The figures reflect this new reality. According to the 2025 Report on Cybercrime in Spain, published by the Ministry of the Interior, 488,426 cybercrimes were recorded last year, 5.1% more than in 2024, now representing 19.8% of all crime recorded in the country. Furthermore, the number of victims increased by 9.3%, exceeding 383,000 people.
At the same time, the widespread use of artificial intelligence is changing the nature of these threats. IBM's latest Cost of a Data Breach Report warns that the accelerated adoption of AI is expanding organizations' attack surface and that the lack of specific controls over these environments has already become a new risk factor for businesses.
The problem is no longer detecting an attack
Over the past few years, companies have invested millions of euros in cybersecurity tools. EDR solutions, SIEM platforms, next-generation firewalls, cloud protection, and threat intelligence are now part of the daily operations of most organizations.
However, having more technology doesn't necessarily mean being better protected.
Most companies are already capable of detecting anomalous behavior, suspicious access, or attempted attacks. However, the real challenge begins when an alert appears and someone must decide, in a matter of minutes, whether it's a false positive or an incident capable of jeopardizing business continuity.
In a context where attackers are continually reducing the time needed to compromise an infrastructure, responsiveness has become the new indicator of maturity in cybersecurity.
“Organizations already have tools capable of generating alerts. What makes the difference is having a team that analyzes them, determines their criticality, and acts in a coordinated manner when a threat actually exists,” explains Álvaro Sánchez, Security Presales at h&k.
From excessive alerts to operational intelligence
One of the biggest challenges IT teams face today is technological fragmentation. Networks, cloud infrastructures, SaaS applications, digital identities, connected devices, and solutions from different manufacturers generate thousands of security events daily that must be analyzed together to understand what is really happening.
This complexity is driving a paradigm shift. Organizations are no longer just looking for new tools, but for capabilities that allow them to monitor, correlate information, and respond continuously.
In this sense, Security Operations Centers (SOCs) are becoming established as one of the pillars of enterprise cybersecurity strategy.
A SOC to respond when every minute counts
With the aim of helping organizations face this new scenario, h&k has reinforced its managed services offering with a Security Operations Center (SOC) that combines continuous monitoring, threat intelligence, automation and specialized incident response.
The service integrates information from multiple technologies (SIEM, EDR, cloud platforms, identity systems, and firewalls) to offer a single platform with a unified view of risk, significantly reducing detection and response times. It also incorporates automated processes and a team of specialized analysts who validate each incident before taking the necessary actions to contain the threat.
"Cybersecurity can no longer be limited to generating alerts. Organizations need operational capacity to act, escalate incidents, apply response procedures, and support the customer throughout the entire process. That's where real value is added," says Carlos Gutiérrez, Go-To-Market Director at h&k.
From reactive cybersecurity to digital resilience
The rise of AI has increased the sophistication of attacks and reduced organizations' ability to react. In this new landscape, the difference is no longer determined by who has more tools, but by who can identify a threat first and act in a coordinated manner to contain it.
Therefore, Security Operations Centers (SOCs) have ceased to be a capability reserved for large corporations and have become a strategic element that allows companies of any size to strengthen their digital resilience and protect business continuity in the face of an increasingly dynamic threat environment.
