Friday, 6.30pm, a garment workshop near Famalicão. The server running the ERP and holding ten years of client technical specification sheets starts flashing ransom messages in English. The most recent backup is eleven days old — someone turned off the scheduling because it "was slowing down the network". The parent company, a European fast fashion brand, wants answers by Monday. There is no plan. There is not even a list of who to call.

This scene is no longer bad luck. With the transposition of NIS2 into the Portuguese legal order, a large slice of the national manufacturing industry now has concrete cybersecurity obligations — and most industrial SMEs still do not know whether they are in or out of scope. This guide settles that: who is covered, what they must do, and in what order to do it by 2026.

We wrote this for a very specific trio: the CEO who signs, the CFO who pays and the IT manager who will execute. Most texts on NIS2 are written for lawyers or for bank security departments. This one is not. It was written with the 80-person factory in Guimarães in mind, where the production server and the accounting PC share the same network socket and the same administrator — who is the owner's nephew and taught himself.

1. The real operational problem

Cybersecurity in the Portuguese industrial SME does not fail for lack of expensive firewalls. It fails because of three mundane things: backups that nobody tests, shared accesses that are never revoked, and operational technology (OT) connected to the same network as email.

On a footwear shop floor in Felgueiras, the production capture terminals, the CNC cutting machines and the accounting PC frequently live on the same flat network segment. A machine contaminated by an infected USB stick spreads to everything. There is no separation. There is no internal firewall. The production manager knows the names of the 40 machines, but nobody knows how many devices are actually connected to the network.

This is the fundamental difference between theory and the field. In theory, security is a matrix of controls. In the field, it is the question "who touched the switch configuration in 2019 and no longer works here?". The technical debt of Portuguese industrial SMEs has accumulated over twenty years of "if it works, don't touch it" — a philosophy that protects production in the short term and exposes it in the long term.

Where it hurts first: the production stoppage

For a factory delivering just-in-time to a parent company such as Inditex or Decathlon, the cost of an incident is not the ransom. It is the stoppage. Three days down in the middle of a collection campaign — women's footwear is delivered in February, men's footwear in August — can mean losing next season's order. The international buyer who visits twice a year does not wait.

It is worth doing the sum in your head. A Felgueiras footwear factory with 120 people and a cadence of 2,000 pairs/day, down for three working days, loses the production of 6,000 pairs. If each pair is worth, at the factory gate, between 12 and 25 euros of gross industrial margin, the direct hole runs between 70,000 and 150,000 euros — before counting wages paid without production, contractual penalties for late delivery and the intangible cost of a difficult meeting with the buyer. The ransom, when it exists, is often the smallest of the sums.

A food distributor with a 20,000 m² warehouse and daily cross-docking cannot withstand the WMS being down for a morning. Picking stops. The vans wait at the door. The warehouse manager — the one who fights any rollout that takes him off the radio for more than two hours — is left without a system for a whole day. In fresh food, with delivery windows at supermarkets and short shelf lives, a morning of stoppage is not recovered. The goods are lost or sent back.

In the industrial SME, the information system is not a back-office cost. It is the assembly line. When it stops, the factory stops — and the factory has no stock of time.

OT versus IT: the boundary no one drew

The concept that separates mature factories from vulnerable ones is the segmentation between operational technology (OT) and information technology (IT). OT is everything that touches physical production: PLCs, CNC machines, controllers, capture terminals, sensors. IT is email, the ERP, accounting, the shared file.

The problem is that these industrial machines were designed to last fifteen or twenty years. A cutting machine installed in 2011 frequently runs a Windows that has not received security updates for years. It cannot be updated without risking breaking the manufacturer's proprietary software — which often no longer even exists. The only real defence is isolation: that machine should not see the internet or email. On a flat network, it sees everything.

CharacteristicIT worldOT world
Equipment life cycle3-5 years15-20 years
Dominant priorityData confidentialityAvailability and physical safety
Security updatesFrequent, automatableRare, risky, manual
Tolerance to restartHigh (out of hours)Almost none (stops production)
Who managesIT / internal heroMaintenance / machine supplier

The human factor and accumulated technical debt

The typical Portuguese industrial SME has an IT hero: 15 years of business knowledge, knows where all the cables are, but with no team and no dedicated security budget. Does everything. When he goes on holiday, the company is blind. This concentration of knowledge in one person is, in itself, a continuity risk that NIS2 requires to be documented.

This hero is one of the greatest strengths and one of the greatest fragilities of these companies. He knows the business in detail — he knows that client X's size chart has an exception nobody documented, he knows why that report runs on Thursdays. But the knowledge is in his head, not in a file. If he falls ill, nobody restores a backup. If he leaves in anger, the company is left without the passwords. NIS2 requires, in practice, taking the knowledge out of the hero's head and putting it into procedure — which also protects him.

Phishing remains the most common entry point, and it requires no sophistication. A credible email imitating the parent company, with an attachment "revised technical sheet.xlsx", reaches a garment workshop at a peak collection time when nobody has time to be suspicious. The person opens it. From then on, on a flat network, the rest is geography.

The overwhelming majority of incidents we see in industrial SMEs did not require sophisticated technique from the attacker. They required a reused password and a backup that nobody validated.

2. What exactly is NIS2 cybersecurity for SMEs in Portugal

NIS2 — Directive (EU) 2022/2555 — is the second generation of the European directive on the security of network and information systems. It replaces the original NIS from 2016 and drastically widens the scope of who is covered, raises the level of obligations and introduces direct responsibility of top management.

The original NIS covered few sectors and left much discretion to Member States to identify who was an "essential services operator". The result was uneven application across Europe. NIS2 corrects this in two ways: it defines sectors much more broadly and establishes an automatic size criterion, removing much of the States' power of choice. In other words, it no longer depends on someone "designating" your factory — it now depends on size and sector.

In Portugal, the transposition is done through the legal cybersecurity regime that frames the work of the National Cybersecurity Centre (CNCS) as the competent national authority. The essential for an industrial manager reduces to three questions: am I covered? what measures must I implement? and what are the deadlines and sanctions?

Essential entities vs. important entities

NIS2 divides the obliged parties into two categories, with different practical implications:

  • Essential entities — highly critical sectors (energy, transport, banking, health, water, digital infrastructure). Proactive supervision: the authority can audit before any incident.
  • Important entities — include manufacturing in various subsectors, production and distribution of chemicals, food, waste management, postal services. Reactive supervision: the authority acts after signs of non-compliance.

Manufacturing — where much of Portuguese textile, footwear, metal and plastic falls — typically enters as an important entity when it meets the size thresholds. It is a category with real obligations, albeit with less intrusive supervision than the essential ones.

The distinction does not change the technical measures to be implemented — those are essentially the same. It changes the supervision regime and the ceiling of the fines. An essential entity lives under permanent scrutiny; an important entity only attracts the authority after something goes wrong or a complaint. For the average factory, this means that the probability of a spontaneous audit is low — but the probability of the parent company asking for evidence is high. The real inspector of the Portuguese industrial SME is not the CNCS. It is the international client.

The subsector matters: not all "manufacturing" enters the same

The NIS2 annexes do not treat all manufacturing the same way. Some manufacturing subsectors are explicitly listed as covered — manufacture of medical devices, of electronic products, of machinery and equipment, of vehicles. Others enter via chemicals or food. Pure textile and footwear do not always appear directly in the annexes, which generates legitimate confusion.

Here is the trap: even if your specific CAE code does not appear explicitly, three routes can pull you in. First, if you manufacture components for a covered sector (for example, technical textiles for the automotive industry). Second, if the food or chemical part of your business qualifies you. Third, and most likely, through the supply chain. Do not assume you are out just because your sector does not jump out in the annex. Document the analysis.

The size criterion: the 50/€10M rule

NIS2 applies, as a rule, to medium and large entities of the covered sectors. The medium enterprise threshold, according to Recommendation 2003/361/EC, is: 50 or more employees, OR annual turnover above 10 million euros and total balance sheet above 10 million. Below this, in principle, the entity is out — except for special cases (critical service providers, communications infrastructure, individually designated entities).

Beware of a subtlety that catches many managers: the size calculation, according to Recommendation 2003/361/EC, may include linked and partner enterprises. If your 40-person factory belongs to a family group with three companies that, combined, exceed 50 employees or €10M, the calculation may consolidate them. Many Portuguese corporate structures — common in textile and footwear, where production is separated from commercialisation into distinct companies — thus discover they are in when they thought they were out.

Type of company (Rec. 2003/361/EC)EmployeesTurnover OR balance sheetNIS2 (covered sector)
Micro< 10≤ €2MIn principle out
Small< 50≤ €10MIn principle out
Medium50-249≤ €50M / ≤ €43M balance sheetIn (important)
Large≥ 250> €50MIn (important/essential)

Practical rule for the CFO: if your factory has 50+ people or turns over above €10M and is in manufacturing, distribution or food, assume you are in until documented proof to the contrary. And do the consolidated group calculation before breathing a sigh of relief.

The supply chain effect: why SMEs below the threshold are also pulled in

Here is the point that generic articles forget. NIS2 requires covered entities to manage the risk of their supply chain. A covered European brand will demand security guarantees from its Portuguese subcontractors — even if these have 30 people and are technically out of direct scope. Compliance flows down the chain through the contracts. A 35-employee garment workshop in the Vale do Ave will eventually receive a security questionnaire from the parent company. And it will have to answer.

The Portuguese apparel sector lives off subcontracting for parent companies such as Inditex, Decathlon, Mango, Tom Tailor and Lacoste. These brands already have compliance departments that send supplier questionnaires with dozens of questions: "do you have MFA?", "do you test the backups?", "do you have an incident response plan?", "where is our design data hosted?". A vague or blank answer does not immediately lose the contract — but it goes into the risk column. And when the buyer needs to cut suppliers, they cut the highest-risk ones first.

This completely reverses the incentive logic. The small garment workshop that ignored cybersecurity because "that's for the big ones" discovers that its commercial survival depends on being able to respond credibly to a two-page PDF. The cost of having nothing is not a CNCS fine — it is falling off the list of approved suppliers. For the Vale do Ave SME, this is existential.

3. The landscape in Portugal today

The numbers dismantle the slide-deck optimism. According to Eurostat, in 2024 only a minority of Portuguese companies reported having documented formal ICT security policies, and the percentage falls further among small companies. Portugal is consistently below the European average in the adoption of cybersecurity measures in SMEs.

The pattern is known: large Portuguese companies have maturity comparable to their European counterparts, but the tail of small and medium ones pulls the national average down. And it is precisely in that tail that the industrial fabric of the North lives — thousands of family textile, footwear and metalworking companies that for decades competed on price and deadline, not on digital sophistication.

The CNCS, in its annual Cybersecurity Observatory reports, has documented a sustained growth in incidents reported in Portugal, with ransomware and phishing among the most frequent threats to the business fabric. Manufacturing is a growing target precisely because it combines low defensive maturity with high sensitivity to stoppages. ENISA, in its annual Threat Landscape, confirms the same trend on a European scale: ransomware remains at the top and industrial SMEs are a preferred target because they are the weak link in larger chains.

Why Portuguese industry is an attractive target

Ransomware attackers do not choose targets out of dislike. They choose by expected return. A factory delivering just-in-time has a characteristic that makes it ideal: urgency. Whoever cannot be down three days is more inclined to pay quickly. The attacker knows this. He knows that a garment workshop in the middle of a collection delivery has a short and desperate negotiation window.

Add the low defensive maturity — untested backups, flat networks, absence of monitoring — and you have the perfect profile: an easy target to compromise and with a strong incentive to pay. It is not because your factory is geopolitically important. It is because it is easy and in a hurry.

The maturity gap between sectors

Common reality in the PT industrial SMETypical state observed
BackupsThey exist, but are rarely tested; restore never rehearsed
OT/IT network segmentationFrequently non-existent — flat network
Multi-factor authentication (MFA)Absent on critical accesses and VPN
Digital asset inventoryInformal, in the IT hero's head
Incident response planNon-existent or undocumented
Employee trainingOccasional or none
Supplier chain risk managementNon-existent; a software supplier was never questioned
Encryption of sensitive data (technical sheets, design)Rare; data in clear in shared folders

There is a sectoral nuance. The metalworking and mould industry of the Aveiro–Marinha Grande corridor, having worked for longer with German and automotive industry clients, tends to have slightly higher maturity — because Industry 4.0 and the requirements of the automotive chain have already forced it to professionalise processes. Textile and apparel, with an ageing workforce and tight margins, generally start from a more fragile base. Footwear sits in the middle, pulled by the demands of the international buyers of APICCAPS.

The real cost of doing nothing

The IBM Cost of a Data Breach Report has placed the global average cost of a data breach above 4 million dollars — a figure inflated by large companies, but the signal is clear. For the Portuguese industrial SME, the concrete cost is measured in days of stopped production, lost collection order and erosion of the parent company's trust. A factory that loses its supplier certification from an international brand due to a security failure does not recover that client in a season.

Let us break down the real cost of an incident in an industrial SME into layers, from the most visible to the most treacherous:

  • Immediate direct cost — possible ransom, hours of incident response consultancy, systems recovery, replaced equipment.
  • Stoppage cost — lost production, wages paid without output, penalties for contractual late delivery.
  • Regulatory cost — NIS2 and GDPR fines if there is personal data exposed, mandatory notifications.
  • Reputational and commercial cost — the most serious and the least accounted for: falling off a parent company's list of approved suppliers and not returning.

It is not the ransom that ruins the Portuguese factory. It is the parent company that changes supplier because it has stopped trusting your operational continuity.

4. The NIS2 compliance implementation models

There are four real approaches for an industrial SME to reach compliance. They are not equally good. Each has a different cost, speed and risk.

Model A: Pure internal (DIY with the IT hero)

The company loads everything onto its existing IT manager. It works only if that person has freed-up time and specific security training. In practice, the hero is already overloaded keeping the ERP and the network working. NIS2 compliance requires documentation, policies, restore tests and continuous risk management — work that does not fit in one person who also fixes printers.

There is a scenario in which this model works: the company that formally frees up half of the IT manager's time, pays for certified training and hires a second technician for current operations. Very rare in the Portuguese industrial SME, where the IT budget is treated as a cost to minimise, not as an investment. When we hear "our IT guy handles that", we mentally translate it to "nobody handles that in a structured way".

Model B: Full outsourcing (MSSP)

Hiring a Managed Security Service Provider that manages monitoring, detection and response. Good for those with no internal competence. The risk is total dependence and disconnection from the operational context — a generic MSSP does not understand why the production capture terminal cannot restart in the middle of the shift.

The Achilles' heel of the generic MSSP reveals itself at the first alert. The system detects "anomalous" traffic from a CNC machine communicating with the production server at 3am and blocks it as a precaution. Except that communication was the legitimate night cycle preparing the morning shift. The MSSP, without industrial context, stopped production to "protect" the company. The result is mutual distrust and, frequently, the progressive turning-off of controls — the worst of worlds.

Model C: Hybrid (internal + specialised partner)

The model we recommend for most industrial SMEs. The business knowledge stays in-house; the technical security competence and critical infrastructure are delegated to a partner who knows the industry. It combines hybrid cloud, managed datacenter and specialised cybersecurity services with the local operation.

The division of responsibilities that works is clear: the IT hero keeps the business knowledge and the relationship with production — knows which machine cannot restart, knows the rhythms of the shop floor. The partner brings the security competence, the tested backup infrastructure, the monitoring and support in incident response. Neither of the two is dispensable. The partner who understands the industry does not block the CNC machine without asking; the hero is not left alone at 6.30pm on a Friday with the server flashing ransom.

Model D: Integrated platform (security embedded in the stack)

Building compliance within the management tools themselves — ERP, document management, access control — instead of treating it as an external layer. An ERP MULTI with granular user management, audit logs and document management with eIDAS qualified signature natively resolves part of the access control and record integrity requirements.

This model shines in moments of transition. Those who are going to renew the ERP anyway have a rare opportunity here: designing security into the architecture from the start, instead of gluing it on top afterwards. Role-based access control, segregation of duties (whoever creates the order cannot approve the payment), immutable audit trail, record integrity for SAF-T. All of this is cheaper and more solid when it is born with the system than when it is patched on later.

ModelSpeedInitial costResidual riskFor whom
A — Pure internalSlowLowHigh (depends on 1 person)Rarely advisable
B — MSSP outsourcingFastHigh recurringMedium (operational disconnection)No internal IT at all
C — HybridMediumMediumLowMost industrial SMEs
D — Integrated platformMedium/longMediumLowThose renewing the ERP in parallel

In practice, models C and D are frequently combined. The company adopts the hybrid for the security operation and, at the same time, embeds controls in the ERP renewal. It is the most solid combination for those modernising the house all at once.

The worst decision is not to decide. Postponing NIS2 while waiting for "more regulatory clarity" leaves you exposed both to the authority and to the parent company — and both arrive without warning.

5. How to assess whether your company needs it

Before spending a euro, do the scope diagnosis. It takes half a day and saves wrong decisions.

Signs that you are in scope

  • You have 50 or more employees or turn over above €10M annually.
  • You operate in manufacturing, food, distribution, waste management or chemicals.
  • You are a subcontractor of a European brand that has already sent you security questionnaires.
  • You received direct communication from a national authority about cybersecurity obligations.
  • You belong to a corporate group that, consolidated, exceeds the size thresholds.
  • You supply components or services to an explicitly covered sector (automotive, medical devices, electronics).

Step by step: NIS2 readiness diagnosis

  1. Determine the scope. Confirm size (employees, turnover, balance sheet) and sector against the NIS2 annexes. Document the conclusion in writing — "we are in as an important entity" or "we are out, but subject via the contractual route of the chain".
  2. Inventory the digital assets. List all servers, industrial terminals, network-connected machines, applications (ERP, WMS, production capture, accounting), user accounts and remote accesses. You cannot protect what you do not know.
  3. Assess the existing controls. For each NIS2 baseline measure — backups, MFA, segmentation, incident management, access control, encryption — classify it as existing, partial or absent. Use a simple sheet with a green/yellow/red traffic light.
  4. Identify the critical gaps. Rank the absences by operational impact. Untested backup and flat OT/IT network almost always come first because they are the ones that stop the factory.
  5. Estimate the effort and prioritise. Assign each gap an approximate cost and a person responsible. Separate quick wins (1-2 weeks) from structural projects (3-6 months).
  6. Present it to top management. NIS2 holds the administration directly responsible. CEO and CFO have to approve the plan and the budget in writing — it is not delegable solely to the IT hero.

The questions the parent company's questionnaire will ask

If you want to anticipate what is coming, prepare honest answers to these questions — they are the ones that appear in the supplier questionnaires of European brands:

  • Do you have multi-factor authentication on remote accesses and on the systems that touch our data?
  • How often do you test backup recovery and what is your restore time?
  • Do you have a documented incident response plan and who is the point of contact?
  • Where are the data we share with you physically hosted (design, technical sheets)?
  • Do you have segmentation between the production network and the administrative network?
  • Do your employees receive security training? How often?
  • Do you have any certification (ISO 27001) or a plan to obtain it?

Quick wins implementable in two weeks

  • Enable MFA on all VPN, email and ERP accesses — drastically reduces the risk of compromised credentials.
  • Test a real backup restore on an isolated server. If you cannot restore, you do not have a backup — you have an illusion of a backup.
  • Revoke all accesses of ex-employees and suppliers who no longer work with you. It is common to find active accounts of people who left years ago.
  • Apply the 3-2-1 backup rule: three copies, on two different media, one of them off-site and offline (immune to ransomware that encrypts the entire network).

6. What to choose and why: decision by company size

The right answer depends on size and maturity. There is no single solution.

SME of 30-50 employees (often out of direct scope)

Focus on basic hygiene and on responding to supply chain questionnaires. Quick wins, tested backup, MFA, minimal segmentation. A light hybrid model with a partner who ensures the datacenter and the backups. The goal is to be able to respond credibly to the parent company.

For this size, the mistake to avoid is overspending on sophisticated tools that nobody will manage. A corporate SIEM in a 35-person company is money badly spent — nobody looks at the alerts. Concentrate the budget on what moves the needle: MFA, tested offline backup and the ability to answer a questionnaire without lying. Basic hygiene done well protects against the overwhelming majority of opportunistic attacks.

SME of 50-150 employees (typical important entity)

Full compliance mandatory. Complete hybrid model: documented policies, incident response plan, real OT/IT segmentation, monitoring. Here it makes sense to embed controls in the industrial ERP and professionalise document management with audit trail and eIDAS signature.

This is the band where most of the Felgueiras footwear factories and the medium-sized textiles of the Vale do Ave live. The qualitative leap here is from informality to documentation. Doing it is not enough — you have to prove that you do it, with written policies, restore test records and administration approval minutes. The difference between "we think we are secure" and "we have a dossier that demonstrates our compliance" is exactly what the authority and the parent company will want to see.

Company of 150+ employees or multi-site

Formal security governance structure, possibly with a dedicated manager, and integration between sites via Multi Connect. For highly complex operations, a QAD Adaptive ERP with robust identity management. Continuous monitoring and periodic incident simulation exercises.

The multi-site adds coordination complexity. A company with production in Felgueiras, a warehouse in Lousada and sales in Porto has three perimeters, three networks and three points of failure. Security has to be thought of centrally but executed locally — common policies, but someone responsible for each site. The integration between sites, if it is via a poorly configured VPN, becomes the motorway along which ransomware travels from one factory to all the others.

SizeNIS2 scopeRecommended modelPriority no. 1
30-50 emp.Indirect (chain)Light hybridTested backup + MFA
50-150 emp.Important entityComplete hybrid + platformOT/IT segmentation + response plan
150+ emp.Important/essentialFormal governance + integrationContinuous monitoring

To go deeper into the concrete controls per site, see our guide NIS2 in practice: technical controls for Portuguese factories and the operational complement NIS2 in industrial SMEs: what changes in operational practice.

7. Applicable regulatory framework and compliance

NIS2 does not live in isolation. It crosses with several obligations the Portuguese industrial SME already has — or should have.

The obligations NIS2 imposes directly

  • Cybersecurity risk management — risk analysis, information security policies, proportionate technical and organisational measures.
  • Incident notification — significant incidents have to be reported to the national authority within tight deadlines: initial alert within 24 hours, full notification within 72 hours, final report within one month.
  • Supply chain security — assess and manage the risk of suppliers and service providers.
  • Management responsibility — the administration approves and supervises the measures and can be held personally responsible for non-compliance.
  • Sanctions — fines that, for important entities, can reach millions of euros or a percentage of annual turnover, according to the national sanctioning regime.

The notification calendar you must know by heart

The notification obligation is where many companies stumble, because the deadlines are short and count from the moment you become aware of the incident — not from the moment you decide to report. Have this pinned to the IT manager's wall:

DeadlineWhat to deliverContent
24 hoursInitial alertIndication that a significant incident has occurred; suspicion of a malicious act
72 hoursIncident notificationInitial assessment: severity, impact, indicators of compromise
1 monthFinal reportDetailed description, root cause, mitigation measures applied

What this means in practice: on the Friday at 6.30pm of our example, the 24-hour clock is already ticking. Without a response plan with the chain of contacts defined, the company spends the first twelve hours figuring out who to call — and loses half the legal deadline in panic alone. This is why the documented response plan is not bureaucracy. It is what turns chaos into procedure.

How it crosses with the rest of the legislation you already comply with

The Portuguese industrial SME already deals with several layers. NIS2 reinforces them:

  • GDPR + Law 58/2019 — personal data protection and information security are cousins. An incident that exposes employee or client data triggers both regimes.
  • DL 28/2019 and Ordinance 195/2020 — certified electronic invoicing and monthly SAF-T communication require integrity and availability of the invoicing systems. Our analysis in document management and DL 28/2019 details compliant paperless.
  • eIDAS 2 — the qualified signature guarantees the integrity of legal documents and contracts, a control that NIS2 values.
  • Law 93/2021 — the mandatory whistleblowing channel for companies with 50+ employees intersects with security governance.
  • AI Act (Regulation EU 2024/1689) — for those who use predictive AI in people management or production, there are risk classification obligations that add to security governance.
  • ISO 27001 — the information security management standard is the best shortcut to demonstrate NIS2 compliance; those already certified have much of the path done.
  • DORA — for those operating in the financial sector or providing it services, the DORA regulation imposes digital operational resilience requirements with logic close to NIS2.

The notification duplication deserves a note. If an incident exposes personal data, it simultaneously triggers the obligation to notify the CNPD under GDPR (72 hours) and the cybersecurity authority under NIS2 (24h/72h/1 month). They are different channels, partially overlapping deadlines. The response plan has to provide for both, or you risk complying with one and failing the other.

The good news for the CFO: investing in ISO 27001 is not money wasted. It is the most recognised path to demonstrate NIS2 compliance and, at the same time, to open doors to international clients who require it.

Funding: PT2030, PRR and the North's instruments

Cybersecurity is eligible in various PT2030, PRR and Norte 2030 calls for digitalisation and capacity-building of SMEs. The rhythm is known: what involves clear infrastructure and verifiable metrics passes; what gets stuck are the poorly grounded technical reports. Structure the application with measurable objectives — number of systems with MFA, restore time, segmented sites — and justify each investment. IAPMEI and CCDR-N are the interlocutors in the North.

A practical piece of advice from someone who has seen many applications approved and rejected: link the cybersecurity investment to a broader digital transition project. An application that presents "we want firewalls" tends to get stuck; one that presents "we modernise the ERP, segment the network, professionalise backups and train the team, with these indicators before and after" passes more easily. The evaluator wants to see measurable transformation, not the purchase of boxes. Align the narrative with the priorities of Industry 4.0 and value chain resilience — those are the ones that open the coffers.

8. How INFOS approaches this

We do not sell security as a loose layer glued on top of an operation we do not understand. We know the shop floor of textiles, footwear, distribution and metal because it is where we have worked for more than three decades. We know that the production capture terminal cannot restart in the middle of the shift and that the warehouse manager will not put down the radio for a firewall upgrade.

Our approach is the hybrid model with security embedded in the management stack. The managed datacenter ensures tested backups and availability; the cybersecurity services handle monitoring and response; and the ERP MULTI, the document management and the identity management natively resolve access control, audit trail and record integrity. The knowledge of your business stays in-house; the technical security competence we support.

Why the industrial context changes everything

The difference between a partner who knows the industry and a generic security supplier appears in the operational details. We know that in a distributor with WMS and warehouse management, the maintenance window has to respect the loading and unloading times — you do not restart the system at 10am when the vans are leaving. We know that in a footwear factory the monitoring has to distinguish the legitimate night cycle of the machines from a malicious lateral movement. This context is not learned in a generic MSSP manual. It is learned in three decades of shop floor.

From audit to proof: the trail the parent company wants to see

When you need to read what is happening — who accessed what, which systems are exposed, where the gaps are — Qlik Sense turns logs and indicators into dashboards that the CEO and the CFO understand in two minutes. The same panel that shows the production OEE can show the state of compliance: percentage of accesses with MFA, last successful restore test, number of orphan accounts to revoke. Turning security into visible indicators is what takes it out of the hero's head and puts it on the administration's table.

Before committing budget, schedule a technical assessment with an INFOS specialist. No slide-deck. With your real network on the table.

9. 30/60/90-day roadmap

NIS2 compliance is not done in a weekend. But in 90 days you reach a defensible and auditable posture. Here is the path with verifiable milestones.

Days 1-30: visibility and quick wins

  • Determine and document the NIS2 scope (important entity, out, or pulled in by the chain).
  • Inventory all digital assets and access accounts — including OT and industrial terminals.
  • Enable MFA on VPN, email and ERP. Verifiable milestone: 100% of critical accesses with MFA.
  • Test a real backup restore. Verifiable milestone: complete successful restore documented.
  • Revoke accesses of ex-employees and inactive suppliers.

Days 31-60: structure and segmentation

  • Segment the OT/IT network — separate production machines and terminals from the administrative network. Milestone: internal VLANs and firewall operational.
  • Draft the baseline policies: information security, access control, management

Frequently asked questions

Is my industrial SME covered by NIS2?

You are covered if you operate in essential or critical sectors (energy, transport, water, health, food, digital infrastructure) and have more than 50 workers or turnover above 10 million euros. Many Portuguese garment workshops, footwear factories and food distributors fall into this category. Check your classification with the ANSSI or a specialist consultant.

What is the deadline to comply with NIS2 in Portugal?

The transposition of NIS2 into Portuguese law requires compliance by 2026. It is recommended to start now, in 2024, with the security diagnosis and the identification of critical assets. Leaving it to 2025 concentrates the operational risk and increases compliance costs. Organise yourself in phases: inventory, network segmentation, tested backups, access controls.

What is OT/IT segmentation and why is it critical?

Segmentation is separating the production network (CNC machines, PLCs, controllers) from the administrative network (email, ERP, accounting). On a flat network, a virus on the accounting PC contaminates the machines. Industrial machines last 15-20 years without security updates. Isolation is the only defence. Without segmentation, an incident stops the entire factory.

How to manage old machines that do not receive updates?

2011 machines with outdated Windows cannot be updated without breaking proprietary software. Solution: isolate them on a separate network, control physical accesses (no USB stick), monitor network traffic, document the risk and communicate it to the administration. Consider an internal firewall or DMZ. Replace gradually according to the life cycle.

What is the real cost of a stoppage from a cyber incident?

It is not the ransom. For a 120-person footwear factory with 2,000 pairs/day, three days down costs 70-150 thousand euros in lost margin, plus wages, contractual penalties and the risk of losing future orders. In a food distributor, a morning without a WMS loses perishable goods. Prevention costs less than the stoppage.

How to document the risk of a single IT manager?

NIS2 requires taking knowledge out of one person's head. Do: an inventory of critical systems, documentation of procedures, segregation of passwords in a secure vault, a succession plan, a regularly tested backup. Define who substitutes during holidays or departure. It is not about firing the hero — it is about protecting the company and giving him sustainable working conditions.

Where do I start if I do not have a large security budget?

Start with the essentials: (1) asset and network inventory, (2) backups tested monthly, (3) revoke accesses of those who have left, (4) separate OT from IT with a basic firewall, (5) unique passwords per person. This costs little and reduces 80% of the risk. Then, according to budget: network monitoring, multi-factor authentication, cyber insurance. Prioritise by operational impact.

Sources

  • Directive (EU) 2022/2555 (NIS2) — Directive on measures for a high common level of cybersecurity across the European Union
  • Law no. 32/2024, of 21 August — Transposition of the NIS2 Directive into the Portuguese legal order
  • Regulation (EU) 2024/1689 — Regulation on the cybersecurity of the supply chain
  • ENISA (European Union Agency for Cybersecurity) — NIS2 implementation guide for operators of essential services and providers of critical digital services
  • CNCS (National Cybersecurity Centre) — Technical guidance for NIS2 compliance in Portugal