Sectors
Managed security for SMEs: what genuinely makes sense to outsource
The NIS2 Directive substantially widened the universe of covered entities. Many Portuguese SMEs now face obligations that were previously only for large organisations.
Corpshore Portugal editorial team
Written by the team that builds these operations. No individual byline: this is internally reviewed work, not personal opinion.
Published

What did NIS2 change?
The scope. The directive widened the covered sectors and lowered the size thresholds, bringing in companies that had never considered themselves critical infrastructure: digital service providers, waste management, food production, manufacturing.
With scope came management accountability, which is now personal, and incident notification obligations with short deadlines. It is that deadline, more than any technical requirement, that forces detection to be working rather than documented.
What do you outsource and what do you keep in-house?
Outsources well: continuous monitoring, which needs out-of-hours coverage an SME cannot sustain in-house; vulnerability management; and first-level incident response.
Stays in-house: the decision on acceptable risk, the regulator relationship and formal incident notification. These are management decisions and no supplier can take them on your behalf, even if they offer to.
Which entities fall under NIS2?
The directive distinguishes essential and important entities, and substantially widened the sectors relative to the previous regime. Beyond energy, transport, banking, health and digital infrastructure, it now covers postal services, waste management, food production and distribution, manufacturing and digital service providers.
The size threshold brings in medium-sized companies, on the usual headcount and turnover criteria, and some entities are covered regardless of size because of how critical their activity is. Many covered companies did not consider themselves critical infrastructure and are not following the subject.
There is also the chain effect. Suppliers to covered entities receive contractual security requirements deriving from their client's obligations, even when not directly covered themselves. In practice the effective scope is wider than the legal scope, and that is how it reaches most SMEs.
What does management accountability mean?
That the management bodies have to approve cybersecurity risk management measures, oversee their implementation, and can be held accountable for failure. It is not an obligation delegable to the IT department, and that is precisely the change the directive intended to introduce.
There is also a training requirement: management has to have sufficient training to understand and assess the risks, and extending it to employees is encouraged. A board that cannot explain its own risk decisions is not meeting the obligation, even if it approved a document.
The practical implication for an SME is that security stops being a technical budget line and becomes a recurring agenda item with a recorded decision. Having minutes showing the risk was presented, discussed and decided is as important as the technical measure that resulted.
How does incident notification work?
In stages, and the first is very fast. An initial alert has to be sent to the competent authority within a deadline counted in hours from becoming aware of the incident, followed by a fuller notification within days, and a final report within a month.
The initial deadline is what forces detection to be working rather than documented. You cannot alert within hours about an incident only discovered the following week, and this is where most SMEs discover the monitoring they had did not cover the hours when incidents happen.
There is also the duty to inform service recipients when an incident may affect them, and possibly the public. This intersects with personal data breach notification obligations, which have their own deadline and their own authority, and the two processes have to exist in parallel.
Which technical measures are the minimum?
Multi-factor authentication on all external and privileged access, backups that are tested and isolated from the main network, patch management with deadlines set by criticality, and segmentation that prevents one compromised workstation from reaching everything.
Then, centralised event logging with enough retention to investigate. Without logs, an incident is not investigable and the final report the directive requires cannot be produced. Many SMEs discover this during the incident, which is when nothing can be done about retention any more.
And a written response plan, rehearsed at least once. A two-hour tabletop exercise a year reveals more gaps than any documentary audit, and it is the measure with the best cost-to-value ratio on this entire list.
How do you choose a managed security supplier?
Start with the hours. A supplier monitoring during office hours does not solve the problem the directive created, because incidents concentrate out of hours and at weekends precisely for that reason. Genuine continuous coverage, with people and not only automated alerts, is the entry criterion.
Then, time to first human action, contractually committed and measured. Receiving an alert in two minutes and having someone look at it four hours later is an operation meeting the wrong metric, and it is a distinction many proposals deliberately blur.
And clarity on the decision boundary. The supplier detects, triages and runs the first containment steps; the decision to take a production system down, to notify the regulator or to communicate publicly belongs to the company. A contract that does not separate this cleanly creates ambiguity at the worst possible moment.
How do you prepare a response exercise?
With a concrete scenario plausible for the company in question, not a generic exercise. Ransomware on a shared file server at six on a Friday evening, with the IT person on holiday, tests exactly what matters: the decisions, not the tools.
With the people who would actually decide in the room, including management. An exercise run only with the technical team tests the part that usually works and does not test the part that usually fails, which is who authorises taking a production system down and on what basis.
With the clock running and real deadlines. The initial regulator alert is counted in hours, and an exercise without time pressure does not reveal that nobody knows who drafts that notification or where the competent authority's contact details are.
And with a record of what failed, treated as an action list rather than as an assessment of people. The exercise's value lies entirely in the gaps it finds, and an organisation treating those gaps as individual failures guarantees the next exercise goes suspiciously well.
What requirements arrive through the supply chain?
Contractual security clauses imposed by covered clients, deriving from their obligations and becoming yours. They typically include incident notification deadlines shorter than the statutory ones, audit rights, and verifiable minimum technical requirements.
Supplier assessment questionnaires, increasingly detailed and increasingly frequent. Answering one well requires having the answers prepared, and answering one badly can cost a contract renewal without the subject ever being explicitly discussed.
And requirements about your own suppliers, because the chain continues. A covered client wants to know who your relevant subprocessors are and what assurances they give, and a company unable to answer that reveals more than it intended about its own management.
The strategic reading is that this preparation has stopped being a cost and become a condition of market access. An SME that can answer these questionnaires credibly has a concrete commercial advantage over competitors that cannot, and the advantage tends to grow.
Where does an SME with nothing in place start?
By knowing what it has. An inventory of systems, data and access is tedious, takes a week, and is the basis of every subsequent decision. Without it, every following measure is guesswork, and the first thing an incident reveals is what nobody knew existed.
Then, privileged access and multi-factor authentication, which is the measure with the best effort-to-risk-removed ratio on the entire list. Most incidents in companies of this size start with a compromised credential, and the additional factor interrupts that path.
Then, tested and isolated backups. A backup never restored is not a backup, it is a hope, and a backup reachable from the main network is destroyed by the same incident that makes it necessary.
And only then continuous monitoring, which is the step requiring a supplier. Starting with monitoring without the basics in place produces alerts about an environment you cannot fix, and pays for a service to watch a problem rather than resolve it.
Frequently asked questions
- Does NIS2 apply to SMEs?
- To many, yes. The directive widened sectors and lowered size thresholds.
- Is management personally accountable?
- The directive establishes management body accountability for security measures.
- What should not be outsourced?
- The decision on acceptable risk, the regulator relationship and formal notification.
- Why external monitoring?
- Because it needs out-of-hours coverage an SME rarely sustains in-house.
- What is the incident notification deadline?
- Short, counted in hours for the initial alert. It is that deadline that forces detection to work.
- Which sectors were widened?
- Among others, digital services, waste management, food production and manufacturing.
- What does continuous monitoring mean?
- Out-of-hours and weekend coverage, which is when most incidents begin.
- Does certification settle compliance?
- It helps demonstrate it, but it replaces neither working measures nor the management decision.
Let us look at the numbers for your case
Tell us which processes you want to outsource, in which languages and at what volume. We come back with a euro estimate and an operating design, with no commitment.
We reply within 6 hours on working days. If you would rather write: info@corpshore.solutions