La Ciberseguridad Industrial en Portugal

Team

Paulo Coelho

Paulo Coelho is a Senior Engineer at Ordem dos Engenheiros (Portugal), has a degree in Electrical Engineering – Automation and Industrial Electronics, by ISEL, Instituto Superior de Engenharia de Lisboa, and has more than 28 years of professional experience. He started his career in June 1995, as a trainee, and from October 1995 to 2000, […]

Maite Carli García

Maite Carli is Communication Manager and General European Coordinator at the Industrial Cybersecurity Center. Specialized in administration of networks and communications, industrial critical infrastructures, industry 4.0, data analysis technologies in the Health sector and industrial cybersecurity, having done several advanced courses and a master. She has developed her professional career in the United Kingdom for […]

Paulo Coelho, the Industrial Cibersecurity Center Coordinator in Portugal (CCI Coordinators Team), helps us to get in context of the state of the industrial cybersecurity in his country, and to do so, he shares with us his impressions.

He describes the level of sensitivity of industrial organizations in his country according to the following percentages:

 

He also affirms that the trend of recent years has grown slightly in awareness.

Portugal counts with local and national public bodies promoting an adequate legal framework, in order to ensure the progressive incorporation of industrial cybersecurity measures in national presence companies (mainly critical infrastructure). The main organizations are:

  • National Cybersecurity Center, CNCS
  • CERT.PT (CNCS)
  • National CSIRT Network
  • National Unit to Combat Cybercrime and Technological Crime (UNC3T), Polícia Judiciária

Among the main national laws and regulations affecting in this context in Portugal, Paulo Coelho mentions:

  • Legal Framework for Cyberspace Security (Law No. 46/2018, of August 13, which transposes Directive (EU) 2016/1148 – NIS)
  • Regulation of the Legal Framework for Cyberspace Security (Decree-Law No. 65/2021, of 30 June)
  • Technical instruction on communications between entities and the CNCS (Regulation No. 183/2022, of February 21)
  • National Cyberspace Security Strategy 2019-2023 (Council of Ministers Resolution No. 92/2019, of June 5)
  • Procedures for identifying, designating, protecting and increasing the resilience of national and European critical infrastructures (Decree-Law No. 20/2022, of 28 January)

Analysing the most widely adopted industrial cybersecurity measures by Sweden organizations to protect industrial automation systems, Paulo Coelho highlights the application of:

  • Conventional Firewalls
  • IDS/IPS
  • Backups
  • Antivirus

The CCI Coordinator in Portugal characterizes the industrial cybersecurity situation in his country with the following SWOT analysis:

Weaknesses

  • Lack of Certifications of OT technology, processes and professionals


  • Lack of specific regulations on industrial cybersecurity


  • Falta de un catálogo de soluciones y servicios en ciberseguridad industrial


  • Falta de CERTs específicos



Strengths

  • Promotion from public organizations (Industry, Interior and Defense)



  • Frequent holding of events and forums on industrial cybersecurity



  • National cybersecurity certification ecosystem




Threats

  • Application of IT security measures without criteria


  • High development of industrial applications without cybersecurity requirements


  • slow legislation


  • Shortage of local cybersecurity professionals in industrial manufacturers



  • Shortage of specific risk management tools for Industrial Cybersecurity



Opportunities

  • Increased of cibersecurity demand for Industry 4.0 and the Internet of things


  • Strategic position in the industrial cyber security sector



CERT's and CSIRT's from this Country

Argentina

CSIRT NQN

Sitio webWebsite View feed

Argentina

CSIRT Córdoba

Argentina

CERTUNLP

  • Academic
  • Ámbito de aplicaciónScope: IT

Academic Security Incident Response Centre (CSIRT) of the National University of La Plata

Argentina

BA-CSIRT

CSIRT for end users, Cybersecurity Centre of the Government of the Autonomous City of Buenos Aires

Argentina

Cert.ar

Austria

CERT.at

Bahamas

CIRT BS

Sitio webWebsite View feed

Belgium

CERT.BE

Sitio webWebsite View feed

Brazil

CTIR Gov

Centre for Prevention, Treatment and Response to Government Cyber Incidents

Brazil

CERTbr

Sitio webWebsite View feed

Canada

Cyber Centre

Chile

CSIRT Nacional

Article 24 of Law No. 21,663 creates within the National Cybersecurity Agency the National Computer Security Incident Response Team.

Sitio webWebsite View feed

Chile

CSIRT REUNA

  • Academic
  • Ámbito de aplicaciónScope: IT

Chile

CLCERT

  • Academic
  • Ámbito de aplicaciónScope: IT

Colombia

Min Defensa – Policia

  • Government
  • Ámbito de aplicaciónScope: Militar Military

Colombia

CSIRT‑CCIT

Colombia

colCERT

Croatia

CERT.hr

Sitio webWebsite View feed

Cuba

CSIRT-BCF

  • Private
  • Ámbito de aplicaciónScope: IT

Cuba

OSRI

Denmark

Airbus Protect CSIRT

  • OT, Private
  • Ámbito de aplicaciónScope: OT

Denmark

DKCERT

Sitio webWebsite View feed

Ecuador

CSIRT UTPL

  • Academic
  • Ámbito de aplicaciónScope: IT

Ecuador

CSIRT CEDIA

  • Academic
  • Ámbito de aplicaciónScope: IT

Ecuador

EcuCERT

Estonia

EDF CIRC

Sitio webWebsite View feed

Estonia

CERT‑EE

Sitio webWebsite View feed

European Union

ENISA CSIRT Network

The European Union CSIRTs network is a network composed of EU Member States’ appointed CSIRTs and CERT-EU (“CSIRTs network members”). The European Commission participates in the network as an observer.

European Union

EGI CSIRT

European Union

ESA CERT

European Union

EATM‑CERT

European Union

CERT‑EU

Finland

NCSC‑FI

France

PSIRT Scheneider Electric

  • OT, Private
  • Ámbito de aplicaciónScope: OT

France

ENGIE CERT

  • Private
  • Ámbito de aplicaciónScope: IT

France

CERT‑FR

Sitio webWebsite View feed

Germany

PSIRT Siemens

  • OT, Private
  • Ámbito de aplicaciónScope: OT

Guatemala

GT Cert

CERT coordinator of the Republic of Guatemala, covered by the regulatory framework of the Law Against Cybercrime and recognised by FIRST

Honduras

CSIRT_HONDURAS

Italy

Enel CERT

  • Private
  • Ámbito de aplicaciónScope: IT

Jamaica

JaCIRT

Sitio webWebsite View feed

Latvia

CERT.LV

Mexico

UNAM‑CERT

  • Academic
  • Ámbito de aplicaciónScope: IT

Mexico

CERT-MX

Sitio webWebsite View feed

Netherlands

NCSC‑NL

Sitio webWebsite View feed

Norway

NSM‑NCSC

Sitio webWebsite View feed

Panama

CertPA

Sitio webWebsite View feed

Paraguay

CERT-PY

Peru

PeCERT

Poland

CERT.PL

Sitio webWebsite View feed

Portugal

Euronext CSIRT

  • Private
  • Ámbito de aplicaciónScope: IT

Portugal

CNCS Portugal

Republica Dominicana

CSIRT-RD

CSIRT belonging to the National Cybersecurity Centre

Romania

CERT.RO

Sitio webWebsite View feed

Slovakia

ENERGOTEL.SK-CSIRT

  • Private
  • Ámbito de aplicaciónScope: IT

Slovakia

SK‑CERT

Sitio webWebsite View feed

Slovenia

SI‑CERT

Sitio webWebsite View feed

Spain

CSIRT-MIR-PJ

Spain

CSIRT-CV

Spain

INCIBE-CERT

Spain

CSIRT.gal

Spain

CCN‑CERT

Sitio webWebsite View feed

Surinam

SUR-CSIRT

Sitio webWebsite View feed

Sweden

CERT‑SE

Sitio webWebsite View feed

Swiss

PSIRT ABB

  • OT, Private
  • Ámbito de aplicaciónScope: OT
Sitio webWebsite View feed

Swiss

Swiss GovCERT

Sitio webWebsite View feed

Trinidad and Tobago

TT-CSIRT

Sitio webWebsite View feed

Ukraine

CERT‑UA

Sitio webWebsite View feed

United Kingdom

UK NCSC

United States

US-CERT OT Cybersecurity

United States

US-CERT Cybersecurity

Uruguay

CSIRT ANTEL

  • Private
  • Ámbito de aplicaciónScope: IT

Uruguay

Cert.uy

Venezuela

VenCERT

Patrocinadores del Centro en el País

Bronze