The AOC promotes new cloud services to strengthen the continuity and cyber resilience of local entities

Catalan local authorities will have new services to strengthen protection against cyberattacks and facilitate the recovery of activity after an incident. The Executive Committee of the AOC Consortium approved, in its session of September 16, 2026, the creation of cloud continuity and resilience services: cloud storage, còpia immutable security and cloud computing. These are managed infrastructure services, especially aimed at entities with fewer resources and technical capabilities. The initiative starts from a pilot with twelve local entities and responds to a real need: before the service was opened, more than thirty entities had already requested to join.

The differential value is the shared model: the AOC deploys and operates a common infrastructure, supervised by its security operations center (SOC), so that local entities can access advanced capabilities without having to build or manage them individually. This allows for economies of scale, standardization of guarantees and reduction of dependence on the resources available in each municipality. In the face of incidents that can interrupt municipal services for days, the response is no longer exclusively local and becomes a country-wide capability.

The new services align with the Generalitat's ESTRATEC strategy and will make preferential use of the Sovereign Public Cloud of Catalonia when it is operational.

When a city council server goes down, a municipality stops

In recent months, several Catalan town councils have suffered serious ransomware attacks that disrupted municipal activity for days. This is not a theoretical risk: cyberattacks increasingly affect the local world and especially affect entities with fewer technical and organizational resources. When a town council's infrastructure fails, it is not only the computer systems that come to a standstill: the population register, the registry, accounting, files and, ultimately, the service provided to citizens can be affected.

The agreement between the Cybersecurity Agency of Catalonia and the Localret Consortium, financed with European funds through the RETECH program, has contributed to strengthening the protection of the local world. However, prevention alone does not resolve an essential question: what data can be recovered and how long it will take to restore the service after an incident.

What the pilot revealed: backups that were non-existent or never tested

The AOC presented, at the July 2026 meeting of the Local World Cybersecurity Advisory Committee, the results of the pilot còpia security and cloud computing, in which twelve local entities participated, with a very positive assessment by the participating entities. The pilot highlighted relevant shortcomings in administrations with fewer resources: some do not have any system còpia security and others have an old one or one without periodic restoration tests. A còpia that has not been attempted to be restored does not offer an effective guarantee of recovery.

Three services for three starting points

The proposal adapts to the degree of maturity and needs of each entity. The cloud storage service is aimed at entities that do not have cloud storage software. còpia or who cannot set up a còpia external; although the process is manual and not integrated, it allows data to be kept outside of the local infrastructure that could be affected by an attack.

The service of còpia immutable security in the cloud is aimed at entities that already have security software còpia or who want to implement it; licenses can be acquired through the Localret Consortium's Cybersecurity Framework Agreement.

Finally, the cloud computing service allows virtual servers to be deployed in a pre-configured landing zone monitored by the AOC's SOC.

Build once to protect 2.250 administrations

The main strength of the AOC is its shared digital public infrastructure model: capabilities are designed, deployed, protected and maintained centrally so that more than 2.250 Catalan administrations can benefit from them without duplicating investments or efforts. This approach facilitates scalability, promotes cost sustainability and allows the application of common security and quality of service criteria.

The new services are integrated into a platform that processes 2,5 million daily operations, manages 4,5 million digital identities and has 22 services certified in the high category of the National Security Scheme, the maximum level provided for by the regulations. In addition, they will take advantage of already consolidated capabilities, such as the AOC's SOC, which supervises and protects shared digital services.

Without a shared solution, each entity would have to separately contract and manage the còpia security, cloud infrastructure and monitoring. For a small municipality, with limited technical resources, this can be difficult to assume. The AOC model expands access to immutable copies, specialized supervision and environments prepared with common criteria, regardless of the size of the administration.

May none of us be left without còpia: the 2027 milestone

The approval of September 16th allows the pilot to evolve into a catalog service. The next step is to deploy it with a clear priority: to move forward so that no Catalan local entity is left without a còpia immutable security in the cloud. With this objective, the AOC is working on a financing model for 2027, within the framework of the new public pricing system.

Having recoverable copies and prepared infrastructures can make the difference between a limited impact and a prolonged interruption of public services. Catalonia's digital resilience also depends on the capacity of smaller entities. With common, scalable and supervised services, the AOC contributes to reducing inequalities, optimizing public resources and ensuring that the continuity of services does not depend on the size of each administration.

To know more

Published in