IT outsourcing
Cybersecurity
Monitoring, incident response, vulnerability management and compliance support.
What is delivered
Detection and response with written, rehearsed procedures
A vulnerability management cycle with deadlines by severity
Support for the documentation the GDPR and Lei n.º 58/2019 require
Why did NIS2 change the calculation for mid-sized companies?
Because it substantially widened the covered sectors and lowered the size thresholds. Beyond energy, transport, banking, health and digital infrastructure, it now covers postal services, waste management, food production and distribution, manufacturing and digital service providers.
With scope came management body accountability, which is now personal, and incident notification obligations with an initial alert counted in hours. It is that deadline, more than any technical requirement, that forces detection to be working rather than documented.
And there is the chain effect: suppliers to covered entities receive contractual security requirements deriving from their client's obligations, even when not directly covered. The effective scope is wider than the legal scope, and that is how it reaches most mid-sized companies.
What does continuous monitoring actually cover?
Centralised event collection from the systems that matter, correlation, and human triage of the alerts correlation raises. The human part is what distinguishes a service from a dashboard: an alert received in two minutes and looked at by someone four hours later is an operation meeting the wrong metric.
It covers the hours when incidents happen, which are disproportionately out of hours and at weekends, precisely because attackers know when nobody is watching. Office-hours monitoring does not solve the problem the directive created.
And it covers maintaining the detection itself. Correlation rules age, new systems arrive without being integrated, and an operation that does not review coverage periodically ends with excellent detection over the infrastructure it had two years ago.
Where is the boundary between us and you during an incident?
We detect, triage, execute the first containment steps agreed in advance, and escalate within the deadline. You decide on taking a production system down, on notifying the regulator, and on communicating publicly. These are decisions with commercial and legal consequences we cannot take on your behalf.
This boundary has to be written and known before the first incident, with names and contacts rather than roles. An escalation path saying security lead works in normal conditions and fails at eight on a Friday evening, which is when it gets used.
The first containment steps we may execute without authorisation are agreed in writing and are deliberately conservative. Isolating a workstation is reversible and cheap; isolating a production server is not, and the difference between the two is where authorisation becomes necessary.
How does vulnerability management work?
By periodic scanning with remediation deadlines set by criticality and exposure rather than by score alone. A critical vulnerability on an internal system with no external exposure and a medium one on an internet-facing system require different priorities, and classifying by score alone produces lists nobody can work through.
With follow-through to remediation rather than to the report. A scan's value lies entirely in what gets fixed afterwards, and operations producing immaculate monthly reports about the same vulnerability list are documenting a problem rather than resolving it.
And with formal risk acceptance where remediation is not viable. A vulnerability that cannot be fixed without stopping a critical system is a management decision, taken with a review date and recorded. Leaving it on the list indefinitely is the alternative and is worse, because nobody decided anything.
What documentation does compliance require?
Risk management measures approved by the management body, with that approval recorded. The directive makes accountability personal, and minutes showing the risk was presented, discussed and decided are as important as the technical measure that resulted.
A written, rehearsed incident response plan. A two-hour tabletop exercise a year reveals more gaps than any documentary audit, and it is the measure with the best cost-to-value ratio on the entire list of obligations.
And evidence that the measures are actually working, which differs from evidence that they exist. Records of scans run, remediations applied, backups successfully restored and alerts triaged are what distinguishes compliance from documentation.
Where does a company with nothing in place start?
By knowing what it has. An inventory of systems, data and access is tedious, takes a week, and is the basis of every subsequent decision. Without it, every following measure is guesswork, and the first thing an incident reveals is what nobody knew existed.
Then privileged access and multi-factor authentication, the measure with the best effort-to-risk-removed ratio. Most incidents in companies of this size start with a compromised credential, and the additional factor interrupts that path.
Then tested, isolated backups, and only then continuous monitoring. Starting with monitoring without the basics in place produces alerts about an environment you cannot fix, and pays for a service to watch a problem rather than resolve it.
What always stays on your side?
The decision on acceptable risk, the regulator relationship, and formal incident notification. These are management decisions with personal accountability attached by the directive, and no supplier can take them on your behalf however much it offers to.
Approval of the measures and the record of that approval also stays. We prepare the material, present the risk in language a management body can assess, and the decision is yours and is minuted. It is precisely that record the directive asks for and that almost no company has.
Where cybersecurity can be run from
Not every delivery model suits every service. The table shows only those that make sense for this work, with the data residency position of each.
| Model | Where | When it makes sense | Personal data |
|---|---|---|---|
| Onshore Portugal | Lisbon, Porto, Braga, Coimbra, Aveiro, Faro, Funchal and Ponta Delgada | When data cannot leave the EEA, or when the end customer is Portuguese | Stay inside the EEA. No transfer. |
| Nearshore in Portugal | Lisbon and Porto, for foreign buyers | When you need a multilingual European base without incorporating | Stay inside the EEA. No transfer. |
| Global network | Uzbekistan, the Philippines, Poland, the Dominican Republic, Mexico, Colombia, Turkiye and Africa | When you need continuous cover, specific languages or the lowest cost | Poland is inside the EEA. The others require standard contractual clauses. |
The data column describes the applicable framework and is not legal advice. The detail is in international data transfers.
Related services
- Software developmentProduct and project teams for web, mobile and backend applications, working inside your processes.
- Managed servicesOngoing management of applications and infrastructure, with SLAs, monitoring and continuous improvement.
- Cloud and DevOpsMigration, delivery automation, infrastructure as code and cloud cost control.
- HelpdeskIT support for employees, by ticket, phone and on site, in Portuguese and English.
Frequently asked questions
Does NIS2 apply to our company?
Possibly directly, by sector and size, and very likely contractually if you supply a covered entity.
Do you cover out of hours?
We do, and it is the point of the service: incidents concentrate out of hours and at weekends precisely for that reason.
Can you take one of our systems down during an incident?
Only within the containment steps agreed in writing. Taking production down is your decision and should stay that way.
Do you notify the regulator for us?
We prepare the information and support the drafting. The notification and the regulator relationship are yours.
What is the initial alert deadline?
Counted in hours from becoming aware of the incident, and it is that deadline that forces detection to be working.
Do you do penetration testing?
We do vulnerability management and work with penetration test results, which we recommend are carried out independently.
Where do we start if we have nothing?
Inventory, then privileged access and multi-factor authentication, then tested backups, and only then monitoring.
Does a certification settle compliance?
It helps demonstrate it and replaces neither working measures nor the management decision on acceptable risk.
Let us look at the numbers for your case
Tell us which processes you want to outsource, in which languages and at what volume. We come back with a euro estimate and an operating design, with no commitment.
We reply within 6 hours on working days. If you would rather write: info@corpshore.solutions