Designated roles layer · Information security
Information security managed as a system, not as a reaction
Support for the information security lead role in Portuguese organisations: policy, risk, controls, suppliers, continuity and culture, with reporting to the management body.
Three sources
Where the requirement comes from
In Portugal, no single rule imposes this role on every organisation. The requirement arrives by three converging routes.
Legal duty of security
Article 32 GDPR requires technical and organisational measures appropriate to the risk, and someone accountable for them.
Certification
ISO/IEC 27001 requires defined roles, risk assessment and continual improvement, verified in an audit.
Contracts and tenders
Clients and public bodies require written evidence of security from their suppliers, before contracting.
Pain points
Six difficulties we solve
The role exists but has no mandate
No time, no budget and no access to the board.
Open service sheet SO-02We do not know where we stand
Without a baseline, priorities are impressions.
Open service sheet SO-04We decide without a risk assessment
Investment driven by insistence rather than by risk.
Open service sheet SO-05Suppliers are not assessed
Most incidents come in through the supply chain.
Open service sheet SO-06The continuity plan has never been tested
Backups that have never been restored.
Open service sheet SO-07Awareness does not change behaviour
One session a year, with no measurement.
Open service sheetDistinct roles
Who does what
Three neighbouring roles with different objects. Confusing them is the most common source of gaps and duplication.
| Role | Object | Source of the requirement |
|---|---|---|
| Security Officer | The information of the organisation, in any medium | Duty of security, certification and contracts |
| Cybersecurity officer | The cyber domain in covered entities | Article 31 of Decree-Law 125/2025 |
| Data protection officer | The processing of personal data | Articles 37 to 39 GDPR |
The roles work together and, in small organisations, may be held by the same team, provided there is no conflict of interests.
What we do
Services
External Security Officer
External performance of the information security lead role, with a policy, an annual plan, risk assessment and periodic reporting to the management body.
Open service sheet SO-02Information Security Maturity Assessment
An assessment of information security maturity by control domain, with a gap map and a prioritised improvement plan.
Open service sheet SO-03Management System and Certification Readiness
Implementation of the information security management system and preparation for the certification audit, with documentation proportionate to the organisation.
Open service sheet SO-04Risk Assessment and Management
Definition of the methodology, asset inventory, risk assessment and a treatment plan approved by the management body.
Open service sheet SO-05Supply Chain and Procurement Security
Supplier assessment criteria, security and incident-alert clauses, and a follow-up process throughout the contract.
Open service sheet SO-06Business Continuity and Recovery
Business impact analysis, definition of recovery objectives, a continuity plan and an exercise that tests it.
Open service sheet SO-07Awareness and Security Culture Programme
An annual awareness programme, with themed campaigns, phishing simulations and measurement of results by team.
Open service sheet SO-08Internal Audit and Third-Party Audit Readiness
Independent internal audit of the management system and its controls, with a report, a corrective plan and preparation for external audits.
Open service sheetMethod
The annual cycle of the role
- 01
Measure
Maturity and risk.
- 02
Treat
Controls, suppliers and continuity.
- 03
Enable
Awareness and competences.
- 04
Verify
Internal audit and management review.
Security that is not measured is not managed
Start with a maturity assessment or ask for a proposal to structure the role.