Spain handled 122,223 cybersecurity incidents in 2025, 261% more than the previous year, according to data from National Cybersecurity Institute (INCIBE). This is the highest figure recorded to date, and it comes with another record: 237,028 vulnerable systems detected, of which more than 26,000 were new vulnerabilities and 4,200 were classified as critical.
This data coincides with a significant regulatory delay. The European NIS2 Directive, which requires thousands of Spanish companies to strengthen their cybersecurity, had a transposition deadline of October 17, 2024. As of mid-2026, it still has not become law in Spain.
SMEs, in the crosshairs
Of the total incidents handled in 2025, 601% affected small and medium-sized enterprises (SMEs)—organizations that, for the most part, do not have a dedicated security department. The private sector confirms the same trend from another angle: Check Point Research recorded an average of 2,105 cyberattacks per week per Spanish company in June 2026, 101% more than the previous year.
Cybersecurity vacancies, around 30,000 unfilled: a deficit that is not due to a lack of vocation
While the threat grows and legal requirements tighten, the market faces a different problem: cybersecurity vacancies in Spain continue to grow, with an estimated deficit of 30,000 unfilled positions and demand increasing between 20% and 20% each year.
And it's not a matter of economic attractiveness. Entry-level salaries in the sector (€20,000–€35,000 gross per year) already exceed the national average, and a junior SOC analyst position commands a similar or higher salary.
So why are so many cybersecurity vacancies still unfilled?
“For two years now, we’ve been seeing the same pattern in the selection processes of our partner companies: the training for these profiles has to be practical and realistic; they must be able to handle an incident from their very first day on the job. That’s the difference between a candidate who gets stuck in the interview stage and one who lands the job. The shortage of specialists is solved by having professionals who have received training aligned with the work environment before even joining the company.”
Jorge González, Head of Employability at EIP International Business School
Where is the real mismatch?
The problem isn't the number of people wanting to enter the sector; it's the type of training available compared to the actual cybersecurity vacancies that exist today. Companies need to fill very specific roles—incident response, regulatory compliance (NIS2, GDPR), cloud security, and OT security—and much of the traditional training remains focused on theory, not on simulating real-world scenarios.
This gap between theory and practice is also reflected in the certifications the market demands. The CISSP has become the benchmark for senior and management positions, while the OSCP leads in offensive environments, such as penetration testing. Both are now standard requirements, not just a way to differentiate oneself on a resume. The market is seeking professionals who have already managed the type of incident they will encounter on their first day of work.

If you want to know how a training program specifically designed to address this gap is structured, you can consult the Master's Degree in Cybersecurity from EIP.
EIP International Business School































