Verified cyberincident context · Portugal / CNCS/CERT.PT, RNCSIRT and CNPD 2024
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach notification context
Market context — not industry-specific evidence
Portugal CNCS report context (Ciberseguranca em Portugal — Riscos e Conflitos 2025) presents data from three distinct datasets: CERT.PT, RNCSIRT, and CNPD. CERT.PT registered 11,163 cybersecurity incidents in 2024 when automated sources are included, and 2,758 when automated sources are excluded — an approximate 36% increase in the automated-sources-excluded count compared with 2023. Approximately 78% of CERT.PT registered incidents occurred in private entities. Among CERT.PT registered incident types: phishing/smishing increased by approximately 13%, login-attempt incidents decreased by approximately 42%, simulated banking brands in phishing/smishing attacks increased by 33%, and ransomware-related incidents decreased by approximately 35%. CERT.PT also recorded 45 incidents associated with exploitation of 36 vulnerabilities. RNCSIRT incident types for 2024: scanning represented 27%, phishing 17%, and login attempts 1% of total RNCSIRT reported incidents. CNPD registered 331 personal data breach notifications in 2024, approximately 19% fewer than 2023, of which 77% were submitted by private entities. CERT.PT, RNCSIRT and CNPD are three separate datasets; their figures must not be merged into a single total or common denominator. These figures are Portugal CNCS 2024 reporting context and are not total Portuguese business incident prevalence, not a national incident census, and not industry-specific evidence.
CERT.PT registered cybersecurity incidents — Portugal 2024
- CERT.PT registered incidents in 2024 — automated sources included
- 11,163
- Unit
- cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are included
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- CERT.PT registered incidents in 2024 — automated sources excluded
- 2,758
- Unit
- cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are excluded
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
The 11,163 value includes automated reporting sources; the 2,758 value excludes them. These are two representations of the same reporting period with different scope boundaries, not peer counts for the same scope.
CERT.PT 2024 registered incident context only. The two values use different scope boundaries (automated sources included vs excluded) and must not be compared as peer counts or summed. Not total Portuguese business incident prevalence and not industry-specific evidence.
CERT.PT 2024 incident context — approximate year-on-year change and entity distribution
- Approximately 36% increase in CERT.PT incidents (automated sources excluded) vs 2023
- 36%
- Unit
- percent increase in CERT.PT registered incidents in 2024 compared with 2023 when automated sources are excluded — approximate source figure
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Approximately 78% of CERT.PT registered incidents occurred in private entities
- 78%
- Unit
- percent of CERT.PT registered incidents in 2024 occurring in private entities — approximate source figure
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
CERT.PT 2024 reporting context only. The 36% is an approximate year-on-year change for the automated-sources-excluded count; the 78% is an approximate share of CERT.PT registered incidents in private entities. These are two distinct types of measure, not shares of the same total. Not total Portuguese business incident prevalence and not industry-specific evidence.
CERT.PT registered incident type changes — approximate year-on-year 2024
- Phishing/smishing — approximately 13% increase
- 13%
- Unit
- percent increase in phishing/smishing incidents registered by CERT.PT in 2024 — approximate source figure
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Login-attempt incidents — approximately 42% decrease
- 42%
- Unit
- percent decrease in login-attempt incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Simulated banking brands in phishing/smishing — 33% increase
- 33%
- Unit
- percent increase in simulated banking brands in CERT.PT registered phishing/smishing attacks in 2024
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Ransomware-related incidents — approximately 35% decrease
- 35%
- Unit
- percent decrease in ransomware-related incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
CERT.PT 2024 approximate year-on-year change context only. Bars display absolute percent values; labels state the direction (increase or decrease). These values do not sum to 100% and are not proportional shares of a total. Not total Portuguese business incident type prevalence and not industry-specific evidence for the sector shown on this page.
RNCSIRT incident type shares — Portugal 2024
- Scanning — 27% of RNCSIRT reported incident types
- 27%
- Unit
- percent of total RNCSIRT reported incident types in 2024 categorised as scanning
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Phishing — 17% of RNCSIRT reported incident types
- 17%
- Unit
- percent of total RNCSIRT reported incident types in 2024 categorised as phishing
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Login attempts — 1% of RNCSIRT reported incident types
- 1%
- Unit
- percent of total RNCSIRT reported incident types in 2024 categorised as login attempts
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
RNCSIRT 2024 incident type share context only. RNCSIRT is a separate dataset from CERT.PT and CNPD — these shares must not be merged with CERT.PT incident counts or CNPD breach notifications. The three categories shown are a subset of RNCSIRT incident types and do not sum to 100%. Not total Portuguese business incident type prevalence and not industry-specific evidence.
Personal data breach notifications registered by CNPD — Portugal 2024
- Personal data breach notifications registered by CNPD in 2024
- 331
- Unit
- personal data breach notifications registered by CNPD in 2024
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
CNPD is the Portuguese data protection authority. The 331 notifications represent CNPD-registered personal data breaches only, separate from CERT.PT incident data and RNCSIRT shares.
CNPD 2024 personal data breach notification context only. CNPD is a separate dataset from CERT.PT and RNCSIRT. This count must not be merged with CERT.PT incident counts or RNCSIRT shares. Not total Portuguese business data breach prevalence and not industry-specific evidence.
CNPD personal data breach notification context — Portugal 2024
- 77% of CNPD breach notifications submitted by private entities
- 77%
- Unit
- percent of CNPD personal data breach notifications in 2024 submitted by private entities
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
- Approximately 19% decrease in CNPD breach notifications vs 2023
- 19%
- Unit
- percent decrease in CNPD personal data breach notifications in 2024 compared with 2023 — approximate source figure, absolute value of decrease
- Period
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
- Scope
- Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
CNPD 2024 breach notification context only. The 77% is a share of CNPD-registered notifications; the 19% is an approximate year-on-year decrease for CNPD notifications — two distinct types of measure, not shares of the same total. CNPD data must not be merged with CERT.PT or RNCSIRT data. Not total Portuguese business data breach prevalence and not industry-specific evidence.
Source: CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025
Scope: Centro Nacional de Ciberseguranca / CNCS report context published in 2025. CERT.PT, RNCSIRT and CNPD are three separate datasets and must not be merged. The 11,163 CERT.PT value includes automated sources; the 2,758 value excludes automated sources — these must not be treated as peer counts for the same scope. The approximate percent values (36% increase, 78% private entity share, 13%, 42%, 33%, 35%, 19%) are stated as approximate in the source and must be presented as such. RNCSIRT incident type shares (27%, 17%, 1%) represent a subset of RNCSIRT incident types and do not sum to 100%. The 45 incidents and 36 vulnerabilities are CERT.PT context only and must not be presented as total Portuguese vulnerability exposure. The 77% and 19% CNPD figures apply to CNPD-registered personal data breach notifications only and must not be merged with CERT.PT or RNCSIRT figures. These figures do not measure total Portuguese business incident prevalence, hidden incident prevalence, population-wide victimisation rates, all-sector incident totals, industry-specific evidence, compliance achievement, certification or security outcomes.
Methodology: Official Centro Nacional de Ciberseguranca / CNCS report context published in 2025. The admitted indicators describe CERT.PT, RNCSIRT and CNPD 2024 reporting context. CERT.PT, RNCSIRT and CNPD are three distinct datasets and must not be merged, their figures must not be summed into a single total, and their incident-type shares must not be combined into a common denominator. The 11,163 CERT.PT value includes automated reporting sources; the 2,758 value excludes automated sources; these are two representations of the same reporting period with different scope boundaries and must not be presented as peer counts. Approximate percent values (flagged as approximate in unit strings) are stated as approximately X% in the source and must be presented as approximate. Do not present any admitted indicator as total Portuguese business incident prevalence, hidden incident prevalence, population-wide victimisation rate, all-sector incident rate, industry-specific evidence, compliance achievement, certification, proof of security, or guaranteed protection.
Accessible data table
| Metric | Value | Source | Scope | Reporting period |
|---|---|---|---|---|
| CERT.PT registered incidents in 2024 — automated sources included | 11,163 cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are included | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| CERT.PT registered incidents in 2024 — automated sources excluded | 2,758 cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are excluded | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Approximately 36% increase in CERT.PT incidents (automated sources excluded) vs 2023 | 36% percent increase in CERT.PT registered incidents in 2024 compared with 2023 when automated sources are excluded — approximate source figure | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Approximately 78% of CERT.PT registered incidents occurred in private entities | 78% percent of CERT.PT registered incidents in 2024 occurring in private entities — approximate source figure | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Phishing/smishing — approximately 13% increase | 13% percent increase in phishing/smishing incidents registered by CERT.PT in 2024 — approximate source figure | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Login-attempt incidents — approximately 42% decrease | 42% percent decrease in login-attempt incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Simulated banking brands in phishing/smishing — 33% increase | 33% percent increase in simulated banking brands in CERT.PT registered phishing/smishing attacks in 2024 | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Ransomware-related incidents — approximately 35% decrease | 35% percent decrease in ransomware-related incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Scanning — 27% of RNCSIRT reported incident types | 27% percent of total RNCSIRT reported incident types in 2024 categorised as scanning | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Phishing — 17% of RNCSIRT reported incident types | 17% percent of total RNCSIRT reported incident types in 2024 categorised as phishing | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Login attempts — 1% of RNCSIRT reported incident types | 1% percent of total RNCSIRT reported incident types in 2024 categorised as login attempts | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Personal data breach notifications registered by CNPD in 2024 | 331 personal data breach notifications registered by CNPD in 2024 | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| 77% of CNPD breach notifications submitted by private entities | 77% percent of CNPD personal data breach notifications in 2024 submitted by private entities | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Approximately 19% decrease in CNPD breach notifications vs 2023 | 19% percent decrease in CNPD personal data breach notifications in 2024 compared with 2023 — approximate source figure, absolute value of decrease | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Portugal CNCS report context states that 45 incidents were associated with exploitation of vulnerabilities in 2024 in CERT.PT reporting. This is a CERT.PT count of vulnerability-exploitation incidents and must not be presented as total Portuguese business vulnerability exposure or industry-specific evidence. | 45 CERT.PT reported incidents associated with exploitation of vulnerabilities in 2024 | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
| Portugal CNCS report context states that 36 vulnerabilities were exploited across the 45 vulnerability-exploitation incidents registered by CERT.PT in 2024. This is a count in the CERT.PT reporting context and must not be presented as total Portuguese vulnerability prevalence or industry-specific evidence. | 36 vulnerabilities exploited in CERT.PT reported incidents in 2024 | CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025 | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context | Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025. |
