (+19%), with phishing the leading technique: 25,133 cases. And it is not a technical problem: it is a well-written email that fools a person in a hurry.
Closing figure
INCIBE's free helpline (017) handled 142,767 enquiries in 2025, up 44.9%. More and more companies ask for help after the problem. Getting off cheap means asking before.
What applies to you?
Take the free check-up —3 minutes, no sign-up, we do not even ask for your email— and you will know which regulations affect you and where to start.
Take the free check-upSources: INCIBE, 2025 Cybersecurity Report and official press release (February 2026). All figures come from that source. We do not include third-party average-cost-per-incident estimates that do not appear in the official source.