Banking Law And Critical Infrastructure Failures Spain .
Banking Law and Critical Infrastructure Failures in Spain
Spain’s legal response to banking failure and critical-infrastructure failure is best understood as two interconnected but distinct regimes:
- Banking crisis / bank failure law — solvency, liquidity, recovery, resolution, bail-in and protection of financial stability.
- Critical-infrastructure and ICT failure law — cyberattacks, system outages, disruption of payment/banking services, operational resilience and continuity.
The two regimes overlap because modern banking depends heavily on information systems, payment infrastructure, cloud providers, telecommunications and other essential services.
Important distinction: A bank can “fail” financially because it is insolvent or lacks liquidity, while a critical-infrastructure failure may occur even where the bank remains solvent—for example, a cyberattack that prevents customers from accessing accounts or disrupts payment systems.
1. Constitutional and institutional framework
The Spanish framework operates within the European Banking Union. For significant Spanish banks, the European Central Bank (ECB) has prudential supervisory responsibilities, while the Single Resolution Board (SRB) is central to resolution under the Single Resolution Mechanism.
At the national level, the principal institutions include:
- Banco de España — banking supervision and certain resolution-planning functions.
- FROB (Fondo de Reestructuración Ordenada Bancaria) — Spain's executive resolution authority.
- CNMV — supervision/resolution functions concerning investment firms.
- Ministry of the Interior / CNPIC — protection of critical infrastructure and cybersecurity coordination.
- INCIBE-CERT / CCN-CERT — cybersecurity incident response.
- ECB and SRB — especially important for significant institutions within the Banking Union.
The Spanish Ley 11/2015 expressly establishes FROB as the executive resolution authority and provides for Banco de España/ECB supervisory responsibilities.
2. Spanish Banking Recovery and Resolution Law
The central domestic statute is:
Ley 11/2015, de 18 de junio, de recuperación y resolución de entidades de crédito y empresas de servicios de inversión.
Its purpose is to regulate:
- early intervention;
- recovery planning;
- resolution planning;
- resolution of failing banks;
- protection of financial stability;
- minimisation of public expenditure;
- orderly restructuring or liquidation.
The statute expressly states that its purpose is to protect financial-system stability while minimising the use of public resources.
This is supplemented by EU law, particularly:
- Bank Recovery and Resolution Directive (BRRD);
- Single Resolution Mechanism Regulation (SRMR);
- Capital Requirements Regulation (CRR);
- Capital Requirements Directive (CRD);
- EU State-aid rules;
- deposit-guarantee legislation.
The European Commission describes the modern EU resolution system as designed to preserve critical functions, maintain financial stability and avoid reliance on taxpayer-funded bailouts.
3. What legally constitutes a banking failure?
A bank does not automatically enter resolution merely because it has financial difficulties.
Broadly, resolution requires three questions:
A. Is the institution “failing or likely to fail”?
This can arise from circumstances such as:
- inability to pay debts when due;
- serious liquidity deterioration;
- balance-sheet insolvency;
- regulatory capital problems;
- circumstances making failure imminent.
B. Are private-sector or supervisory alternatives reasonably capable of preventing failure?
Resolution is not intended to replace ordinary supervisory intervention whenever a problem can be solved privately.
C. Is resolution necessary in the public interest?
This is particularly important where ordinary insolvency would create serious risks to:
- financial stability;
- depositors;
- payment systems;
- credit provision;
- other banks;
- the wider economy.
This public-interest concept is fundamental to understanding the Banco Popular litigation.
4. Critical functions are legally different from the bank itself
One of the most important principles is that the objective of resolution is not necessarily to save the bank's shareholders or its existing corporate structure.
Instead, the law seeks to preserve functions that society cannot easily do without.
Examples include:
- deposit-taking;
- payment services;
- access to current accounts;
- clearing and settlement;
- lending functions;
- certain market infrastructure;
- essential banking IT systems.
This explains why a failing bank can be placed into resolution while important services continue.
The European Commission specifically identifies continuity of critical functions as one of the central objectives of the EU bank-resolution framework.
5. Major Spanish case: Banco Popular
Banco Popular Español — 2017
The most important Spanish banking-resolution case is undoubtedly the failure of Banco Popular Español S.A.
On 6 June 2017, the ECB determined that Banco Popular was “failing or likely to fail”, following a severe deterioration in its liquidity position. The next day, the SRB adopted a resolution scheme and the bank was transferred to Banco Santander.
The Spanish FROB subsequently adopted measures necessary to execute the EU resolution decision.
What happened legally?
The resolution involved:
- write-down of capital;
- conversion/write-down of certain capital instruments;
- transfer of the bank to Santander;
- preservation of critical banking functions;
- protection of depositors and financial stability.
The SRB concluded that:
- Banco Popular was failing or likely to fail;
- alternative measures were insufficient;
- resolution was necessary in the public interest;
- the sale-of-business tool was appropriate.
6. Case law: Del Valle Ruiz and Others v Commission and SRB
General Court, Case T-510/17
Antonio Del Valle Ruíz and Others v European Commission and Single Resolution Board, Case T-510/17, judgment of 1 June 2022.
This is a leading authority on the legality of the Banco Popular resolution.
The applicants challenged the resolution on several grounds, including:
- right to be heard;
- delegation of powers;
- right to property;
- reasoning of the resolution;
- legality of the resolution process;
- valuation of Banco Popular.
The General Court dismissed the action.
The Court therefore accepted the basic legality of the resolution framework and the authorities' decision-making in the circumstances.
The judgment is particularly important because it demonstrates the substantial judicial deference given to specialised EU resolution authorities where complex economic and financial assessments are involved.
The case is also important for understanding the relationship between property rights and financial stability: shareholders and subordinated creditors may suffer complete or substantial losses when a bank is resolved under the statutory resolution framework.
The case subsequently proceeded on appeal to the Court of Justice. The CJEU case reference is C-539/22 P.
7. Other Banco Popular cases
The Banco Popular litigation generated a substantial body of case law.
Important General Court proceedings included:
| Case | Main issue |
|---|---|
| T-481/17 | Challenges concerning the Banco Popular resolution |
| T-510/17 | Del Valle Ruiz — shareholders/investors and legality of resolution |
| T-523/17 | Challenges to resolution |
| T-570/17 | Algebris (UK) and Anchorage Capital Group |
| T-628/17 | Aeris Invest |
The General Court dismissed the actions challenging the Banco Popular resolution and/or Commission decision.
These cases collectively establish an important principle:
The legal protection of investors does not prevent authorities from imposing losses where resolution conditions are satisfied and the statutory safeguards are respected.
8. Right to property and bank resolution
A particularly difficult legal issue is the interaction between resolution powers and Article 17 of the EU Charter of Fundamental Rights, concerning the right to property.
Shareholders can argue:
“My shares were taken away without adequate compensation.”
But resolution law operates on a different principle:
shareholders bear losses before taxpayers do.
The legal system therefore balances:
Property rights
against
financial stability + depositor protection + continuity of critical functions.
The Banco Popular litigation is important because the General Court examined precisely this tension. The case title itself identifies the right to property as one of the legal issues.
9. “No creditor worse off” principle
Another major safeguard is the no creditor worse off than liquidation principle.
In simplified terms:
A creditor should not ultimately be placed in a worse economic position by resolution than the position that creditor would have occupied under ordinary insolvency, subject to the applicable legal framework.
This is crucial because resolution can involve:
- bail-in;
- cancellation of shares;
- conversion of debt into equity;
- transfer of assets/liabilities;
- sale of business.
It provides a judicial/economic safeguard against arbitrary destruction of creditor value.
10. Critical infrastructure law in Spain
The principal Spanish statute is:
Ley 8/2011, de 28 de abril
It establishes measures for the protection of critical infrastructures.
The concept is broader than banking.
Strategic sectors include areas such as:
- energy;
- transport;
- health;
- water;
- financial system;
- information technology;
- communications;
- other strategic infrastructure.
The financial system is therefore treated as part of Spain's strategic infrastructure framework.
11. Cybersecurity and essential services
Spain implemented the EU NIS framework principally through:
Real Decreto-ley 12/2018
This regulates the security of networks and information systems used to provide essential services and digital services.
It expressly connects the cybersecurity regime with Ley 8/2011 on critical infrastructure and identifies the financial system among the relevant strategic sectors.
This is extremely important for banking.
A bank can therefore face legal obligations arising from both banking regulation and cybersecurity/critical-infrastructure regulation.
12. Obligations of essential-service operators
Under the Spanish NIS framework, operators of essential services must adopt appropriate and proportionate measures to manage cybersecurity risks.
These include:
- risk assessment;
- security policies;
- preventive measures;
- incident management;
- recovery;
- business continuity;
- third-party/vendor risk management;
- notification of significant incidents.
Real Decreto 43/2021 develops these requirements and specifically requires appropriate technical and organisational measures, including policies based on risk management, prevention, response and recovery.
13. Third-party outsourcing is not a complete defence
This is particularly relevant to modern banking.
Suppose:
Bank X outsources its cloud infrastructure to Company Y.
If Company Y's systems fail and Bank X's customers cannot access their accounts, the bank cannot simply say:
“The failure was caused by our supplier.”
Spanish cybersecurity rules expressly contemplate risks arising from external providers. The Real Decreto 43/2021 requires operators to manage risks affecting systems used for their services, including systems operated through external providers.
This principle has become even more important under DORA.
14. DORA — Digital Operational Resilience Act
The EU's Digital Operational Resilience Act (DORA) is now central to financial-sector ICT resilience.
DORA addresses risks such as:
- cyberattacks;
- IT outages;
- software failures;
- cloud-provider failures;
- telecommunications disruption;
- operational incidents;
- ICT third-party concentration risk.
It applies to a broad range of financial entities.
DORA became applicable on 17 January 2025.
A notable current Spanish-law issue is that, as of the European Commission's 4 May 2026 implementation-status update, Spain had not notified national transposition measures for the related DORA implementing directive and infringement proceedings were pending concerning Spain.
That does not mean DORA itself is simply “not applicable” in Spain: an EU regulation is directly applicable. The national implementation issue principally concerns the accompanying directive and national supervisory/enforcement arrangements.
15. Banking + critical infrastructure = overlapping regimes
A useful way of understanding Spanish law is:
| Failure | Main legal regime |
|---|---|
| Bank becomes insolvent | Banking prudential/resolution law |
| Bank suffers liquidity crisis | ECB/Banco de España + resolution framework |
| Bank is “failing or likely to fail” | SRMR/BRRD + Ley 11/2015 |
| Shareholders lose their investment in resolution | Resolution law + EU Charter |
| Payment platform collapses | Operational/ICT + payment-system regulation |
| Cyberattack disables bank | DORA + cybersecurity rules |
| Critical infrastructure is attacked | Ley 8/2011 + cybersecurity framework |
| Cloud provider fails | DORA + outsourcing/ICT-risk requirements |
| Significant cyber incident | Incident-reporting obligations |
| Bank failure threatens financial stability | Resolution/public-interest mechanisms |
| Critical banking functions must continue | Resolution + operational-resilience law |
16. Case-law principle from Banco Popular
The Banco Popular litigation provides a particularly good illustration of the relationship between bank failure and critical functions.
The SRB did not simply ask:
“Can Banco Popular survive as a corporation?”
It asked whether resolution was necessary to maintain the bank's critical functions and avoid significant adverse effects on financial stability, particularly in Spain.
This is a major conceptual shift in modern banking law.
Traditional insolvency
The question is essentially:
How should the insolvent company be liquidated?
Bank resolution
The question becomes:
How can the failing institution be restructured while keeping the economically critical functions operating?
That distinction is fundamental to modern banking law.
17. Critical infrastructure failure without insolvency
Consider a hypothetical Spanish bank:
Banco X has:
- adequate capital;
- adequate liquidity;
- no insolvency problem.
But a ransomware attack destroys access to:
- core banking databases;
- ATMs;
- online banking;
- payment-processing infrastructure.
Millions of customers cannot access their money.
Legally, this is not necessarily a bank failure in the resolution-law sense.
Instead, it may constitute an:
ICT/operational/critical-infrastructure incident.
The relevant response may involve:
- incident detection;
- notification;
- activation of business-continuity plans;
- cyber incident response;
- restoration;
- regulatory supervision;
- protection of customers;
- investigation;
- potentially administrative sanctions.
If the operational failure subsequently creates a liquidity crisis—for example, because customers withdraw massive amounts—the incident can evolve into a banking stability event.
18. The “failure cascade”
This is one of the most important concepts for an examination answer.
A modern banking crisis can follow this chain:
Cyberattack
↓
ICT outage
↓
Payment-system disruption
↓
Customer confidence collapses
↓
Deposit withdrawals
↓
Liquidity crisis
↓
Emergency liquidity assistance
↓
Bank becomes unable to meet obligations
↓
“Failing or likely to fail” determination
↓
Resolution
↓
Sale / bail-in / transfer of critical functions
Thus, critical-infrastructure failure can become a banking-resolution problem.
Banco Popular provides a different but related example: its immediate resolution was driven by a severe liquidity deterioration and deposit outflows rather than a classic cyberattack. The ECB expressly identified the deterioration of liquidity as the basis for its failing-or-likely-to-fail determination.
19. Incident reporting and supervisory powers
Spanish cybersecurity law provides authorities with substantial supervisory powers.
For example, authorities can require operators to provide:
- security information;
- documentation concerning security policies;
- evidence of implementation;
- information concerning their security arrangements.
Authorities may also audit operators or require independent external audits.
Failure to implement required measures or repeatedly fail to report significant incidents can constitute administrative offences, including very serious offences in specified circumstances.
20. Liability issues
When critical banking infrastructure fails, several possible forms of liability can arise.
A. Regulatory liability
The bank may face sanctions for:
- inadequate risk management;
- failure to maintain controls;
- inadequate incident reporting;
- inadequate outsourcing controls;
- failure to comply with resilience requirements.
B. Civil liability
Customers or counterparties may potentially claim losses depending on:
- contractual obligations;
- negligence;
- applicable banking/payment law;
- causation;
- exclusions and force-majeure clauses.
C. Corporate/governance liability
Management may face scrutiny where there has been:
- inadequate risk governance;
- failure to maintain continuity plans;
- failure to address known vulnerabilities;
- inadequate oversight of outsourcing.
D. Criminal liability
In serious cases involving deliberate conduct, fraud, unauthorised access, destruction of data or other criminal conduct, Spanish criminal law may become relevant.
21. DORA's importance for directors and boards
The modern approach increasingly treats ICT risk as a board-level governance issue, rather than merely an IT department issue.
That means the legal question is no longer simply:
“Did the bank have cybersecurity software?”
Instead:
“Did the institution have an effective governance framework for identifying, managing, testing and recovering from ICT risks?”
Spain's securities legislation already incorporates sanctions for failures relating to DORA requirements, including ICT-risk management, incident-management processes, serious incident notification and business continuity.
22. NIS2 and Spain
Spain is also moving from the earlier NIS framework toward NIS2.
However, there is an important current-law point for a 2026 answer: the European Commission reported that Spain had not fully notified NIS2 transposition and had received a reasoned opinion concerning the failure to notify full transposition.
Therefore, an academically careful answer should not simply say “Spain has fully implemented NIS2.”
Instead, say:
Spain has an established cybersecurity and critical-infrastructure framework based principally on Ley 8/2011, Real Decreto-ley 12/2018 and Real Decreto 43/2021, while the transition to the NIS2 framework remains relevant at EU/national implementation level.
23. Key case-law propositions
For an examination or dissertation, the following propositions are particularly useful.
Banco Popular — T-510/17, Del Valle Ruiz
Principle: Resolution of a failing bank can lawfully result in the loss of shareholder interests where the statutory resolution conditions are satisfied and the measures pursue financial stability and continuity of critical functions.
Banco Popular — T-481/17, T-523/17, T-570/17 and T-628/17
Principle: The General Court rejected challenges to the Banco Popular resolution framework in the judgments issued on 1 June 2022.
Banco Popular resolution decision
Principle: “Failing or likely to fail,” absence of an adequate private alternative and public interest are central elements in determining whether resolution should occur.
24. Critical legal principles
The Spanish system can therefore be reduced to six major principles:
1. Financial stability
The banking system is treated as an area of systemic public interest.
2. Continuity of critical functions
The objective is to preserve essential banking services even if the bank itself cannot survive.
3. Bail-in rather than taxpayer bailout
Shareholders and certain creditors should absorb losses before public funds are used.
4. Operational resilience
Banks must be capable of preventing, absorbing and recovering from ICT disruption.
5. Accountability
Outsourcing ICT operations does not eliminate the institution's regulatory responsibilities.
6. Multi-level governance
Spanish banking failures are governed simultaneously by:
Spanish law + EU banking law + ECB supervision + SRB resolution + cybersecurity/critical-infrastructure law.
25. Conclusion
The Spanish approach to banking and critical-infrastructure failure has evolved from a traditional “insolvency and rescue” model into a sophisticated “resilience and resolution” model.
The Banco Popular crisis is the leading case study. It demonstrates that modern banking law prioritises:
financial stability → depositor protection → continuity of critical functions → minimisation of public funds → orderly resolution.
At the same time, the increasing dependence of banks on digital infrastructure means that cybersecurity and operational resilience are now inseparable from banking law. Spain's Ley 8/2011, Real Decreto-ley 12/2018 and Real Decreto 43/2021 provide the critical-infrastructure/cybersecurity architecture, while DORA provides the specialised EU financial-sector operational-resilience regime.
The most important doctrinal point is therefore:
A bank can fail because its balance sheet fails, but the financial system can also fail because the infrastructure on which banking depends fails. Spanish and EU law increasingly regulate both risks together, with the preservation of critical financial functions as the connecting principle.
Key authorities to cite
- Ley 11/2015, recovery and resolution of credit institutions and investment firms.
- Ley 8/2011, protection of critical infrastructures.
- Real Decreto-ley 12/2018, security of networks and information systems.
- Real Decreto 43/2021, implementing the Spanish NIS framework.
- Regulation (EU) No 806/2014, Single Resolution Mechanism.
- Directive 2014/59/EU, BRRD.
- Regulation (EU) 2022/2554, DORA.
- T-510/17, Del Valle Ruíz and Others v Commission and SRB, ECLI:EU:T:2022:312.
- T-481/17, T-523/17, T-570/17 and T-628/17, Banco Popular-related litigation.
- C-539/22 P, appeal concerning Del Valle Ruíz.

comments