-
Canadá
The Contract Covers the Dispute. But Who Explains It?
25 de agosto de 2026
- Compliance
- Contratos
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Larry
Ceo fraud in Portugal: how to react fast, recover funds and strengthen payment security
4 de junio de 2026
-
Portugal
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Carolina
España | Franquicia, Teoria Del Riesgo Y Garantia De Los Socios
15 de mayo de 2026
-
España
- Contratos de distribución
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Javier
Crisis Management for Law Firms
26 de febrero de 2026
-
Canadá
- Compliance
- Litigios
- Delitos financieros
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Larry
Managing Lawsuit Risk: A Budgeting Framework for Legal Costs
19 de febrero de 2026
-
Italia
- Contratos
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Roberto
El abogado-coach: una nueva forma de ejercer
23 de diciembre de 2025
-
España
- Contratos
- Litigios
- Mediación
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Ignacio
España – La estafa Man in the Middle y el Reglamento UE 2024/886: cambio de paradigma
3 de noviembre de 2025
-
España
- Bancario
- Litigios
- Títulos e instrumentos financieros
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Javier
The New Dutch Shareholder Dispute Resolution Scheme
22 de octubre de 2025
-
Países Bajos
- Derecho Societario
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.
Contacta con Hein
Contratos de Agencia y Distribución. Frases que hay que evitar al terminar una relación comercial sin contrato escrito
11 de octubre de 2025
-
España
- Agencia
- Contratos
- Contratos de distribución
- Litigios
A European manufacturer supplies a critical component to a New York-based distributor. Shortly after delivery, questions emerge about whether the product complies with U.S. safety requirements. The distributor pauses shipments while the issue is reviewed.
Customers want to know when orders will resume. Sales teams are fielding questions. A trade publication calls for comment. Regulators want information.
The distributor tells customers that shipments have been paused while the issue is investigated. The manufacturer believes that explanation is incomplete and may leave customers with the impression that the product is unsafe or that the manufacturer caused the problem.
The contract is detailed. It says what happens if a party defaults, who can terminate and where a dispute will be heard. It also deals with confidentiality and public disclosure. What it does not say is how the parties should communicate when the problem becomes public and both need to respond.
The legal position may still be unclear. The facts may still be coming together. But someone has to answer the customer asking why a shipment has not arrived or the journalist seeking comment.
And what one party says can quickly become the other party’s problem.
Publicity clauses only take you so far
Most international agreements already deal with confidentiality and public announcements. Some commercial contracts may restrict the use of a counterparty’s name or the disclosure of information about the relationship.
Those provisions usually focus on consent and disclosure. They are less useful when both parties need to respond to the same event at the same time.
The communication that causes trouble may not be a press release at all. It could be a customer email saying, “Our supplier has failed to deliver.” It could be a technology company telling users that an outage originated in its client’s systems.
The sender may see the wording as factual. The other side may see blame being shifted.
By the time lawyers are debating whether the statement breached the agreement, customers may already have formed their own conclusions.
Cross-border relationships make coordination harder
Time zones are the obvious example.
Suppose the problem comes to light in New York after the European working day has ended. Customers want an answer. Reporters are calling. The people who would normally approve a statement are in Paris, Frankfurt or Milan and cannot be reached.
A requirement for prior consent to every external statement may look sensible on paper. In practice, it may be impossible to follow.
Some of these practical issues can be settled in advance. The contract can identify the types of events that require consultation, the right contacts on each side and expected response times. It can also say what happens if one side cannot be reached, including whether the other may issue a holding statement.
The clause can be short. Consultation, advance notice where practicable and enough information-sharing to keep communications accurate may be all that is needed.
The contract does not need to become a crisis plan. It just needs to give the parties a process they can use when the problem is already unfolding.
One party may also have to speak before the other is ready. A public company may face a disclosure deadline even while its commercial partner is still investigating the facts.
In the United States, for example, a public company generally has four business days after determining that a cybersecurity incident is material to file the required disclosure on Form 8-K. In that situation, consultation and advance notice where possible usually make more sense than giving either party an absolute veto.
When the stories start to diverge
The bigger challenge is when the two sides no longer agree on what happened.
One party may think the other is giving customers an inaccurate account and want to correct it. It may want to contact shared customers directly. The other party may see that as an escalation.
The same issue can continue after termination. Each party may want to reassure customers and employees and explain why the relationship ended. Their accounts may not match.
If the parties want consultation requirements or restrictions on naming one another to continue after termination, the contract should say so.
Keep it practical
There are limits to what a communications clause can do.
It cannot override a legal disclosure obligation. It cannot make two companies agree on disputed facts. It should not require either side to disclose privileged or otherwise protected information, or give one party an open-ended right to stop the other from speaking.
Commercial contracts are usually very detailed about what happens if the relationship breaks down. They specify who can terminate, what remedies are available, where disputes will be heard and which law applies.
They are often less useful once the problem becomes public and people outside the contract want answers.
By then, what each side says may be affecting the commercial relationship as much as the dispute itself. Agreeing in advance on who needs to be consulted and what happens when time is short can prevent the communications problem from becoming another dispute.
Imagine you are the CFO of a multinational group. You receive an urgent WhatsApp message from your CEO:
“We’re closing an acquisition in Portugal. I need you to transfer 850,000 EUR to this account immediately. It’s confidential and urgent.”
The pressure feels real. The profile picture matches. The context sounds plausible.
Or imagine a long‑standing foreign supplier suddenly “updates” the IBAN for the payment of a recent order. The email arrives inside an existing email thread about that very supply. Same document style, same signatures, same tone. Everything looks normal.
The next day, you discover the CEO never sent that message – and the supplier never changed bank details. Your company’s funds have been transferred to a Portuguese bank account controlled by fraudsters.
These scenarios are not hypothetical. In recent years, Portuguese authorities have dismantled networks that diverted millions of euros through these methods, often using Portugal as a transit jurisdiction to receive and rapidly dissipate fraudulent proceeds.
What is CEO Fraud (BEC) and how does “money mulling” work?
CEO Fraud is part of a broader family of schemes commonly referred to as Business Email Compromise (BEC), invoice fraud, or CEO impersonation. The objective is simple: induce a company to make a payment to an account controlled by criminals by exploiting trust, urgency, confidentiality, and internal processes.
The tactics have evolved well beyond crude spoofed emails. Today, fraudsters frequently use:
- Messaging apps (WhatsApp, Telegram, Signal) to impersonate senior executives;
- Compromised email accounts (real inbox access) to insert themselves into legitimate conversations;
- Typosquatting (look‑alike domains), e.g. companybeta.com vs companybetas.com;
- Payment diversion at the last minute (“new bank account details”, “audit reason”, “confidential deal”, etc.).
Once funds are transferred, they are typically routed through money mules (or “money mulling” schemes): individuals (often young or in financial distress) who allow their bank accounts to be used to receive and quickly forward funds. The most common method is doing this operation scheme through newly incorporated companies whose accounts are used as temporary “pass‑through” vehicles.
In many cases, the money mule is the only identifiable link when the fraud is detected, while the organisers remain behind layers of transfers and cross‑border complexity.
Why immediate action matters: the first 48–72 hours
Speed is a decisive factor in the recovery of assets. The first 48 to 72 hours are often critical to prevent funds from being fragmented across multiple accounts, moved abroad, or converted into cryptoassets.
Even if that immediate reaction does not occur, companies should act as quickly as possible. A coordinated response is typically required across multiple jurisdictions (e.g., where the company is based, where the recipient account is located, and where subsequent transfers may have gone). This coordination helps ensure urgent engagement with the banks involved (payer bank and recipient bank), payment service providers, and the relevant judicial authorities.
The goal is to preserve evidence, obtain timely information, and pursue measures that may prevent dissipation of funds.
Criminal investigation in Portugal: effective tools, practical limitations
CEO Fraud schemes typically involve conduct that may qualify (depending on the factual pattern) as offences such as computer fraud, money laundering and criminal association.
Portuguese criminal procedure provides mechanisms that can be effective in these cases, including measures that may lead to freezing the movement of funds and seizing amounts held in bank accounts.
In practice, however, the pace of criminal investigations does not always match the operational speed of fraud networks. These cases are usually handled under judicial secrecy, follow their own procedural rhythm, and may require international cooperation to track transfers and identify the individuals behind the scheme.
For victim companies, this can mean long periods without meaningful updates – a reality that often generates understandable frustration and prompts consideration of alternative or parallel strategies.
Civil alternatives: information gathering and precautionary freezing measures
A route that is often overlooked in the initial crisis — but can be valuable — is the civil strategy.
Depending on the circumstances, civil proceedings (including precautionary measures) may help a victim company:
- obtain relevant information regarding the recipient account(s) and transaction flows (subject to judicial assessment and proportionality), and/or
- seek preventive freezing of available balances.
This approach is case‑specific and must be assessed urgently. When viable, it can play an important role in bridging information gaps and acting before funds are dissipated.
Can the recipient bank be liable? Traditional stance and a changing landscape
When fraudulent funds are received into Portuguese bank accounts — especially accounts opened by newly created companies, followed by rapid high‑value outgoing transfers — questions often arise about the role of the recipient bank.
Historically, Portuguese courts have tended to take a restrictive approach to the civil liability of recipient banks, particularly where the payer provided the correct IBAN (even if under deception). In addition, breaches of anti‑money laundering (AML) obligations have often been treated primarily as matters of regulatory, administrative or criminal enforcement, rather than as a straightforward basis for civil liability towards third parties.
That said, each case should be assessed on its own facts, including what was knowable and observable by the recipient bank, the transaction pattern, the customer profile, the timing, and the specific compliance obligations at play.
For additional perspectives within the Legalmondo network, see the Spanish analysis on Man‑in‑the‑Middle fraud and bank liability and the Italian perspective on CEO fraud in international groups.
Verification of Payee (VoP): a major compliance and fraud‑prevention shift in Europe
Against this background, the regulatory environment is evolving.
Regulation (EU) 2024/886 (the “Instant Payments Regulation”) strengthens the framework for euro credit transfers and introduces, among other measures, the obligation for payment service providers to offer a Verification of Payee (VoP) service. In short, before a transfer is authorised, the payer should be informed whether the beneficiary name matches the IBAN (or whether there is a close match/no match), helping reduce misdirected payments and social‑engineering fraud.
In Portugal, the Central Bank (Banco de Portugal) has indicated that its VoP service is available from 5 October 2025, and EU‑level implementation deadlines for banks in the euro area are tied to October 2025 obligations under the Regulation.
For corporate finance teams, VoP will not eliminate CEO Fraud (criminals adapt quickly) but it adds a meaningful friction point that can prevent (or at least flag) certain payment diversions.
Practical checklist: what companies should do immediately after discovering CEO Fraud
- Stop and document: Preserve emails (including headers), chat logs, attachments, invoices, and internal approvals.
- Notify banks urgently: Contact both the payer bank and the recipient bank; request immediate action to trace/freeze funds where possible.
- Escalate internally: Finance, legal, IT/security, and management should coordinate a single incident response.
- Engage counsel across jurisdictions: Parallel steps may be needed in the jurisdictions involved.
- Consider criminal and civil paths: Criminal complaint and cooperation with authorities; assess civil/precautionary measures for speed and information.
- Contain the breach: If email compromise is suspected, secure accounts, reset credentials, review forwarding rules, and harden Multi-factor authentication (MFA).
Conclusion
CEO Fraud (BEC) is a fast‑moving threat that exploits corporate trust and payment workflows. When Portugal is part of the payment chain (whether as recipient jurisdiction or as a transit route) a successful response depends on speed, cross‑border coordination, and a clear strategy combining criminal and, where appropriate, civil measures.
At the same time, regulatory developments such as Verification of Payee under Regulation (EU) 2024/886 signal a new European focus on preventing misdirected payments — an important step, particularly for corporates exposed to high‑value cross‑border transfers.
Los franquiciadores extranjeros que firmen contratos de franquicia en España deben tomar buena nota del contenido de la sentencia de la Audiencia Provincial de Cordoba de 20 de noviembre de 2025 y exigir que el socio o los socios y los administradores de la compañía franquiciada garanticen y avalen expresamente el pago de las posibles deudas que genere el contrato de franquicia.
La legislación societaria española establece el principio de responsabilidad de los administradores de las compañías anónimas o de responsabilidad limitada cuando la sociedad se halle en causa de disolución (por ejemplo por pérdidas que reduzcan el patrimonio por debajo del 50% de la cifra de capital social) y pese a ello no convocaren junta para la adopción de las medidas correctoras (disolución o aumento de capital).
En el caso de la sentencia arriba citada, el franquiciador no pudo cobrar a la sociedad franquiciada la deuda derivada del contrato de franquicia por su insolvencia; entonces decidió reclamar al administrador de la sociedad dicha deuda con fundamento en el precepto arriba comentado, es decir, por el hecho de que la sociedad franquiciada estaba en causa de disolución por pérdidas y el administrador no había convocado junta de socios como era su obligación para que los socios decidieran como solventar la situación.
La sentencia que comentamos de la Audiencia de Cordoba confirma la de primera instancia y desestima la demanda del franquiciador contra el administrador único de la sociedad franquiciada afirmando que:
Por lo que se refiere a la responsabilidad por deudas sociales del artículo 367 de la Ley de Sociedades de Capital, se reconocía la existencia de las deudas sociales, la concurrencia de la causa de disolución, el incumplimiento de las obligaciones legales del administrador social y su imputabilidad, pero concurría una causa de exoneración de responsabilidad de conformidad con la doctrina del «riesgo conocido». Así se indicaba que la actora es una sociedad franquiciadora y X.S.L. era la franquiciada, resultando de las comunicaciones electrónicas que la franquiciada era monitorizada de forma permanente y la franquiciadora conocía el riesgo de las operaciones, paralizando el envío de género (ropa) en el momento que se superaban los límites de los avales concedido, por lo que la actora asumió voluntariamente el riesgo. Por todo ello desestimaba la demanda.
En conclusión y a tenor de lo expuesto, la presente relación jurídica de franquicia y su desenvolvimiento permite considerar acreditar la existencia por parte de la franquiciadora (acreedora) de un mayor conocimiento de la situación económica financiera de la franquiciada (deudora), más allá de la información que aparece en las cuentas anuales depositadas en el Registro Mercantil al ser su principal proveedor. Y este conocimiento y situación de control de la deuda por parte de la franquiciadora (mediante el incremento de envío de pedidos) justifica la exoneración de la responsabilidad del administrador social por las deudas sociales del artículo 367 de la Ley de Sociedades de Capital, lo que determina la desestimación del recurso de apelación
La teoría o principio de derecho del Riesgo Conocido/Aceptado, al que se refiere la sentencia, defiende que un daño ocasionado a un tercero, con o sin relación contractual por medio, no se considera antijurídico si la víctima conocía el riesgo y lo asumió voluntariamente.
Inicialmente se desarrolló esa doctrina en el marco de la responsabilidad extracontractual, quien realiza una actividad de riesgo y se aprovecha de sus beneficios debe asumir sus consecuencias negativas, es decir el riesgo, (cuius commodum, eius incommodum).
Pero la jurisprudencia ha extendido la aplicación de teoría al campo de la responsabilidad contractual, como se muestra en la sentencia que comentamos.
Por lo tanto al conocer el demandante la situación económica y de solvencia de la demandada, por “monitorizar” como franquiciador su actividad y pese a ello, haber decidido mantener la vigencia del contrato, incrementando la deuda, entiende la sentencia que el franquiciador asumió el riesgo, lo que constituyó una causa de exoneración de responsabilidad del administrador. Ahora bien, más preocupante que lo anterior, es que se considerase aplicable esta teoría del “riesgo conocido” a la propia responsabilidad de la sociedad franquiciada, la que pudiera ser exonerada de responsabilidad con fundamento en esa monitorización de sus actividades por le franquiciador.
La conclusión de todo lo anterior es que en base a esta aplicación de la teoría del riesgo conocido, los franquiciadores pueden tener dificultades para reclamar las deudas de la sociedad franquiciada, en caso de insolvencia de la misma, a sus administradores, por lo que es muy aconsejable que a la hora de firmar el contrato de franquicia se exija la garantía solidaria de las posibles y futuras deudas de la franquicia a sus administradores y socios, lo que por otra parte constituye una práctica bastante estandarizada.
De este modo, no entraría en juego la objeción derivada de la teoría del riesgo conocido.
Trust is the only thing a law firm sells.
It takes years to build a reputation and minutes to damage it. In a crisis, that reality becomes visible. Client calls increase. Internal questions surface. Reporters start asking questions. Recruiters take note.
What begins as an individual lapse, a client controversy, or an internal weakness quickly becomes a communications test. How leadership responds, who speaks, and how consistently the message is delivered will determine how the firm is judged.
Crisis management in a law firm is not primarily a legal problem. It is a leadership problem, expressed through communication.
The Added Complexity Facing Modern Firms
Legal practice is more exposed than it was even a decade ago. Firms operate across jurisdictions and serve sophisticated clients. Expectations about transparency and accountability are not the same everywhere. What sounds careful in one jurisdiction can sound evasive in another.
When something goes wrong, reactions do not stay local. Clients, regulators, employees, and the media may all respond at the same time, often in different markets. If offices or practice groups answer differently, confusion grows and scrutiny increases.
Staying silent rarely helps. If the firm does not explain what is happening, it loses control of the narrative.
Where Law Firm Crises Begin
Most law firm crises originate in one of three areas:
- Individual behaviour
- Client-related risk
- Systemic issues within the firm itself
Individual misconduct is usually the most visible.
Widely reported cases in recent years involving senior partners at major firms have followed a familiar pattern. An incident at a firm event is initially treated as isolated. Leadership hesitates, weighing relationships and reputational risk. Within weeks, the issue moves beyond the room. Focus shifts from the conduct itself to how the firm responded. What began as a behavioural issue becomes a test of leadership judgment.
Hesitation changes the narrative. Once that shift occurs, the firm is no longer addressing behaviour. It is defending its decision not to act.
Technology has created a different kind of exposure. Several firms have faced scrutiny after courts or opposing counsel identified AI-generated citations that did not exist. Internally, the explanation was familiar. A junior lawyer relied on a tool. Supervision was assumed rather than confirmed. Externally, those details mattered far less than the perception that basic controls had failed.
The communications challenge is not explaining how the error occurred. It is addressing the confidence gap that follows. Courts and clients do not reward technical explanations when oversight appears weak.
Client-related crises are often the most difficult to navigate publicly.
Firms may believe that engagement letters create a buffer between client and firm. In practice, when a client becomes controversial, that distance collapses. Media coverage rarely distinguishes between legal advice and endorsement. Once the firm’s name appears in the same headline, it becomes part of the story.
Communications strategy must reflect the fact that clients, regulators, employees, and journalists will interpret the situation through different lenses. A single message rarely satisfies all of them.
Systemic and cultural issues present a different communications risk.
Pay disparities, unclear promotion criteria, tolerance of poor behaviour, or weak reporting channels often develop over time. When lawyers leave and speak openly about their experiences, internal issues become external narratives. Culture becomes part of the firm’s public identity.
What a firm can say credibly in a crisis depends on what it has done consistently before one. Reputation limits the range of believable responses.
* * *
Where Law Firm Crisis Communications Often Falters
Lawyers are trained to be careful and precise. That is usually a strength. However, in a crisis, it can backfire. Statements may be technically accurate, but they leave obvious questions unanswered.
The pattern is familiar. A carefully worded statement is released. Reporters and clients focus on what was not said. Follow-up questions arrive. Another clarification is issued. Each round keeps the story alive. What felt prudent inside the firm can look like hesitation from the outside.
Mixed messaging makes things worse. Different partners speak to different audiences. Offices respond on their own. Legal advice and communications advice are not aligned. The result is inconsistency, and inconsistency weakens credibility.
In a reputational crisis, people form views quickly. Once confidence slips, it is hard to rebuild.
What Effective Law Firm Crisis Communications Looks Like
Effective crisis communications is disciplined and coordinated. It begins with a clear understanding of what is known, what is not known, and what can responsibly be said. Acknowledging facts early, without speculation, builds credibility. Overstatement creates risk. Evasion creates suspicion.
Decisions reinforce messages. Policy changes, leadership actions, or the appointment of an independent investigator often carry more weight than carefully chosen language.
Structure matters. One spokesperson. Clear internal guidance. Alignment between leadership, legal counsel, and communications advisors. Without that alignment, even strong decisions can appear uncertain.
Above all, the institution must come first. Communications strategies that appear designed to protect a single individual at the expense of the firm tend to fail. That risk is greatest when senior figures are involved. Allegations concerning senior partners attract heightened scrutiny and test whether the firm’s standards apply consistently or only when convenient.
Externally, the focus should remain on process and oversight rather than contested detail. Internally, communication must reduce speculation while respecting confidentiality. The objective is to demonstrate that the firm’s standards apply consistently.
Anything less invites doubt.
Crisis as a Communications Test
Every crisis ultimately becomes a communications test.
The underlying issue matters. So does how leadership responds, how consistently it speaks, and whether actions align with words.
Firms that respond with clarity, fairness, and coordination are more likely to preserve trust, even in serious situations. Firms that respond slowly or unevenly often extend the story and deepen reputational harm.
Crisis communications is not about spin. It is about protecting credibility when it is under pressure. And for law firms, that credibility is the business.
Summary: The challenge with preventive legal work is that it’s difficult to justify in the corporate budget—especially in organizations lacking a strong culture of risk prevention and mitigation. This article offers a practical solution: applying a “value-at-risk” approach helps leadership understand why every euro spent on preventive legal assessment can prevent multiple euros in litigation costs, sanctions, business disruption, and avoidable losses. A simple Return on Legal (ROL) metric makes that value tangible by calculating avoided costs from past disputes and modeling the financial effects of potential future lawsuits.
Why Legal Risk Management Needs a Financial Metric
Most companies already invest in preparedness—just not consistently in legal. They run security drills, insure assets, addres civil and product liability, test business continuity plans, and model financial risk. However, legal risk is often overlooked and, when considered, remains in the “qualitative” bucket: high/medium/low, red/amber/green, or a list of concerns in a memo.
That becomes a problem when decisions are made. Budgets are approved in numbers, not adjectives. If companies want legal preparedness to be funded like business preparedness, they need a framework that decision-makers are already familiar with. That’s where applying a value-at-risk approach helps.
Legal Risk as Value-at-Risk
Value-at-Risk in finance asks a simple question: how severe could the downside be, and how often might it happen? Legal risk can be approached in a similar way by considering two factors: the likelihood of an event (such as a claim, dispute, investigation, enforcement action, fine, lawsuit, or class action) and the impact if it occurs. Things can get very complicated, but for the sake of this article, a very simplified way to express it for a single- well defined, loss event might be:

“Total impact” is often underestimated when assessing legal risk. Direct legal costs are just one part of the picture. A dispute can consume leadership time, divert key teams from revenue-generating work, slow down delivery or product launches, damage supplier relationships, and cause customer hesitation. In other words, legal risk is often an operational risk with legal triggers.
Therefore, we should consider that legal risk rarely appears as a «fixed impact if it happens,» and the expected risk value often accumulates through the correlation of different factors. For example, one investigation can trigger follow-on lawsuits, a license can be revoked, a class-action can start, or enforcement can occur across multiple jurisdictions. If we want to account for this scenario (“how severe could the downside be and how frequently”), then the framework should involve a loss distribution over a period, which might look like this.
Expected legal loss (per period) = expected frequency x expected severity
This isn’t about finding the perfect formula. It’s about making legal exposure comparable to other risk areas where investment decisions are routinely supported with quantified downside.
Introducing Return on Legal (ROL)
Preventive legal work often goes unnoticed when it succeeds. When a contract dispute is avoided or a claim is settled early, there is no dramatic event—only the absence of damage. This is exactly why preventive advisory is often seen as a cost during budgeting: it appears more like an expense than an investment. A Return on Legal (ROL) metric addresses that gap by translating prevention into business results. In practical terms, ROL shows how much cost and disruption you save for every euro/dollar invested in legal risk assessment and prevention.
A definition could be expressed as follows:

When considering avoided losses, one should factor in a projection over a period of time (e.g., 3 years), the probability of a claim (e.g., 10%), and a baseline frequency of disputes. From there, it’s easy to get lost in complex calculations that take many variables into account; my point is not to achieve perfect precision but to make a credible, quantifiable estimate that supports better decisions in legal risk assessment and budgeting.
Measuring ROL: Retrospective vs. Forward-Looking
A convincing ROL approach combines what companies already know from experience with what can reasonably be modeled going forward.
First, there is the backward-looking perspective: assessing costs based on past litigation and disputes. Most companies have at least a few cases that can serve as reference points. The task is to identify where earlier legal intervention could have minimized the likelihood of escalation or the severity once a matter arose. This could be something as simple as improved clauses that prevent a dispute from escalating, earlier involvement of external counsel leading to quicker settlements on better terms, or custom dispute resolution clauses that reduce discovery burdens and strengthen the negotiating position.
To estimate backward-looking ROL without overclaiming, we can set a baseline for “what happened” or what usually occurs when that type of risk materializes without intervention. Then, compare that baseline with the results achievable when preventive measures are in place. There’s no need to pretend we can calculate the exact euro value to the last cent. What we require is a defensible range, based on actual costs (fees, settlement amounts, internal time) and business impacts that can be reasonably estimated (delayed launches, downtime, diverted capacity).
Second, there is the forward-looking perspective: forecasting the financial impact of potential future lawsuits. This is where the value-at-risk approach proves powerful. Decision makers identify the most relevant exposure types for their business and develop scenarios for each—typically best case, base case, and worst case—then assign probability ranges. The simulation becomes more meaningful when they consider how specific preventive measures influence the model. Some actions decrease probability (for example, compliance controls and training). Others lessen impact (such as better contracts, liability limitation clauses, response protocols).
Many do both. In the end, leadership gets a quantified story: this prevention program lowers expected annual legal losses and reduces exposure to litigation-related damages. This mirrors the decision-making approach used in other preparedness and risk-management programs.
Let’s make an example of how ROL works
Imagine a business line where disputes often come from contract ambiguity and inconsistent negotiation practices. In the past, the company occasionally faced lawsuits or arbitration, but more frequently it dealt with costly «pre-litigation” escalations that still took months and used up a lot of internal resources.
A preventive program—featuring updated templates, negotiation playbooks, and targeted training—incurs a clear cost. From a value-at-risk perspective, you compare that expense to the expected loss without the program over a certain period: not only external fees and settlements but also the estimated operational impact of ongoing disputes. If the program decreases how often disputes escalate and accelerates resolution times, the avoided losses can quickly outweigh the preventive costs. That difference reflects what ROL captures in a way that leadership can act on.
ROL Implementation: Keep It Lean and Actionable
ROL does not require a perfect dataset on day one. What it needs is consistent categorization, conservative assumptions, and a commitment to improve the model over time. A practical starting point is to gather three streams of information: historical disputes and their total costs; recurring risk hotspots (such as contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, client disputes); and operational impact estimates that the business already uses in other contexts (like cost per hour of downtime, cost of delays, internal resource allocation).
A practical starting point is to pull together three streams of information:
- historical disputes and their total cost;
- recurring risk hotspots (contracting patterns, product or market launches, HR issues, data/privacy exposure, supplier disputes, clients disputes); and
- operational impact estimates that the business already uses in other contexts (cost per hour of downtime, cost of delays, internal resource allocation).
Where data is uncertain, ranges can be helpful. Managers can assign confidence levels and keep the model honest by using conservative estimates. Over time, the ROL model becomes more accurate as the company consistently tracks legal events and as prevention initiatives develop. The most important mindset shift is to treat legal as you would other risk functions: as a measurable way to minimize downside, not just a reactive cost center.
Turning ROL Into a Decision Tool
Once legal risk exposure can be expressed in value-at-risk terms, companies can prioritize legal work using the same logic as other investments: risk reduction per euro spent. This shifts the conversation from “Should we spend on prevention?” to “Where do we get the biggest reduction in expected loss and tail risk?” ROL also improves alignment with business teams. Instead of speaking in purely legal categories, it is possible to connect legal work to operational outcomes—fewer delays, fewer escalations, faster resolution, reduced management distraction, greater predictability in commercial relationships. Over time, this fosters a healthier operating rhythm: legal risk reviews transition from being ad hoc to becoming a routine part of preparedness, similar to finance risk reviews or security protocols assessments.
Conclusion
Applying a value-at-risk perspective to preparedness reveals legal risk in the language corporate leadership already uses to allocate resources. A Return on Legal (ROL) metric then makes preventive legal advice concrete by turning avoided costs and operational losses into measurable value. By combining evidence from past disputes with future-focused simulations of potential lawsuits, companies can build a credible, data-driven argument that every euro invested in legal risk assessment can prevent multiple euros in losses—and that prevention is not just a “nice to have,” but a vital part of operational resilience.
Durante más de 35 años como abogado mercantilista he visto cómo muchos, yo el primero, confundíamos un asesoramiento eficaz con la respuesta inmediata y exhaustiva. Ahora tengo la percepción de que el mundo del derecho y el de la empresa están cambiando: no basta con saber (cada vez más leyes, más requisitos, más sentencias contradictorias… y más ruido), sino que hay que escuchar, acompañar y facilitar decisiones. Y ahí es donde la actuación también como coach ejecutivo ofrece un marco extraordinariamente útil.
De los abogados se espera que resolvamos. Los coaches ejecutivos, sin embargo, ayudamos (dentro de un marco ético) a que el otro descubra por sí mismo la respuesta. Y esto puede ser una fuente de enorme riqueza profesional y para el cliente. Cuando éste se enfrenta a un problema no necesita un análisis jurídico, sino necesita claridad y perspectiva para decidir… desde “su problema”, y no desde “nuestra solución”. Integrar en nuestro ejercicio profesional las herramientas de coaching ejecutivo transforma la conversación y el asesoramiento jurídico en algo más eficaz: un proceso de toma de decisiones en el que acompañamos al cliente de principio a fin.
Imagino tres ámbitos donde se encuentran el abogado y el coach ejecutivo:
- La relación con el cliente. Escuchar bien antes de aconsejar.
Decía Plutarco que “escuchar bien es la base de vivir bien”. Y a veces el cliente no busca tanto una respuesta, como claridad para decidir. Escuchar más allá de lo que dice (y de lo que calla) permite entender qué le preocupa. Una pregunta puede abrir más caminos que una disertación que, lo más seguro, le va a dejar frío. Cuando escuchamos sin prisa y sin sesgo propiciamos un espacio de reflexión que ayuda al cliente a ordenar, priorizar y tomar decisiones con sentido. Con sentido… para él.
- La negociación y la mediación.
En estos procesos ayudamos con las técnicas de coaching a desactivar resistencias y a pasar de la confrontación a la comprensión. El abogado-coach facilita que las partes se escuchen y descubran qué hay detrás de sus demandas. Una negociación puede desbloquearse cuando se permite al otro expresarse. Los acuerdos dejan de ser meras transacciones y se convierten en decisiones compartidas, más estables y sostenibles en el tiempo y menos fuentes de conflictos.
- Acompañar procesos de cambio en el cliente y su organización
El abogado-coach puede convertirse no solo en el redactor del acuerdo sino en facilitador del cambio. Ayuda a que los implicados comprendan lo que está en juego y alineen decisiones con sus valores y objetivos gestionando resistencias. El abogado deja de ser un mero “proveedor” de servicios (al que muchas veces se recurre solo al final del proceso) y pasa a ser un socio de reflexión.
En suma, percibo que hoy se nos demanda ejercer de forma diferente: menos técnica y más humana, menos reactiva y más transformadora. Las técnicas de coaching ayudan: escucha consciente, feedback constructivo, claridad de propósito… permiten gestionar mejor el conflicto, el estrés y la incertidumbre. El coaching, por supuesto, no sustituye al derecho, sino que lo ensancha y le da herramientas. En estos momentos, la inteligencia artificial (mucho más rápida y potencialmente mucho más completa y exhaustiva) nos está desubicando de nuestros hábitos. Quizás esto nos permita entrever que el abogado no deberá ser solo un experto en normas, sino un facilitador de conversaciones difíciles, alguien capaz de unir análisis y empatía, precisión y presencia. Alguien que entienda que su valor está en ayudar a sus clientes para que eviten sus conflictos o puedan resolverlos como mejor les satisfaga. Y ahí es donde el abogado-coach tiene mucho que aportar.
El incremento de la llamada cibercriminalidad en los últimos años presenta una magnitud tal que exige reacciones legislativas y judiciales contundentes. Las pérdidas por fraudes online en Europa superan los 100.000 millones de dólares según Nasdaq Ventures de los que 5.000 millones corresponden a España.
En España se denunciaron en 2019, 192.375 casos de estafas informáticas, pero en 2023 ascendieron a 427.448. Según los últimos datos oficiales disponibles las estafas informáticas representan el 90,4% de toda la cibercriminalidad y su crecimiento en el periodo 2016-2023 fue del 378%.
Las variedades que presentan las estafas informáticas son múltiples y están bautizadas en inglés, (al fin y al cabo, la lingua franca de nuestro tiempo), incluyendo, entre otras ingeniosas modalidades de los hábiles estafadores, las conocidas con los curiosos y divertidos nombres (salvo para los que las padecen) como phishing, pharming,, juice jacking, tabnabbing, bluesnarfing, catfishing, spoofing, vishing, smishing, whaling, carding, y la que hoy nos interesa, man in the middle (MITM).
¿Qué es el ataque Man in the Middle?
El fraude MITM consiste en la interceptación las comunicaciones entre dos dispositivos conectados a una red, permitiendo al ciber caco alterar y desviar los mensajes intercambiados entre los usuarios. El estafador intercepta una comunicación en la que un usuario solicita a otro un pago y a continuación modifica el IBAN de la cuenta bancaria en la que debe realizarse la transferencia con el objetivo de hacerse con el dinero. El proceso se desarrolla generalmente de la siguiente manera:
- Sin que la empresa lo detecte, un atacante intercepta y manipula un correo electrónico, cambiando el número IBAN de la cuenta en la que debe realizarse el pago.
- El ciberdelincuente se hace pasar por el proveedor, enviando el mensaje desde una dirección de correo electrónico casi idéntica a la original, pero con una ligera alteración que resulta casi imperceptible.
- La empresa receptora, confiando en la autenticidad del mensaje, realiza la transferencia a la cuenta fraudulenta.
De este modo, se consigue un desplazamiento patrimonial en detrimento del ordenante de la transferencia y a favor del ciber ladrón, de suerte que cuando el ordenante advierte el error, su primera reacción es intentar contactar con el banco receptor con la esperanza de que los fondos puedan ser bloqueados a tiempo. Sin embargo, en la mayoría de los casos, el ciberdelincuente ha sido más rápido: el dinero ya ha sido transferido a otra cuenta o retirado, dejando poco margen de maniobra, salvo el inicio de actuaciones judiciales a las que a continuación nos referimos.
La pregunta inmediata es qué responsabilidad tiene el banco que ha recibido la orden de transferencia del usuario engañado y abona en la cuenta del ciber estafador el importe en cuestión, en aquellos casos en los que el ordenante del pago identifica no solo el IBAN (fraudulento) sino también el nombre del beneficiario de la orden de pago que obviamente no coincide con el titular de la cuenta bancaria receptora de los fondos.
La respuesta desde el sentido común sería que el banco receptor de la transferencia debería confirmar que el titular de la cuenta de abono y la persona física o entidad identificada como beneficiario en la orden de transferencia coinciden; y si no fuere así, debería suspender el abono y solicitar aclaraciones al ordenante. Pero no es así en aplicación de la legislación de la UE y de la transposición de la misma al ordenamiento jurídico español como a continuación veremos.
Hasta el pasado 9 de octubre, el sistema bancario europeo ha operado bajo la premisa de que la validez de una transferencia se basa exclusivamente en la corrección del IBAN. Es decir, si el número de cuenta es correcto, la operación se considera válida, incluso si el nombre del beneficiario no coincide. Esta práctica ha generado numerosos casos de fraude, errores involuntarios y pérdida de fondos, especialmente en el ámbito de las transferencias inmediatas, donde la rapidez puede jugar en contra de la seguridad.
La opción más razonable del ordenante estafado para recuperar su dinero es demandar por la vía civil al banco receptor de la orden de abono (con quien carece de relación contractual) por responsabilidad extracontractual al amparo del art. 1124 del Código Civil; en efecto la vía penal contra el titular de la cuenta, que habitualmente es lo que en el argot se denomina “mula”, no suele tener recorrido exitoso, tanto porque lo normal es que el pájaro vuele como por su falta de solvencia.
La jurisprudencia de las Audiencias Provinciales ha estado dividida entre aquellos fallos en los que se acudía a una aplicación rigurosa y fiel del artículo 59 del Real Decreto-ley 19/2018, de 23 de noviembre, de servicios de pago y otras medidas urgentes en materia financiera, desestimando las reclamaciones de los estafados y otros en los que se buscaban argumentos bajo la premisa de falta de diligencia para condenar al banco a indemnizar al ordenante del pago.
Así se ha configurado la figura de una responsabilidad cuasi-objetiva de las entidades bancarias en materia de fraude digital, imponiéndoles un estándar reforzado de diligencia y trasladándoles el riesgo inherente a la actividad de banca en línea, salvo supuestos de dolo o negligencia grave del cliente. Esta línea, que se proyecta desde la jurisprudencia menor (AAP Madrid 178/2015; AP Alicante 107/2018; AP Valencia 212/2021) hasta el propio Tribunal Supremo (STS 571/2025, entre otras), se alinea con la idea de que corresponde al banco acreditar que sus sistemas eran seguros, actualizados y suficientes para evitar la consumación del ilícito.
En este marco, el concepto de bonus argentarius cobra renovada vigencia. Este es un principio que recogió la ley 57/68 para proteger a los compradores de viviendas en el sector inmobiliario, pero que el Tribunal Supremo sentenció en varias ocasiones que también se puede aplicar a otras inversiones financieras. En lo que a MITM se refiere, significa que, en caso de pérdidas por negligencia de la entidad financiera, el cliente puede presentar una demanda al amparo de la Ley 57/68 y reclamar la responsabilidad de la entidad bancaria.
El bonus argentarius se basa en la presunción de culpa de la entidad financiera, lo que significa que, aunque el cliente no tenga pruebas concretas de la negligencia, esta se da por sentada debido al deber de cuidado que debe tener la entidad en la gestión de las inversiones.
En base a aquel principio, la diligencia exigible al profesional financiero no es la del comerciante medio ni la del pater familias, sino la de un experto cualificado que asume la obligación de proteger los fondos confiados mediante la implantación de mecanismos de seguridad “necesarios y renovables”. Ello implica no solo el mantenimiento de medidas técnicas básicas de autenticación reforzada, sino la adopción proactiva de soluciones antifraude reconocidas internacionalmente, como la verificación nombre-IBAN (Confirmation of Payee o IBAN-Naam Check), que han demostrado eficacia en jurisdicciones comparadas.
En línea con aquella doctrina y jurisprudencia, la omisión de medidas de verificación del beneficiario constituiría una infracción del deber contractual de diligencia y de la buena fe (arts. 1104 y 1258 CC), generadora de responsabilidad civil por el daño causado de suerte que el fraude MITM no puede considerarse un riesgo residual imputable al cliente, sino un fallo de seguridad sistémico imputable a la entidad financiera, en tanto que diseñadora y custodio del canal de pagos electrónicos.
Pero en este estado de cosas el Tribunal Supremo en su reciente sentencia de 27 de marzo de 2025 se decantaba por la alternativa de la aplicación estricta del artículo 59 argumentando que “si el usuario de servicios de pago facilita información adicional a la requerida (especificación de la información o del identificador único que el usuario de servicios de pago debe facilitar para la correcta iniciación o ejecución de una orden de pago), el proveedor de servicios de pago únicamente será responsable de la ejecución de las operaciones de pago de acuerdo con el identificador único facilitado por el usuario de servicios de pago… y que la responsabilidad del proveedor de los servicios de pago, tanto a nivel comunitario como nacional, se desprende que cumple su obligación ejecutando la operación de pago de acuerdo con el identificador único, sin que la adición de información adicional implique una mayor diligencia exigible
Cierto que para finalizar, el TS abría una rendija a la esperanza de los usuarios estafados cuando afirmaba que “la interpretación expuesta no exime de responsabilidad al proveedor de los servicios de pago cuando se constate la concurrencia de circunstancias, ajenas al suministro de datos adicionales, que pudieren haber influido en la ejecución defectuosa de la operación, sea porque se hubiere estipulado expresamente entre el usuario y el proveedor algún requisito o exigencia añadida (v.gr. la identificación del beneficiario), sea porque el proveedor de servicios de pago del ordenante o del beneficiario hubieren aprovechado el error en beneficio propio, sea porque, comunicada sin demora la existencia del error, uno u otro no hubieran adoptado las medidas que imponía la diligencia de un comerciante experto para permitir la retroacción o, en su caso, minimizar el daño.”
Y en este escenario trufado de dudas irrumpe el Reglamento (UE) 2024/886 que supone un giro de 180 grados y un cambio de paradigma: el nuevo Reglamento europeo, aprobado en abril de 2024 y con entrada en vigor el 9 de octubre de 2025, establece una obligación clara para las entidades bancarias: deben verificar que el nombre del beneficiario proporcionado por el ordenante coincida con el titular del IBAN antes de ejecutar una transferencia inmediata en euros.
Las novedades de este nuevo Reglamento son (i) la aplicación obligatoria a todas las transferencias inmediatas dentro del espacio SEPA, (ii) el nuevo sistema de coincidencia de nombres: si hay discrepancia entre el nombre y el IBAN, el banco debe alertar al cliente antes de ejecutar la operación y (iii) la responsabilidad reforzada para las entidades financieras en caso de fraude o error por falta de verificación.
En suma se pretende reducir el riesgo de fraude, proteger al consumidor y aumentar la confianza en los pagos digitales.
Ello provoca que la Ley 19/2018, que regula los servicios de pago en España, que no contempla la obligación de verificar la identidad del beneficiario queda desfasada, lo que plantea la necesidad de una revisión legislativa a nivel nacional para armonizar el marco jurídico con las exigencias europeas.
En conclusión la obligación de verificar al beneficiario en las transferencias representa un avance significativo en la protección del consumidor y en la lucha contra el fraude financiero. El Reglamento (UE) 2024/886 marca un antes y un después en la operativa bancaria, imponiendo una responsabilidad activa a las entidades para garantizar la autenticidad de las transferencias.
Queda en todo caso abierta la cuestión respecto a la solución a los fraudes MITM ejecutados antes del 9 de octubre de 2025 y la responsabilidad de la entidad bancaria; de momento la sentencia STS de 27 de marzo arriba citada cierra la puerta a las reclamaciones contra los bancos pero no puede descartarse que la entrada en vigor del Reglamento 2024/886 y el cambio de paradigma produzca un replanteamiento de la posición del TS en la línea de la responsabilidad cuasi objetiva que la jurisprudencia menor viene manteniendo. Habrá que esperar acontecimientos pero ese cambio sería un gran éxito para los usuarios bancarios sufridores de este fraude MITM y de todos los demás dentro de las múltiples variedades de las ciber estafas.
“He out… or me out”
In the Netherlands, the legal landscape for resolving shareholder disputes has recently undergone a significant transformation. As of January 1, 2025, a new scheme—the so-called “geschillenregeling”—offers companies and shareholders a more practical and efficient way to address internal conflicts.
Shareholder conflicts are not unique to the Netherlands; they arise in companies everywhere, often because of unclear agreements, differing expectations, or personal tensions. Previously, Dutch law provided only lengthy and complex procedures, which sometimes made it impossible to reach a timely and effective solution. The new scheme changes this by introducing clear legal pathways for both majority and minority shareholders to break deadlocks and protect their interests.
At the heart of the new regulation is the theme “He out… or me out.” This phrase captures the essence of the two main legal actions now available. The first is the forced exit, where shareholders representing at least one-third of the company’s capital can ask the court – the Enterprise Chamber, known locally as the Ondernemingskamer – to force the departure of a shareholder whose conduct seriously harms the company. This conduct can include actions outside the formal role of shareholder, such as engaging in competing business activities.
The second route is the forced buyout, which allows a shareholder who has been seriously harmed by the actions of the other shareholders or by the company itself, to request to be bought out. In such cases, the court may order the remaining shareholders or the company to acquire the shares at a fair price.
What sets the Dutch approach apart is the speed and flexibility of the new procedure. Disputes are handled directly by the Enterprise Chamber, bypassing lower courts and reducing delays. Once the court decides on the merits of the case, the determination of the share price and the transfer of shares follow swiftly, with only one possible appeal to the Supreme Court. The court can also address related claims, such as damages or director liability, within the same procedure. To safeguard the company during the dispute, temporary measures – like suspension of voting rights or changes in management – can be imposed.
Determining the value of the shares is a crucial aspect of the process. Independent experts advise the court, taking into account all relevant circumstances and the parties’ agreements. The court is not bound by these opinions and can adjust the price if it would otherwise be manifestly unfair. If the value of the shares has been reduced by the departing shareholder’s conduct, the court may award additional compensation to the affected party.
While the new scheme provides robust dispute-resolution mechanisms, Dutch law also encourages companies to prevent such conflicts from arising in the first place. This is best achieved by drafting clear articles of association and shareholder agreements, covering matters such as voting rights, decision-making processes, restrictions on share transfers, and dispute resolution clauses. For international investors and business owners, seeking proactive legal advice is recommended when setting up or investing in Dutch entities.
In summary, the new Dutch shareholder dispute resolution scheme offers international businesses a reliable, efficient, and fair way to resolve internal conflicts. Whether you are a majority or minority shareholder, understanding your rights and options under Dutch law is crucial. If you are considering doing business in the Netherlands or facing a shareholder dispute, consulting a Dutch corporate lawyer will help ensure your interests are protected and your agreements are future-proof.
Should you wish to explore practical examples of dispute clauses or receive advice tailored to your situation, do not hesitate to reach out for expert guidance.










