From the NIS2 Law to Massive Ransomware Attacks: The Cybersecurity Challenge in Spain and Latin America

26 de August de 2026

Talking about cybersecurity is no longer about a distant threat or a future obligation. In Spain, the entry into force of NIS2 has made regulatory compliance a specific date on the calendar. In Latin America, the problem has another side to it: the region has become the world's primary target for ransomware. Two different realities, united by the same conclusion: without visibility into IT assets, neither security nor compliance is possible.

Spain: NIS2 Moves from Proposal to Law

For nearly two years, NIS2 was a directive in Spain that was "pending transposition." That changed in April 2026, when the Royal Decree that completes its transposition into Spanish law took effect. Essential and important entities now have a maximum of nine months to fully comply.

The data explains the urgency. INCIBE's cybersecurity report, published in February 2026, recorded 122,223 incidents handled in 2025, a 26% increase from the previous year:

  • 55,411 malware incidents, the most common category.
  • 45,445 cases of online fraud, a 19% increase from 2024.
  • 25,133 cases of phishing, the most common entry vector.
  • 392 ransomware attacks, with an average cost of between 80,000 and 150,000 euros per incident for a medium-sized Spanish company.
  • 237,028 vulnerable systems detected and proactively reported by INCIBE-CERT.

Among the essential and important operators regulated by NIS2, INCIBE handled 401 incidents in 2025, with the banking sector accounting for 34% of the attacks, followed by transportation (14%) and energy (8%).

The proposed penalty regime is among the most severe in the European regulatory framework: up to 10 million euros or 2% of annual global revenue for critical entities, and up to 7 million euros or 1.4% for significant entities, with personal liability for management in cases of gross negligence. The scope is also broad: it is estimated that NIS2 directly affects some 5,760 entities in Spain, spread across 18 sectors, with a relatively low threshold for inclusion (more than 50 employees or more than 10 million euros in revenue in regulated sectors).

Latin America: The Region with the Highest Rate of Ransomware Attacks Worldwide

While Spain is putting its regulatory framework in order, Latin America is facing a problem of a different magnitude: according to Kaspersky’s “State of Ransomware 2026” report, the region emerged in 2025 as the most affected by ransomware in the world, with 8.13% of Latin American organizations falling victim to this type of attack, ahead of Asia-Pacific (8%), Africa (7.62%), and Europe (3.82%).

Other data confirm the magnitude of the problem:

  • Ransomware breaches in the region increased by 78% in a single year, from more than 250 in 2024 to more than 450 in 2025, according to Intel 471's "Latin America Cyber Threat Landscape " report. The number of active variants nearly doubled, from 48 to 79.
  • Check Point Research reported that Latin American organizations were subjected to an average of more than 3,000 cyberattacks per week in 2026, well above the global average.
  • In the first half of 2026, Brazil accounted for more than 100 reported ransomware victims, Mexico for nearly 80, Argentina for 39, and Colombia for 33, according to data compiled by ESET from ransomware.live.
  • In Mexico alone, more than 237,000 ransomware attacks were recorded over a 12-month period, according to Kaspersky—the equivalent of more than 19,000 attacks per month.

Brazil accounts for approximately 30% of all victims in the region, with the consumer goods, energy, agriculture, and professional services sectors among the hardest hit.

Two realities, one common root: you can't protect what you can't see

In Spain, the challenge is to demonstrate compliance to a regulatory agency with specific deadlines and penalties. In Latin America, the challenge is to contain a surge in attacks that is growing at a rate far exceeding the global average. But in both cases, the answer starts at the same point: knowing exactly what hardware and software assets an organization has deployed, who uses them, and what level of exposure each one represents.

Without an up-to-date and reliable asset inventory, no organization can assess the risk in its supply chain, report an incident within the timeframes required by NIS2, or quickly identify which systems are vulnerable to a ransomware attack. IT asset management (ITAM) is not a secondary administrative requirement: it is the foundation upon which any cybersecurity strategy is built, whether the goal is to comply with a European regulator or to withstand the pressure from threats that have made Latin America the global epicenter of ransomware today.

 

Do you really know which assets you need to protect?

With Proactivanet, you can discover 110% of your IT inventory, identify vulnerabilities before they turn into an incident, and make progress toward NIS2 compliance using real data—not assumptions.

Request a free demo and discover how to take the first step toward cybersecurity based on total visibility, whether you operate in Spain or Latin America.


Data sources: INCIBE (Cybersecurity Report 2025), Kaspersky (State of Ransomware 2026), Intel 471 (Latin America Cyber Threat Landscape, January 2026), Check Point Research, and ESET/ransomware.live (first half of 2026).

Subscribe to our Blog
Loading

CyberITAM and cost-effectiveness: The key to getting your cybersecurity budget approved

Increasing cybersecurity budgets in Latin America and Spain has become a...

AI in ITSM: 8 Real Capabilities (and What's Just Marketing)

AI in ITSM is everywhere... on paper. Virtually all providers claim...
Do you really know what software your company has installed? Here's how you can find out

Do you really know what software your company has installed? Here's how you can find out

The company's software inventory is something that few IT managers could...