Home / Industries / Defense & Security
Wise Limen
Wise Pirates · Industries · Defense & Security

Sovereignty, resilience and cybersecurity, for organizations that cannot fail.

SovereigntyResilienceCybersecurity+ Compliance

The threats most organizations face are not tanks. They are disinformation, intrusions, outages, sabotage and deepfakes.

Wise Limen, the defense and security unit of Wise Pirates, is the layer between information, threat and decision, for governments, municipalities, police, critical infrastructure and companies.

SIGNAL THRESHOLD DECISION DISINFORMATIONINTRUSIONOUTAGESABOTAGEDEEPFAKESOVEREIGNTYnarrative · intelligenceRESILIENCEdecision · continuityCYBERSECURITYrisk · protection COMPLIANCE · EVERY DELIVERABLE CHECKED
Signal in, decision out. The Limen is the threshold in between.
Signal inThresholdDecision outCompliance checked
ISO 27001and ISO 9001, certified on our own operations
24/7crisis activation for retainer clients
3 + 1three pillars on one compliance foundation
Independentproducts we supply, ours or a partner’s, always optional and disclosed
In short

What Wise Limen does, in one minute.

If you read one part of this page, read this. We work on three pillars and one foundation. Each pillar answers a different leadership question. The foundation makes sure everything we deliver can be shown to a board, an auditor or a regulator.

Pillar 01 · Sovereignty

Who controls your story?

Narrative, information and influence: early detection of manipulation, a narrative you can defend, geopolitical briefings.

Pillar 02 · Resilience

Can you cross the crisis?

Readiness, playbooks, simulations and continuity: the first hours rehearsed before they happen.

Pillar 03 · Cybersecurity

Does the board see the real risk?

Advisory and governance: health checks, board reporting in euros, security for AI agents.

Foundation · Compliance & Risk

Can you show it?

GDPR, NIS2, the AI Act, ISO 27001: every deliverable is checked against the rule that applies, with a record.

Why now

Security became everyone’s business, and it now has a budget line.

In June 2025 NATO Allies agreed to reach 5% of GDP by 2035, with up to 1.5% for infrastructure, networks, civil preparedness and industry. The EU adds €150B of SAFE loans.

Threats moved into the information space and the supply chain, and regulation put dates on security duties.

5%

of GDP by 2035, NATO target: at least 3.5% core defense plus up to 1.5% for resilience and security

€800B

ReArm Europe: about €650B of national fiscal room plus €150B of SAFE loans

540

foreign information manipulation incidents recorded by the EEAS in 2025, 27% of them using AI

+36%

real cyber incidents in Portugal in 2024, 2,758 handled by CERT.PT

Sources: NATO Hague Summit Declaration (25 Jun 2025); European Commission statement 25/673 (4 Mar 2025); EEAS 4th FIMI Threat Report (26 Mar 2026); CNCS Riscos & Conflitos 2025 (Sep 2025).
Portugal

€5.8B of SAFE loans coming

Portugal’s tentative SAFE allocation is about €5.84B, and its plan was in the first approval wave in January 2026. Defense spending rose from 1.55% to 2.0% of GDP between 2024 and 2025.

A&O Shearman (Sep 2025); European Commission (Jan 2026); NATO via The Portugal Brief (Apr 2026)
Public sector

The most targeted sector in the EU

Public administration was the target in 38% of the incidents ENISA analyzed, and phishing opened the door in 60% of intrusions. Local administration is now in scope of Portugal’s NIS2 law.

ENISA Threat Landscape 2025 (Oct 2025); Decreto-Lei 125/2025
Industry

A defense base made of small companies

Portugal’s defense economy counts 440 entities and €8.68B in sales, and 62% are micro or small companies. Most have no in-house team for security, compliance or B2G communication.

idD Portugal Defence via Lusa (Feb 2026)
Funding this work

How SAFE money reaches security

SAFE lends up to €150B to member states for the joint procurement of defense products, and non-EU components are capped at 35% of an end product’s cost, which favors European suppliers. It rarely funds advisory work directly; its effect on most organizations is through the supply chains and security requirements that come with it.

Council of the EU (27 May 2025)
Selling into it

What a defense supplier needs

A demonstrable security posture (NIS2, often ISO 27001), Cyber Resilience Act readiness for products with digital elements, security accreditation from the National Security Authority (GNS) for classified work, and a B2G story procurement teams can verify.

Case · Baltic Sea, Dec 2024

Five cables, no verdict

The Eagle S dragged its anchor across five undersea cables; Estlink 2 was out of service for months. The Finnish court dismissed the case for lack of jurisdiction. In the gray zone, leaders decide and speak before legal certainty arrives.

Submarine Networks (Oct 2025)
Case · Copenhagen, Sep 2025

Drones close an airport

On 22 September 2025 drones closed Copenhagen Airport for about four hours; Oslo, Munich and others followed within weeks. The disruption was physical, the pressure on communication immediate.

CNN (Oct 2025)
The 1.5% explained

The 1.5% names the work we do.

Read what the up to 1.5% of GDP may cover and it describes Sovereignty, Resilience and Cybersecurity, not tanks. It is the part of defense that reaches councils, operators, police, banks and suppliers. What counts toward it is decided by each Ally; the map helps explain how the work relates to those priorities.

NATO HAGUE DECLARATION · UP TO 1.5% OF GDP, "INTER ALIA" TO: SOVEREIGNTYRESILIENCECYBERSECURITYprotect our critical infrastructuredefend our networksensure our civil preparedness and resilienceunleash innovationstrengthen our defence industrial base COMPLIANCE & RISK · THE FOUNDATION
“protect our critical infrastructure”
ResilienceCybersecurity
“defend our networks”
Cybersecurity
“ensure our civil preparedness and resilience”
ResilienceSovereignty
“unleash innovation”
Cybersecurity
“strengthen our defence industrial base”
SovereigntyResilienceCybersecurity
Quoted wording from the NATO Hague Summit Declaration, 25 June 2025. The mapping to the pillars is ours.
The gap nobody owns

The incident was technical. The crisis was informational.

On 28 April 2025 the Iberian grid collapsed in under 90 seconds. The cause was technical, yet in Portugal public alerts took hours, under half of the messages were delivered, and rumors filled the silence.

Between signal and statement sits a decision that has to be made in the first hour. That gap is why Wise Limen exists.

11:0012:0013:0014:0015:0016:0017:0018:0019:0020:0021:0022:0023:0000:00 THE SILENCE WINDOW no effective mass alert; SMS began at 17:15, under half delivered (the cause was later confirmed as technical, not a cyberattack) 11:33 · grid collapse 50 million+ people lose power in under 90 seconds 17:15 alert SMS starts 20:00 · alerts effective under 50% delivered 23:22 fully restored PORTUGAL · 28 APRIL 2025 · LOCAL TIME · SOURCES: ENTSO-E EXPERT PANEL (MAR 2026); PARLIAMENTARY WORKING GROUP REPORT (APR 2026)
  1. Grid collapse11:3350 million+ people lose power across Iberia in under 90 seconds.
  2. The silence window11:33 to 20:00No effective mass alert: SMS alerts began at 17:15 and under half were delivered, while rumors of a cyberattack spread. The cause proved technical.
  3. Alert SMS starts17:15Public alert messages begin to go out.
  4. Alerts effective20:00Under 50% of messages delivered.
  5. Fully restored23:22Power back across Portugal.
What leaders had to decide

Before the cause was known

What to say, on which channel, with phones and internet degraded, without speculating on attribution and without losing the public’s trust.

What usually breaks

Communication, not the plan

Plans assume that phones and internet work. Contact lists are outdated. Nobody has pre-approved the holding statement. The silence becomes the story.

What we build

Decision chains that hold

Rehearsed first-hour protocols, degraded-mode communication, pre-approved messages by scenario, and the monitoring that tells you what people are hearing.

The value proposition

Three pillars. One foundation. One team.

Organized the way a leader experiences risk: what is said about you, whether you hold under pressure, and whether your systems and data are safe. Compliance is not a fourth pillar; it is the ground the three stand on. Each pillar has its own page with every service.

PILLAR 01

Sovereignty

Sovereignty is also narrative, information and communication. An organization that cannot see an influence campaign coming, or has no clear message under pressure, is sovereign only on paper.

Who controls what is said about you, including by AI assistants?
Communications AuditEssential
Disinformation MonitoringIntermediate
AI Answer Sovereignty AuditIntermediate
Counter-Narrative & Influence ResponseAdvanced
Geopolitical Risk IntelligenceAdvanced
All 10 Sovereignty services →
PILLAR 02

Resilience

Resilience is the capacity to cross a crisis without collapsing. It is built before the crisis, in the plan and the rehearsal, and proven during it, in the first hours.

Will your leadership decide and speak well in the first hour?
Crisis Readiness AssessmentEssential
Crisis Playbook DevelopmentEssential
Crisis Simulation & Tabletop ExercisesIntermediate
Citizen Preparedness & Public Risk CommunicationEssential
CER Critical Entity Resilience ProgramAdvanced
All 9 Resilience services →
PILLAR 03

Cybersecurity

Cybersecurity stopped being an IT problem and became a leadership one. We work at the advisory and governance layer, and we already secure the newest attack surface: AI agents.

Does your board see the real risk, in euros, with an owner and a date?
Cyber Health CheckEssential
Phishing Simulation & Security AwarenessEssential
Third-Party & Supply-Chain Cyber RiskIntermediate
Cyber Risk Assessment & Board ReportingAdvanced
Agentic SecurityAdvanced
All 11 Cybersecurity services →
THE FOUNDATION

Compliance & Risk

Compliance is not a fourth pillar, because no regulation stops at a pillar’s edge. NIS2 asks for crisis management, incident communication and board oversight at the same time; the CER Directive asks critical entities to prepare for every hazard, from sabotage to blackout, alongside their NIS2 cyber duties; the AI Act and the GDPR reach into how we monitor, test and communicate. So compliance works inside each pillar in three ways. Every deliverable is checked against the rule that applies before it reaches you. Seven dedicated services cover what a regulator or auditor will ask for: Compliance Readiness Assessment, Compliance Audits (GDPR, NIS2, AI Act), Technology Sovereignty & Third-Country Risk Assessment, ISO 27001 Implementation Support, AI Act Readiness, DPO support and Regulatory Watch. And each engagement leaves an evidence record you can show a regulator, an insurer or your own board. Responsibility stays with you; the evidence comes with the work.

GDPRNIS2 · DL 125/2025AI ActISO 27001DORACERCRA

Not sure which pillar comes first?Most clients start with one fixed-price assessment that looks across all three. The self-check further down takes two minutes.

Take the two-minute self-check →
Who we serve

Built for the organizations Europe relies on.

Six kinds of client, six different starting points. Pick yours to see the pressures we usually find and the services that answer them.

For ministries, agencies and government offices

Governments & ministries

You are the first target of foreign information manipulation and the first voice people expect in a crisis. You also buy under public scrutiny, so every program needs a clear mandate and evidence.

We help you see adverse campaigns early, keep a coherent narrative across institutions, rehearse the first hours with leadership, and document every decision.

For câmaras, inter-municipal bodies and parish networks

Municipalities & local authorities

Local administration is now in scope of Portugal’s NIS2 law, and the last mile of every crisis is local: the radio, the parish council, the school. After the blackout, the call for 72-hour preparedness is aimed squarely at you.

We deliver the cyber baseline, the crisis playbook and the public campaigns citizens actually act on, sized for a municipal team.

Typical services
Where most start: Start with a Cyber Health Check sized for a municipal team, plus a NIS2 readiness review. See the Cybersecurity services →
For police, civil protection and emergency services

Police & security forces

Your credibility is operational: when an incident breaks, what you say in the first hour is part of the response. You also face targeted disinformation and deepfakes of your own people.

We prepare spokespeople and decision chains, monitor the narratives around operations, and build deepfake response and content provenance into your official channels.

For energy, water, transport, telecom and health operators

Critical infrastructure

You sit under NIS2, the CER Directive and, for many, DORA. Your incidents become public events, and the regulator wants proof, not intentions.

We join the three regimes into one resilience system, with notification clocks built into the playbook and every deliverable checked.

For banks, insurers, health and multinationals under EU rules

Banks & regulated companies

Boards now carry personal responsibility, and supervisors expect reporting in hours. Reputation moves faster than any recovery plan.

We translate technical risk into board decisions in euros, and make sure your first statement is ready before it is needed.

Typical services
Where most start: Start with a 90-minute board crisis drill with a documented evidence pack. See the Resilience services →
For suppliers entering NATO and EU programs

Defense industry & dual-use SMEs

SAFE and the European defense programs favor European supply chains. To sell into them you need a credible security posture, product compliance and a B2G story that procurement teams trust.

We give smaller suppliers the security, compliance and positioning that primes have in-house, at a size that makes sense.

Communication is part of defense

Preparedness you can say out loud.

Security that nobody understands does not change behavior, and a defense supplier that cannot explain itself does not win the tender. This is where Wise Limen draws on what Wise Pirates does every day: content, campaigns, social, data and digital channels, under one roof.

B2C · Citizens

Campaigns people act on

72-hour preparedness, alert literacy and scam awareness, in plain language, accessible and multilingual, with local radio and parish kits for when the network is down. Measured before and after.

  • Public risk communication
  • Degraded-mode message banks
  • Deepfake and scam awareness
B2B · Partners & buyers

A credible B2G story

For defense and dual-use companies: positioning, technical content, proposal narratives and a digital presence procurement teams and primes can verify, aligned with what you can prove.

  • B2G positioning and messaging
  • Program and tender narratives
  • Trade-show and partner content
Boards, regulators, media

The first statement, ready

Holding statements by scenario, spokesperson preparation, regulator notifications written to the clock, and board briefs that turn a technical finding into a decision.

  • Incident communications, 24/7
  • Board and regulator reporting
  • Media and stakeholder handling
The regulatory clock

The deadlines are already on the calendar.

Security in Europe now runs on dates. Some have passed and are being enforced, others are still ahead. Each colored mark is a date one of our pillars works to.

DORA applies17 Jan 2025Preparedness Union26 Mar 2025NATO 5% pledge25 Jun 2025Democracy Shield12 Nov 2025NIS2 law in force (PT)3 Apr 2026CER entities due17 Jul 2026AI Act Art. 50 applies2 Aug 2026CRA reporting live11 Sep 2026AI marking, legacy systems2 Dec 2026PT central gov. data classified30 Jun 2027CRA fully applies11 Dec 2027NATO review2029PQC for critical systems2030NATO 5% of GDP2035 SEP 2026 2025202620272028 → 2035
SovereigntyResilienceCybersecurityDefense spendingStill ahead
  1. DORA applies17 Jan 2025
  2. Preparedness Union Strategy26 Mar 2025
  3. NATO 5% pledge25 Jun 2025
  4. European Democracy Shield12 Nov 2025
  5. NIS2 law in force in Portugal3 Apr 2026
  6. CER critical entities due to be named17 Jul 2026
  7. AI Act Article 50 applies2 Aug 2026
  8. Cyber Resilience Act reporting live11 Sep 2026
  9. Where we areSeptember 2026
  10. AI content marking for legacy systems2 Dec 2026
  11. Central government data classified for the sovereign cloud30 Jun 2027
  12. Cyber Resilience Act fully applies11 Dec 2027
  13. NATO spending review2029
  14. Post-quantum crypto for critical systems2030
  15. NATO 5% of GDP2035
Selected dates. Sources: EU Official Journal and Commission; NATO; Decreto-Lei 125/2025; Resolution of the Council of Ministers 102/2026; Regulation (EU) 2026/1744 amending the AI Act.

One of these dates is yours.In one conversation we map which deadlines apply to you and what the first fixed-price step is.

Map my deadlines →
One incident, three pillars

Sold separately. Working as one.

A single ransomware case, hour by hour, and which pillar acts at each moment. This is what the layer between threat and decision looks like in practice.

Hour 0
Cybersecurity

Ransomware hits a supplier; your systems slow down and staff cannot log in.

Hour 1
Resilience

The crisis team activates, the first holding statement goes out, the notification clock starts.

Hour 4
Sovereignty

A false claim of a data leak spreads; we detect the coordinated reposting and brief the spokesperson.

Hour 24
Cybersecurity

NIS2 early warning filed; forensic partners confirm scope; the board gets a one-page brief.

Hour 72
Resilience

Formal notification; continuity plan keeps critical services running; customers get a clear update.

Week 2
Compliance

Final report, after-action review and a documented record for the regulator and insurer.

An illustrative scenario, not a client case. It shows why the pillars are sold separately but work as one.

How we work

Start small, prove value, then stay ready.

Most engagements start with a fixed-price assessment, short in time. In an active incident we step in directly and do the assessment afterwards.

Step 1 · Diagnose

A readiness assessment

Fixed price · 2 to 4 weeks

Communications Audit, Crisis Readiness Assessment, Cyber Health Check or Compliance Readiness. A short, honest report that tells you where you stand and what matters first.

Step 2 · Build

Projects with a clear scope

Fixed price by scope

Playbooks, narrative frameworks, audits, board reporting, program set-up. Delivered by our team, with certified partners where hands-on testing is needed.

Step 3 · Stay ready

Always-on retainers

Monthly

Disinformation monitoring, dark web monitoring, crisis command, regulatory watch and DPO support. The layer that keeps you ready between crises.

The check behind every deliverable

Input

A pillar deliverable

A playbook, a risk report, a narrative strategy, a pentest summary, an OSINT dashboard.

Check 1

The rule that applies

We identify the framework that governs it for your sector: NIS2, GDPR, the AI Act, DORA, CER.

Check 2

A structured checklist

The deliverable is reviewed against the requirements of that framework, point by point.

Output

A documented record

Who checked, when, and against what. A record you can show your board, auditor or regulator; it is our review, not a certification.

Two-minute self-check

Where should you start?

Five questions any leadership team can answer honestly. Each “not yet” points to a fixed-price first step.

Do you know which rules apply to you, and by when?NIS2, CER, DORA, the AI Act, the Cyber Resilience Act

Has your leadership rehearsed a crisis in the last 12 months?A tabletop or simulation with the people who would decide

Would you know within hours if a coordinated campaign targeted you?Including what AI assistants say about you

Does your board see cyber risk in euros, with owners and dates?Not a technical report, a decision document

Could you show all of the above to a regulator tomorrow?Documented, dated, reviewed evidence

Your starting point

Five questions, two minutes

Answer the 5 questions.

    Talk it through with us →

    Nothing is sent anywhere: the check runs in your browser.

    One unit, the whole house behind it

    The specialists of Wise Limen, with the capabilities of Wise Pirates.

    Wise Limen is a dedicated team inside Wise Pirates, the way Inner Data is our data unit, backed by about 120 people who build AI, software, data platforms and campaigns.

    That is why we can move from a finding to a working tool, a monitored dashboard or a public campaign without handing you over to someone else.

    AI & Development

    Agents and tools, built in-house

    Our own AI agents, secure model layers and software. The same team that builds agents for clients knows how they break, which is where Agentic Security comes from.

    Agentic Security →
    Inner Data

    Dashboards and signals

    Data engineering and analytics for threat and narrative dashboards, risk indicators and the evidence registers regulators ask for.

    Data & analytics →
    Process Automation

    Faster, documented operations

    Automated monitoring, alerting and reporting workflows, so a lean client team can meet notification clocks without heroics.

    Process Automation →
    R&D

    New methods before they are standard

    Research into AI security, content provenance and sovereign stacks. It produced Wise Shield, our firewall for LLM applications and agents.

    R&D projects →
    Listening & Crisis

    8+ years of practice

    Social and web listening and crisis management, aligned with ISO 22361, with 24/7 activation for retainer clients. The operational core of Sovereignty and Resilience.

    Social & listening →
    Content & Campaigns

    The voice that reaches people

    Studio, social, media and digital channels to turn a message into a campaign that citizens, partners and buyers actually see.

    Content & social →
    Who you will work with

    A senior lead, not a pyramid

    Every engagement is led by a senior Wise Limen lead for strategy and communication, with cyber and compliance specialists, data and OSINT analysts, and certified partners where testing is needed.

    What clients say

    NPS above 60

    In Wise Pirates’ own client satisfaction surveys, 94% rate our technical readiness as good or excellent, and 94% say the same about our availability to communicate and resolve.

    Source: Wise Pirates client surveys, successive waves to 2026
    How we hold ourselves

    Certified on our own operations

    Wise Pirates is ISO 9001 and ISO 27001 certified. We ask of our clients what we already do ourselves, and our ISO 27001 support is built on that experience.

    Why Wise Pirates

    Your business result. A great team and five pillars to move it.

    Two pillars we run for you, three we own, and the crew at the center answering for your number.

    Judged on your KPIs, with part of our fee on the line.

    62client NPS
    500+brands since 2017
    100+crew, one house
    See our value proposition
    Your result at the center, the crew around it, and five pillars joined by ten connectionsYOUR KPI140ServicesWE RUN ITTech EnablingWE RUN ITProprietaryTechnologyWE OWN ITProprietaryFrameworksWE OWN ITCustom DataWE OWN IT10 of 10 connections lit · illustrative indexYour result at the center, the crew around it, and five pillars joined by ten connectionsYOUR KPI140ServicesWE RUN ITTech EnablingWE RUN ITProprietaryTechnologyWE OWN ITProprietaryFrameworksWE OWN ITCustom DataWE OWN IT10 of 10 connections lit · illustrative index
    Center: your result. Ring: the crew. Corners: the five pillars.
    Why Wise Limen

    Others do one part well. We join the parts.

    We respect the firms in these categories, and we partner with specialists in several of them. This is our reading of where each category usually focuses, not a judgment on any firm.

    Swipe the table to compare →
    Wise LimenBig consultanciesCyber firms and MSSPsPR and communication firms
    Where they are strongestThe decision between signal and statementStrategy, procurement, transformation at scaleDetection, response, technical testingReputation, media, crisis messaging
    Narrative and information threatsMonitored, coded to EU frameworksOccasionalRarelyAfter the fact
    Board-level cyber riskIn euros, with owners and datesYes, at enterprise pricesTechnical reportsNot their core offer
    Public and citizen communicationCampaigns, alerts and degraded-mode kitsNot their core offerNot their core offerSometimes
    Compliance record on every deliverableBuilt in, documentedAs a separate projectFor their own scopeNot their core offer
    IndependenceNo SOC to sell; products we supply, ours or a third party’s, always optional and disclosedOften implement what they adviseOften sell their platform or SOCIndependent
    Size of client served wellFrom a municipality or a 40-person supplier to a ministryPrimes, ministriesEnterpriseEnterprise and brands

    Where hands-on technical work is needed (penetration testing, forensics, a 24/7 SOC), certified partners execute and Wise Limen owns the client, the report and the relationship. We say so up front.

    FAQ

    Defense and security, answered.

    What does Wise Limen do?

    Wise Limen is the defense and security unit of Wise Pirates. It works on three pillars, Sovereignty, Resilience and Cybersecurity, on a common Compliance & Risk foundation. It helps governments, municipalities, police, critical infrastructure and companies lower risk, prepare for crises and communicate with credibility.

    What is NATO’s 5% target, and what counts toward the 1.5%?

    At The Hague in June 2025, Allies committed to 5% of GDP by 2035: at least 3.5% for core defense and up to 1.5% to, among other purposes, protect critical infrastructure, defend networks, ensure civil preparedness and resilience, unleash innovation and strengthen the defense industrial base. What counts toward it is decided by each Ally; cyber resilience, crisis readiness and continuity are among the purposes it names.

    Does NIS2 apply to Portuguese municipalities?

    Yes. Decreto-Lei 125/2025, in force since 3 April 2026, includes local administration among the relevant public entities, grouped by size. Obligations include a cybersecurity officer, registration with the CNCS, 24-hour incident notification and security measures. Check your group against the published decree; a readiness assessment gives you a first reading quickly, and the formal qualification is made with the CNCS.

    Are you a cybersecurity company?

    Not in the MSSP sense. Wise Limen works at the advisory and governance layer and owns the diagnosis, the report and the relationship. Hands-on work such as penetration testing is executed by certified partners (CREST or OSCP). We do not run your SOC, and any product we supply, ours or a third party’s, is optional and disclosed. Where our own Wise Shield firewall fits, we say so, it stays optional, and the report includes a declaration of interest and at least one market alternative.

    What should a leader say in the first hour of a cyberattack or blackout?

    Say what you know, what you are doing, what people should do and when you will update. Do not speculate on attribution. In the April 2025 Iberian blackout, rumors of a cyberattack spread while public alerts lagged, and the cause proved technical. Pre-approved holding statements and a rehearsed decision chain make the difference.

    What is FIMI, and should my organization worry about it?

    FIMI is Foreign Information Manipulation and Interference: coordinated, manipulative behavior, not just false content. The EEAS recorded 540 incidents in 2025, 27% using AI, targeting more than 100 countries, around 200 organizations and nearly 140 individuals. Ministries, security forces, critical infrastructure and defense firms are typical targets.

    We are a defense SME. What do we need to sell into NATO and EU programs?

    Usually a demonstrable cybersecurity posture (NIS2 and often ISO 27001), Cyber Resilience Act readiness if you ship products with digital elements, security accreditation for classified work where required, and a B2G story procurement teams can verify. We start with a gap assessment against your target program.

    How is compliance handled across the three pillars?

    Compliance is not a fourth pillar, because no regulation stops at a pillar’s edge: NIS2, the CER Directive, the AI Act and the GDPR each reach across sovereignty, resilience and cybersecurity. So compliance works inside each pillar: every deliverable is checked against the rule that applies, seven dedicated services cover what a regulator or auditor will ask for, and each engagement leaves an evidence record for a regulator, an insurer or your board. Responsibility stays with you; the evidence comes with the work.

    How do engagements start, and how long do they take?

    With a fixed-price readiness assessment, usually 2 to 4 weeks: a Communications Audit, a Crisis Readiness Assessment, a Cyber Health Check or a Compliance Readiness Assessment. The report tells you what matters first, and larger projects or retainers follow only if they make sense.

    Can SAFE funding pay for security or resilience work?

    SAFE finances defense products bought jointly by member states; it is a loan instrument, not a grant for organizations, and it rarely pays for advisory work directly. Its real effect for suppliers is the demand and the security and European-content requirements that come with those procurements, which is where we help.

    Are we a critical entity under the CER Directive?

    Member states had to identify critical entities in eleven sectors by 17 July 2026, including energy, transport, health, water, digital infrastructure, food and public administration. If you have been notified, you have about nine months for the risk assessment and ten until obligations apply; if you supply one, expect their requirements to reach you.

    What does a defense supplier need for classified work in Portugal?

    Security accreditation from the National Security Authority (Gabinete Nacional de Segurança) for the company and the people involved, plus the cyber and physical measures that come with it. It sits alongside NIS2, ISO 27001 and, for products, the Cyber Resilience Act.

    How much does Wise Limen cost?

    Every engagement starts with a fixed-price assessment, scoped and priced in writing before anything starts, usually over 2 to 4 weeks. We do not publish a price list because a municipality and a critical operator need very different scopes; the first 20-minute conversation is free.

    Public procurement

    How public bodies buy from us

    Every engagement starts with a fixed-price assessment, scoped and priced in writing, and sized for simplified public procurement procedures. Larger programs follow only if they make sense.

    CPV codes we work under

    • 79411000-8 General management consultancy services
    • 79416200-5 Public relations consultancy services
    • 79417000-0 Safety consultancy services
    • 79419000-4 Evaluation consultancy services
    • 79430000-7 Crisis management services
    • 72220000-3 Systems and technical consultancy services
    • 72222000-7 Information systems or technology strategic review and planning services
    • 72810000-1 Computer audit services
    • 80510000-2 Specialist training services
    • 79341400-0 Advertising campaign services

    Procurement documentation and our ISO 27001 and ISO 9001 certificates are available on request.

    Talk to us about a procurement →

    Declaration of interest: Wise Pirates has its own products (Wise Shield) and cloud services: we disclose them in every proposal, they are always optional, and no assessment depends on buying them. When we recommend one, the report includes a declaration of interest and at least one market alternative.General information only; it does not constitute legal advice. Acts reserved to lawyers under Portuguese Law No. 49/2004 are performed only by professionals legally authorized to perform them.
    Wise Limen · Defense & Security

    Be ready before it is tested.

    Tell us who you are and what concerns you most. In 20 minutes our senior team will tell you where most organizations like yours are exposed, which of the three pillars matters first, and what a fixed-price first step would look like.

    Book a 20-minute readiness conversation →
    1 · Two minutesTell us your contextSector, size and what worries you. No sales form maze.
    2 · Twenty minutesA call with a senior leadSomeone who runs this work, not a salesperson.
    3 · In writingA fixed-price first stepScope, duration and price agreed before anything starts.

    In a crisis right now? Retainer clients activate our crisis team 24/7 on their dedicated line. Not a client yet? Send an urgent request and a senior lead calls you back.

    Or go straight to a pillar:SovereigntyResilienceCybersecurity