Cybersecurity is no longer an IT problem. It is a leadership one.
Attacks that stop hospitals or cut energy are strategic events, and under Portugal’s NIS2 law the board’s name is now on them.
We work at the advisory and governance layer: from an affordable first diagnosis to board-level risk and the security of AI agents.
You are on Pillar 03 of Wise Limen, the defense and security unit of Wise Pirates. Wise Limen works on three pillars, Sovereignty, Resilience and Cybersecurity, that stand on one Compliance & Risk foundation. Each can be hired alone; together they cover the path from signal to decision.
How the three pillars fit together →The rules changed, the attack surface changed, and the bill went up.
Portugal’s NIS2 law brings fines up to €10M or 2% of turnover and personal liability for directors. The Cyber Resilience Act’s reporting started in September 2026. AI agents act with more access than most staff.
Most of the answer is governance: knowing your risk, deciding with evidence, and holding suppliers and machines to the same standard as people.
average cost of a data breach worldwide in 2026, up 12% in a year
malicious breaches were AI-enabled, costing about $6M each
of the incidents ENISA analyzed targeted public administration, the most of any sector
real cyber incidents in Portugal in 2024, 2,758 handled by CERT.PT
The clock started on 3 April
Decreto-Lei 125/2025 is in force, the CNCS MyCiber platform opened on 23 June 2026, and Article 25(2) makes directors personally liable for acts or omissions committed with intent or gross negligence. Incident notification runs to 24 hours from day one.
Decreto-Lei 125/2025; CNCS Regulation 756/2026More access than your interns
OWASP published its first Top 10 for Agentic Applications in December 2025. Gartner expects 25% of enterprise breaches to trace back to AI agent abuse by 2028.
OWASP (Dec 2025); Gartner (Oct 2024)Not only a big-company problem
In September 2026 a ransomware attack hit the e-mail server of the Leiria inter-municipal community, which serves ten municipalities. Local administration is in scope of NIS2.
ECO (16 Sep 2026)Your AI agents need the same security as your people.
An AI agent can read your email, update your CRM, move files and trigger payments. It can also be steered by an instruction hidden in a document. Agentic Security audits agents in production against the OWASP Top 10 for Agentic Applications, sets the controls, and keeps a human on every high-impact decision.
Wise Pirates builds AI agents. That is exactly why we know how they break.
Mapped to OWASP, one to one
Every finding is tied to a named risk, from goal hijack to memory poisoning, with severity and a fix.
Humans where it matters
Least privilege, sandboxing, approval gates and monitoring, documented for the AI Act and your auditors.
Eleven services, from a first health check to the post-quantum era.
Eleven services in three levels. Three are new for 2026, answering what changed most this year: supply-chain cyber risk, Cyber Resilience Act readiness and post-quantum readiness. Open any card to see what is included and when it fits.
Essential
Where most start: know your posture and reduce the human risk.
Cyber Health Check
A fast diagnosis of your digital security posture: a structured maturity assessment, the most critical vulnerabilities and an immediate action roadmap, delivered in 2 to 4 weeks.
What is included and when it fits (Cyber Health Check)
- What is included
- Maturity assessment by domain (people, process, technology); the ten most critical vulnerabilities; digital attack-surface analysis; review of existing policies and controls; an executive report with maturity scoring and a prioritized roadmap; a presentation to leadership.
- When it fits
- The entry service for any organization that wants to know where it stands before investing in more complex solutions. The report is the starting point for everything that follows.
Phishing Simulation & Security Awareness
A combined program of behavioral security testing and training: realistic phishing and social-engineering simulations, followed by training tailored to the results, to reduce the human risk.
What is included and when it fits (Phishing Simulation & Security Awareness)
- What is included
- Simulated phishing campaigns by level of sophistication, including AI-written lures; technical execution through a certified partner; results by department and profile; modular training on the gaps found; progress reporting over time; completion records per employee.
- When it fits
- For any organization, whatever its size or sector. Around six in ten breaches involve a human action, which makes this the easiest service to justify internally and the one with the most immediate, measurable effect.
Intermediate
Test, monitor and govern the exposure around you.
Penetration Testing & Vulnerability Assessment
A controlled simulation of a real attack on your systems and infrastructure, combined with a systematic scan for known vulnerabilities, delivered with findings prioritized by criticality and an actionable remediation roadmap.
What is included and when it fits (Penetration Testing & Vulnerability Assessment)
- What is included
- Scope and method defined with you; testing through our partners: CREST-accredited firms or testers holding OSCP or equivalent certifications; vulnerability assessment of infrastructure, web applications and cloud; a full technical report with CVSS scoring; an executive report for non-technical leaders; debrief and remediation plan.
- When it fits
- When you need to validate your posture with concrete evidence, because of regulation (NIS2, DORA), a client or partner requirement, or your own risk management.
Dark Web & Threat Monitoring
Continuous monitoring of your data and credentials exposed on the dark web and in cybercrime forums, delivered as a monthly retainer with immediate alerts when compromised data is detected.
What is included and when it fits (Dark Web & Threat Monitoring)
- What is included
- Continuous monitoring of dark web markets, Telegram channels, cybercrime forums and paste sites; immediate alerts on credentials, data or documents; context and risk assessment per exposure; a monthly exposure and trends report; mitigation recommendations per incident.
- When it fits
- For any organization, and especially those handling sensitive client or employee data. The value is visible fast: many discover in the first week that credentials they did not know about are already out there.
- Related
- Threat Intelligence & OSINT (Sovereignty) →
Cloud & Data Sovereignty Advisory
Strategic advisory to align your data architecture with European digital sovereignty requirements, including migration strategy to EU sovereign clouds, GDPR and AI Act alignment, and the management of dependency on non-European providers.
What is included and when it fits (Cloud & Data Sovereignty Advisory)
- What is included
- Assessment of where your data sits and flows; dependency risk on non-European cloud providers; migration strategy to sovereign options (European providers, Gaia-X-aligned offers); a GDPR and AI Act framework for your data systems; data residency and governance policy; a phased roadmap. It follows the Technology Sovereignty assessment of the compliance layer: that one documents the exposure, this one designs the move.
- When it fits
- For public bodies with data sovereignty duties, companies processing EU citizens’ data on non-European infrastructure, and anyone anticipating stricter European rules on data location.
- Related
- Technology sovereignty assessment (Sovereignty) → · Wise Pirates Cloud Services →
Third-Party & Supply-Chain Cyber Risk
A governance program for supplier cyber risk: tiering, due diligence, contract clauses, continuous monitoring and board reporting, aligned with NIS2 Article 21 and, for finance, DORA’s third-party rules.
What is included and when it fits (Third-Party & Supply-Chain Cyber Risk)
- What is included
- Supplier inventory and criticality tiering, including AI and SaaS vendors and third-country exposure; security questionnaires mapped to ISO 27001, NIS2 and DORA; external attack-surface ratings through a partner tool; NIS2 and DORA contract security requirements for your legal team to include in supplier contracts; concentration and exit-strategy analysis; a quarterly supplier-risk dashboard for the board.
- When it fits
- Every NIS2 essential or important entity now implementing its measures, financial entities under DORA, and the suppliers who must answer those questionnaires, a second market in itself.
- Related
- Always-on Crisis Command, supply-chain module (Resilience) →
Cyber Resilience Act Readiness
Readiness for the Cyber Resilience Act: for manufacturers, the reporting duties live since 11 September 2026; for importers and distributors, their own verification duties; and for all, full application on 11 December 2027.
What is included and when it fits (Cyber Resilience Act Readiness)
- What is included
- Scope and product classification; a reporting runbook for ENISA’s Single Reporting Platform (24 hours, 72 hours, 14 days, one month) with a tabletop; a coordinated vulnerability disclosure policy; SBOM and vulnerability-handling process design; support-period policy; technical documentation gap analysis and choice of conformity route; board and product-owner briefing.
- When it fits
- Portuguese and Iberian makers of software, IoT, OT and industrial equipment, dual-use suppliers to the defense sector, and software houses. Wise Pirates builds software itself, so we speak product teams’ language.
Advanced
NIS2 governance, board-level risk, AI agents and the next cryptographic transition.
NIS2 & Cyber Governance Advisory
Strategic advisory for NIS2 compliance (Decreto-Lei 125/2025 in Portugal) and for the cybersecurity governance framework, from the first gap analysis to the implementation roadmap and reporting for board and regulator.
What is included and when it fits (NIS2 & Cyber Governance Advisory)
- Typical scope
- 6 to 10 weeks for the gap analysis and roadmap; half-yearly reviews
- What is included
- NIS2 gap analysis against your current state; actions prioritized by criticality and deadline; security policies and procedures; governance aligned with NIST CSF and ISO 27001; board and regulator reporting, including the 24-hour, 72-hour and one-month notification chain; coordination with technical partners; half-yearly maturity review.
- When it fits
- For any entity in scope of NIS2, essential or important, that needs to structure compliance strategically and not only technically.
- Related
- Cyber Health Check → · Compliance Audits →
Cyber Risk Assessment & Board Reporting
A formal, periodic assessment of your digital risk with structured output for the board, auditors and regulators, using recognized frameworks (NIST CSF 2.0, ISO 27005) and translating technical risk into business language and decisions.
What is included and when it fits (Cyber Risk Assessment & Board Reporting)
- What is included
- A full risk assessment using NIST CSF or ISO 27005; risk quantified as potential financial impact; a board report in executive, non-technical language; a risk-indicator dashboard for periodic reporting; presentation to the board with Q&A; integration with internal and external audit.
- When it fits
- For boards that need clear visibility of digital risk, because of regulatory pressure (NIS2 and DORA require board oversight), cyber-insurer demands or their own governance maturity.
- Related
- Executive Resilience Program (Resilience) →
Agentic Security
Security for autonomous AI systems (AI agents): audit of agents in production, protection against prompt injection and tool manipulation, a governance framework for autonomous decisions and AI Act alignment for high-risk contexts.
What is included and when it fits (Agentic Security)
- What is included
- Security audit of AI agents in production; assessment of agentic attack vectors mapped to the OWASP Top 10 for Agentic Applications (goal hijack, tool misuse, privilege abuse, memory and context poisoning and more); a governance framework for autonomous decisions; sandboxing and access-control policies for agents; AI Act alignment; secure agentic design training; an optional testing tier (AI red teaming). Can be paired with Wise Shield, our own firewall for LLM applications and agents; it is always optional and declared as our own product.
- When it fits
- For any organization already using, or planning to use, AI agents in critical processes, which in 2026 includes almost every regulated sector adopting generative AI.
- Why it is a differentiator
- An agent can be steered by a malicious instruction hidden in a document to leak data or take a wrong action, with no human noticing. Traditional security does not cover this. Wise Pirates builds agents, which is why we know how they break.
- Related
- Wise Pirates Agentic Security → · Wise Shield →
Post-Quantum Readiness & Crypto-Agility Roadmap
An advisory engagement that finds where and how you use cryptography and produces a board-approved migration roadmap aligned with the EU’s coordinated post-quantum roadmap: first steps by end 2026, critical systems by 2030.
What is included and when it fits (Post-Quantum Readiness & Crypto-Agility Roadmap)
- What is included
- A cryptographic inventory (discovery tooling through a partner, plus interviews); exposure analysis for data that must stay confidential for years (harvest now, decrypt later); a vendor readiness survey (HSM, PKI, VPN, cloud key management); a roadmap with 2026, 2030 and 2035 gates; a crypto-agility policy supporting NIS2’s cryptography measure; a board one-pager.
- When it fits
- NIS2 essential entities, finance under DORA, health, energy, public administration, the defense supply chain and anyone holding data that must stay secret for more than ten years.
Not sure where to start?Five questions show which service comes first. Most boards start with the Cyber Health Check and its one-page brief.
Take the two-minute self-check →New 2026 marks services new in 2026. In-house is delivered by the Wise Limen team; Certified partner means hands-on work by a specialist partner holding the relevant accreditation or certification, with Wise Limen owning the client, the report and the relationship.
People and suppliers are governance problems, not firewall problems.
The latest breach data points the same way year after year: most breaches involve a person, half now involve a third party, and the way in is increasingly a known vulnerability that was never fixed. Each of those has an owner, a decision and a date, which is where we work.
Is my house in order?
A broad, fast diagnosis of governance and controls. Two to four weeks. Start here.
Can someone get in?
A technical attack simulation by certified testers. Targeted by what the health check finds.
Can I prove it?
A gap audit against a framework such as NIS2, GDPR or ISO 27001, with a documented record. It is not a certification.
Could your board sign off on its cyber risk?
Five questions for a CEO, a CFO or a board member. Each “not yet” points to a first step.
Do you know whether NIS2 applies to you, and as which kind of entity?Essential, important or relevant public entity
Has your board seen a cyber risk report in euros in the last six months?With owners and dates, not only a technical report
Do you have an inventory of your AI agents and what they can access?Email, CRM, files, payments, code
Are your critical suppliers tiered and assessed for cyber risk?Half of breaches now involve a third party
If you make products with software, are you ready for the Cyber Resilience Act?Reporting has applied since 11 September 2026
Five questions, two minutes
Answer the 5 questions.
Nothing is sent anywhere: the check runs in your browser.
Where cybersecurity meets the rule book.
Compliance & Risk is the foundation under all three pillars. Cybersecurity is where three of its services have their home, alongside the three cross-pillar services that open every engagement and keep it current.
ISO 27001 Implementation & Maintenance Support
Implement and maintain an ISO 27001:2022 management system, from certification readiness to continuous improvement, based on our own certification. We support; independent auditors certify.
AI Act Readiness
Inventory and risk classification, Article 50 transparency duties (since 2 August 2026), synthetic-content labeling, playbooks and training. High-risk duties from 2 December 2027 (stand-alone) and 2 August 2028 (products).
DPO Support / DPO-as-a-Service
Support for your Data Protection Officer: regulatory monitoring, impact assessments, data-subject requests, authority communications and records. Delivered by Wise Limen or by a specialist partner, depending on the engagement; the provider is named in the proposal. We do not audit organizations for which we act as DPO.
Compliance Readiness Assessment
A fast diagnosis of your regulatory posture across GDPR, NIS2 and the AI Act: gaps by rule, priority by risk and deadline, and a roadmap with effort estimates. The entry point that opens all three pillars in one conversation.
Compliance Audits: GDPR, NIS2, AI Act
A formal audit per rule, or all three in one integrated review: documented evidence, non-conformities classified as critical, major or minor, and a remediation plan with owners and dates.
Regulatory Watch & Horizon Scanning
A monthly retainer that follows the EU and national legislative pipeline, filters what matters for your sector and typically gives you months of warning before new obligations apply.
How it verifies this pillar: a pentest summary leaves mapped to the security requirements of your sector; an agent audit leaves mapped to the AI Act obligations that apply to you. Responsibility stays with you; the evidence comes with the work.
Advice that is not tied to a product.
Big consultancies sell programs, MSSPs sell their SOC, AI security vendors sell their platform and compliance software sells a dashboard. All useful. None of them owns the question the board asks: what is our real risk, and what do we decide? That question is where we start, and our signature deliverable is the one-page board brief.
| Wise Limen | Big-4 cyber practices | MSSPs and SOC providers | AI security vendors | Compliance software | |
|---|---|---|---|---|---|
| Board-level risk in euros | A one-page board brief | Yes, enterprise prices | Technical reports | No | Dashboards |
| Independence from products | Products we supply, ours or a third party’s, always optional and disclosed | Often implementation-led | Often sell their SOC | Sell their platform | Sell their platform |
| AI agents in production | Audited to the OWASP Agentic Top 10 | Emerging | Not their core offer | Tooling first | Policy templates |
| NIS2 and DL 125/2025, in Portuguese | Native | Yes | Partly | No | Framework library |
| Hands-on testing | Certified partners, we own the report | In-house | In-house | Product testing | No |
| Right-sized | From a 40-person supplier to a ministry | Large accounts | Mid to large | Enterprise | SME to mid |
Compliance platforms and AI security products can be excellent; we often recommend and work alongside them. What we add is the judgment, the scope and a documented recommendation.
A senior lead and named specialists
A senior Wise Limen lead owns your engagement; cyber, compliance and AI specialists join as needed, and certified partners (CREST or OSCP) run hands-on tests.
Certified on our own operations
Wise Pirates is ISO 27001 and ISO 9001 certified. Our ISO 27001 support is built on that experience, not on theory.
The one-page board brief
Risk, impact in euros, owner, decision and the rule that applies, on one page. Every Cyber Health Check ends with one.
Where you should be on the NIS2 clock today.
Dates from the decree, the CNCS regulation and published legal guidance. Confirm the ones that depend on your qualification date; that is the first thing a readiness assessment does.
- Decree-Law 125/2025 published4 Dec 2025Portugal transposes NIS2 into its cyberspace security regime.
- The law enters into force3 Apr 2026Obligations apply; directors carry personal responsibility (Art. 25(2)).
- MyCiber opens23 Jun 2026CNCS Regulation 756/2026 activates the registration platform.
- Registration window for existing entitiesAbout 60 business days, to mid-September 2026Late? Register now and document your adaptation effort.
- Contact point and cybersecurity officerWithin 20 business days of qualification
- Asset inventoryBy 31 Jan 2027, or 6 months after qualification
- Exemption from fines can be requestedUntil 3 Apr 2027By justified request to the CNCS, showing your adaptation effort.
- Security measures implementedWithin 24 months of qualificationTiered measures under the national reference framework (QNRCS).
Agent security and NIS2 meet here: an agent with payment access is part of the security measures Article 21 asks you to govern.
For boards that want to decide with evidence.
We work with organizations of every size, from a 40-person supplier to a ministry. What they share is that someone at the top has to sign off on the risk.
Public administration and municipalities
NIS2 readiness and health checks sized for public teams and budgets.
Security forces and agencies
Risk assessment, dark web monitoring and security for AI in public services.
Critical infrastructure and utilities
Board reporting, supplier risk and post-quantum roadmaps for long-lived systems.
Banks, insurers and fintech
DORA-aligned supplier risk, board reporting in euros, AI governance.
Defense industry and manufacturers
Cyber Resilience Act readiness and a posture primes will accept.
Companies deploying AI agents
Agent audits, controls and human approval gates.
Where Cybersecurity leads, and where it hands over.
A single ransomware case, hour by hour. The highlighted steps are this pillar’s; the others are its sister pillars.
Ransomware hits a supplier; your systems slow down and staff cannot log in.
The crisis team activates, the first holding statement goes out, the notification clock starts.
A false claim of a data leak spreads; we detect the coordinated reposting and brief the spokesperson.
NIS2 early warning filed; forensic partners confirm scope; the board gets a one-page brief.
Formal notification; continuity plan keeps critical services running; customers get a clear update.
Final report, after-action review and a documented record for the regulator and insurer.
An illustrative scenario, not a client case. It shows why the pillars are sold separately but work as one.
We work in the frameworks your auditors already use.
Our reports use recognized frameworks, so they can be compared year on year, audited and read by insurers and regulators.
From a health check to continuous assurance.
Advanced services are not sold before the essentials, except in an active incident, when we step in directly. Otherwise every Cybersecurity engagement climbs the same ladder.
Cyber Health Check
Maturity by domain, the ten most critical vulnerabilities, and our signature deliverable: a one-page board brief with risk, euros, owner and date.
Programs with a clear scope
Pentests through partners, board reporting, supply-chain programs, CRA and post-quantum roadmaps, agent audits.
Monitoring and assurance
Dark web monitoring, supplier-risk dashboards and quarterly board updates, so the picture stays current.
Cybersecurity works best with Sovereignty and Resilience.
A cyber incident becomes a communication crisis within hours, and a narrative attack often comes with a technical one. The rest of Wise Limen, and the Wise Pirates services it draws on, are one click away.
Cybersecurity, answered.
Does NIS2 apply to my organization in Portugal?
Probably, if you are a medium-sized or larger entity in one of the covered sectors, part of the public administration, or a critical supplier to one. Decreto-Lei 125/2025 has been in force since 3 April 2026, and entities register with the CNCS on its MyCiber platform, whose window for existing entities ran to mid-September 2026. A readiness assessment gives an indicative reading of your likely classification early in the engagement.
What are the fines under Portugal’s NIS2 law?
Up to €10M or 2% of worldwide turnover for essential entities, and up to €7M or 1.4% for important entities. Directors can also be held personally liable for acts or omissions committed with intent or gross negligence, and management bodies must receive periodic training.
Are board members personally responsible for cybersecurity?
Yes. Under Decreto-Lei 125/2025, management bodies approve and oversee cybersecurity measures, must be trained, and can be held individually liable for acts or omissions committed with intent or gross negligence. That is why we report risk to the board in euros, with owners and dates.
How much does a data breach cost?
$4.99M on average worldwide in 2026, according to IBM, and about $6M when the attack is AI-enabled. IBM does not publish a Portugal figure, so we quantify exposure for your own organization in the Cyber Risk Assessment.
What is the difference between a cyber health check, a pentest and an audit?
A health check is a fast, broad diagnosis of governance and controls in 2 to 4 weeks. A pentest is a technical attack simulation by certified testers. An audit checks conformity against a framework such as NIS2, GDPR or ISO 27001. Most organizations should start with the health check, which tells you where the other two are worth doing.
How do I secure AI agents in production?
Inventory your agents and the tools and data they can reach. Test them against the OWASP Top 10 for Agentic Applications, which covers goal hijack, tool misuse, privilege abuse, memory poisoning and more. Then apply least privilege, guardrails and monitoring, and require human approval for high-impact actions. An Agentic Security audit does this in weeks.
When do the AI Act obligations apply?
Prohibitions and AI literacy have applied since February 2025 and general-purpose AI rules since August 2025. Article 50 transparency duties apply since 2 August 2026, with a grace period to 2 December 2026 for marking content from generative systems already on the market. High-risk obligations were postponed to 2 December 2027 and 2 August 2028 by Regulation (EU) 2026/1744.
What changed on 11 September 2026 under the Cyber Resilience Act?
Manufacturers of products with digital elements must now report actively exploited vulnerabilities and severe incidents through ENISA’s Single Reporting Platform: an early warning within 24 hours, a notification within 72 hours and a final report within 14 days or one month. Full obligations apply from 11 December 2027.
Do I need ISO 27001 to comply with NIS2?
No, it is not legally required. But an ISO 27001:2022 management system covers most NIS2 measures and is the most efficient evidence base. Wise Pirates is ISO 27001 certified itself, and we support organizations through implementation; we do not certify them.
Are you a managed security provider?
No. We do not run a SOC, and any product we supply, ours or a third party’s, is optional and disclosed. Wise Limen owns the diagnosis, the governance and the board reporting, and certified partners (CREST or OSCP) execute hands-on testing. Where our own Wise Shield firewall fits an AI agent deployment we say so, it always stays optional, and the report includes a declaration of interest and at least one market alternative: the audit stands on its own.
What is the QNRCS?
The Quadro Nacional de Referência para a Cibersegurança is Portugal’s national cybersecurity reference framework. Under the NIS2 regime, entities implement security measures in tiers set against it. A Cyber Health Check maps your current controls to the tier that applies to you.
We missed the MyCiber registration window. What now?
Register as soon as possible and document the steps you are taking: until 3 April 2027, entities can submit a justified request to the CNCS for exemption from fines, showing their adaptation effort. A Compliance Readiness Assessment gives you an indicative reading of your classification (the formal qualification is made with the CNCS) and builds that evidence.
How much does a Cyber Health Check cost?
It is sold at a fixed price agreed in writing before we start, scoped to your size, number of sites and systems. It takes 2 to 4 weeks and ends with a maturity score by domain, the ten most critical vulnerabilities and a one-page board brief.
Public buyers: Cybersecurity work is usually procured under CPV 72220000-3 (systems and technical consultancy), 72810000-1 (computer audit), 79417000-0 (safety consultancy) and 80510000-2 (specialist training). See how public bodies buy from us →
Declaration of interest: Wise Pirates has its own products (Wise Shield) and cloud services: we disclose them in every proposal, they are always optional, and no assessment depends on buying them. When we recommend one, the report includes a declaration of interest and at least one market alternative.General information only; it does not constitute legal advice. Acts reserved to lawyers under Portuguese Law No. 49/2004 are performed only by professionals legally authorized to perform them.Know your real risk, and put a date on it.
Start with a Cyber Health Check. In 2 to 4 weeks, at a fixed price, you will know your maturity by domain, your ten most critical vulnerabilities and what the board should decide first.
Book a Cyber Health Check conversation →In a crisis right now? Retainer clients activate our crisis team 24/7 on their dedicated line. Not a client yet? Send an urgent request and a senior lead calls you back.