Computer Sabotage in Public Administrations and Emergency Contracts under the LCSP

Padlock on a computer keyboard representing cybersecurity and cyber sabotage in the public sector.

Cyberattacks against Spanish public bodies have intensified in recent years, jeopardizing the continuity of essential services and exposing critical vulnerabilities in the State’s digital infrastructure. From denial-of-service attacks to sophisticated ransomware programs, massive hacks and actions by organized hackers that encrypt entire databases, Public Administrations face a permanent threat that requires agile and effective legal responses.

When computer sabotage, a hack, or a hacking attack paralyzes critical systems—such as municipal tax management, the census, local health services, or electronic administrative processing—especially in city councils and local entities, public officials must act immediately. In this context, the emergency contract regulated in Article 120 of Law 9/2017, of November 8, on Public Sector Contracts (LCSP) emerges as a fundamental legal tool that allows for contracting without following ordinary bidding procedures.

At IN DIEM Abogados, we regularly advise city councils and Public Administrations on the legal management of cybersecurity incidents, hacks, and computer attacks, analyzing when a cyberattack can legally justify an emergency contract, what requirements must be met, what risks its improper use entails, and how to correctly document the file to pass subsequent auditing.

What is considered computer sabotage in the Public Administration?

The computer sabotage constitutes a specific form of cyberattack aimed at deliberately damaging, altering, or disabling computer systems. Unlike other digital threats, sabotage seeks to cause direct harm to the operability of systems, causing service interruptions, data destruction, or blocking access to critical resources.

In administrative practice, these scenarios usually materialize through hacks executed by individual hackers or organized groups, who exploit technical vulnerabilities to gain illicit access to public systems. Although terms like hack or hacking are used in common language, from a legal point of view, only those attacks that cause serious and deliberate damage to systems can be classified as computer sabotage.

Legally, the Spanish Penal Code criminalizes these acts in Articles 264 and following, punishing anyone who “by any means, without authorization and in a serious manner, deletes, damages, deteriorates, alters, suppresses, or makes inaccessible data, computer programs, or electronic documents belonging to others”. When these attacks affect critical infrastructures or essential services of Public Administrations, the penalties are considerably increased.

It is important to distinguish between concepts that, although related, are not identical.

  • A cyberattack is any malicious action against computer systems (phishing, malware, unauthorized intrusions).
  • Computer sabotage implies a specific intent to cause serious harm and destabilize operations.
  • On the other hand, a security incident may include technical failures, human errors, or lower-impact attacks that do not necessarily constitute sabotage.

The National Institute of Cybersecurity (INCIBE) and the National Cryptologic Center – Government CERT (CCN-CERT) are the official bodies that coordinate the response to these incidents in the Spanish public sector, providing alerts, forensic analysis, and action protocols for critical threats.

Most frequent types of computer sabotage, hacks, and hacking attacks

  • Ransomware: Encryption of critical data with a demand for a financial ransom for its recovery.
  • Denial-of-service (DDoS) attacks: Server saturation that prevents access to electronic headquarters and public services.
  • Database destruction: Deletion or corruption of administrative information and essential records.
  • Manipulation of sensitive data: Alteration of tax, health, or administrative information with a direct impact on citizens.
  • Unauthorized access to internal systems: Intrusions into public networks for the theft of confidential information or operational sabotage.
  • Blocking of critical digital infrastructures: Paralysis of key systems such as tax management, justice, healthcare, or municipal census.

Impact of computer sabotage on public services

The consequences of computer sabotage in a Public Administration go far beyond the technical sphere. The interruption of systems can prevent the provision of essential services to citizens, affecting fundamental rights and generating serious social and economic harm.

An attack that blocks a hospital’s systems compromises the safety of patients. Sabotage in a tax administration can paralyze collection and file management. The failure of judicial platforms delays proceedings and violates the right to effective judicial protection.

The risks to personal data are equally critical. Administrations safeguard sensitive information of millions of citizens—health data, tax information, criminal records, data on minors—whose exposure or destruction constitutes a violation of the General Data Protection Regulation and Organic Law 3/2018 on Data Protection and Guarantee of Digital Rights. The Spanish Data Protection Agency can impose million-euro fines for non-compliance resulting from inadequate management of security breaches.

Given this scenario, the Administration has the obligation to act quickly to restore services, which justifies the use of exceptional procurement mechanisms when legal requirements are met.

And it is important to understand that, from an administrative perspective, the officials of the affected body assume direct responsibility for the crisis management. Inaction or an inadequate response can generate financial liability toward injured third parties and, in serious cases, personal liability for public managers.

In the local sphere, city councils are especially vulnerable to this type of hacking, as they manage multiple essential services with limited technical resources. The paralysis of municipal electronic headquarters, administrative registries, or economic management systems can directly affect thousands of citizens, reinforcing the need for a correctly articulated immediate legal and technical response.

The emergency contract in the Public Sector Contracts Law

The Article 120 of the LCSP regulates the emergency contract as an exceptional procedure that allows for contracting without following ordinary procedures when it is necessary to act immediately in the face of catastrophic events, situations of grave danger, or needs that do not allow for delay.

This type of contract allows for the direct awarding of works, services, or supplies without prior bidding, without publicity, and without the usual deadlines. Its purpose is to guarantee an immediate response when the urgency is incompatible with ordinary procurement procedures.

However, its use is subject to very clear limits. The emergency contract can only cover what is strictly necessary to address the critical situation and for the essential duration. Furthermore, even if there is no prior bidding, the expenditure is subject to subsequent auditing by the control bodies.

When can a cyberattack justify an emergency contract?

Nevertheless, this extraordinary power is subject to strict limits. Emergency procurement can only be used for what is strictly necessary during the essential time to resolve the urgent situation. The LCSP establishes that these contracts cannot exceed four months, although they may be extended for another four in duly justified exceptional cases. Additionally, the price must be reasonable and in line with the market, avoiding the unjustified enrichment of the contractor due to the situation of necessity.

Transparency and accountability are safeguarded by the obligation to immediately communicate the processing of the file to the competent fiscal control body, which will subsequently audit the fulfillment of legal requirements and the adequacy of the expenditure. This subsequent auditing constitutes an essential control over the use of exceptional mechanisms that involve a temporary breach of the ordinary principles of competition and publicity.

Can a cyberattack justify an emergency contract?

A computer sabotage can legally justify an emergency contract provided that three essential requirements are met simultaneously.

  1. Firstly, there must be an objective emergency situation, characterized by its severity, unpredictability, and capacity to paralyze essential public services.
  2. Secondly, it must be proven that it is impossible to use an ordinary procedure or even an urgent one without aggravating the damage or unacceptably delaying the recovery of the service. Not all security incidents allow for emergency procedures; only those that require immediate action.
  3. Finally, there must be a direct relationship between the attack suffered and the services contracted. The services must be aimed at containing the incident, recovering systems, forensic analysis, or restoring operability, not at structural improvements that can be put out to tender later.

The Administration must exhaustively document these circumstances, as the burden of proof lies with the contracting body.

Fundamental difference between urgency and emergency

It is essential to distinguish between urgency and emergency. Urgency, regulated in Article 119 of the LCSP, allows for the acceleration of deadlines but maintains the basic guarantees of the procurement procedure. Emergency, on the other hand, enables the bypassing of those procedures in exceptional situations. A security incident that requires rapid action but can be managed through an ordinary urgent procedure does not justify resorting to an emergency contract.

Legal risks of improper use of the emergency contract

The incorrect use of the emergency procedure entails serious legal consequences for both the Administration and the officials who make the decision. Fiscal control bodies, especially the Court of Auditors and regional and local audit departments, examine these files with particular rigor precisely because of their exceptional nature.

  • Declaration of nullity of the contract

If the subsequent audit determines that the legal requirements to use the emergency procedure were not met, the contract may be declared null and void for violating mandatory rules.

Although this nullity does not prevent the contractor from receiving the amount corresponding to the services already executed—to avoid unjust enrichment—it does cause significant administrative, legal, and reputational problems for the Administration.

  • Responsibility of the contracting body

Public officials who irregularly process an emergency contract may incur accounting liability when their actions cause financial harm to the public treasury.

The Court of Auditors may demand the reimbursement of the amounts improperly paid, along with the corresponding interest.

In cases of gross negligence or bad faith, criminal liabilities may even arise, such as crimes of embezzlement or malfeasance.

  • Disqualifications and professional consequences

Irregular procurement can lead to disqualifications from holding public office, as well as disciplinary sanctions for the officials involved. These consequences directly affect the professional careers of public managers.

  • Obligation to indemnify injured third parties

If it is proven that the improper use of the emergency procedure unjustifiably prevented competition, the Administration may be forced to indemnify third parties who were harmed.

  • Challenges by excluded companies

Companies that did not participate in the emergency contract cannot challenge it if the emergency was correctly justified.

However, they can do so when they manage to demonstrate that a real emergency situation did not exist, opening the door to appeals and claims with significant legal consequences.

The importance of correctly documenting every step of the file is crucial. The file must contain a detailed technical report on the incident and its severity, a legal opinion on the appropriateness of the emergency procedure, proof of the impossibility of using other channels, justification for the choice of contractor, and complete documentation of all actions taken. This documentation not only fulfills formal requirements but also constitutes essential evidence in the event of a subsequent audit.

Opportunities for technology companies and public sector providers

Emergency contracts resulting from cyberattacks represent a significant opportunity for companies specialized in cybersecurity, system recovery, and digital forensic analysis. However, these opportunities are only sustainable if one acts with rigor, transparency, and market-adjusted prices.

In critical situations, Administrations usually turn to providers with proven experience and immediate response capacity. Therefore, prior preparation, certifications, and knowledge of the legal framework of public procurement are decisive.

Most demanded services in cyberattack emergencies

  • Digital forensic analysis to determine the origin, scope, and authorship of the attack
  • Immediate recovery of compromised systems through backup restoration or infrastructure reconstruction
  • Urgent implementation of security patches and critical updates
  • Temporary reinforcement of infrastructure through cloud services or backup servers
  • Intensive monitoring of systems during the critical period
  • Specialized technical advice for decision-making during crisis management

For provider companies, it is essential to understand that the absence of bidding does not imply an absence of controls. Although the emergency procedure bypasses publicity and competition, the contractor must scrupulously fulfill all contractual obligations, exhaustively document their actions, and adjust their fees to market criteria. Abusive prices or deficient services can lead to financial claims and future disqualifications from contracting with the public sector.

Importance of specialized legal advice

Prior legal advice constitutes a strategic investment for both companies and Administrations. Technology providers must have specialized advice in public procurement to properly structure their offers, know their rights and obligations, and correctly manage contractual documentation. This advice also allows for the identification of legitimate opportunities for collaboration with the public sector beyond emergencies, through framework agreements, dynamic acquisition systems, or ordinary procedures that guarantee a stable and predictable contractual relationship.

How Can IN DIEM Help You?

IN DIEM Abogados provides specialized legal advice to city councils and public sector entities in the management of cybersecurity incidents, hacks, and computer sabotage, accompanying contracting bodies from the initial phase of the crisis to the correct processing and defense of the emergency procurement file.

The technical and legal complexity of emergency contracts due to cyberattacks requires highly specialized advice that integrates deep knowledge of public procurement, digital law, and cybersecurity. Firms with experience in this field can provide value to both contracting Administrations and provider companies.

For Public Administrations, preventive legal advice is fundamental for designing action protocols for critical incidents that allow for an agile response without incurring irregularities. This includes the preparation of contingency plans that identify in advance which services would be critical in the event of a cyberattack, which providers could act quickly, and what documentation must be prepared to justify the emergency.

During crisis management, legal support allows for the correct processing of the emergency file, ensuring that all legal requirements are met, that the supporting documentation is solid and complete, and that the decisions made are defensible before control bodies. This assistance includes drafting legal reports, reviewing technical proposals, negotiating contractual conditions, and supervising the fulfillment of formal obligations.

The subsequent review of the file constitutes another high-value service. An independent legal analysis before the official audit allows for the identification of documentary weaknesses, the correction of formal deficiencies, and the preparation of defensive arguments against possible objections. This preventive review significantly reduces the risks of subsequent questioning and facilitates passing fiscal controls.

For technology and consulting companies, specialized advice allows for an understanding of the specific demands of the public sector, adapting their business models to the particularities of administrative contracting and properly managing contractual relationships with public bodies. This includes designing commercial strategies compatible with procurement regulations, preparing solid technical-legal offers, and managing contractual incidents.

The experience accumulated in real cases allows these firms to offer a practical approach based on precedents, resolutions from advisory bodies, and consolidated administrative doctrine. This applied knowledge is especially valuable in a field where case studies are decisive and where small nuances in documentation or procedure can make the difference between an impeccable file and a questionable one.

If a Public Administration, especially a city council, faces a cyberattack, hack, or serious computer security incident, or needs specialized legal advice on public procurement, emergency contracts, and digital law, having expert legal support is decisive for acting with speed, legal certainty, and full coverage before control bodies.

At IN DIEM Abogados, we advise local entities and public bodies on the legal management of technological crises, the correct processing of emergency contracts in accordance with the LCSP, and the prevention of administrative, accounting, or criminal liabilities.
Contact our firm to analyze your specific situation and receive advice tailored to the needs and particularities of your Administration.


Preguntas frecuentes sobre ciberataques y contratos de emergencia en el sector público

¿Puede un ciberataque justificar un contrato de emergencia?

Sí, siempre que exista una situación grave, imprevisible y que no admita demora. El contrato de emergencia puede utilizarse cuando el ciberataque paraliza servicios públicos esenciales y resulta necesario actuar de forma inmediata para contener el incidente o recuperar la operatividad.

¿Qué es un contrato de emergencia en la contratación pública?

Es un mecanismo excepcional previsto en la Ley de Contratos del Sector Público que permite contratar de forma inmediata cuando concurren acontecimientos catastróficos, situaciones de grave peligro o necesidades que no admiten demora.

¿Todo incidente informático permite acudir a la contratación de emergencia?

No. No todo incidente de seguridad permite utilizar este procedimiento. Debe tratarse de una situación especialmente grave que exija una respuesta inmediata y que no pueda abordarse mediante los procedimientos ordinarios o urgentes de contratación.

¿Qué diferencia hay entre urgencia y emergencia?

La urgencia permite acelerar determinados plazos manteniendo las garantías ordinarias de contratación. La emergencia, en cambio, permite prescindir de trámites previos cuando la situación es excepcional y exige una actuación inmediata para evitar o reparar daños graves.

¿Qué servicios pueden contratarse tras un ciberataque?

Pueden contratarse servicios estrictamente necesarios para contener el ataque, recuperar sistemas, restaurar copias de seguridad, realizar análisis forense digital, implementar parches urgentes, reforzar infraestructuras críticas o monitorizar sistemas durante la crisis.

¿Puede usarse el contrato de emergencia para mejorar sistemas informáticos?

No debería utilizarse para mejoras estructurales que puedan licitarse por los cauces ordinarios. La contratación de emergencia debe limitarse a lo imprescindible para afrontar la situación crítica y restablecer los servicios afectados.

¿Qué debe documentar la Administración en estos casos?

Debe documentar la gravedad del incidente, la imposibilidad de acudir a otros procedimientos, la relación directa entre el ciberataque y los servicios contratados, la elección del proveedor, el precio, las actuaciones realizadas y la necesidad de la respuesta inmediata.

¿Qué riesgos tiene usar indebidamente un contrato de emergencia?

El uso indebido puede generar nulidad del contrato, reparos de fiscalización, responsabilidad contable, reclamaciones de terceros, sanciones disciplinarias e incluso responsabilidades penales en supuestos graves de actuación irregular.

¿Qué obligaciones tienen las empresas proveedoras?

Las empresas proveedoras deben actuar con rigor técnico, documentar sus trabajos, ajustar sus precios a mercado, cumplir las obligaciones contractuales y facilitar la trazabilidad de las actuaciones realizadas durante la gestión del incidente.


Cryptoveritas 360: Our Technology Partner

Crypto Financial Technological Intelligence. Cryptoveritas 360.

Did you know that Abogados IN DIEM offers online and expedited services?

We offer our clients the option of receiving assistance via video call or videoconference, as well as by phone, depending on their preference, so that the assistance is as personalized as possible, provided immediately, and without the need to travel. This service is complemented by communication via email, which facilitates the review and delivery of documentation.

In addition, for businesses and individuals, IN DIEM Abogados offers urgent services and 24-hour support for matters that require a quick response.


Would you like to know more about IN DIEM Abogados? Here is this short introductory video…

To acknowledge some of you, here’s this link.

You can find us in Seville, Madrid, Las Palmas de Gran Canaria, Málaga, Tomares, Coria del Río, Dos Hermanas, Mairena del Alcor, Estepona, Marbella, and Mairena del Aljarafe. We look forward to serving you.

Leave a Reply

Your email address will not be published. Required fields are marked *

Legal Vision

Other posts on our blog that might interest you

BNEXT Is Unable to Operate: Issues with the Token and Legal Analysis Under MiCA. Real-Life Case

How does CNMV supervision work under MiCA?

Errors in Crypto Tax Software: How Our Technical Debugging Prevented €27,600 in Unnecessary Taxes

Legal remedies and actions after an airport detention: how to challenge a refusal of entry in Spain

DAC7: What the Tax Agency Does with Received Data and How It Uses It in Inspections. What Do They Review and How to Defend Yourself?

MXC Bit2Me Claim: Transaction Cancellation and Funds Blocking