CaixaBank down: what an online banking outage teaches us about digital continuity
Thousands of users reported problems accessing CaixaBank online banking and mobile application. The entity has not communicated that this was a security incident, and the episode leaves a clear lesson for any company: digital continuity is prepared beforehand, not during.

News summary
The fact that CaixaBank went down for a few hours once again brought an uncomfortable reality to the table: when a mass digital service stops responding, there is no improvised plan B that works. Users reported access errors to online banking and the mobile application, and the entity restored the service without communicating that it was a cyberattack. It is worth underlining: without official information, attributing a specific cause is speculation.
What is relevant for a Spanish company is not the technical detail of a specific entity, but the pattern. More and more business processes —payments, reconciliations, payroll, invoicing, customer collections— depend on services we do not control. When one of them stops, the downtime is transferred in full to our operations even if our infrastructure is functioning perfectly.
Seintec analysis is that most organisations have well identified the risk of their own server going down, but not that of a critical third party. There is no maintenance window, no internal SLA, nor a team to call: just waiting. And that waiting costs money when it coincides with a month-end closing, a remittance expiry, or a peak in orders.
The reasonable response is not to stop using external services, but to treat them as what they are: dependencies with a direct impact on the P&L account. That implies knowing which ones they are, how much it hurts for each one to stop, what alternative exists, and who decides to activate it.
In practice, the companies that best manage these episodes share three things: a real inventory of external dependencies, manual contingency procedures agreed with finance and operations, and internal communication prepared so as not to leave teams guessing what is happening.
A downtime of several hours in a major provider is a cheap warning. The question it leaves behind is simple: if the service upon which your billing depends stops tomorrow, how long would it take you to continue working by other means?
Source: El Español — 7 September 2026
Why this matters to a company operating in Spain
Behind every tech market shift, there is a practical consequence for businesses: price changes, end-of-support for a product, new capabilities, or providers refocusing their strategy. Anticipating these moves avoids rushed purchases and ill-timed renewals.
Our criteria are simple: every innovation must translate into a specific action within the annual technology plan, or it does not deserve management’s time.
Real business impact
Before deciding on an investment, it is advisable to identify what is at stake. In disaster recovery projects, we typically review these four areas with management and the IT manager:
- Out-of-support equipment that no longer receives security updates.
- Licence renewals without prior comparison or adjustment to actual usage.
- Technological projects lacking a clear internal lead, causing delays and budget overruns.
- Purchasing decisions made out of urgency rather than planning.
Five-step action plan
A useful plan fits on one page. This is the roadmap we apply with our clients to move from news to measurable improvement, without disrupting daily operations:
- List the external services on which each critical process depends: banking, ERP, email, electronic signature, payment gateways, and logistics.
- Put a figure on the impact: how much one hour of downtime costs for each one, in euros and in unprocessed orders or payments.
- Agree on an alternative procedure for each critical dependency, even if it is manual, and keep it documented and accessible offline.
- Define who detects, who decides to activate the plan, and who communicates with clients and the internal team.
- Rehearse it once a year with a short drill and adjust what did not work.
Key indicators you should be measuring
What is not measured is not managed. These indicators allow you to verify if the technological investment is yielding results and serve as the basis for the periodic reports we deliver to our clients:
- Number of critical processes with a documented alternative compared to the total.
- Time from the detection of an external outage to the activation of the contingency plan.
- Estimated cost per hour of unavailability for each critical external service.
- Date of the last continuity drill conducted with management.
How we approach it at Seintec: Disaster Recovery
Data accessible in less than 4 hours. We operate from our own datacenter in Spain, with a certified technical team and a single point of contact who knows your infrastructure, so you do not have to explain your environment every time an incident arises.
These are the capabilities we bring to the table in a disaster recovery project:
- Continuous replication: Virtual machine synchronisation.
- Cloud boot: One-click failover on our platform.
- Failover testing: Documented and repeatable drills.
- DRP Runbook: Clear procedure for every scenario.
- Periodic reporting: Replication status and measured times.
- Quarterly review: The plan evolves with your infrastructure.
What you gain by working with a technology partner
Outsourcing does not mean losing control: it means gaining predictability, coverage, and independent technical insight. These are the benefits our clients highlight:
- Target RTO < 4 h and RPO close to 0: Recover servers, applications, and databases before the client notices.
- Full replication in a private cloud: We continuously copy your virtual machines and keep them ready to boot.
- Competitive pay-per-use model: Forget about purchasing extra hardware: you only pay for the protected capacity.
- 24 × 7 managed service: We design, operate, and test the DRP; you simply receive peace-of-mind reports.
Frequently Asked Questions
- Was the CaixaBank outage a cyberattack?
- There is no official information to confirm this. The entity restored the service without reporting a security incident, so any attribution of cause would be speculation. What is verifiable is that there was unavailability of online and mobile access for a limited period.
- How can an SME protect itself from the failure of a provider it does not control?
- It cannot prevent the failure, but it can reduce its impact: by identifying critical dependencies, defining an alternative procedure for each one, and testing it. The difference between a nuisance and a business standstill usually lies in that prior preparation.
- How often should infrastructure be renewed?
- When maintenance costs and incidents exceed the cost of renewal, usually between four and six years. A staggered renewal plan avoids investment spikes and out-of-support equipment.
- Where should a company wanting to address disaster recovery begin?
- With an audit of the current environment. At Seintec, we perform an initial no-cost review that identifies risks, dependencies, and priorities, resulting in a phased plan with fixed deadlines and budgets.
- Is it necessary to halt business operations during the project?
- No. We plan migrations and changes within agreed windows, with prior pilot tests and rollback options, ensuring disruption is minimal or non-existent for users.
- What type of companies do you serve?
- SMEs and mid-market companies in sectors such as industry, automotive, logistics, retail, legal, and healthcare, with both on-premises and hybrid cloud infrastructure.
- What coverage and response times (SLA) do you offer?
- Support from Monday to Friday, 09:00 to 18:00, and 24x7 emergencies 365 days a year, with a committed response SLA and a 99.98% service SLA in 2025.
If the downtime of an external service can stop your invoicing, it deserves a plan and not improvisation. At Seintec, we review your critical dependencies and design a realistic continuity and recovery plan for your size. Speak with our team.
Contact SeintecRelated service
Disaster Recovery
Data accessible in less than 4 hours.