Cybersecurity 2026

PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

tailored to the individual needs and capabilities of each entity. A general compliance methodology follows a five-step actionable plan: • risk appetite setting; • asset mapping; Any compliance project must start with the delimita - tion of risk appetite, and the establishment of internal risk-taking policies and dynamics (including defining acceptable operational downtime, data loss thresh - olds and maximum tolerable legal exposure), followed by a mapping of the entity’s cyber-assets – these should include data, information and ICT systems and hardware, which should be classified by criticality and sensitivity. • governance; • control; and • monitoring. Once cyber-assets have been mapped, responsibili - ties over implementation and oversight of cyberse - curity tools and measures must be distributed and allocated among the different company departments and to their higher-ranking staff (directors, chief offic - ers, managers or others, as applicable). Companies may, for example, create a RACI matrix showing who is responsible, accountable, consulted and informed. Only upon having mapped cyber-assets and allocated responsibilities can applicable obligations be identi - fied and the mechanisms, processes and tools to per - form them selected by the competent person(s). Iden - tifying compliance risks in the design process itself, by embedding compliance checkpoints into everyday processes, ensures that the solutions implemented are robust and tailored to the company’s specific sce - narios. Such identification requires a prior decision on the company’s risk management approach – ie, which risks require immediate response, which can have response delayed and how is response effective - ness tracked.

Implementation of these mechanisms, processes and tools must then be supervised by a competent indi - vidual and should be followed by periodical reviews. In this context, it is worth noting that design processes that simplify compliance without compromising effi - ciency or the experience of end users (employees, customers and stakeholders) should be prioritised. Hence, companies should establish key performance indicators (KPIs) in relation to, for instance, supplier compliance rates and incident detection and commu - nication time. Continuous assistance by legal counsel throughout the implementation process, and afterwards, may prove beneficial. Companies must create sustainable compliance structures that ensure ongoing compli - ance with standards, even as regulations evolve or changes occur in the organisation’s operations. To navigate the complex network of obligations to which ICT services providers and receivers are sub - ject, these actors must arm themselves with suitable measures: adherence to official statutes, regulations and best operational standards assist them with com - plying with the applicable framework.

279 CHAMBERS.COM

Powered by