started · updated
Portugal cybersecurity governance faces restructuring debate
Discussions regarding the restructuring of Portugal's cybersecurity governance highlight potential errors in proposed organizational changes. There is a debate concerning whether the Portuguese Information System should oversee the National Cybersecurity Center (CNCS).
Critics argue that changing organizational charts does not necessarily increase operational capacity. The CNCS currently functions as a regulator, supervising thousands of public and private entities and possessing the authority to issue fines of up to ten million euros. The argument suggests that rather than being absorbed by information services, the CNCS should evolve into a full national authority with effective cyberspace regulation powers, independent of the National Security Office (GNS).
Furthermore, the role of the Internal Security System (SSI) is under scrutiny. While the new Cybersecurity Legal Regime correctly designated the Secretary-General of the SSI as the national authority for large-scale cybersecurity crisis management, there remains a disconnect between the original design of the SSI as an advisory body and its current implementation.
Entities
Centro Nacional de Cibersegurança · Gabinete Nacional de Segurança · Sistema de Segurança Interna