Home / Industries / Defense & Security / Cybersecurity
Wise Limen
Wise Limen · Pillar 03 · Cybersecurity

Cybersecurity is no longer an IT problem. It is a leadership one.

SovereigntyResilienceCybersecurity+ Compliance

Attacks that stop hospitals or cut energy are strategic events, and under Portugal’s NIS2 law the board’s name is now on them.

We work at the advisory and governance layer: from an affordable first diagnosis to board-level risk and the security of AI agents.

TECHNICAL FINDINGSWHAT THE BOARD GETSAdmin accounts without MFASupplier with remote admin accessUnpatched VPN applianceAI agent with write access to CRMStaff credentials on a leak siteBOARD BRIEF · EXAMPLERISKRansomware via a supplierIMPACTIn euros, with likelihoodOWNERA named executiveDECISIONApprove the fix, by a dateRULENIS2 Art. 21, DL 125/2025
From findings to a decision, in the language of the board.
Findings inBoard brief outRisk in eurosOwner and date
ISO 27001and ISO 9001, certified on our own operations
2 to 4 wksfor a fixed-price Cyber Health Check
CREST · OSCPaccredited firms and certified testers
OWASPAgentic Top 10 mapped in every agent audit

You are on Pillar 03 of Wise Limen, the defense and security unit of Wise Pirates. Wise Limen works on three pillars, Sovereignty, Resilience and Cybersecurity, that stand on one Compliance & Risk foundation. Each can be hired alone; together they cover the path from signal to decision.

How the three pillars fit together →
Why now

The rules changed, the attack surface changed, and the bill went up.

Portugal’s NIS2 law brings fines up to €10M or 2% of turnover and personal liability for directors. The Cyber Resilience Act’s reporting started in September 2026. AI agents act with more access than most staff.

Most of the answer is governance: knowing your risk, deciding with evidence, and holding suppliers and machines to the same standard as people.

$4.99M

average cost of a data breach worldwide in 2026, up 12% in a year

1 in 4

malicious breaches were AI-enabled, costing about $6M each

38%

of the incidents ENISA analyzed targeted public administration, the most of any sector

+36%

real cyber incidents in Portugal in 2024, 2,758 handled by CERT.PT

Sources: IBM Cost of a Data Breach 2026 (29 Jul 2026); ENISA Threat Landscape 2025 (Oct 2025); CNCS Riscos & Conflitos 2025 (Sep 2025).
NIS2 in Portugal

The clock started on 3 April

Decreto-Lei 125/2025 is in force, the CNCS MyCiber platform opened on 23 June 2026, and Article 25(2) makes directors personally liable for acts or omissions committed with intent or gross negligence. Incident notification runs to 24 hours from day one.

Decreto-Lei 125/2025; CNCS Regulation 756/2026
AI agents

More access than your interns

OWASP published its first Top 10 for Agentic Applications in December 2025. Gartner expects 25% of enterprise breaches to trace back to AI agent abuse by 2028.

OWASP (Dec 2025); Gartner (Oct 2024)
Local government

Not only a big-company problem

In September 2026 a ransomware attack hit the e-mail server of the Leiria inter-municipal community, which serves ten municipalities. Local administration is in scope of NIS2.

ECO (16 Sep 2026)
The frontier

Your AI agents need the same security as your people.

An AI agent can read your email, update your CRM, move files and trigger payments. It can also be steered by an instruction hidden in a document. Agentic Security audits agents in production against the OWASP Top 10 for Agentic Applications, sets the controls, and keeps a human on every high-impact decision.

Wise Pirates builds AI agents. That is exactly why we know how they break.

Wise Limen · Agentic Security
Audit

Mapped to OWASP, one to one

Every finding is tied to a named risk, from goal hijack to memory poisoning, with severity and a fix.

Govern

Humans where it matters

Least privilege, sandboxing, approval gates and monitoring, documented for the AI Act and your auditors.

AN AI AGENT IN PRODUCTIONCONTROLS · LEAST PRIVILEGE · GUARDRAILS · MONITORINGEmailCRMFilesHUMAN OKPaymentsCodeWeb searchAGENTASI01 Goal hijackASI02 Tool misuseASI03 Privilege abuseASI06 Memory poisoning
Attacks we test every agent against
ASI01Goal hijack
ASI02Tool misuse
ASI03Privilege abuse
ASI06Memory and context poisoning
ControlsLeast privilege, guardrails, monitoring
High impactHuman approval before payments
The Cybersecurity services

Eleven services, from a first health check to the post-quantum era.

Eleven services in three levels. Three are new for 2026, answering what changed most this year: supply-chain cyber risk, Cyber Resilience Act readiness and post-quantum readiness. Open any card to see what is included and when it fits.

Essential

Where most start: know your posture and reduce the human risk.

Cyber Health Check

Essential

A fast diagnosis of your digital security posture: a structured maturity assessment, the most critical vulnerabilities and an immediate action roadmap, delivered in 2 to 4 weeks.

What is included and when it fits (Cyber Health Check)
What is included
Maturity assessment by domain (people, process, technology); the ten most critical vulnerabilities; digital attack-surface analysis; review of existing policies and controls; an executive report with maturity scoring and a prioritized roadmap; a presentation to leadership.
When it fits
The entry service for any organization that wants to know where it stands before investing in more complex solutions. The report is the starting point for everything that follows.
In-houseCertified partnerB2GB2B

Phishing Simulation & Security Awareness

Essential

A combined program of behavioral security testing and training: realistic phishing and social-engineering simulations, followed by training tailored to the results, to reduce the human risk.

What is included and when it fits (Phishing Simulation & Security Awareness)
What is included
Simulated phishing campaigns by level of sophistication, including AI-written lures; technical execution through a certified partner; results by department and profile; modular training on the gaps found; progress reporting over time; completion records per employee.
When it fits
For any organization, whatever its size or sector. Around six in ten breaches involve a human action, which makes this the easiest service to justify internally and the one with the most immediate, measurable effect.
In-houseCertified partnerB2BB2G

Intermediate

Test, monitor and govern the exposure around you.

Penetration Testing & Vulnerability Assessment

Intermediate

A controlled simulation of a real attack on your systems and infrastructure, combined with a systematic scan for known vulnerabilities, delivered with findings prioritized by criticality and an actionable remediation roadmap.

What is included and when it fits (Penetration Testing & Vulnerability Assessment)
What is included
Scope and method defined with you; testing through our partners: CREST-accredited firms or testers holding OSCP or equivalent certifications; vulnerability assessment of infrastructure, web applications and cloud; a full technical report with CVSS scoring; an executive report for non-technical leaders; debrief and remediation plan.
When it fits
When you need to validate your posture with concrete evidence, because of regulation (NIS2, DORA), a client or partner requirement, or your own risk management.
Certified partnerB2GB2B

Dark Web & Threat Monitoring

Intermediate

Continuous monitoring of your data and credentials exposed on the dark web and in cybercrime forums, delivered as a monthly retainer with immediate alerts when compromised data is detected.

What is included and when it fits (Dark Web & Threat Monitoring)
What is included
Continuous monitoring of dark web markets, Telegram channels, cybercrime forums and paste sites; immediate alerts on credentials, data or documents; context and risk assessment per exposure; a monthly exposure and trends report; mitigation recommendations per incident.
When it fits
For any organization, and especially those handling sensitive client or employee data. The value is visible fast: many discover in the first week that credentials they did not know about are already out there.
Related
Threat Intelligence & OSINT (Sovereignty) →
In-houseCertified partnerB2B

Cloud & Data Sovereignty Advisory

Intermediate

Strategic advisory to align your data architecture with European digital sovereignty requirements, including migration strategy to EU sovereign clouds, GDPR and AI Act alignment, and the management of dependency on non-European providers.

What is included and when it fits (Cloud & Data Sovereignty Advisory)
What is included
Assessment of where your data sits and flows; dependency risk on non-European cloud providers; migration strategy to sovereign options (European providers, Gaia-X-aligned offers); a GDPR and AI Act framework for your data systems; data residency and governance policy; a phased roadmap. It follows the Technology Sovereignty assessment of the compliance layer: that one documents the exposure, this one designs the move.
When it fits
For public bodies with data sovereignty duties, companies processing EU citizens’ data on non-European infrastructure, and anyone anticipating stricter European rules on data location.
Related
Technology sovereignty assessment (Sovereignty) → · Wise Pirates Cloud Services →
In-houseB2GB2B

Third-Party & Supply-Chain Cyber Risk

New 2026Intermediate

A governance program for supplier cyber risk: tiering, due diligence, contract clauses, continuous monitoring and board reporting, aligned with NIS2 Article 21 and, for finance, DORA’s third-party rules.

What is included and when it fits (Third-Party & Supply-Chain Cyber Risk)
What is included
Supplier inventory and criticality tiering, including AI and SaaS vendors and third-country exposure; security questionnaires mapped to ISO 27001, NIS2 and DORA; external attack-surface ratings through a partner tool; NIS2 and DORA contract security requirements for your legal team to include in supplier contracts; concentration and exit-strategy analysis; a quarterly supplier-risk dashboard for the board.
When it fits
Every NIS2 essential or important entity now implementing its measures, financial entities under DORA, and the suppliers who must answer those questionnaires, a second market in itself.
Related
Always-on Crisis Command, supply-chain module (Resilience) →
In-houseCertified partnerB2BB2G

Cyber Resilience Act Readiness

New 2026Intermediate

Readiness for the Cyber Resilience Act: for manufacturers, the reporting duties live since 11 September 2026; for importers and distributors, their own verification duties; and for all, full application on 11 December 2027.

What is included and when it fits (Cyber Resilience Act Readiness)
What is included
Scope and product classification; a reporting runbook for ENISA’s Single Reporting Platform (24 hours, 72 hours, 14 days, one month) with a tabletop; a coordinated vulnerability disclosure policy; SBOM and vulnerability-handling process design; support-period policy; technical documentation gap analysis and choice of conformity route; board and product-owner briefing.
When it fits
Portuguese and Iberian makers of software, IoT, OT and industrial equipment, dual-use suppliers to the defense sector, and software houses. Wise Pirates builds software itself, so we speak product teams’ language.
In-houseCertified partnerB2B

Advanced

NIS2 governance, board-level risk, AI agents and the next cryptographic transition.

NIS2 & Cyber Governance Advisory

Advanced

Strategic advisory for NIS2 compliance (Decreto-Lei 125/2025 in Portugal) and for the cybersecurity governance framework, from the first gap analysis to the implementation roadmap and reporting for board and regulator.

What is included and when it fits (NIS2 & Cyber Governance Advisory)
Typical scope
6 to 10 weeks for the gap analysis and roadmap; half-yearly reviews
What is included
NIS2 gap analysis against your current state; actions prioritized by criticality and deadline; security policies and procedures; governance aligned with NIST CSF and ISO 27001; board and regulator reporting, including the 24-hour, 72-hour and one-month notification chain; coordination with technical partners; half-yearly maturity review.
When it fits
For any entity in scope of NIS2, essential or important, that needs to structure compliance strategically and not only technically.
Related
Cyber Health Check → · Compliance Audits →
In-houseCertified partnerB2BB2G

Cyber Risk Assessment & Board Reporting

Advanced

A formal, periodic assessment of your digital risk with structured output for the board, auditors and regulators, using recognized frameworks (NIST CSF 2.0, ISO 27005) and translating technical risk into business language and decisions.

What is included and when it fits (Cyber Risk Assessment & Board Reporting)
What is included
A full risk assessment using NIST CSF or ISO 27005; risk quantified as potential financial impact; a board report in executive, non-technical language; a risk-indicator dashboard for periodic reporting; presentation to the board with Q&A; integration with internal and external audit.
When it fits
For boards that need clear visibility of digital risk, because of regulatory pressure (NIS2 and DORA require board oversight), cyber-insurer demands or their own governance maturity.
Related
Executive Resilience Program (Resilience) →
In-houseCertified partnerB2BB2G

Agentic Security

Advanced

Security for autonomous AI systems (AI agents): audit of agents in production, protection against prompt injection and tool manipulation, a governance framework for autonomous decisions and AI Act alignment for high-risk contexts.

What is included and when it fits (Agentic Security)
What is included
Security audit of AI agents in production; assessment of agentic attack vectors mapped to the OWASP Top 10 for Agentic Applications (goal hijack, tool misuse, privilege abuse, memory and context poisoning and more); a governance framework for autonomous decisions; sandboxing and access-control policies for agents; AI Act alignment; secure agentic design training; an optional testing tier (AI red teaming). Can be paired with Wise Shield, our own firewall for LLM applications and agents; it is always optional and declared as our own product.
When it fits
For any organization already using, or planning to use, AI agents in critical processes, which in 2026 includes almost every regulated sector adopting generative AI.
Why it is a differentiator
An agent can be steered by a malicious instruction hidden in a document to leak data or take a wrong action, with no human noticing. Traditional security does not cover this. Wise Pirates builds agents, which is why we know how they break.
Related
Wise Pirates Agentic Security → · Wise Shield →
In-houseB2GB2B

Post-Quantum Readiness & Crypto-Agility Roadmap

New 2026Advanced

An advisory engagement that finds where and how you use cryptography and produces a board-approved migration roadmap aligned with the EU’s coordinated post-quantum roadmap: first steps by end 2026, critical systems by 2030.

What is included and when it fits (Post-Quantum Readiness & Crypto-Agility Roadmap)
What is included
A cryptographic inventory (discovery tooling through a partner, plus interviews); exposure analysis for data that must stay confidential for years (harvest now, decrypt later); a vendor readiness survey (HSM, PKI, VPN, cloud key management); a roadmap with 2026, 2030 and 2035 gates; a crypto-agility policy supporting NIS2’s cryptography measure; a board one-pager.
When it fits
NIS2 essential entities, finance under DORA, health, energy, public administration, the defense supply chain and anyone holding data that must stay secret for more than ten years.
In-houseCertified partnerB2GB2B

Not sure where to start?Five questions show which service comes first. Most boards start with the Cyber Health Check and its one-page brief.

Take the two-minute self-check →

New 2026 marks services new in 2026. In-house is delivered by the Wise Limen team; Certified partner means hands-on work by a specialist partner holding the relevant accreditation or certification, with Wise Limen owning the client, the report and the relationship.

What the numbers say

People and suppliers are governance problems, not firewall problems.

The latest breach data points the same way year after year: most breaches involve a person, half now involve a third party, and the way in is increasingly a known vulnerability that was never fixed. Each of those has an owner, a decision and a date, which is where we work.

HOW BREACHES HAPPEN · VERIZON DBIR 2026Breaches involving a human action62%Breaches involving a third party48%Breaches with ransomware present48%Exploited vulnerability as the way in31%
Breaches involving a human action62%
Breaches involving a third party48%
Breaches with ransomware present48%
Exploited vulnerability as the way in31%
Verizon DBIR 2026
Source: Verizon Data Breach Investigations Report 2026, via Help Net Security (25 May 2026).
Health check

Is my house in order?

A broad, fast diagnosis of governance and controls. Two to four weeks. Start here.

Pentest

Can someone get in?

A technical attack simulation by certified testers. Targeted by what the health check finds.

Audit

Can I prove it?

A gap audit against a framework such as NIS2, GDPR or ISO 27001, with a documented record. It is not a certification.

Two-minute self-check

Could your board sign off on its cyber risk?

Five questions for a CEO, a CFO or a board member. Each “not yet” points to a first step.

Do you know whether NIS2 applies to you, and as which kind of entity?Essential, important or relevant public entity

Has your board seen a cyber risk report in euros in the last six months?With owners and dates, not only a technical report

Do you have an inventory of your AI agents and what they can access?Email, CRM, files, payments, code

Are your critical suppliers tiered and assessed for cyber risk?Half of breaches now involve a third party

If you make products with software, are you ready for the Cyber Resilience Act?Reporting has applied since 11 September 2026

Your starting point

Five questions, two minutes

Answer the 5 questions.

    Talk it through with us →

    Nothing is sent anywhere: the check runs in your browser.

    The compliance foundation

    Where cybersecurity meets the rule book.

    Compliance & Risk is the foundation under all three pillars. Cybersecurity is where three of its services have their home, alongside the three cross-pillar services that open every engagement and keep it current.

    Primary for Cybersecurity

    ISO 27001 Implementation & Maintenance Support

    Implement and maintain an ISO 27001:2022 management system, from certification readiness to continuous improvement, based on our own certification. We support; independent auditors certify.

    Intermediate
    Primary for Cybersecurity

    AI Act Readiness

    Inventory and risk classification, Article 50 transparency duties (since 2 August 2026), synthetic-content labeling, playbooks and training. High-risk duties from 2 December 2027 (stand-alone) and 2 August 2028 (products).

    Intermediate
    Primary for Cybersecurity

    DPO Support / DPO-as-a-Service

    Support for your Data Protection Officer: regulatory monitoring, impact assessments, data-subject requests, authority communications and records. Delivered by Wise Limen or by a specialist partner, depending on the engagement; the provider is named in the proposal. We do not audit organizations for which we act as DPO.

    Intermediate
    Cross-pillar

    Compliance Readiness Assessment

    A fast diagnosis of your regulatory posture across GDPR, NIS2 and the AI Act: gaps by rule, priority by risk and deadline, and a roadmap with effort estimates. The entry point that opens all three pillars in one conversation.

    Essential
    Cross-pillar

    Compliance Audits: GDPR, NIS2, AI Act

    A formal audit per rule, or all three in one integrated review: documented evidence, non-conformities classified as critical, major or minor, and a remediation plan with owners and dates.

    Essential
    Cross-pillar

    Regulatory Watch & Horizon Scanning

    A monthly retainer that follows the EU and national legislative pipeline, filters what matters for your sector and typically gives you months of warning before new obligations apply.

    Advanced

    How it verifies this pillar: a pentest summary leaves mapped to the security requirements of your sector; an agent audit leaves mapped to the AI Act obligations that apply to you. Responsibility stays with you; the evidence comes with the work.

    Where we sit

    Advice that is not tied to a product.

    Big consultancies sell programs, MSSPs sell their SOC, AI security vendors sell their platform and compliance software sells a dashboard. All useful. None of them owns the question the board asks: what is our real risk, and what do we decide? That question is where we start, and our signature deliverable is the one-page board brief.

    Swipe the table to compare →
    Wise LimenBig-4 cyber practicesMSSPs and SOC providersAI security vendorsCompliance software
    Board-level risk in eurosA one-page board briefYes, enterprise pricesTechnical reportsNoDashboards
    Independence from productsProducts we supply, ours or a third party’s, always optional and disclosedOften implementation-ledOften sell their SOCSell their platformSell their platform
    AI agents in productionAudited to the OWASP Agentic Top 10EmergingNot their core offerTooling firstPolicy templates
    NIS2 and DL 125/2025, in PortugueseNativeYesPartlyNoFramework library
    Hands-on testingCertified partners, we own the reportIn-houseIn-houseProduct testingNo
    Right-sizedFrom a 40-person supplier to a ministryLarge accountsMid to largeEnterpriseSME to mid

    Compliance platforms and AI security products can be excellent; we often recommend and work alongside them. What we add is the judgment, the scope and a documented recommendation.

    Who you will work with

    A senior lead and named specialists

    A senior Wise Limen lead owns your engagement; cyber, compliance and AI specialists join as needed, and certified partners (CREST or OSCP) run hands-on tests.

    How we hold ourselves

    Certified on our own operations

    Wise Pirates is ISO 27001 and ISO 9001 certified. Our ISO 27001 support is built on that experience, not on theory.

    The signature deliverable

    The one-page board brief

    Risk, impact in euros, owner, decision and the rule that applies, on one page. Every Cyber Health Check ends with one.

    NIS2 in Portugal, step by step

    Where you should be on the NIS2 clock today.

    Dates from the decree, the CNCS regulation and published legal guidance. Confirm the ones that depend on your qualification date; that is the first thing a readiness assessment does.

    Structure it with NIS2 & Cyber Governance Advisory →

    1. Decree-Law 125/2025 published4 Dec 2025Portugal transposes NIS2 into its cyberspace security regime.
    2. The law enters into force3 Apr 2026Obligations apply; directors carry personal responsibility (Art. 25(2)).
    3. MyCiber opens23 Jun 2026CNCS Regulation 756/2026 activates the registration platform.
    4. Registration window for existing entitiesAbout 60 business days, to mid-September 2026Late? Register now and document your adaptation effort.
    5. Contact point and cybersecurity officerWithin 20 business days of qualification
    6. Asset inventoryBy 31 Jan 2027, or 6 months after qualification
    7. Exemption from fines can be requestedUntil 3 Apr 2027By justified request to the CNCS, showing your adaptation effort.
    8. Security measures implementedWithin 24 months of qualificationTiered measures under the national reference framework (QNRCS).
    A worked example: the poisoned invoice Illustrative
    The attackA supplier PDF hides an instruction: change the bank details
    OWASP codeASI01 goal hijack, ASI02 tool misuse
    What the agent triesUpdate the IBAN in the payments tool
    The controlTool allow-list, then human approval on payment changes
    The resultBlocked, logged, flagged to the owner

    Agent security and NIS2 meet here: an agent with payment access is part of the security measures Article 21 asks you to govern.

    Who it is for

    For boards that want to decide with evidence.

    We work with organizations of every size, from a 40-person supplier to a ministry. What they share is that someone at the top has to sign off on the risk.

    B2G

    Public administration and municipalities

    NIS2 readiness and health checks sized for public teams and budgets.

    B2G

    Security forces and agencies

    Risk assessment, dark web monitoring and security for AI in public services.

    B2B

    Critical infrastructure and utilities

    Board reporting, supplier risk and post-quantum roadmaps for long-lived systems.

    B2B

    Banks, insurers and fintech

    DORA-aligned supplier risk, board reporting in euros, AI governance.

    B2B

    Defense industry and manufacturers

    Cyber Resilience Act readiness and a posture primes will accept.

    B2B

    Companies deploying AI agents

    Agent audits, controls and human approval gates.

    One incident, three pillars

    Where Cybersecurity leads, and where it hands over.

    A single ransomware case, hour by hour. The highlighted steps are this pillar’s; the others are its sister pillars.

    Hour 0
    Cybersecurity

    Ransomware hits a supplier; your systems slow down and staff cannot log in.

    Hour 1
    Resilience

    The crisis team activates, the first holding statement goes out, the notification clock starts.

    Hour 4
    Sovereignty

    A false claim of a data leak spreads; we detect the coordinated reposting and brief the spokesperson.

    Hour 24
    Cybersecurity

    NIS2 early warning filed; forensic partners confirm scope; the board gets a one-page brief.

    Hour 72
    Resilience

    Formal notification; continuity plan keeps critical services running; customers get a clear update.

    Week 2
    Compliance

    Final report, after-action review and a documented record for the regulator and insurer.

    An illustrative scenario, not a client case. It shows why the pillars are sold separately but work as one.

    The frameworks we work in

    We work in the frameworks your auditors already use.

    Our reports use recognized frameworks, so they can be compared year on year, audited and read by insurers and regulators.

    NIST CSF 2.0The six functions (govern, identify, protect, detect, respond, recover) most board reporting is built on.
    ISO 27001 and 27005The information security management standard and its risk-management companion.
    NIS2 and Decreto-Lei 125/2025The EU directive and its Portuguese law: measures, 24-hour reporting, board accountability.
    DORADigital operational resilience for finance, including ICT third-party risk and threat-led testing.
    Cyber Resilience ActSecurity by design for products with digital elements; reporting live since September 2026.
    OWASP Top 10 for LLM and AgenticThe reference lists of risks for LLM applications (2025) and AI agents (December 2025).
    AI ActProhibitions, transparency duties since August 2026, and high-risk obligations from 2 December 2027 (stand-alone) and 2 August 2028 (products).
    EU post-quantum roadmapFirst steps by end 2026, high-risk and critical systems by 2030, as much as feasible by 2035.
    How an engagement runs

    From a health check to continuous assurance.

    Advanced services are not sold before the essentials, except in an active incident, when we step in directly. Otherwise every Cybersecurity engagement climbs the same ladder.

    Step 1 · Diagnose

    Cyber Health Check

    Fixed price · 2 to 4 weeks

    Maturity by domain, the ten most critical vulnerabilities, and our signature deliverable: a one-page board brief with risk, euros, owner and date.

    Step 2 · Build

    Programs with a clear scope

    Fixed price by scope

    Pentests through partners, board reporting, supply-chain programs, CRA and post-quantum roadmaps, agent audits.

    Step 3 · Stay ready

    Monitoring and assurance

    Monthly

    Dark web monitoring, supplier-risk dashboards and quarterly board updates, so the picture stays current.

    FAQ

    Cybersecurity, answered.

    Does NIS2 apply to my organization in Portugal?

    Probably, if you are a medium-sized or larger entity in one of the covered sectors, part of the public administration, or a critical supplier to one. Decreto-Lei 125/2025 has been in force since 3 April 2026, and entities register with the CNCS on its MyCiber platform, whose window for existing entities ran to mid-September 2026. A readiness assessment gives an indicative reading of your likely classification early in the engagement.

    What are the fines under Portugal’s NIS2 law?

    Up to €10M or 2% of worldwide turnover for essential entities, and up to €7M or 1.4% for important entities. Directors can also be held personally liable for acts or omissions committed with intent or gross negligence, and management bodies must receive periodic training.

    Are board members personally responsible for cybersecurity?

    Yes. Under Decreto-Lei 125/2025, management bodies approve and oversee cybersecurity measures, must be trained, and can be held individually liable for acts or omissions committed with intent or gross negligence. That is why we report risk to the board in euros, with owners and dates.

    How much does a data breach cost?

    $4.99M on average worldwide in 2026, according to IBM, and about $6M when the attack is AI-enabled. IBM does not publish a Portugal figure, so we quantify exposure for your own organization in the Cyber Risk Assessment.

    What is the difference between a cyber health check, a pentest and an audit?

    A health check is a fast, broad diagnosis of governance and controls in 2 to 4 weeks. A pentest is a technical attack simulation by certified testers. An audit checks conformity against a framework such as NIS2, GDPR or ISO 27001. Most organizations should start with the health check, which tells you where the other two are worth doing.

    How do I secure AI agents in production?

    Inventory your agents and the tools and data they can reach. Test them against the OWASP Top 10 for Agentic Applications, which covers goal hijack, tool misuse, privilege abuse, memory poisoning and more. Then apply least privilege, guardrails and monitoring, and require human approval for high-impact actions. An Agentic Security audit does this in weeks.

    When do the AI Act obligations apply?

    Prohibitions and AI literacy have applied since February 2025 and general-purpose AI rules since August 2025. Article 50 transparency duties apply since 2 August 2026, with a grace period to 2 December 2026 for marking content from generative systems already on the market. High-risk obligations were postponed to 2 December 2027 and 2 August 2028 by Regulation (EU) 2026/1744.

    What changed on 11 September 2026 under the Cyber Resilience Act?

    Manufacturers of products with digital elements must now report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days or one month. Full obligations apply from 11 December 2027.

    Do I need ISO 27001 to comply with NIS2?

    No, it is not legally required. But an ISO 27001:2022 management system covers most NIS2 measures and is the most efficient evidence base. Wise Pirates is ISO 27001 certified itself, and we support organizations through implementation; we do not certify them.

    Are you a managed security provider?

    No. We do not run a SOC, and any product we supply, ours or a third party’s, is optional and disclosed. Wise Limen owns the diagnosis, the governance and the board reporting, and certified partners (CREST or OSCP) execute hands-on testing. Where our own Wise Shield firewall fits an AI agent deployment we say so, it always stays optional, and the report includes a declaration of interest and at least one market alternative: the audit stands on its own.

    What is the QNRCS?

    The Quadro Nacional de Referência para a Cibersegurança is Portugal’s national cybersecurity reference framework. Under the NIS2 regime, entities implement security measures in tiers set against it. A Cyber Health Check maps your current controls to the tier that applies to you.

    We missed the MyCiber registration window. What now?

    Register as soon as possible and document the steps you are taking: until 3 April 2027, entities can submit a justified request to the CNCS for exemption from fines, showing their adaptation effort. A Compliance Readiness Assessment gives you an indicative reading of your classification (the formal qualification is made with the CNCS) and builds that evidence.

    How much does a Cyber Health Check cost?

    It is sold at a fixed price agreed in writing before we start, scoped to your size, number of sites and systems. It takes 2 to 4 weeks and ends with a maturity score by domain, the ten most critical vulnerabilities and a one-page board brief.

    Public buyers: Cybersecurity work is usually procured under CPV 72220000-3 (systems and technical consultancy), 72810000-1 (computer audit), 79417000-0 (safety consultancy) and 80510000-2 (specialist training). See how public bodies buy from us →

    Declaration of interest: Wise Pirates has its own products (Wise Shield) and cloud services: we disclose them in every proposal, they are always optional, and no assessment depends on buying them. When we recommend one, the report includes a declaration of interest and at least one market alternative.General information only; it does not constitute legal advice. Acts reserved to lawyers under Portuguese Law No. 49/2004 are performed only by professionals legally authorized to perform them.
    Wise Limen · Cybersecurity

    Know your real risk, and put a date on it.

    Start with a Cyber Health Check. In 2 to 4 weeks, at a fixed price, you will know your maturity by domain, your ten most critical vulnerabilities and what the board should decide first.

    Book a Cyber Health Check conversation →
    1 · Two minutesTell us your contextSector, size and what worries you. No sales form maze.
    2 · Twenty minutesA call with a senior leadSomeone who runs this work, not a salesperson.
    3 · In writingA fixed-price first stepScope, duration and price agreed before anything starts.

    In a crisis right now? Retainer clients activate our crisis team 24/7 on their dedicated line. Not a client yet? Send an urgent request and a senior lead calls you back.

    Explore the rest of Wise Limen:Defense & SecuritySovereigntyResilience