Skip to main content
BilgeQor
Back to industries

CTO, VP Engineering, CISO

SaaS & B2B Platforms

Verified cyberincident context · Portugal / CNCS/CERT.PT, RNCSIRT and CNPD 2024

Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach notification context

Market context — not industry-specific evidence

Portugal CNCS report context (Ciberseguranca em Portugal — Riscos e Conflitos 2025) presents data from three distinct datasets: CERT.PT, RNCSIRT, and CNPD. CERT.PT registered 11,163 cybersecurity incidents in 2024 when automated sources are included, and 2,758 when automated sources are excluded — an approximate 36% increase in the automated-sources-excluded count compared with 2023. Approximately 78% of CERT.PT registered incidents occurred in private entities. Among CERT.PT registered incident types: phishing/smishing increased by approximately 13%, login-attempt incidents decreased by approximately 42%, simulated banking brands in phishing/smishing attacks increased by 33%, and ransomware-related incidents decreased by approximately 35%. CERT.PT also recorded 45 incidents associated with exploitation of 36 vulnerabilities. RNCSIRT incident types for 2024: scanning represented 27%, phishing 17%, and login attempts 1% of total RNCSIRT reported incidents. CNPD registered 331 personal data breach notifications in 2024, approximately 19% fewer than 2023, of which 77% were submitted by private entities. CERT.PT, RNCSIRT and CNPD are three separate datasets; their figures must not be merged into a single total or common denominator. These figures are Portugal CNCS 2024 reporting context and are not total Portuguese business incident prevalence, not a national incident census, and not industry-specific evidence.

Portugal · CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context — three separate datasets2024 reporting period · Published 2025

CERT.PT registered cybersecurity incidents — Portugal 2024

CERT.PT registered incidents in 2024 — automated sources included
11,163
Unit
cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are included
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
CERT.PT registered incidents in 2024 — automated sources excluded
2,758
Unit
cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are excluded
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

The 11,163 value includes automated reporting sources; the 2,758 value excludes them. These are two representations of the same reporting period with different scope boundaries, not peer counts for the same scope.

CERT.PT 2024 registered incident context only. The two values use different scope boundaries (automated sources included vs excluded) and must not be compared as peer counts or summed. Not total Portuguese business incident prevalence and not industry-specific evidence.

CERT.PT 2024 incident context — approximate year-on-year change and entity distribution

Approximately 36% increase in CERT.PT incidents (automated sources excluded) vs 2023
36%
Unit
percent increase in CERT.PT registered incidents in 2024 compared with 2023 when automated sources are excluded — approximate source figure
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Approximately 78% of CERT.PT registered incidents occurred in private entities
78%
Unit
percent of CERT.PT registered incidents in 2024 occurring in private entities — approximate source figure
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

CERT.PT 2024 reporting context only. The 36% is an approximate year-on-year change for the automated-sources-excluded count; the 78% is an approximate share of CERT.PT registered incidents in private entities. These are two distinct types of measure, not shares of the same total. Not total Portuguese business incident prevalence and not industry-specific evidence.

CERT.PT registered incident type changes — approximate year-on-year 2024

Phishing/smishing — approximately 13% increase
13%
Unit
percent increase in phishing/smishing incidents registered by CERT.PT in 2024 — approximate source figure
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Login-attempt incidents — approximately 42% decrease
42%
Unit
percent decrease in login-attempt incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Simulated banking brands in phishing/smishing — 33% increase
33%
Unit
percent increase in simulated banking brands in CERT.PT registered phishing/smishing attacks in 2024
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Ransomware-related incidents — approximately 35% decrease
35%
Unit
percent decrease in ransomware-related incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decrease
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

CERT.PT 2024 approximate year-on-year change context only. Bars display absolute percent values; labels state the direction (increase or decrease). These values do not sum to 100% and are not proportional shares of a total. Not total Portuguese business incident type prevalence and not industry-specific evidence for the sector shown on this page.

RNCSIRT incident type shares — Portugal 2024

Scanning — 27% of RNCSIRT reported incident types
27%
Unit
percent of total RNCSIRT reported incident types in 2024 categorised as scanning
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Phishing — 17% of RNCSIRT reported incident types
17%
Unit
percent of total RNCSIRT reported incident types in 2024 categorised as phishing
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Login attempts — 1% of RNCSIRT reported incident types
1%
Unit
percent of total RNCSIRT reported incident types in 2024 categorised as login attempts
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

RNCSIRT 2024 incident type share context only. RNCSIRT is a separate dataset from CERT.PT and CNPD — these shares must not be merged with CERT.PT incident counts or CNPD breach notifications. The three categories shown are a subset of RNCSIRT incident types and do not sum to 100%. Not total Portuguese business incident type prevalence and not industry-specific evidence.

Personal data breach notifications registered by CNPD — Portugal 2024

Personal data breach notifications registered by CNPD in 2024
331
Unit
personal data breach notifications registered by CNPD in 2024
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

CNPD is the Portuguese data protection authority. The 331 notifications represent CNPD-registered personal data breaches only, separate from CERT.PT incident data and RNCSIRT shares.

CNPD 2024 personal data breach notification context only. CNPD is a separate dataset from CERT.PT and RNCSIRT. This count must not be merged with CERT.PT incident counts or RNCSIRT shares. Not total Portuguese business data breach prevalence and not industry-specific evidence.

CNPD personal data breach notification context — Portugal 2024

77% of CNPD breach notifications submitted by private entities
77%
Unit
percent of CNPD personal data breach notifications in 2024 submitted by private entities
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context
Approximately 19% decrease in CNPD breach notifications vs 2023
19%
Unit
percent decrease in CNPD personal data breach notifications in 2024 compared with 2023 — approximate source figure, absolute value of decrease
Period
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scope
Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach context

CNPD 2024 breach notification context only. The 77% is a share of CNPD-registered notifications; the 19% is an approximate year-on-year decrease for CNPD notifications — two distinct types of measure, not shares of the same total. CNPD data must not be merged with CERT.PT or RNCSIRT data. Not total Portuguese business data breach prevalence and not industry-specific evidence.

Source: CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025

Scope: Centro Nacional de Ciberseguranca / CNCS report context published in 2025. CERT.PT, RNCSIRT and CNPD are three separate datasets and must not be merged. The 11,163 CERT.PT value includes automated sources; the 2,758 value excludes automated sources — these must not be treated as peer counts for the same scope. The approximate percent values (36% increase, 78% private entity share, 13%, 42%, 33%, 35%, 19%) are stated as approximate in the source and must be presented as such. RNCSIRT incident type shares (27%, 17%, 1%) represent a subset of RNCSIRT incident types and do not sum to 100%. The 45 incidents and 36 vulnerabilities are CERT.PT context only and must not be presented as total Portuguese vulnerability exposure. The 77% and 19% CNPD figures apply to CNPD-registered personal data breach notifications only and must not be merged with CERT.PT or RNCSIRT figures. These figures do not measure total Portuguese business incident prevalence, hidden incident prevalence, population-wide victimisation rates, all-sector incident totals, industry-specific evidence, compliance achievement, certification or security outcomes.

Methodology: Official Centro Nacional de Ciberseguranca / CNCS report context published in 2025. The admitted indicators describe CERT.PT, RNCSIRT and CNPD 2024 reporting context. CERT.PT, RNCSIRT and CNPD are three distinct datasets and must not be merged, their figures must not be summed into a single total, and their incident-type shares must not be combined into a common denominator. The 11,163 CERT.PT value includes automated reporting sources; the 2,758 value excludes automated sources; these are two representations of the same reporting period with different scope boundaries and must not be presented as peer counts. Approximate percent values (flagged as approximate in unit strings) are stated as approximately X% in the source and must be presented as approximate. Do not present any admitted indicator as total Portuguese business incident prevalence, hidden incident prevalence, population-wide victimisation rate, all-sector incident rate, industry-specific evidence, compliance achievement, certification, proof of security, or guaranteed protection.

Accessible data table
Verified Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident context data from CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025, reporting period Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025..
MetricValueSourceScopeReporting period
CERT.PT registered incidents in 2024 — automated sources included11,163 cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are includedCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
CERT.PT registered incidents in 2024 — automated sources excluded2,758 cybersecurity incidents registered by CERT.PT in 2024 when automated reporting sources are excludedCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Approximately 36% increase in CERT.PT incidents (automated sources excluded) vs 202336% percent increase in CERT.PT registered incidents in 2024 compared with 2023 when automated sources are excluded — approximate source figureCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Approximately 78% of CERT.PT registered incidents occurred in private entities78% percent of CERT.PT registered incidents in 2024 occurring in private entities — approximate source figureCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Phishing/smishing — approximately 13% increase13% percent increase in phishing/smishing incidents registered by CERT.PT in 2024 — approximate source figureCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Login-attempt incidents — approximately 42% decrease42% percent decrease in login-attempt incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decreaseCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Simulated banking brands in phishing/smishing — 33% increase33% percent increase in simulated banking brands in CERT.PT registered phishing/smishing attacks in 2024CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Ransomware-related incidents — approximately 35% decrease35% percent decrease in ransomware-related incidents registered by CERT.PT in 2024 — approximate source figure, absolute value of decreaseCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Scanning — 27% of RNCSIRT reported incident types27% percent of total RNCSIRT reported incident types in 2024 categorised as scanningCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Phishing — 17% of RNCSIRT reported incident types17% percent of total RNCSIRT reported incident types in 2024 categorised as phishingCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Login attempts — 1% of RNCSIRT reported incident types1% percent of total RNCSIRT reported incident types in 2024 categorised as login attemptsCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Personal data breach notifications registered by CNPD in 2024331 personal data breach notifications registered by CNPD in 2024CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
77% of CNPD breach notifications submitted by private entities77% percent of CNPD personal data breach notifications in 2024 submitted by private entitiesCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Approximately 19% decrease in CNPD breach notifications vs 202319% percent decrease in CNPD personal data breach notifications in 2024 compared with 2023 — approximate source figure, absolute value of decreaseCNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Portugal CNCS report context states that 45 incidents were associated with exploitation of vulnerabilities in 2024 in CERT.PT reporting. This is a CERT.PT count of vulnerability-exploitation incidents and must not be presented as total Portuguese business vulnerability exposure or industry-specific evidence.45 CERT.PT reported incidents associated with exploitation of vulnerabilities in 2024CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.
Portugal CNCS report context states that 36 vulnerabilities were exploited across the 45 vulnerability-exploitation incidents registered by CERT.PT in 2024. This is a count in the CERT.PT reporting context and must not be presented as total Portuguese vulnerability prevalence or industry-specific evidence.36 vulnerabilities exploited in CERT.PT reported incidents in 2024CNCS/CERT.PT, Ciberseguranca em Portugal — Riscos e Conflitos 2025, 2025Portugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 cyberincident and breach contextPortugal CNCS/CERT.PT, RNCSIRT and CNPD 2024 reporting context as published in Ciberseguranca em Portugal — Riscos e Conflitos 2025.

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Tenant Data Leakage
  • API Abuse
  • Insider Threat

Digital surfaces in scope

Admin ConsolesEnterprise APIsTenant Portals

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.