2,758
CERT.PT incidents — 2024
Cybersecurity incidents recorded by CERT.PT in calendar year 2024, excluding automated-source incidents. Must not be compared with figures that include automated sources.
Security Services·Mobile App & Product Services
Organizations in Portugal assessing NIS2-oriented cybersecurity readiness where relevant to their scope may require clear gap visibility and practical preparation guidance. BilgeQor provides independent security reviews, readiness gap identification, and secure product delivery support — without providing certification, regulatory determination, or official compliance status.
Written proposal-stage scope before any engagement decision






Verified Portugal risk signals
CNCS / CERT.PT's 2024 incident context (excluding automated-source incidents) shows the volume, year-on-year growth, and entity-type distribution of reported cybersecurity incidents in Portugal. For leadership, the practical issue is whether phishing exposure, ransomware paths, and incident-response readiness are being reviewed before they become operational, payment, customer-trust or recovery-cost issues.
2,758
CERT.PT incidents — 2024
Cybersecurity incidents recorded by CERT.PT in calendar year 2024, excluding automated-source incidents. Must not be compared with figures that include automated sources.
+36%
year-on-year
Year-on-year increase in CERT.PT incidents (excluding automated sources) from 2023 to 2024. Increase may reflect improved reporting and detection, not only actual attack volume change.
78%
private-entity share
Share of CERT.PT 2024 incidents (excluding automated sources) involving private entities.
Source: CNCS Riscos e Conflitos 2025 / CERT.PT 2024 context
Portugal CNCS / CERT.PT 2024 incident context only, excluding automated-source incidents. The 2,758 figure must not be compared with figures that include automated sources. CERT.PT, RNCSIRT, and CNPD are three separate datasets and must not be merged or summed. Not total Portuguese business cyberattack prevalence and not industry-specific evidence.
Use the service family that best describes your current objective
Start with a practical baseline to identify priority security gaps, then move to structured hardening when scope is clear — documented findings and clear remediation guidance throughout.
Start here
Security Baseline Review
Or consider
Website Security Hardening
Build or fix your mobile product — MVP development, rescue services, and security-integrated delivery.
Start here
Mobile App MVP Sprint
Or consider
Security-First App Launch
Scoped backend, API, cloud, production, rescue, and platform modernisation work with documented boundaries, controlled transition, operational visibility, and technical handover.
Start here
Secure Backend & API Engineering
Or consider
Cloud Platform & Production Engineering
For teams assessing AI tools: governance documentation, security review, and permission-limited workflow discussion with written boundaries.
Start here
AI Governance, Policy & Data Safety Review
Or consider
AI Adoption & Workflow Discovery Review
Use these service families to describe the outcome you want to discuss. Availability, scope, entity, timing, and any commercial terms are confirmed later in writing.
Security reviews, assessment support, and documented readiness guidance for organizations in Portugal.
A practical baseline security review for existing web and mobile assets, with prioritised findings and a clear readiness roadmap before deeper security work
From 2 050,00 € EUR
Informational
Proactive website protection and security implementation
From 2 760,00 € EUR
Informational
Proposal-stage secure product and platform delivery discussions for organizations in Portugal.
Rapid MVP delivery with security-first development
From 17 700,00 € EUR
Informational
Recovery-focused rebuild scope for an existing product. Displayed rebuild-scope prices apply only after paid diagnostic assessment and confirmed rebuild scope. These are NOT diagnostic fees; a diagnostic request does not start rebuild work.
From 10 600,00 € EUR
Informational
Additional Security Services: AI & Cloud Security Readiness Review, Incident Recovery Sprint, Care, Maintenance & Validation Plan →
Need custom scope or combined packages? Book a discovery call
BilgeQor Method
Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.
View servicesChoose Service
Explore the service context that best matches your objective.
Proposal-stage discussion
Email the team with non-sensitive context. A later written proposal determines whether work is offered.
Written confirmation, if applicable
No contract, payment, intake, delivery, or work start follows from browsing or an email inquiry.
Separate activation only when authorized
Any future engagement follows its own written scope, approvals, and applicable terms.
Proof stream
A compact, attributed view of app delivery, security reviews, Engineering and Applied R&D work, and AI readiness cases drawn from the public case libraries.
Each card keeps its source and attribution boundary visible. Client identities and identifying operational details remain withheld where confidentiality requires it.
Supported by a verified operational network of more than 50 specialists, with documented scope, senior-led review, and accountable handoff.
Remote proposal-stage communication is coordinated through documented written follow-up.
Security-sensitive engagements follow a documented review workflow with scoped findings, written outputs and clear handoff.
Structured delivery discipline: scope defined before commitment, documented outputs, structured follow-up, and a buyer-visible handoff on every engagement.
Each engagement proceeds within confirmed written scope, agreed inputs and clearly documented delivery boundaries.
Describe your readiness priorities and receive a structured proposal.
Selected services show informational local-currency estimates with exact USD sources available through Show USD estimate; no checkout, payment, or intake on this route