Cybersecurity Officer
Frequently Asked Questions
Direct answers to the most frequent questions.
Questions
Frequently asked questions
What is the difference between this website and responsaveldeciberseguranca.pt?
That website deals with the duty of the entity: who must appoint, by when and with what consequences. This one deals with performing the role: mandate, competences, evidence and coordination with group functions based abroad.
Can the cybersecurity officer be external?
The appointment is an act of the entity and falls on a person. Permanent external support to the role is possible and common, but responsibility towards the authority is not transferred to the provider.
Can the group cybersecurity function perform the role in Portugal?
It depends on the specific set-up and on the ability to meet the Portuguese obligations in good time, including notification deadlines and dealing with the authority. In practice, a local appointment coordinated with the group function is recommended.
Is the cybersecurity officer the same as the permanent point of contact?
They are distinct roles, set out in different articles. The point of contact ensures permanent availability for dealing with the authority during activation; this is developed at pontodecontacto.pt.
Does the scope checker replace an opinion?
No. It gives indicative guidance from three criteria. Definitive qualification requires analysis of the exact sector, the size and the services provided.
Why is the website also in English?
Because in many groups the decisions on the role, its resources and its budget are taken outside Portugal, in English, even though the obligation is owed here.
An appointed role is not yet a role performed
Start by checking your organisation scope or ask for a proposal to structure the role.