Wednesday, 30 September 2026

diarioempresas

IBEX 3519.476,10▼ -0,21%EuroStoxx 506280,82▼ -0,62%S&P 5007715,53▲ +0,58%€/$1,1353▲ +0,05%Brent98,68▲ +2,62%Bitcoin73.834▲ +0,13%
Breaking

CCN-CERT demands administrations to self-assess their defence against offensive AI

CCN-CERT requests ENS entities to complete a self-assessment form to measure their response capability against AI attacks.

Álvaro Sáez Ferrer
Álvaro Sáez Ferrer
· 3 min read

The National Cryptological Centre asks entities of the National Security Scheme for a self-assessment form to measure their response capability against AI attacks. This measure comes after the first breach in Spain executed by an autonomous agent.

The National Cryptological Centre (CCN-CERT) has requested that entities subject to the National Security Scheme (ENS) complete a self-assessment form to understand their actual capacity for prevention, detection, and response to cyberattacks, as reported by El Confidencial Digital. The request follows the Spanish Data Protection Agency (AEPD) receiving in September the first notification of a breach executed by an artificial intelligence agent in Spain.

The form must be coordinated with the Security Officer of each organisation, and the results must be submitted to the Information Security Committee. With this data, CCN-CERT aims to incorporate the identified risks into the risk analysis, improvement plans, and follow-up audits of the ENS.

The guide BP/36, published by CCN-CERT in June 2026, identifies the vectors that administrations must review. These include social engineering and advanced phishing generated by AI, deepfakes impersonating executives in video calls, voice cloning to authorise sensitive operations, the protection of credentials and tokens with excessive permissions, the integrity of documents and communications, and dependency on technology providers.

"Any company that does not have this in mind will suffer," warned Eloy Rafael Sanz Tapia, head of the Cybersecurity service at the Andalusian Digital Agency (ADA), during the forum "Offensive AI vs. Defensive AI: the challenge of protecting essential services," organised by EL ESPAÑOL-Invertia and the Oesía Group in Seville.

At the same forum, Ana María Chups Rodríguez, head of cybersecurity operations in the Southern Zone of Cipherbit – Oesía Group, pointed out that attackers use AI to reduce the time between exploiting a vulnerability and the impact on the organisation. Speed is no longer measured in days but in minutes, which forces a rethink of the public sector's defence model.

CCN-CERT has also called for an update to the Law 9/2017 on Public Sector Contracts to incorporate cybersecurity criteria and align with the NIS2 directive, according to demands made by representatives of the Andalusian Government, Emasesa, and CCN-CERT itself.

The agency published the BP/36 guide after detecting an increase in AI-related attacks. In November 2025, hackers linked to China used Claude Code to attack about 30 targets worldwide, with AI performing between 80% and 90% of the work. In September 2026, Adif and Renfe suffered an attack attributed to a criminal group that allegedly used a similar system.

Administrations have until the Information Security Committee of each organisation receives the results to incorporate them into improvement plans. CCN-CERT has urged the completion of the form as soon as possible to assess the situation before new incidents occur.

Álvaro Sáez Ferrer

Written by

Álvaro Sáez Ferrer

Redactor

Economista por ICADE y una de las pocas personas que disfruta leyendo la ley de presupuestos. Cafetero, padre a tiempo completo y azote de la letra pequeña; en Diario Empresas escribe de economía y fiscalidad.