PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
• Date and time when the incident had a significant impact. • Date and time when the incident ceased to have a significant impact. • Impact of the incident, considering: (a) number of users affected by the service disrup - tion; (b) duration of the incident; (c) geographical distribution, with regard to the area affected by the incident, including an indi - cation of cross-border impact; and (d) description of the incident, indicating the cat - egory of cause and the effects produced. • Indication of the measures taken to mitigate the incident. • Description of the residual situation of the impact existing at the date of the final notification, namely: (a) number of users affected by the service disrup - tion; (b) geographical distribution, with regard to the area affected by the incident, including an indi - cation of cross-border impact; (c) estimated time for full recovery of services still affected; (d) indication, where applicable, of the submission of notification of the incident in question to the competent authorities, namely the Public Pros - ecutor’s Office or the CNPD and other sectoral authorities; and (e) other information that the essential and impor - tant entity considers relevant. Entities may also be required to submit one (or more) interim report(s) on a weekly basis if, after the dead - line for submitting the final report, the incident is still ongoing. Without prejudice to mandatory notifications, any nat - ural or legal person may voluntarily report incidents, cyber-threats or vulnerabilities that they detect. Such voluntary notifications do not trigger any additional obligation for the notifying entity. Lastly, essential, important and relevant public entities must inform the recipients of their services, without undue delay, of any incidents with a significant impact (and significant cyber-threats) that are likely to affect them negatively.
The format and process for the aforementioned noti - fications will be further defined by the CNCS through the issuance of a technical instruction. 2.4 State Responsibilities and Obligations The Cybersecurity Legal Framework is grounded in a strong institutional architecture designed to operate through close co-operation with the private sector. This co-operation may be achieved through public- private partnerships that facilitate the exchange of knowledge, dissemination of best practices, and the utilisation of private sector expertise in support of the competent cybersecurity authority. Decree-Law No 125/2025 also governs the establishment of agree - ments for sharing cybersecurity information among the entities that form the institutional framework of the Portuguese NIS2 Law and, where appropriate, their suppliers or service providers, for purposes of the following. • Prevention, detection, response to and recovery from incidents or mitigation of their impact. • Strengthening the level of cybersecurity, in particu - lar by: (a) raising awareness of cyber-threats; (b) limiting or preventing their ability to spread; (c) supporting a range of defensive capabilities; (d) the correction and disclosure of vulnerabilities; (e) threat detection, containment and prevention techniques; (f) mitigation strategies; (g) response and recovery phases; or (h) promoting collaborative research on cyber- threats between public and private entities. Additionally, the role of the CERT.PT should be emphasised. This team is responsible for (inter alia) monitoring and analysing cyber-threats, vulnerabilities and incidents at the national level and for activating early-warning mechanisms, sending alert messages, and communicating and disseminating information to relevant essential, important and public entities, com - petent authorities and other interested parties about cyber-threats, vulnerabilities and incidents, including in real time. The CERT.PT is the national co-ordinat - ing body for the disclosure of vulnerabilities affect - ing networks and information systems, products, components, and information and communication
265 CHAMBERS.COM
Powered by FlippingBook