Sovereignty, resilience and cybersecurity, for organizations that cannot fail.
The threats most organizations face are not tanks. They are disinformation, intrusions, outages, sabotage and deepfakes.
Wise Limen, the defense and security unit of Wise Pirates, is the layer between information, threat and decision, for governments, municipalities, police, critical infrastructure and companies.
What Wise Limen does, in one minute.
If you read one part of this page, read this. We work on three pillars and one foundation. Each pillar answers a different leadership question. The foundation makes sure everything we deliver can be shown to a board, an auditor or a regulator.
Who controls your story?
Narrative, information and influence: early detection of manipulation, a narrative you can defend, geopolitical briefings.
Can you cross the crisis?
Readiness, playbooks, simulations and continuity: the first hours rehearsed before they happen.
Does the board see the real risk?
Advisory and governance: health checks, board reporting in euros, security for AI agents.
Can you show it?
GDPR, NIS2, the AI Act, ISO 27001: every deliverable is checked against the rule that applies, with a record.
Security became everyone’s business, and it now has a budget line.
In June 2025 NATO Allies agreed to reach 5% of GDP by 2035, with up to 1.5% for infrastructure, networks, civil preparedness and industry. The EU adds €150B of SAFE loans.
Threats moved into the information space and the supply chain, and regulation put dates on security duties.
of GDP by 2035, NATO target: at least 3.5% core defense plus up to 1.5% for resilience and security
ReArm Europe: about €650B of national fiscal room plus €150B of SAFE loans
foreign information manipulation incidents recorded by the EEAS in 2025, 27% of them using AI
real cyber incidents in Portugal in 2024, 2,758 handled by CERT.PT
€5.8B of SAFE loans coming
Portugal’s tentative SAFE allocation is about €5.84B, and its plan was in the first approval wave in January 2026. Defense spending rose from 1.55% to 2.0% of GDP between 2024 and 2025.
A&O Shearman (Sep 2025); European Commission (Jan 2026); NATO via The Portugal Brief (Apr 2026)The most targeted sector in the EU
Public administration was the target in 38% of the incidents ENISA analyzed, and phishing opened the door in 60% of intrusions. Local administration is now in scope of Portugal’s NIS2 law.
ENISA Threat Landscape 2025 (Oct 2025); Decreto-Lei 125/2025A defense base made of small companies
Portugal’s defense economy counts 440 entities and €8.68B in sales, and 62% are micro or small companies. Most have no in-house team for security, compliance or B2G communication.
idD Portugal Defence via Lusa (Feb 2026)How SAFE money reaches security
SAFE lends up to €150B to member states for the joint procurement of defense products, and non-EU components are capped at 35% of an end product’s cost, which favors European suppliers. It rarely funds advisory work directly; its effect on most organizations is through the supply chains and security requirements that come with it.
Council of the EU (27 May 2025)What a defense supplier needs
A demonstrable security posture (NIS2, often ISO 27001), Cyber Resilience Act readiness for products with digital elements, security accreditation from the National Security Authority (GNS) for classified work, and a B2G story procurement teams can verify.
Five cables, no verdict
The Eagle S dragged its anchor across five undersea cables; Estlink 2 was out of service for months. The Finnish court dismissed the case for lack of jurisdiction. In the gray zone, leaders decide and speak before legal certainty arrives.
Submarine Networks (Oct 2025)Drones close an airport
On 22 September 2025 drones closed Copenhagen Airport for about four hours; Oslo, Munich and others followed within weeks. The disruption was physical, the pressure on communication immediate.
CNN (Oct 2025)The 1.5% names the work we do.
Read what the up to 1.5% of GDP may cover and it describes Sovereignty, Resilience and Cybersecurity, not tanks. It is the part of defense that reaches councils, operators, police, banks and suppliers. What counts toward it is decided by each Ally; the map helps explain how the work relates to those priorities.
The incident was technical. The crisis was informational.
On 28 April 2025 the Iberian grid collapsed in under 90 seconds. The cause was technical, yet in Portugal public alerts took hours, under half of the messages were delivered, and rumors filled the silence.
Between signal and statement sits a decision that has to be made in the first hour. That gap is why Wise Limen exists.
- Grid collapse11:3350 million+ people lose power across Iberia in under 90 seconds.
- The silence window11:33 to 20:00No effective mass alert: SMS alerts began at 17:15 and under half were delivered, while rumors of a cyberattack spread. The cause proved technical.
- Alert SMS starts17:15Public alert messages begin to go out.
- Alerts effective20:00Under 50% of messages delivered.
- Fully restored23:22Power back across Portugal.
Before the cause was known
What to say, on which channel, with phones and internet degraded, without speculating on attribution and without losing the public’s trust.
Communication, not the plan
Plans assume that phones and internet work. Contact lists are outdated. Nobody has pre-approved the holding statement. The silence becomes the story.
Decision chains that hold
Rehearsed first-hour protocols, degraded-mode communication, pre-approved messages by scenario, and the monitoring that tells you what people are hearing.
Three pillars. One foundation. One team.
Organized the way a leader experiences risk: what is said about you, whether you hold under pressure, and whether your systems and data are safe. Compliance is not a fourth pillar; it is the ground the three stand on. Each pillar has its own page with every service.
Sovereignty
Sovereignty is also narrative, information and communication. An organization that cannot see an influence campaign coming, or has no clear message under pressure, is sovereign only on paper.
Resilience
Resilience is the capacity to cross a crisis without collapsing. It is built before the crisis, in the plan and the rehearsal, and proven during it, in the first hours.
Cybersecurity
Cybersecurity stopped being an IT problem and became a leadership one. We work at the advisory and governance layer, and we already secure the newest attack surface: AI agents.
Compliance & Risk
Compliance is not a fourth pillar, because no regulation stops at a pillar’s edge. NIS2 asks for crisis management, incident communication and board oversight at the same time; the CER Directive asks critical entities to prepare for every hazard, from sabotage to blackout, alongside their NIS2 cyber duties; the AI Act and the GDPR reach into how we monitor, test and communicate. So compliance works inside each pillar in three ways. Every deliverable is checked against the rule that applies before it reaches you. Seven dedicated services cover what a regulator or auditor will ask for: Compliance Readiness Assessment, Compliance Audits (GDPR, NIS2, AI Act), Technology Sovereignty & Third-Country Risk Assessment, ISO 27001 Implementation Support, AI Act Readiness, DPO support and Regulatory Watch. And each engagement leaves an evidence record you can show a regulator, an insurer or your own board. Responsibility stays with you; the evidence comes with the work.
Not sure which pillar comes first?Most clients start with one fixed-price assessment that looks across all three. The self-check further down takes two minutes.
Take the two-minute self-check →Built for the organizations Europe relies on.
Six kinds of client, six different starting points. Pick yours to see the pressures we usually find and the services that answer them.
Governments & ministries
You are the first target of foreign information manipulation and the first voice people expect in a crisis. You also buy under public scrutiny, so every program needs a clear mandate and evidence.
We help you see adverse campaigns early, keep a coherent narrative across institutions, rehearse the first hours with leadership, and document every decision.
- Disinformation Monitoring with DISARM-coded reporting
- Public Affairs & Stakeholder Strategy
- Crisis Simulation for cabinets and executive teams
- Agentic Security for AI used in public services
Municipalities & local authorities
Local administration is now in scope of Portugal’s NIS2 law, and the last mile of every crisis is local: the radio, the parish council, the school. After the blackout, the call for 72-hour preparedness is aimed squarely at you.
We deliver the cyber baseline, the crisis playbook and the public campaigns citizens actually act on, sized for a municipal team.
- Cyber Health Check and NIS2 readiness
- Citizen Preparedness & 72-hour campaigns
- Crisis Playbook with degraded-mode communication
- DPO-as-a-Service
Police & security forces
Your credibility is operational: when an incident breaks, what you say in the first hour is part of the response. You also face targeted disinformation and deepfakes of your own people.
We prepare spokespeople and decision chains, monitor the narratives around operations, and build deepfake response and content provenance into your official channels.
- Incident Response Communications
- Synthetic Media Readiness & Deepfake Response
- Threat Intelligence & OSINT Monitoring
- Executive Resilience Program
Critical infrastructure
You sit under NIS2, the CER Directive and, for many, DORA. Your incidents become public events, and the regulator wants proof, not intentions.
We join the three regimes into one resilience system, with notification clocks built into the playbook and every deliverable checked.
- CER Critical Entity Resilience Program
- Business Continuity Planning
- Cyber Risk Assessment & Board Reporting
- Third-Party & Supply-Chain Cyber Risk
Banks & regulated companies
Boards now carry personal responsibility, and supervisors expect reporting in hours. Reputation moves faster than any recovery plan.
We translate technical risk into board decisions in euros, and make sure your first statement is ready before it is needed.
- Cyber Risk Assessment & Board Reporting
- AI Act Readiness
- Always-on Crisis Command
- AI Answer Sovereignty Audit
Defense industry & dual-use SMEs
SAFE and the European defense programs favor European supply chains. To sell into them you need a credible security posture, product compliance and a B2G story that procurement teams trust.
We give smaller suppliers the security, compliance and positioning that primes have in-house, at a size that makes sense.
- Cyber Resilience Act Readiness
- Post-Quantum Readiness roadmap
- Narrative & Messaging Strategy for B2G
- ISO 27001 Implementation Support
Preparedness you can say out loud.
Security that nobody understands does not change behavior, and a defense supplier that cannot explain itself does not win the tender. This is where Wise Limen draws on what Wise Pirates does every day: content, campaigns, social, data and digital channels, under one roof.
Campaigns people act on
72-hour preparedness, alert literacy and scam awareness, in plain language, accessible and multilingual, with local radio and parish kits for when the network is down. Measured before and after.
- Public risk communication
- Degraded-mode message banks
- Deepfake and scam awareness
A credible B2G story
For defense and dual-use companies: positioning, technical content, proposal narratives and a digital presence procurement teams and primes can verify, aligned with what you can prove.
- B2G positioning and messaging
- Program and tender narratives
- Trade-show and partner content
The first statement, ready
Holding statements by scenario, spokesperson preparation, regulator notifications written to the clock, and board briefs that turn a technical finding into a decision.
- Incident communications, 24/7
- Board and regulator reporting
- Media and stakeholder handling
The deadlines are already on the calendar.
Security in Europe now runs on dates. Some have passed and are being enforced, others are still ahead. Each colored mark is a date one of our pillars works to.
- DORA applies17 Jan 2025
- Preparedness Union Strategy26 Mar 2025
- NATO 5% pledge25 Jun 2025
- European Democracy Shield12 Nov 2025
- NIS2 law in force in Portugal3 Apr 2026
- CER critical entities due to be named17 Jul 2026
- AI Act Article 50 applies2 Aug 2026
- Cyber Resilience Act reporting live11 Sep 2026
- Where we areSeptember 2026
- AI content marking for legacy systems2 Dec 2026
- Central government data classified for the sovereign cloud30 Jun 2027
- Cyber Resilience Act fully applies11 Dec 2027
- NATO spending review2029
- Post-quantum crypto for critical systems2030
- NATO 5% of GDP2035
One of these dates is yours.In one conversation we map which deadlines apply to you and what the first fixed-price step is.
Map my deadlines →Sold separately. Working as one.
A single ransomware case, hour by hour, and which pillar acts at each moment. This is what the layer between threat and decision looks like in practice.
Ransomware hits a supplier; your systems slow down and staff cannot log in.
The crisis team activates, the first holding statement goes out, the notification clock starts.
A false claim of a data leak spreads; we detect the coordinated reposting and brief the spokesperson.
NIS2 early warning filed; forensic partners confirm scope; the board gets a one-page brief.
Formal notification; continuity plan keeps critical services running; customers get a clear update.
Final report, after-action review and a documented record for the regulator and insurer.
An illustrative scenario, not a client case. It shows why the pillars are sold separately but work as one.
Start small, prove value, then stay ready.
Most engagements start with a fixed-price assessment, short in time. In an active incident we step in directly and do the assessment afterwards.
A readiness assessment
Communications Audit, Crisis Readiness Assessment, Cyber Health Check or Compliance Readiness. A short, honest report that tells you where you stand and what matters first.
Projects with a clear scope
Playbooks, narrative frameworks, audits, board reporting, program set-up. Delivered by our team, with certified partners where hands-on testing is needed.
Always-on retainers
Disinformation monitoring, dark web monitoring, crisis command, regulatory watch and DPO support. The layer that keeps you ready between crises.
The check behind every deliverable
A pillar deliverable
A playbook, a risk report, a narrative strategy, a pentest summary, an OSINT dashboard.
The rule that applies
We identify the framework that governs it for your sector: NIS2, GDPR, the AI Act, DORA, CER.
A structured checklist
The deliverable is reviewed against the requirements of that framework, point by point.
A documented record
Who checked, when, and against what. A record you can show your board, auditor or regulator; it is our review, not a certification.
Where should you start?
Five questions any leadership team can answer honestly. Each “not yet” points to a fixed-price first step.
Do you know which rules apply to you, and by when?NIS2, CER, DORA, the AI Act, the Cyber Resilience Act
Has your leadership rehearsed a crisis in the last 12 months?A tabletop or simulation with the people who would decide
Would you know within hours if a coordinated campaign targeted you?Including what AI assistants say about you
Does your board see cyber risk in euros, with owners and dates?Not a technical report, a decision document
Could you show all of the above to a regulator tomorrow?Documented, dated, reviewed evidence
Five questions, two minutes
Answer the 5 questions.
Nothing is sent anywhere: the check runs in your browser.
The specialists of Wise Limen, with the capabilities of Wise Pirates.
Wise Limen is a dedicated team inside Wise Pirates, the way Inner Data is our data unit, backed by about 120 people who build AI, software, data platforms and campaigns.
That is why we can move from a finding to a working tool, a monitored dashboard or a public campaign without handing you over to someone else.
Agents and tools, built in-house
Our own AI agents, secure model layers and software. The same team that builds agents for clients knows how they break, which is where Agentic Security comes from.
Agentic Security →Dashboards and signals
Data engineering and analytics for threat and narrative dashboards, risk indicators and the evidence registers regulators ask for.
Data & analytics →Faster, documented operations
Automated monitoring, alerting and reporting workflows, so a lean client team can meet notification clocks without heroics.
Process Automation →New methods before they are standard
Research into AI security, content provenance and sovereign stacks. It produced Wise Shield, our firewall for LLM applications and agents.
R&D projects →8+ years of practice
Social and web listening and crisis management, aligned with ISO 22361, with 24/7 activation for retainer clients. The operational core of Sovereignty and Resilience.
Social & listening →The voice that reaches people
Studio, social, media and digital channels to turn a message into a campaign that citizens, partners and buyers actually see.
Content & social →A senior lead, not a pyramid
Every engagement is led by a senior Wise Limen lead for strategy and communication, with cyber and compliance specialists, data and OSINT analysts, and certified partners where testing is needed.
NPS above 60
In Wise Pirates’ own client satisfaction surveys, 94% rate our technical readiness as good or excellent, and 94% say the same about our availability to communicate and resolve.
Source: Wise Pirates client surveys, successive waves to 2026Certified on our own operations
Wise Pirates is ISO 9001 and ISO 27001 certified. We ask of our clients what we already do ourselves, and our ISO 27001 support is built on that experience.
Your business result. A great team and five pillars to move it.
Two pillars we run for you, three we own, and the crew at the center answering for your number.
Judged on your KPIs, with part of our fee on the line.
Others do one part well. We join the parts.
We respect the firms in these categories, and we partner with specialists in several of them. This is our reading of where each category usually focuses, not a judgment on any firm.
| Wise Limen | Big consultancies | Cyber firms and MSSPs | PR and communication firms | |
|---|---|---|---|---|
| Where they are strongest | The decision between signal and statement | Strategy, procurement, transformation at scale | Detection, response, technical testing | Reputation, media, crisis messaging |
| Narrative and information threats | Monitored, coded to EU frameworks | Occasional | Rarely | After the fact |
| Board-level cyber risk | In euros, with owners and dates | Yes, at enterprise prices | Technical reports | Not their core offer |
| Public and citizen communication | Campaigns, alerts and degraded-mode kits | Not their core offer | Not their core offer | Sometimes |
| Compliance record on every deliverable | Built in, documented | As a separate project | For their own scope | Not their core offer |
| Independence | No SOC to sell; products we supply, ours or a third party’s, always optional and disclosed | Often implement what they advise | Often sell their platform or SOC | Independent |
| Size of client served well | From a municipality or a 40-person supplier to a ministry | Primes, ministries | Enterprise | Enterprise and brands |
Where hands-on technical work is needed (penetration testing, forensics, a 24/7 SOC), certified partners execute and Wise Limen owns the client, the report and the relationship. We say so up front.
Go deeper into each pillar.
Each pillar has its own page with the full list of services, the frameworks we use and how an engagement runs. Related Wise Pirates services sit alongside.
Defense and security, answered.
What does Wise Limen do?
Wise Limen is the defense and security unit of Wise Pirates. It works on three pillars, Sovereignty, Resilience and Cybersecurity, on a common Compliance & Risk foundation. It helps governments, municipalities, police, critical infrastructure and companies lower risk, prepare for crises and communicate with credibility.
What is NATO’s 5% target, and what counts toward the 1.5%?
At The Hague in June 2025, Allies committed to 5% of GDP by 2035: at least 3.5% for core defense and up to 1.5% to, among other purposes, protect critical infrastructure, defend networks, ensure civil preparedness and resilience, unleash innovation and strengthen the defense industrial base. What counts toward it is decided by each Ally; cyber resilience, crisis readiness and continuity are among the purposes it names.
Does NIS2 apply to Portuguese municipalities?
Yes. Decreto-Lei 125/2025, in force since 3 April 2026, includes local administration among the relevant public entities, grouped by size. Obligations include a cybersecurity officer, registration with the CNCS, 24-hour incident notification and security measures. Check your group against the published decree; a readiness assessment gives you a first reading quickly, and the formal qualification is made with the CNCS.
Are you a cybersecurity company?
Not in the MSSP sense. Wise Limen works at the advisory and governance layer and owns the diagnosis, the report and the relationship. Hands-on work such as penetration testing is executed by certified partners (CREST or OSCP). We do not run your SOC, and any product we supply, ours or a third party’s, is optional and disclosed. Where our own Wise Shield firewall fits, we say so, it stays optional, and the report includes a declaration of interest and at least one market alternative.
What should a leader say in the first hour of a cyberattack or blackout?
Say what you know, what you are doing, what people should do and when you will update. Do not speculate on attribution. In the April 2025 Iberian blackout, rumors of a cyberattack spread while public alerts lagged, and the cause proved technical. Pre-approved holding statements and a rehearsed decision chain make the difference.
What is FIMI, and should my organization worry about it?
FIMI is Foreign Information Manipulation and Interference: coordinated, manipulative behavior, not just false content. The EEAS recorded 540 incidents in 2025, 27% using AI, targeting more than 100 countries, around 200 organizations and nearly 140 individuals. Ministries, security forces, critical infrastructure and defense firms are typical targets.
We are a defense SME. What do we need to sell into NATO and EU programs?
Usually a demonstrable cybersecurity posture (NIS2 and often ISO 27001), Cyber Resilience Act readiness if you ship products with digital elements, security accreditation for classified work where required, and a B2G story procurement teams can verify. We start with a gap assessment against your target program.
How is compliance handled across the three pillars?
Compliance is not a fourth pillar, because no regulation stops at a pillar’s edge: NIS2, the CER Directive, the AI Act and the GDPR each reach across sovereignty, resilience and cybersecurity. So compliance works inside each pillar: every deliverable is checked against the rule that applies, seven dedicated services cover what a regulator or auditor will ask for, and each engagement leaves an evidence record for a regulator, an insurer or your board. Responsibility stays with you; the evidence comes with the work.
How do engagements start, and how long do they take?
With a fixed-price readiness assessment, usually 2 to 4 weeks: a Communications Audit, a Crisis Readiness Assessment, a Cyber Health Check or a Compliance Readiness Assessment. The report tells you what matters first, and larger projects or retainers follow only if they make sense.
Can SAFE funding pay for security or resilience work?
SAFE finances defense products bought jointly by member states; it is a loan instrument, not a grant for organizations, and it rarely pays for advisory work directly. Its real effect for suppliers is the demand and the security and European-content requirements that come with those procurements, which is where we help.
Are we a critical entity under the CER Directive?
Member states had to identify critical entities in eleven sectors by 17 July 2026, including energy, transport, health, water, digital infrastructure, food and public administration. If you have been notified, you have about nine months for the risk assessment and ten until obligations apply; if you supply one, expect their requirements to reach you.
What does a defense supplier need for classified work in Portugal?
Security accreditation from the National Security Authority (Gabinete Nacional de Segurança) for the company and the people involved, plus the cyber and physical measures that come with it. It sits alongside NIS2, ISO 27001 and, for products, the Cyber Resilience Act.
How much does Wise Limen cost?
Every engagement starts with a fixed-price assessment, scoped and priced in writing before anything starts, usually over 2 to 4 weeks. We do not publish a price list because a municipality and a critical operator need very different scopes; the first 20-minute conversation is free.
How public bodies buy from us
Every engagement starts with a fixed-price assessment, scoped and priced in writing, and sized for simplified public procurement procedures. Larger programs follow only if they make sense.
CPV codes we work under
- 79411000-8 General management consultancy services
- 79416200-5 Public relations consultancy services
- 79417000-0 Safety consultancy services
- 79419000-4 Evaluation consultancy services
- 79430000-7 Crisis management services
- 72220000-3 Systems and technical consultancy services
- 72222000-7 Information systems or technology strategic review and planning services
- 72810000-1 Computer audit services
- 80510000-2 Specialist training services
- 79341400-0 Advertising campaign services
Procurement documentation and our ISO 27001 and ISO 9001 certificates are available on request.
Be ready before it is tested.
Tell us who you are and what concerns you most. In 20 minutes our senior team will tell you where most organizations like yours are exposed, which of the three pillars matters first, and what a fixed-price first step would look like.
Book a 20-minute readiness conversation →In a crisis right now? Retainer clients activate our crisis team 24/7 on their dedicated line. Not a client yet? Send an urgent request and a senior lead calls you back.