Cybersecurity 2026

PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

Mercado de Valores Mobiliários or CMVM), in line with otherwise applicable regulations. As for the executory acts necessary for the imple - mentation of DORA in Portugal, Law No 73/2025 establishes that voluntary notice of significant cyber- threats must be submitted before the national Com- puter Security Incident Response Team (CSIRT), in addition to submission before the BdP, ASF or CMVM, as applicable. The BdP, ASF and CMVM are empowered to establish further regulation, in particular concerning: • the channels and operational steps for communi - cation between financial entities and the compe - tent authority; • the channels and operational steps for communi - cation to competent authorities of the necessary contractual information concerning the receipt of ICT services; • the standardised models, forms and procedures for communication to competent authorities of the necessary contractual information concerning the receipt of ICT services that support important or critical functions; • the frequency and expected minimum content of communication to competent authorities concern - ing the financial institutions’ ICT risk reference framework preparation and review; • the conditions, channels and proceedings of com - munication to competent authorities concerning the financial institutions’ estimates of ICT-related severe incidents’ costs; • the standardised models, forms and procedures for communication to competent authorities of threat- led penetration testing (TLPT) executions; and • the conditions, channels and proceedings of com - munication to competent authorities of agreements which include sharing specific and sensitive infor - mation concerning cyber-attacks. Concerning breaches – the enforcement on which Law No 73/2025 also entrusts to the BdP, ASF and CMVM – both the financial entities and their managers and administrators may be held administratively liable for intentional and negligent acts.

Company breaches include: • failure to provide information requested by a com - petent authority, as well as the provision of infor - mation to competent authorities that is not com - plete, truthful, current, clear, objective or lawful; • absence of a demonstrably implemented suitable ICT-related internal governance framework and documented ICT risk-management framework; • absence of suitable systems, protocols, tools, poli - cies, solutions, strategies and procedures in use in the context of ICT; and • non-documentation of these security elements, absence of their review or overdue updating (including their obsolescence), in addition to the breach of any and all duties not referred to indi - vidually under Law No 73/2025, but which are “enshrined in Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 and in applicable European or national legislation or regulations on digital opera - tional resilience”. Personal liability is in turn attached to non-perfor - mance, by members of the board of administration and higher directorship positions ( quadros superiores responsáveis ), of the “functions, competences and responsibilities” entrusted to them in connection with ICT within the financial entity. Considering that the management body of the financial entity shall “define, approve, oversee and be respon - sible for the implementation of all arrangements relat - ed to the ICT risk management framework”, for the purpose of which the management body shall “bear the ultimate responsibility for managing the financial entity’s ICT risk” (Article 5 (2) of DORA), it could be argued that members of the board of administration and those holding higher directorship positions also hold direct responsibility – thus being administratively liable – for any and all company breaches connected to their own areas of responsibility. This is especially relevant given that these breaches are considered to be serious infractions, and that decisions on application of sanctions for the breach - es described above must be made publicly available online.

275 CHAMBERS.COM

Powered by