Cybersecurity 2026

SPAIN Law and Practice Contributed by: Vicente Moret, Rodrigo González, María Teresa Martínez and Cristina Durante, Deloitte Legal

rity frameworks, requiring controls over training‑data pipelines, model integrity, inference processes, and continuous monitoring of system behaviour in produc - tion. For many organisations in Spain, these require - ments fall outside established cybersecurity practices and necessitate much closer co-ordination between legal, security, and data‑science teams. Additional complexity arises when AI systems also qualify as products with digital elements under the Cyber Resilience Act. In such cases, manufacturers and deployers must comply simultaneously with the CRA’s security‑by‑design obligations and the AI Act’s requirements related to robustness and cybersecu - rity. While the two frameworks partially overlap, they address different forms of risk: the CRA focuses on horizontal product security, whereas the AI Act targets risks linked to algorithmic behaviour and outcomes. Incident reporting demonstrates the operational challenge clearly. A cybersecurity incident affecting a high‑risk AI system may trigger parallel obligations under multiple frameworks: AI Act serious‑incident reporting, NIS2 notification where the deployer is an essential or important entity, GDPR breach notification if personal data is involved, and DORA reporting in the financial sector. These regimes operate on differ - ent timelines and require different types of informa - tion, making integrated incident‑response governance essential. From a data‑protection perspective, AI systems processing personal data must also comply with GDPR’s requirements for data protection by design and by default. Spanish supervisory practice empha - sises that technical measures addressing AI‑specific risks – such as inference of sensitive attributes or re‑identification through model outputs – are central to compliance. Overall, the AI Act, CRA, and GDPR together create a layered compliance architecture that requires co-ordinated governance rather than siloed implementation. 6.3 Cybersecurity in the Healthcare Sector Healthcare occupies a distinctive position within the cybersecurity regulatory landscape – not because it is governed by fundamentally different legal instruments, but because the consequences of cybersecurity fail -

ures are uniquely severe. In this sector, cyber incidents directly affect patient safety, clinical continuity and the delivery of essential public services. Disruptions that might be primarily economic in other industries can, in healthcare, lead to delayed treatment, compromised clinical decision‑making and risks to life. This reality increasingly shapes both EU‑level and Spanish regu - latory approaches. At EU level, the European Commission’s Action Plan on the Cybersecurity of Hospitals and Healthcare Providers (January 2025) reflects a clear recognition that horizontal frameworks such as NIS2, CER and the GDPR require sector‑specific operational support to be effective in healthcare environments. The Action Plan prioritises prevention, detection, response and deterrence, and aligns closely with Cyber Solidarity mechanisms, which designate healthcare as a priority sector for EU‑level incident response support. Healthcare as a Critical Entity Hospitals and healthcare networks designated as critical entities under CER and Spain’s reformed critical infrastructure framework must follow an integrated resilience model that combines physical security, cybersecurity, organisational measures and supply‑chain resilience. Designation brings a govern - ance shift: responsibility for resilience moves to the governing body, with accountability that cannot be delegated. This marks a departure from traditional approaches in which cybersecurity was treated as an IT function rather than a core governance and patient‑safety obligation. NIS2 Implementation Challenges in Healthcare Healthcare providers qualifying as essential entities under NIS2 face sector‑specific constraints. Many clinical systems operate on legacy platforms that cannot easily support modern security controls such as multi‑factor authentication or automated patch management. While these constraints do not reduce regulatory obligations, they significantly influence how compliance must be achieved. Compensating controls – such as network segmentation, enhanced monitoring, and accelerated replacement planning – therefore become central. Incident classification under NIS2 also has a distinct clinical dimension: any incident affecting the availability of clinical systems or

342 CHAMBERS.COM

Powered by