When the crisis hits, resilience is what keeps you deciding.
Unprepared organizations fail first in communication, then in decisions, then in recovery. Resilience is the capacity to keep all three working while the crisis happens.
We work in three moves, Prepare, Hold and Recover: the readiness, playbook and rehearsal; the war room in the first hours; and the lessons that make the next crisis smaller.
You are on Pillar 02 of Wise Limen, the defense and security unit of Wise Pirates. Wise Limen works on three pillars, Sovereignty, Resilience and Cybersecurity, that stand on one Compliance & Risk foundation. Each can be hired alone; together they cover the path from signal to decision.
How the three pillars fit together →The crises of 2025 were technical. The damage was organizational.
One supplier’s ransomware stopped check-in at Brussels, Heathrow and Berlin. A cyberattack halted Jaguar Land Rover for five weeks. In the Iberian blackout, Portugal’s public alerts arrived hours late.
Regulation followed: NIS2 is law in Portugal, critical entities are being named under CER, and a crisis now runs on a legal clock.
estimated cost to the UK economy of the 2025 Jaguar Land Rover cyberattack, the costliest in UK history
of US public-company boards surveyed took part in a scenario or tabletop exercise
of organizations saw staff fail to respond to emergency communications
of EU citizens say they are not well prepared for disasters
The blackout lesson
Public alerts became effective hours after the collapse and under half of the messages were delivered; 74 of 550 emergency-radio stations were down. Hospitals now need 72 hours of energy autonomy.
Parliamentary working group report via Renascença (Apr 2026); Euronews (Apr 2026)Your crisis may start at a supplier
Third parties were involved in 48% of breaches in Verizon’s 2026 report, up from 30% in 2025. Collins Aerospace showed how one vendor can stop airports across Europe.
Verizon DBIR 2026 via Help Net Security (May 2026); DBIR 2025; ENISA via TechCrunch (Sep 2025)Now personally accountable
Under Portugal’s NIS2 law, management bodies approve and oversee security measures, must be trained, and can be held liable for acts or omissions committed with intent or gross negligence. A rehearsal is the fastest way to show that oversight.
Decreto-Lei 125/2025When the incident starts, so do the clocks.
Four hours for a first DORA report once an incident is classified as major. Twenty-four for a NIS2 early warning and for a CER notice. Seventy-two for the NIS2 notification. The clocks run whether or not you are ready, so our playbooks ship with them built in, templates pre-written and the approval chain rehearsed.
A playbook nobody has used in a drill is only a draft.
Readiness you can show
Assessment, playbooks and exercises that leave evidence: who decided what, in how long, against which rule.
People, not only procedures
A senior team in your war room, statements drafted to the clock, the regulator and the public told the same story.
The last mile of every crisis is local.
58% of Europeans say they are not prepared for a disaster, and the EU now asks every household to cope for 72 hours. Municipalities, civil protection and utilities have to make that happen, usually without a campaign team. This is where almost no private firm works, and where Wise Pirates’ content, digital and listening teams make the difference.
Baseline
A citizen survey and social listening: what people fear, believe and trust.
Campaign
Web, social, radio, printed household guide and school kits, accessible and multilingual.
Message bank
Approved alerts and holding messages by hazard, ready for SMS and Cell Broadcast.
Degraded mode
Radio, parish councils and printed trees for when networks are down.
Measure
Kit ownership and alert recall, before and after, reported to the executive.
Running a municipality, a civil protection service or a utility?Ask for the Citizen Preparedness program outline and a sample household guide.
Request the program outline →Nine services, from a first readiness check to standing command.
Nine services in three levels. Three are new for 2026, answering what changed most this year: citizen preparedness, the CER Directive and always-on crisis command. Open any card to see what is included and when it fits.
Essential
Where most start: know your readiness, write it down, and tell citizens what to do.
Crisis Readiness Assessment
A structured diagnosis of how ready you are for a digital, reputational or operational crisis: processes, existing plans, communication gaps, decision-making under pressure and the readiness of your response teams.
What is included and when it fits (Crisis Readiness Assessment)
- Typical scope
- 2 to 4 weeks; 6 to 10 interviews; one maturity report and a board read-out
- What is included
- Interviews with leadership and the communication team; review of existing crisis plans; assessment of escalation and decision processes; crisis communication capacity; benchmarking against sector practice and ISO 22361; a maturity report with a prioritized roadmap.
- When it fits
- A natural entry point when you suspect you are not ready but are not sure what is missing. The report is also the internal case for what follows.
Crisis Playbook Development
Operational crisis playbooks: structured documents that define who does what, when and how in each identified scenario, with decision trees, escalation protocols, spokesperson guides and templates by audience.
What is included and when it fits (Crisis Playbook Development)
- Typical scope
- 4 to 8 weeks; 3 to 6 priority scenarios; templates in Portuguese and English
- What is included
- The most likely crisis scenarios for your sector, prioritized; a playbook per scenario with decision trees; roles and responsibilities (a crisis RACI); templates for internal, media and stakeholder communication; activation and escalation protocols; regulatory notification clocks built in; offline contact trees; spokesperson guide by scenario.
- When it fits
- When you have no formal playbooks, or have them but they predate hybrid threats, cyberattacks and the new notification deadlines.
Citizen Preparedness & Public Risk Communication
Public preparedness and risk-communication programs for municipalities, inter-municipal bodies, civil protection, utilities and critical operators, designed so citizens act (a 72-hour kit, a family plan, knowing how alerts reach them) and so you can prove they did.
What is included and when it fits (Citizen Preparedness & Public Risk Communication)
- Typical scope
- 3 to 6 months per campaign wave; baseline and follow-up survey included
- What is included
- A baseline citizen survey and social listening; a multichannel campaign in plain language (web, social, printed household guide, local radio kits, school and senior-center toolkits); a library of pre-approved alert and holding messages by hazard; accessible and multilingual versions; a degraded-mode communication plan; a municipal communication tabletop; before-and-after KPIs.
- When it fits
- Municipalities and inter-municipal bodies, especially coastal, wildfire-prone or seismic ones; water, energy and telecom operators; hospitals and schools. Natural moments: EU Preparedness Day, the start of the wildfire season, the Cell Broadcast rollout.
- Related
- Narrative & Messaging Strategy (Sovereignty) → · Wise Pirates Social Media →
Intermediate
Rehearse it, and have people beside you when it happens.
Crisis Simulation & Tabletop Exercises
Facilitated crisis exercises, from a half-day tabletop with the management team to multi-day simulations with the executive, testing plans, processes and people against realistic and progressively harder hybrid scenarios.
What is included and when it fits (Crisis Simulation & Tabletop Exercises)
- Typical scope
- From a 90-minute board drill to a two-day simulation; one to three scenarios
- What is included
- Scenario design for your sector and profile; professional facilitation; live injects and complications, including simulated media and social pressure; assessment of communication, decision and coordination; structured debrief; findings report with improvement actions and an evidence pack for auditors.
- When it fits
- When you have playbooks that were never tested under pressure, or a board that needs to see for itself that the organization is ready for a major crisis.
Incident Response Communications
Real-time communication support during serious incidents: the Wise Limen team beside your leadership in the acute phase, so that communication with media, regulators, partners and staff is coordinated and strategic.
What is included and when it fits (Incident Response Communications)
- Typical scope
- Retainer with agreed activation terms, or ad-hoc support during an incident
- What is included
- Activation of a dedicated team (virtual or on-site war room); internal communication during the incident; drafting and approval of statements; spokesperson briefing; real-time media monitoring; coordination with regulatory notifications; social media management during the incident.
- When it fits
- As a retainer you activate when needed, or as response to an incident already under way. Critical in cyberattacks with public impact, where the first hours set the reputational path.
- Related
- Counter-Narrative & Influence Response (Sovereignty) → · Cyber Risk Assessment (Cybersecurity) →
Advanced
Continuity, leadership and regulated resilience, run as programs.
Business Continuity Planning
Structured operational continuity plans for digital and hybrid threat scenarios, including recovery time and recovery point objectives (RTO and RPO), crisis governance and a program of tests and periodic updates.
What is included and when it fits (Business Continuity Planning)
- Typical scope
- 8 to 12 weeks for the first critical processes; annual test cycle
- What is included
- Business Impact Analysis of critical processes; RTO and RPO by function; continuity plans by scenario; activation and management governance; integration with technical cybersecurity plans through a partner; periodic tests; annual review. Aligned with ISO 22301.
- When it fits
- For critical infrastructure, essential services or any organization where an interruption would have serious impact, and that must show regulators (NIS2, DORA, CER) that its plans are robust and tested.
- Related
- Third-Party & Supply-Chain Cyber Risk (Cybersecurity) →
Executive Resilience Program
An ongoing program to build resilient leadership: training and coaching for executive teams to decide and communicate well under extreme pressure, with periodic simulations and individual coaching.
What is included and when it fits (Executive Resilience Program)
- Typical scope
- 6 to 12 months; quarterly simulations; individual coaching sessions
- What is included
- Individual and team resilience assessment; modular training in crisis management, decision-making under pressure and leadership communication; individual executive coaching; periodic simulations with feedback; organizational resilience culture; progress metrics and an annual report.
- When it fits
- For organizations that know technical preparation is not enough: the quality of leadership during a crisis decides the result.
CER Critical Entity Resilience Program
A program that takes an entity designated, or likely to be designated, under the Critical Entities Resilience Directive (Decreto-Lei 22/2025 in Portugal) from notification to documented readiness for supervision, joined with its NIS2 and continuity work into one resilience system.
What is included and when it fits (CER Critical Entity Resilience Program)
- Typical scope
- Sized to the Directive and to DL 22/2025: risk assessment within 9 months and resilience plan within 10 months of notification; liaison officer designated and communicated within 10 days of designation
- What is included
- Dual-regime gap assessment (CER, NIS2 and DORA where relevant); all-hazards risk assessment including hybrid threats, sabotage and interdependencies such as energy autonomy; the resilience plan; set-up of the liaison officer role; an incident-notification playbook with a timed drill; alignment with crisis playbooks and continuity plans; an annual exercise program; an evidence pack prepared for inspections.
- When it fits
- Entities in the eleven CER sectors, including energy, transport, health, water, digital infrastructure, food and public administration, and the suppliers designated entities rely on.
- Related
- NIS2 & Cyber Governance Advisory (Cybersecurity) →
Always-on Crisis Command
A subscription that turns listening and 24/7 activation into a standing crisis capability: AI-assisted early warning, a pre-built war room and approved message bank, notification-clock management, quarterly micro-drills and contracted activation times.
What is included and when it fits (Always-on Crisis Command)
- Typical scope
- Monthly subscription in three tiers: Watch, Command, Command plus supply chain
- What is included
- A watch list of risks, stakeholders, executives, critical suppliers and sites; AI-assisted monitoring with analyst triage; monthly horizon briefings; holding statements and deepfake and false-narrative protocols; a NIS2, DORA and CER notification-clock tool; quarterly 60 to 90 minute drills, including for boards; a 24/7 activation line with contracted activation times; after-action reviews. Optional supply-chain module for defense-industry clients.
- When it fits
- Mid-size and large organizations without an in-house crisis team, regulated NIS2 entities, retailers and manufacturers with just-in-time supply chains, defense suppliers, and public bodies after an incident.
- Related
- Disinformation Monitoring (Sovereignty) →
In an incident right now?Retainer clients use their dedicated line. Everyone else: send an urgent request and a senior lead calls you back. Not urgent? The self-check below shows where to start.
Send an urgent request →New 2026 marks services new in 2026. In-house is delivered by the Wise Limen team; Certified partner means hands-on work by a specialist partner holding the relevant accreditation or certification, with Wise Limen owning the client, the report and the relationship.
Most crisis plans fail at the phone.
Plans assume that mobile networks, internet and email keep working. In the blackout they did not. We design the communication for the day they fail: who talks to whom, on which fallback channel, with which pre-approved message, and we rehearse it.
Often fails first
- Mobile network
- Mobile data and internet
- Email and messaging
- Social media
- Corporate apps
Rehearsed fallbacks
- Battery radio and local stations
- Parish councils and municipal boards
- Printed contact trees
- Satellite phones for the crisis team
- Liaison points and runners
- Cell Broadcast alerts, where cell sites have backup power
For municipalities and critical operators this is also public communication: the parish council, the local radio and the printed guide are the last mile to the citizen. It is where our Citizen Preparedness program starts.
Would your organization hold?
Five questions for a CEO, a mayor or a crisis lead. Each “not yet” points to a first step.
Is your crisis playbook updated for cyberattacks, hybrid threats and the notification clocks?NIS2 24h and 72h, DORA 4h, CER 24h
Has your leadership rehearsed a crisis in the last 12 months?A tabletop or simulation with the people who decide
Would your crisis communication work without mobile networks or internet?Radio, printed trees, satellite, liaison points
Do you know whether you are in scope of NIS2, CER or DORA?And what you must show the regulator
Are your critical suppliers part of your exercises?Your crisis may start at a supplier
Five questions, two minutes
Answer the 5 questions.
Nothing is sent anywhere: the check runs in your browser.
No compliance services of its own. By design.
Resilience already carries a heavy regulatory load through the CER program, and works hand in hand with NIS2 & Cyber Governance Advisory in Cybersecurity. So the compliance foundation does not add services here. It verifies what the pillar delivers, and three cross-pillar services open and sustain the work.
Every playbook ships checked
A crisis playbook ships with a documented review against NIS2: the notification chain, the roles and the evidence register mapped to the rule. A continuity plan ships mapped to ISO 22301 and, where relevant, DORA and CER. It is our review, not a certification.
Compliance Readiness Assessment
A fast diagnosis of your regulatory posture across GDPR, NIS2 and the AI Act: gaps by rule, priority by risk and deadline, and a roadmap with effort estimates. The entry point that opens all three pillars in one conversation.
Compliance Audits: GDPR, NIS2, AI Act
A formal audit per rule, or all three in one integrated review: documented evidence, non-conformities classified as critical, major or minor, and a remediation plan with owners and dates.
Regulatory Watch & Horizon Scanning
A monthly retainer that follows the EU and national legislative pipeline, filters what matters for your sector and typically gives you months of warning before new obligations apply.
Resilience is the pillar that benefits most from the foundation: not as extra services, but as the verification that turns a document into evidence you can show a board, an auditor or a regulator.
Plans, people and the public, in one team.
The resilience market splits three ways: consultancies strong on governance, crisis PR firms strong on reputation, and software platforms strong on tooling. Free exercise templates set a floor on price. Our place is the combination, sized for the organizations that need it most.
| Wise Limen | Big-4 and risk consultancies | Crisis PR firms | Resilience software | Free templates | |
|---|---|---|---|---|---|
| Playbooks with regulatory clocks | Built in and checked | Yes | Partly | Templates | Generic |
| Simulation with media and social pressure | Yes, with our own content team | Yes, premium | Yes | Self-serve | No |
| Citizen and public communication | Campaigns and degraded-mode kits | Rarely | Sometimes | Alerting only | No |
| Continuity, NIS2 and CER evidence | Yes, with partners, documented | Yes | Not their core offer | Tool support | No |
| A war room in the first hours | 24/7 activation on retainer | Large accounts | Yes | Software | No |
| Fit for municipalities and mid-market | Sized and priced for it | Rarely | Sometimes | License-based | Free, but generic |
| Listening, content studio and AI, in-house | Yes, the Wise Pirates teams | Rarely | Partly | No | No |
Platforms such as crisis-exercise and alerting tools are partners for us, not rivals: we bring the scenario, the facilitation and the communication layer.
The 90-minute board drill
One realistic scenario from your sector, played with your board or executive team, with simulated media and regulator pressure. It is the quickest way to see whether your plan survives contact with the people who decide.
Book a board drill →- Duration
- 90 minutes, on-site or remote, plus a 30-minute preparation call
- Scenario
- Built on your sector, suppliers and regulators: ransomware, blackout, deepfake or supplier failure
- Facilitation
- A senior Wise Limen lead, following ISO 22361 and exercise good practice (ISO 22398, NIST SP 800-84)
- You receive
- An evidence pack: decisions and timings, gaps found, and three priority fixes
- Price
- Fixed, agreed in writing before we start
What the Directive says, and what Portugal adds.
Most resilience obligations come from Brussels but are enforced in Lisbon. This is the map we work from.
| Rule | What the EU text says | What Portugal adds | What we build |
|---|---|---|---|
| NIS2 | Continuity and crisis management are mandatory measures; 24-hour early warning, 72-hour notification, final report within one month | Decreto-Lei 125/2025, in force since 3 April 2026; CNCS registration through MyCiber; directors liable for acts or omissions with intent or gross negligence | Playbooks with the notification chain, board training, evidence register |
| CER | Critical entities identified by 17 July 2026; about 9 months for the risk assessment and 10 months until obligations apply; incident notification | Decreto-Lei 22/2025: liaison officer within 10 days of designation; risk assessment within 9 months and resilience plan within 10 months of notification; national notification rules to check against the decree | The CER program, joined with NIS2 and continuity work |
| DORA | Initial report within 4 hours of classifying an ICT incident as major, and no later than 24 hours from awareness | Supervised through the financial authorities | Reporting chains, board drills, third-party scenarios |
| Preparedness Union | 30 actions, including 72-hour household self-sufficiency | Municipal 72-hour emergency pack promoted by the association of municipalities; 72-hour energy autonomy for hospitals and emergency services | Citizen Preparedness campaigns and degraded-mode plans |
National implementing rules change and summaries sometimes disagree. We always verify deadlines against the published decree for your case.
For organizations that cannot stop.
Resilience clients share one trait: an interruption becomes somebody else’s problem within hours.
Municipalities and civil protection
Crisis playbooks, degraded-mode communication and citizen preparedness campaigns that reach the last mile.
Ministries and government offices
Executive simulations, crisis governance and communication that keeps institutions aligned.
Police and emergency services
Incident communications, spokesperson preparation and first-hour protocols rehearsed on real scenarios.
Critical infrastructure
CER and NIS2 programs, continuity plans with RTO and RPO, and exercises with suppliers.
Banks, insurers and health
DORA-ready reporting chains, board drills and always-on crisis command.
Defense industry and manufacturers
Supply-chain crisis modules and continuity for just-in-time operations.
Where Resilience holds the line in one incident.
A single ransomware case, hour by hour. The highlighted steps are this pillar’s; the others are its sister pillars.
Ransomware hits a supplier; your systems slow down and staff cannot log in.
The crisis team activates, the first holding statement goes out, the notification clock starts.
A false claim of a data leak spreads; we detect the coordinated reposting and brief the spokesperson.
NIS2 early warning filed; forensic partners confirm scope; the board gets a one-page brief.
Formal notification; continuity plan keeps critical services running; customers get a clear update.
Final report, after-action review and a documented record for the regulator and insurer.
An illustrative scenario, not a client case. It shows why the pillars are sold separately but work as one.
We work in the standards regulators and auditors read.
Every Resilience deliverable is built on recognized frameworks, so it can be audited, compared and improved.
Prepare, hold, recover: how an engagement grows.
Advanced programs are not sold before the essentials, except in an active incident, when we step in directly. Otherwise every Resilience engagement climbs the same ladder.
Crisis Readiness Assessment
Where the plan, the people and the communication will break first. Often followed by a 90-minute board drill.
Playbooks and exercises
Scenario playbooks with clocks and templates, continuity plans, NIS2 and CER programs, tabletops with an evidence pack.
Crisis command retainer
Early warning, 24/7 activation, quarterly drills and after-action reviews, so readiness does not decay.
Resilience works best with Sovereignty and Cybersecurity.
Most crises start as a narrative or a technical incident. The rest of Wise Limen, and the Wise Pirates services it draws on, are one click away.
Resilience, answered.
What is the difference between crisis management and business continuity?
Business continuity (ISO 22301) keeps critical activities running within set recovery times. Crisis management (ISO 22361) is the leadership, decision-making and communication that deals with an unexpected, whole-organization threat. You need both: the continuity plan restores operations while the crisis team protects people, strategy and reputation.
Does NIS2 require a crisis management plan?
Yes. Article 21 lists business continuity and crisis management among mandatory risk-management measures, and Article 23 requires a 24-hour early warning, a 72-hour notification and a final report within one month. In Portugal, Decreto-Lei 125/2025 has been in force since 3 April 2026, and board members can be held liable.
What is the CER Directive and does it apply to us?
CER is the EU law on the physical and all-hazards resilience of critical entities in eleven sectors. Member states had to identify critical entities by 17 July 2026, and designated entities then have about nine months for the risk assessment and ten until the resilience obligations apply. In Portugal it is Decreto-Lei 22/2025, which follows the Directive’s timelines and requires the liaison officer to be designated within 10 days, so we check the dates against your designation. If you run or supply essential services, assume it is relevant.
How often should we run a crisis exercise?
At least once a year for the crisis team, and again after any major change or incident. Good practice mixes short drills with a larger annual simulation. Only 15% of the US public-company boards in the latest Deloitte survey took part in a tabletop, so a board drill is often the highest-value first step.
What should a crisis playbook contain?
Activation criteria and severity levels; the team and a RACI; decision trees; escalation paths; regulatory notification clocks; stakeholder maps; approved holding statements; a spokesperson guide; contact trees that work offline; and a log and after-action template. A playbook nobody has tested in a drill is only a draft.
Can we not just use free tabletop templates?
Free packages exist and suit internal awareness. A facilitated exercise earns its cost when you need a scenario tailored to your suppliers and regulators, independent facilitation, simulated media and social pressure, and an evidence report built for auditors and insurers.
What did the April 2025 Iberian blackout teach organizations?
That plans assuming mobile and internet access fail. In Portugal, public alert messages became effective only hours in and under half of them were delivered, and dozens of emergency-radio stations were down. Build degraded-mode communication and energy autonomy, and rehearse both.
Should our municipality run a 72-hour preparedness campaign?
Yes, if you want citizens to cope in the first three days of a major disruption. It is EU policy since the March 2025 Preparedness Union Strategy, Portugal’s association of municipalities promotes a 72-hour emergency pack, and 58% of Europeans say they are not prepared. Pair a clear household checklist with local channels and measure the change.
Are we under NIS2, DORA or both?
Financial entities covered by DORA follow DORA for ICT risk and incident reporting, which takes precedence over NIS2 for those topics; other sectors follow NIS2 and, where designated, CER. Many groups have entities under different regimes, so we map them entity by entity before building one reporting chain.
How much does a crisis exercise cost?
A 90-minute board drill is the lightest option; a multi-day simulation with injects and media pressure is the heaviest. Both are sold at a fixed price agreed in writing before we start, based on the number of scenarios, participants and sites.
Public buyers: Resilience work is usually procured under CPV 79430000-7 (crisis management), 79417000-0 (safety consultancy), 80510000-2 (specialist training) and 79341400-0 (advertising campaigns). See how public bodies buy from us →
Declaration of interest: Wise Pirates has its own products (Wise Shield) and cloud services: we disclose them in every proposal, they are always optional, and no assessment depends on buying them. When we recommend one, the report includes a declaration of interest and at least one market alternative.General information only; it does not constitute legal advice. Acts reserved to lawyers under Portuguese Law No. 49/2004 are performed only by professionals legally authorized to perform them.Rehearse the crisis before it rehearses you.
Start with a Crisis Readiness Assessment or a 90-minute board drill. You will leave with a clear view of where the plan, the people and the communication would break first, and a fixed-price path to fix it.
Book a Crisis Readiness Assessment →In a crisis right now? Retainer clients activate our crisis team 24/7 on their dedicated line. Not a client yet? Send an urgent request and a senior lead calls you back.