← Back to the cybersecurity blog

CyberMadrid's second SME Cybersecurity Congress: AI, suppliers and the human factor

By Adrián González · CEO y socio fundador · Published: 30 September 2026 · Updated: 30 September 2026
Round table speakers on stage at CyberMadrid's second SME Cybersecurity Congress

On Tuesday 29 September, Digitaliza Madrid hosted the second SME Cybersecurity Congress organised by CyberMadrid, the Madrid cybersecurity cluster, with tickets sold out. Hard2bit took part as a member of the cluster and a Silver sponsor, with a stand in the exhibition area, and our COO and technical security director, Thilina Manana, spoke on the round table about the human factor and the supply chain.

Who backed the second SME Cybersecurity Congress?

The congress had institutional support from Madrid City Council's Cybersecurity Centre and the Cybersecurity Agency of the Community of Madrid, part of the regional government, whose logos headed the auditorium screen. Below them were those of the Madrid Chamber of Commerce, Madrid Network and CEIM, the Madrid business confederation.

Agustín Muñoz-Grandes, president of CyberMadrid, spoke for the organisers.

Agustín Muñoz-Grandes, president of CyberMadrid, speaking at the SME Cybersecurity Congress
Agustín Muñoz-Grandes, president of CyberMadrid, during his address.

For the institutions, the speakers were Alfonso Alcalá, Deputy Director General of Operations at the Cybersecurity Agency of the Community of Madrid, and Mabel González, head of Cybersecurity Culture at Madrid City Council's Cybersecurity Centre.

Alfonso Alcalá of the Cybersecurity Agency of the Community of Madrid speaks from the lectern
Alfonso Alcalá, Deputy Director General of Operations at the Cybersecurity Agency of the Community of Madrid.
Mabel González of Madrid City Council's Cybersecurity Centre speaks from the lectern at the congress
Mabel González, head of Cybersecurity Culture at Madrid City Council's Cybersecurity Centre.
Alfonso Alcalá, Mabel González and Agustín Muñoz-Grandes at the SME Cybersecurity Congress
Alfonso Alcalá (Cybersecurity Agency of the Community of Madrid), Mabel González (Madrid City Council) and Agustín Muñoz-Grandes (CyberMadrid).

Our CEO, Adrián González, and Thilina Manana also talked with Alfonso Alcalá at the Hard2bit stand.

Adrián González and Thilina Manana of Hard2bit talk with Alfonso Alcalá by the Hard2bit stand
Adrián González and Thilina Manana (Hard2bit) talking with Alfonso Alcalá by the Hard2bit stand.

Which themes did Thilina bring to the panel on people and suppliers?

The panel, titled "The human factor: employees, suppliers and the supply chain, the most vulnerable link", was moderated by Víctor Villagrá, deputy director of the ETSIT engineering school at the Universidad Politécnica de Madrid, and brought together Nicolás Ballesteros, Account Executive at Formalize, Bernardino Cortijo, CEO of Dacor Intelligence, and Thilina Manana. He focused on four themes: the state of cybersecurity in SMEs, the new challenges that artificial intelligence brings, the supply chain, and the main risks and how to tackle them.

Thilina Manana of Hard2bit speaks on the round table about the human factor and the supply chain
Thilina Manana (Hard2bit) during the round table, alongside the moderator and the other panellists.

The sections below set out our position on each of those four themes. They do not report what was said on the panel.

Few hands, many fronts

A company with twenty to fifty staff does not usually have anyone working on security full time. Decisions fall to whoever looks after IT, often an outside provider. And security competes with every other priority. The measures that hold up are the ones that do not need a team to keep them going: multi-factor authentication on email and remote access, isolated backups, automatic patching and a written plan for the day something goes wrong. Our cybersecurity service for SMEs starts from that premise.

AI makes attacks cheaper

Artificial intelligence has invented few new techniques; above all, it has made the old ones cheaper. A fraudulent email arrives free of mistakes and in the tone of a regular supplier, a phone call can mimic an executive's voice with a deepfake, and hunting for flaws can be automated. This month Spain's data protection authority (AEPD) reported the first breach notification it has received for an attack carried out through an AI agent.

Add to that the unsanctioned use of AI tools inside the business, known as shadow AI, through which data can leave without anyone deciding to share it.

The supplier as a way in

A supplier with remote access to the ERP or the file server is, in effect, one more employee. The difference is that often nobody has trained or supervised them. A supply chain attack gets in through the supplier's defences and can reach the SME with legitimate credentials. In the incident at the Spanish rail companies Adif and Renfe on 24 and 25 September, according to Renfe, attackers used previously compromised Adif servers interconnected with Renfe's systems.

Many SMEs fall outside NIS2, but many of their larger customers are within scope, and they are starting to require controls by contract, as we explain in NIS2 for supplier SMEs.

The main risks and how to tackle them

Three routes in come up again and again in the SME incidents we handle: tricking a person, stolen or reused credentials, and third-party access with more permissions than needed. All three can be reduced at modest cost. The condition is that someone owns the job of keeping the measures in place.

Where should an SME start?

Four steps a small business can take this quarter, in order of the risk they reduce:

  1. Multi-factor authentication on email, VPN and every remote access route, starting with management and admin accounts.
  2. An inventory of suppliers with access to your systems, recording what they can reach and who approved it, using third-party risk management as the framework.
  3. Hands-on training against phishing and social engineering, with examples that include AI-generated voice and text; our cybersecurity training works with cases like these.
  4. An internal rule on which AI tools can be used, and with what data.

Hard2bit's stand was staffed by Álvaro Cruz, head of Managed Security, and Belén González, head of Administration.

Álvaro Cruz and Belén González staff the Hard2bit stand while Adrián González and Thilina Manana review a leaflet
Álvaro Cruz and Belén González at the Hard2bit stand, with Adrián González and Thilina Manana.

Our thanks to CyberMadrid for organising the congress, to Digitaliza Madrid for hosting it and to everyone who stopped by the stand. If you left with a question, get in touch through the website and we will look at it properly.

Job titles and the round table line-up reflect the information available on the day of the congress. The sections on each theme set out Hard2bit's position and do not report what the speakers said. Photographs: CyberMadrid.

Frequently asked questions

When and where was the second SME Cybersecurity Congress held? ▾

On Tuesday 29 September 2026 at Digitaliza Madrid (calle de Embajadores, 181, Madrid). It was organised by CyberMadrid, the Madrid cybersecurity cluster, and tickets sold out.

Which institutions backed the congress? ▾

Madrid City Council's Cybersecurity Centre and the Cybersecurity Agency of the Community of Madrid, together with the Madrid Chamber of Commerce, Madrid Network and CEIM, whose logos appeared on the auditorium screen. The speakers included Agustín Muñoz-Grandes, president of CyberMadrid, Alfonso Alcalá, Deputy Director General of Operations at the regional Cybersecurity Agency, and Mabel González, head of Cybersecurity Culture at Madrid City Council's Cybersecurity Centre.

What was Hard2bit's role at the congress? ▾

Hard2bit took part as a member of CyberMadrid and a Silver sponsor, with a stand in the exhibition area. Its COO, Thilina Manana, spoke on the round table about the human factor, suppliers and the supply chain.

Which themes did Thilina Manana cover on the human factor and supply chain panel? ▾

Thilina Manana covered the state of cybersecurity in SMEs, the new challenges AI brings, the supply chain, and the main risks and how to tackle them. The panel, moderated by Víctor Villagrá (ETSIT, Universidad Politécnica de Madrid), also included Nicolás Ballesteros (Formalize) and Bernardino Cortijo (Dacor Intelligence).

What new challenges does AI bring to SME cybersecurity? ▾

AI has invented few new techniques, but it makes existing ones cheaper: fraudulent emails free of mistakes and in a regular supplier's tone, voice impersonation and automated hunting for flaws. On top of that comes the unsanctioned use of AI tools inside the business, through which data can leave without anyone deciding to share it.

Where can an SME start reducing its risk? ▾

With multi-factor authentication on email and remote access, an inventory of the suppliers that can get into its systems, hands-on training against phishing and social engineering that includes AI-generated examples, and an internal rule on which AI tools can be used and with what data.

Want a straight answer on scope, priorities and price?

Most organizations reach us mid-question: something needs fixing, nobody has scoped it, and finance wants a number. Thirty minutes with a technical consultant — not a salesperson — gets you a defined scope, priorities ranked by risk and a price range. With what comes out of that call, we turn it into a fixed proposal. We work with organizations in Spain, across the EU and in LATAM.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours