What a cybersecurity event with the sea in the background left us with.
Yesterday we attended the 5th Cybersecurity Conference by the Sea, an event organized by COITTA/AAGIT about cybersecurity with the Mediterranean Sea as a backdrop. It sounds almost contradictory: talking about digital threats, cybercrime, and crises with the calm sea behind you. But perhaps that's why it worked so well. Because what was said at the roundtables wasn't the typical technical talk, but an honest conversation about how ill-prepared we still are, as a society, for something that has already overwhelmed us.
We discussed artificial intelligence, cybercrime, budgets, banking, and why we continue to separate the digital world from the real world when it no longer makes sense to do so. We've gathered several ideas that have been on our minds, and we've organized them to provide a snapshot of the current state of cybersecurity in Spain.
Index
- “Both are real right now”: Antonio Fernandes’ reflection
- Cybersecurity and Law Enforcement: anticipating cybercrime
- The message that was repeated at all the tables: the lack of budget
- Artificial intelligence is advancing faster than our ability to control it.
- The financial sector on the front lines: NIS2, Bank of Spain and cryptographic control
- Frequently Asked Questions about Cybersecurity, AI and NIS2
- What we took away from the event
“Both are real right now”: the reflection of Antonio Fernandes
We owe the phrase to Antonio Fernandes, a teacher at EIP, during his panel on Cybersecurity and Law Enforcement Agencies: anticipating cybercrime. He was talking about the relationship between the digital world and the physical world, and he corrected himself live on air, almost without realizing how important that correction was:
“The digital world and the real world… no, the digital world and the physical world. Both are real right now.”

That small slip-up speaks volumes. For years we've talked about "the digital world" as if it were a separate realm, almost a parallel simulation to "real" life. But it isn't, and it's becoming less so all the time. An attack on critical infrastructure, a leak of personal data, online extortion of a small business: all of these have consequences as real, as economic, and as human as a robbery on the street. The difference is that we often don't see them coming because we continue to think of cybercrime as something abstract, distant, from another dimension.
Cybersecurity and Law Enforcement: anticipating cybercrime
Antonio Fernandes' panel discussion focused precisely on this: how cybersecurity incidents are investigated today and how collaboration between private security specialists and law enforcement agencies is no longer optional; it's the only real way to stay one step ahead of organized cybercrime. They discussed specific investigative experiences, the difficulty of prosecuting crimes that know no borders, and the need for companies and law enforcement agencies to share information much more readily than they currently do.
The conclusion, though no one stated it so directly, was clear: cybercrime is no longer fought with firewalls alone. It is fought with shared intelligence, public-private collaboration protocols, and professionals capable of navigating both worlds.
The message that was repeated at all the tables: the lack of budget
There was one idea that came up, almost word for word, in virtually every conversation of the day, regardless of the sector being discussed: there is still a lack of budget.
Not as a generic industry complaint, but as a diagnosis shared by people who deal with the problem every day: consultants, educators, security managers. Many of them supported their arguments with personal anecdotes, real cases they had experienced or managed, which helped us to better contextualize something that, described from the outside, can sound abstract. Heard in this way, with firsthand examples, the diagnosis became much clearer: cybersecurity continues to be treated, in far too many organizations, as a secondary expense or as an IT budget line item that gets cut when numbers get tight. And that, with the level of sophistication that cybercrime has reached today, is simply not being prepared.
Not at every table, but at several, another idea emerged that seemed equally relevant: treating cybersecurity as another public issue that could trigger a crisis, with real contingency plans like those already in place for heat waves, storms, or riots, instead of improvised reactive protocols. It wasn't as widespread a consensus as the one on the budget, but it was an idea that surfaced strongly in some of the day's conversations.
Artificial intelligence is advancing faster than our ability to control it.
This was the other recurring theme of the day, and probably the most uncomfortable of all. At every table, at some point, the discussion turned to the speed at which artificial intelligence is advancing and how difficult it is to keep it under control before cybercrime uses it to its advantage on an even greater scale than it already does.
It wasn't an abstract debate about "the future of AI." It was a very concrete and pressing concern: the very tools we use today to automate processes, optimize operations, and detect threats are the same ones that, in the wrong hands, accelerate fraud, hyper-personalized phishing, voice and video impersonation, and social engineering on an industrial scale. AI didn't create cybercrime, but it has given it speed, scale, and a level of sophistication that was unthinkable for an individual attacker just a few years ago.
The gap between the speed of technological development and the speed of regulation and the training of professionals was, without anyone saying it in those exact words, the elephant in the room all day.

The financial sector on the front lines: NIS2, Bank of Spain and cryptographic control
The table of Sergio Padilla and Óscar Sánchez, Cybersecurity as a strategic focus of the financial sector, He brought all of this down to a very specific and very tangible level: banking.
Some of the points that were discussed:
- How the Bank of Spain is preparing Faced with current cybersecurity risks, in a context where financial institutions are one of the most attractive targets for organized cybercrime, precisely because of the direct value of what is at stake.
- The importance of updating the NIS2 (the European cybersecurity directive that extends the obligations of risk management, incident reporting and monitoring to a much larger number of sectors and companies) as a regulatory framework that is no longer "for some time from now", but a present requirement that is already conditioning how security teams are organized within entities.
- The growing weight of cryptographic control, The management, rotation, and protection of the keys that encrypt sensitive information is a central component of any serious financial security strategy, and not a secondary technical detail.
And one question remained hanging in the air, perhaps the most difficult of all: what immediate capacity does the financial sector need to develop now, not in the future, to guarantee the security of its users? There was no single answer, and probably there isn't. But the fact that it's being framed as such, as an urgent matter rather than a five-year roadmap, speaks volumes about where we are as a sector.

Frequently Asked Questions about Cybersecurity, AI and NIS2
What is the NIS2 directive and who does it affect?
NIS2 is the European directive that updates cybersecurity obligations for a much wider range of sectors considered essential or important, including the financial sector. It requires, among other things, stricter risk management, early incident reporting, and greater oversight of the technology supply chain.
Why is artificial intelligence said to be a cybersecurity risk?
Not because AI is malicious in itself, but because it multiplies the capabilities of attackers: it automates phishing, allows the creation of very convincing fake content, and reduces the time and technical knowledge needed to launch a sophisticated attack.
How do cybersecurity companies collaborate with the State Security Forces and Corps today?
Primarily through the exchange of information on incidents, joint investigation of cases, and public-private collaboration protocols that still have much room for improvement, as was discussed at the event.
What career opportunities are available to those who train in cybersecurity today?
From technical roles in analysis and incident response, to more strategic profiles linked to regulatory compliance (such as NIS2), risk management in banking, or collaboration between the private sector and public bodies.
What we took away from the event
If there's one thing that connects all the discussions yesterday, it's this: cybersecurity is no longer just an IT department issue. It's about budgets, public policy, financial regulation, collaboration with law enforcement agencies, and increasingly, a race against time against the development of artificial intelligence.
Facing the sea, with all of that on the table, it became clear that the sector needs professionals who understand the problem in its entirety: technical, strategic, and regulatory. This is precisely the kind of perspective we strive to cultivate at the Master's Degree in Cybersecurity from EIP, where we work with teachers like Antonio Fernandes who experience this world from within, not just from theory.
With all of that on the table, it became clear that the sector needs professionals who understand the problem in its entirety: technical, strategic, and regulatory. This is precisely the kind of perspective we strive to cultivate at [the organization/organization]. Master's Degree in Cybersecurity from EIP, where we work with teachers like Antonio Fernandes who experience this world from within, not just from theory.
Thanks also to COITTA Thank you for making such an event possible, with a caliber of speakers that is not easy to assemble. We hope it won't be the last.































