Skip to main content

CaixaBank down: what an online banking outage teaches about digital continuity

Thousands of users reported problems accessing CaixaBank's online banking and mobile app. The bank has not said this was a security incident, and the episode leaves a clear lesson for any company: digital continuity is prepared beforehand, not during.

ITSeintec Team2-3 min read
CaixaBank down: what an online banking outage teaches about digital continuity

News summary

CaixaBank going down for a few hours put an uncomfortable reality back on the table: when a mass-market digital service stops responding, no improvised plan B works. Users reported access errors in online banking and the mobile app, and the bank restored service without reporting a cyberattack. It is worth stressing: with no official information, attributing a specific cause is speculation.

What matters for a company operating in Spain is not the technical detail of one bank, but the pattern. More and more business processes — payments, reconciliations, payroll, invoicing, customer collections — depend on services we do not control. When one of them stops, the outage transfers in full to our operations even though our own infrastructure is working perfectly.

Seintec's analysis is that most organisations have clearly identified the risk of their own server failing, but not the risk of a critical third party failing. There is no maintenance window, no SLA of your own and no team to call: only waiting. And that wait costs money when it coincides with a month-end close, a payment run or a peak in orders.

The sensible response is not to stop using external services, but to treat them as what they are: dependencies with a direct impact on the bottom line. That means knowing which they are, how much it hurts when each one stops, what alternative exists and who decides to activate it.

In practice, the companies that handle these episodes best share three things: a real inventory of external dependencies, manual contingency procedures agreed with finance and operations, and internal communication ready so teams are not left guessing what is happening.

A few hours of downtime at a large provider is a cheap warning. The question it leaves is simple: if the service your invoicing depends on stopped tomorrow, how long would it take you to carry on working another way?

Source: El Español 7 September 2026

Why this matters to a company operating in Spain

Behind every tech market shift, there is a practical consequence for businesses: price changes, end-of-support for a product, new capabilities, or providers refocusing their strategy. Anticipating these moves avoids rushed purchases and ill-timed renewals.

Our criteria are simple: every innovation must translate into a specific action within the annual technology plan, or it does not deserve management’s time.

Real business impact

Before deciding on an investment, it is advisable to identify what is at stake. In disaster recovery projects, we typically review these four areas with management and the IT manager:

  • Out-of-support equipment that no longer receives security updates.
  • Licence renewals without prior comparison or adjustment to actual usage.
  • Technological projects lacking a clear internal lead, causing delays and budget overruns.
  • Purchasing decisions made out of urgency rather than planning.

Five-step action plan

A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:

  • List the external services each critical process depends on: banking, ERP, email, electronic signature, payment gateways and logistics.
  • Put a figure on the impact: what one hour of downtime costs for each, in euros and in orders or payments not processed.
  • Agree an alternative procedure for every critical dependency, even a manual one, and keep it written down and available offline.
  • Define who detects the problem, who decides to activate the plan and who communicates with customers and staff.
  • Rehearse it once a year with a short drill and adjust whatever did not work.

Key indicators you should be measuring

What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:

  • Number of critical processes with a documented alternative, against the total.
  • Time from detecting an external outage to activating the contingency plan.
  • Estimated cost per hour of unavailability for each critical external service.
  • Date of the last continuity drill run with the management team.

How we approach it at Seintec: Disaster Recovery

Data accessible in less than 4 hours. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.

These are the capabilities we bring to the table in a disaster recovery project:

  • Continuous replication: Synchronisation of virtual machines.
  • Cloud boot-up: One-click failover on our platform.
  • Failover testing: Documented and repeatable drills.
  • DRP Runbook: Clear procedure for every scenario.
  • Periodic reports: Replication status and measured times.
  • Quarterly review: The plan evolves with your infrastructure.

What you gain by working with a technology partner

Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:

  • Target RTO < 4 h and RPO close to 0: Recover servers, applications, and databases before the client notices.
  • Full replication in private cloud: We continuously copy your virtual machines and keep them ready to boot.
  • Competitive pay-per-use model: Forget about purchasing extra hardware: you pay only for the protected capacity.
  • 24 × 7 managed service: We design, operate and test the DRP; you simply receive peace-of-mind reports.

Frequently Asked Questions

Was the CaixaBank outage a cyberattack?
There is no official information confirming it. The bank restored service without reporting a security incident, so attributing any cause would be speculation. What is verifiable is that online and mobile access were unavailable for a limited period.
How can an SME protect itself from an outage at a provider it does not control?
It cannot prevent the outage, but it can reduce the impact: by identifying critical dependencies, defining an alternative procedure for each and testing it. The difference between an inconvenience and a business stoppage usually lies in that preparation.
How often should infrastructure be renewed?
When maintenance costs and incidents exceed the cost of renewal, usually between four and six years. A staggered renewal plan avoids investment spikes and out-of-support equipment.
Where should a company wanting to address disaster recovery begin?
With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
Is it necessary to halt business operations during the project?
No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
What type of companies do you serve?
SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
What coverage and response times (SLA) do you offer?
Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.

If an external service going down can halt your invoicing, it deserves a plan rather than improvisation. At Seintec we review your critical dependencies and design a continuity and recovery plan that fits your size. Talk to our team.

Contact Seintec

Related service

Disaster Recovery

Data accessible in less than 4 hours.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.