An operational guide to the 19 most frequent security incidents in a company. A reference manual written for the day the incident is already happening: what to do before, what to do during and what to do afterwards, incident by incident.
Please note: the book is written in Spanish and published in Spain. The outline below is translated for reference.
Most cybersecurity literature explains how attacks work. This book starts from a different assumption: you already know they exist, and what you need is a procedure you can open at the right chapter on the day it happens to you.
Book details
- Authors: Juan M. and Fernando Romero Urdiain
- Publisher: FC Editorial · Fundación Confemetal
- Pages: 400
- ISBN: 978-84-10315-58-7
- Language: Spanish
- Format: paperback
What it covers
Each of the nineteen chapters follows the same structure: characterisation of the attack, preventive actions, corrective actions while the incident is still unfolding, and post-incident actions including the regulatory side. That repetition is deliberate — it turns the book into a reference manual rather than an essay to be read end to end.
The procedures are aligned with the NIST Cybersecurity Framework 2.0 and with the obligations that actually bind a company operating in Spain and the EU: GDPR, NIS2, DORA, the Spanish National Security Framework (ENS) and ISO 27001. The selection of incidents is not an opinion: it comes from the annual reports of ENISA, INCIBE-CERT, the Verizon DBIR and IBM Cost of a Data Breach.
And a caveat the book makes explicit: it does not promise immunity. It promises that, when it happens, you know what to do in the first minutes — which is where the scope of the damage is decided.
The 19 incidents
- Ransomware with data exfiltration
- Data breach with exfiltration
- Use of pirated software
- Backups: the last line of defence
- Denial of service (DoS and DDoS)
- Phishing, social engineering and impersonation
- Password cracking
- Brute force and dictionary attacks
- Man-in-the-middle attacks (software and hardware)
- Infected devices (USB, microSD and others)
- Public Wi-Fi and working on the move
- Insider threats
- Physical attack devices (Hak5 and similar)
- Email hijacking and Business Email Compromise
- Hijacking of corporate social media accounts
- Loss or theft of a smartphone
- Loss or theft of storage devices
- Data loss prevention (DLP) programme
- Cybersecurity maturity of the organisation
Who it is written for
- Systems and IT managers who are, in practice, the security owners of their company.
- Executives and boards who need to understand which decisions they will be asked to take during an incident.
- Consultants and auditors looking for tested procedures to work from.
- Students and practitioners who want the operational side, not only the theory.
Where to get it
The book is sold directly by the publisher: Ciberseguridad: protocolos y procedimientos prácticos — FC Editorial, where you can also read the full table of contents and the opening pages.
From the book to your company
The book explains the procedure. If what you need is someone to run it, that is exactly what we do:
- Incident response and ransomware post-mortem, when it has already happened.
- Digital forensics and expert evidence, when it has to be proven.
- Cybersecurity consulting and security master plan, when it is time to put things in order before it happens.
Write to info@jaymonsecurity.com or call +34 686 250 244.
The authors
Juan M.. Court-appointed computer forensics expert with more than fifteen years in cybersecurity. He has led Red Team and Blue Team operations, and signs and ratifies expert reports before the courts. He leads Jaymon Security.
Fernando Romero Urdiain. Computer engineer from the Universidad Politécnica de Madrid and PMP-certified, with more than twenty years managing projects, mainly in the public sector.


