Regulated Incident Management Ecosystem Versão portuguesa

Designated roles layer · Information security

Information security managed as a system, not as a reaction

Support for the information security lead role in Portuguese organisations: policy, risk, controls, suppliers, continuity and culture, with reporting to the management body.

ISO/IEC 27001 GDPR Art. 32 ISO 22301 QNRCS Risk
ISO 27001RGPD 32.ºISO 22301QNRCSRiscoCadeiaCulturaAuditoria

Three sources

Where the requirement comes from

In Portugal, no single rule imposes this role on every organisation. The requirement arrives by three converging routes.

Legal duty of security

Article 32 GDPR requires technical and organisational measures appropriate to the risk, and someone accountable for them.

Certification

ISO/IEC 27001 requires defined roles, risk assessment and continual improvement, verified in an audit.

Contracts and tenders

Clients and public bodies require written evidence of security from their suppliers, before contracting.

Distinct roles

Who does what

Three neighbouring roles with different objects. Confusing them is the most common source of gaps and duplication.

RoleObjectSource of the requirement
Security OfficerThe information of the organisation, in any mediumDuty of security, certification and contracts
Cybersecurity officerThe cyber domain in covered entitiesArticle 31 of Decree-Law 125/2025
Data protection officerThe processing of personal dataArticles 37 to 39 GDPR

The roles work together and, in small organisations, may be held by the same team, provided there is no conflict of interests.

What we do

Services

SO-01

External Security Officer

External performance of the information security lead role, with a policy, an annual plan, risk assessment and periodic reporting to the management body.

Open service sheet
SO-02

Information Security Maturity Assessment

An assessment of information security maturity by control domain, with a gap map and a prioritised improvement plan.

Open service sheet
SO-03

Management System and Certification Readiness

Implementation of the information security management system and preparation for the certification audit, with documentation proportionate to the organisation.

Open service sheet
SO-04

Risk Assessment and Management

Definition of the methodology, asset inventory, risk assessment and a treatment plan approved by the management body.

Open service sheet
SO-05

Supply Chain and Procurement Security

Supplier assessment criteria, security and incident-alert clauses, and a follow-up process throughout the contract.

Open service sheet
SO-06

Business Continuity and Recovery

Business impact analysis, definition of recovery objectives, a continuity plan and an exercise that tests it.

Open service sheet
SO-07

Awareness and Security Culture Programme

An annual awareness programme, with themed campaigns, phishing simulations and measurement of results by team.

Open service sheet
SO-08

Internal Audit and Third-Party Audit Readiness

Independent internal audit of the management system and its controls, with a report, a corrective plan and preparation for external audits.

Open service sheet

Method

The annual cycle of the role

  1. 01

    Measure

    Maturity and risk.

  2. 02

    Treat

    Controls, suppliers and continuity.

  3. 03

    Enable

    Awareness and competences.

  4. 04

    Verify

    Internal audit and management review.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.