#

Izertis places SEPE as a model of progress and resilience in public cybersecurity

Izertis places SEPE as a model of progress and resilience in public cybersecurity

Five years after the cyber incident it suffered in March 2021, Spain’s State Public Employment Service (SEPE) has reached a high level of cybersecurity maturity. This progress was presented at TIC Ciber 2026, held on 11 June at the National Institute of Public Administration (INAP), during a session in which Izertis and SEPE shared the key milestones of a journey defined by recovery, continuous improvement and public-private collaboration.

The event brought together leading cybersecurity decision-makers from across the public sector. In this context, Izertis presented a success story focused on SEPE’s transformation following an incident that occurred at a particularly challenging time: during the pandemic, when the organisation was playing a critical role in the management of furlough schemes (ERTEs).

Izertis is already working, under the supervision of the CCN, in areas linked to government

The situation demanded not only a strong technical response, but also exceptional coordination, continuity and the ability to steer the organisation through a highly pressured environment.

Drawing on a retrospective analysis of the actions undertaken during the recovery phase and the years that followed, Izertis demonstrated how that turning point became the catalyst for a sustained programme to strengthen SEPE’s cybersecurity capabilities.

Under the leadership of Spain’s National Cryptologic Centre (CCN) and through a continuous service model, SEPE has steadily advanced its security assessment processes. This progression has enabled the organisation to move from initial evaluations to more sophisticated activities, including offensive security testing conducted from an attacker’s perspective.

The objective of this approach is clear: to gain a deeper understanding of potential vulnerabilities, anticipate risks and strengthen system resilience before threats can materialise. The aim is not simply to restore normal operations after an incident, but to build a stronger, better-prepared and more adaptable model capable of responding to an ever-evolving threat landscape.

The aim is to build a more robust, better-prepared and more adaptable model

During the session, speakers highlighted that one of the key principles of cybersecurity is understanding it as an ongoing process requiring constant review, rather than as a fixed destination.

It also demands avoiding complacency, particularly in public-sector organisations that provide essential services to citizens.

The session concluded with remarks from Angelines Turón, Deputy Director General for ICT at SEPE, who expressed her appreciation for the collective effort undertaken by the organisation’s staff and partners such as the CCN and Izertis. She emphasised the work carried out to overcome a particularly complex situation and highlighted the significant progress achieved over recent years.

The SEPE case demonstrates how a crisis can become an opportunity to raise protection standards, consolidate new capabilities and foster a more mature cybersecurity culture. It also reinforces the principle that safeguarding public services requires continuity, collaboration and proactive risk management.

Protecting public services requires continuity, collaboration and foresight

In line with this approach, Izertis is already working, under the supervision of the CCN, on new initiatives related to the governance and secure adoption of artificial intelligence within SEPE.

This marks a further step in a strategy that looks beyond recovery and positions cybersecurity as a fundamental pillar of the secure transformation of public administrations.

Through this project, Izertis further strengthens its position as a strategic cybersecurity partner for the public sector, particularly in environments where trust, resilience and rapid response capabilities are essential.

You may also be interested in these contents