description Article
How should you respond to a security breach in your company?
Security breaches are becoming increasingly common across all types of organisations, regardless of their size, sector, or turnover. These incidents can compromise systems, networks, strategic know-how, operations, reputation and, in some cases, they also result in the exposure of personal data —with all the legal and financial consequences that entails.
Given the complexity and potential impact of such breaches, it is essential to understand not only the legal implications but also the practical and strategic steps that companies must take to respond effectively and in compliance with applicable regulations.
A clear example was seen this past weekend in the cyberattack on a check-in and baggage handling service provider operating at several airports, including Heathrow, Berlin and Brussels.
The importance of a swift and compliant response
In the face of such incidents, it is essential to act swiftly and diligently both to contain the attack and mitigate its effects. A delayed or inadequate response may worsen the damage and result in non-compliance with applicable regulations, such as the General Data Protection Regulation (GDPR) or the Law on Information Society Services (LSSI), among others. This could lead to significant sanctions from competent authorities, such as Spain’s Data Protection Authority (AEPD) in the case of personal data breaches.
Given the risks involved, below, we outline key steps to follow in the event of a cyberattack. A prompt, coordinated, and legally compliant response can make the difference between a controlled incident and a major crisis.
Key steps in the event of a security breach
1. Internal reporting of the incident
Immediately inform your company’s legal department. If you have a Data Protection Officer (DPO) and the breach involves personal data, they must also be notified without delay. The DPO plays a crucial role in such situations.
Under the GDPR, the DPO is responsible for advising and informing the data controller or processor (i.e., the company or organisation), and for monitoring compliance with data protection regulations.
The DPO must act independently and cooperate with supervisory authorities such as the AEPD. Therefore, when a breach occurs, it is essential to assess whether the breach must be reported to the AEPD.
If you are unsure whether your company is legally required to appoint a Data Protection Officer, we recommend reading this article: “When and why do you need a Data Protection Officer?”
2. Seek specialist legal advice
If your company does not have an in-house legal team with expertise in technology law and data protection, we recommend consulting professionals in these fields to assess the situation and determine the next steps, which may include:
- Evaluating the severity and scope of the breach from civil, criminal, data protection and other legal perspectives.
- Determining whether the breach must be reported to the AEPD and, if applicable, to affected individuals, in accordance with the GDPR (typically within 72 hours of becoming aware of the incident).
- Implementing technical and containment measures, such as system restoration, credential changes, forensic analysis, and organisational improvements.
- Reviewing existing internal procedures, policies, response protocols, staff training and other technical and organisational measures, and updating them as necessary—not only due to the incident but also to address any outdated practices. This will enhance prevention and reduce the risk of human error in the future.
- Documenting the incident in a security incident register, accompanied by a technical and legal report detailing the origin, impact, measures taken and potential consequences.
- If notification to the AEPD and/or affected individuals is required, proceed with it under appropriate legal guidance to ensure all actions are carried out diligently.
Cyberattacks on the rise: recent data and examples
Cyberattacks are not only persisting— in fact they are increasing. In Spain alone, it is currently estimated that organizations suffer an average of 2,057 cyberattacks per week, representing a 20% increase compared to 2024.This growing phenomenon affects not only well-known companies, but any organisation can be a target.
Some of the most high-profile cases in 2025 include:
- The cyberattack on Marks & Spencer (M&S), one of the UK’s most recognised retailers, with estimated losses of up to £300 million.
- A massive data breach at Telefónica in June 2025.
- Exposure of customer data at El Corte Inglés.
- Unauthorised access to personal data of DKV Seguros clients.
Risks and consequences of a security breach
The risks stemming from a cyberattack go far beyond financial or reputational damage. These incidents can have far-reaching and severe consequences, including identity theft affecting both the company itself and its employees, resulting in cyber fraud, scams or unauthorised access to services and platforms.
Furthermore, in some cases, stolen information may be used to launch phishing campaigns targeting clients or suppliers, compromising corporate accounts and manipulating communications. Other rights may also be affected, such as intellectual property, confidentiality, and trade secrets.
Final recommendations to protect your business
At AGM Abogados, we recommend implementing all necessary organisational and technical measures to help prevent and avoid such attacks.
And, if your organisation suffers an incident of this nature, do not hesitate to contact our TMT & IP team. They can provide expert legal advice and support in managing the situation swiftly, effectively and in full compliance with current regulations.
Technology, Media & Telecommunications (TMT) description Article

