For years, cybersecurity and privacy regulation was seen as a problem for large organisations. GDPR, in 2018, was the first sign that this was changing: all organisations that process personal data of European citizens were covered, regardless of size. But it was between 2022 and 2025 that regulatory pressure became truly democratised.
NIS2 extended cybersecurity obligations to many more sectors. DORA imposed stringent requirements on the financial sector, including IT suppliers. The EU AI Act introduced obligations for organisations using high-risk AI systems. CSRD made sustainability reporting mandatory for a growing number of companies. In Portugal, Decree-Law 125/2025 transposed NIS2 with ANACOM as the competent authority.
| Regulation | Maximum Fine | Application Condition |
|---|---|---|
| GDPR | €20M or 4% global turnover | Personal data breach, lack of legal basis |
| NIS2 | €10M or 2% global turnover | Inadequate measures, notification failure |
| DORA | Per national authority | Insufficient operational resilience |
| EU AI Act | €35M or 7% global turnover | High-risk AI systems without compliance |
Many organisations respond to regulatory pressure in the most obvious way: they hire a consultant, conduct an assessment, produce documentation, and pass an audit. A year later, the consultant is gone, the person who coordinated the process has moved to another company, and the organisation starts from scratch.
This is the problem EterShield was designed to solve. It is not a problem of lacking tools — it is a problem of knowledge that disappears. Every decision taken, every risk assessed, every policy approved should be a growing asset of the organisation.
The market has responded with solutions at the extremes: Enterprise GRC (OneTrust, IBM OpenPages) with prices of €50,000–€500,000 annually and implementations taking months; or isolated tools (Eramba, spreadsheets) with no integration or AI. The gap is clear: no affordable solution preserves organisational knowledge, integrates multiple European frameworks in Portuguese, and uses contextual AI — all in a single product for SMEs.
A vCISO (Virtual Chief Information Security Officer) externalises the function of strategic security leadership. A vCISO platform is the technological evolution: software that structures, automates, and systematises the functions of a CISO in an interface that any IT or compliance manager can operate — without being a security specialist.
EterShield is a vCISO platform, but goes further: it is an organisational security knowledge management system that collects and structures everything the organisation knows about its own security, uses AI to transform that knowledge into actionable assessments and policies, and accumulates value over time.
| Model | Description | Suitable for |
|---|---|---|
| Self-managed | Organisation uses the platform directly | SME with a dedicated IT manager |
| Assisted | Eter Growth operates the platform with the organisation | SME without internal technical capacity |
| Full vCISO | Eter Growth assumes the vCISO role | Organisations with no security resources whatsoever |
| MSP / partner | Consultancy uses EterShield for multiple clients | MSSPs, compliance consultancies |
| Framework | Scope | Controls |
|---|---|---|
| ISO 27001:2022 | Information Security | 93 (complete Annex A) |
| NIST CSF 2.0 | Cybersecurity Framework | 106 subcategories |
| GDPR (2016/679) | Data Protection | 57 |
| ISO 42001:2023 | AI Management | 57 |
| EU AI Act (2024/1689) | High-Risk AI Systems | 54 |
| ISO 9001:2015 | Quality | 52 |
| ISO 31000:2018 | Risk Management | 47 |
| ISO 22301 | Business Continuity | 43 |
| NIS2 (2022/2555) | Cybersecurity | 41 |
| DORA (2022/2554) | Digital Resilience | 40 |
| MITRE ATT&CK | Threat Modelling | 38 |
| SOC 2 | Security and Availability | 38 |
| ISO 20000-1 | IT Service Management | 37 |
| CIS Controls v8 | Security Baseline (IG1) | 72 safeguards |
| HIPAA Security Rule | Healthcare Data Security | 65 safeguards |
| PCI DSS v4.0 | Payments | 29 |
| Cyber Resilience Act (2024/2847) | Products with Digital Elements | 29 |
| AMLD6 (2018/1673) | Anti-Money Laundering | 23 |
| ISO 23894 | AI Risk Management | 22 |
| MITRE CTID Fraud | Fraud and Abuse | 16 |
| ISO 45001:2018 | Health and Safety | 13 |
| ISO 14001:2015 | Environmental Management | 12 |
| OWASP Top 10 | Application Security | 10 |
Instead of going through 93 ISO 27001 controls manually, the user activates the AI Gap Analysis. Based on the organisation's profile and accumulated Knowledge Base, the AI automatically identifies the most likely gaps, suggests remediation priority, and proposes response texts for each control. The compliance score (0–100%) updates in real time by category and by framework.
An ISO 27001 control can simultaneously satisfy NIS2 and DORA requirements. An organisation working ISO 27001 in parallel with NIS2 and DORA can have 60–70% of DORA controls already answered by the work done on ISO 27001. No duplicate questions, no redundant effort.
The policy repository generates contextualised drafts — not generic templates. Based on the organisation's profile, sector of activity, and active frameworks, the AI creates a policy that references the specific reality of the company. Full versioning with revision history, approvals, and next scheduled review.
Most risk tools stop at coloured matrices. EterShield quantifies risks financially using the FAIR model (Factor Analysis of Information Risk) with Monte Carlo simulation: 10,000 simulations produce an annual expected loss (ALE) distribution with P10, P50, and P90 percentiles in euros.
| Risk (example) | Median ALE (P50) | ALE P90 |
|---|---|---|
| Ransomware on a Windows endpoint | €78,000 | €310,000 |
| Unauthorised access to customer database | €45,000 | €180,000 |
| Critical cloud vendor failure | €25,000 | €95,000 |
FAIR quantification requires parameters that few IT managers know how to estimate. The AI proposes frequency and magnitude parameters with justification based on benchmarks from DBIR (Verizon), ENISA, and CNCS, presenting a TransparencyBadge with the complete reasoning and sources used.
For each implemented security control, EterShield automatically calculates the risk reduction in euros — allowing investments to be prioritised by financial return, not intuition. Each risk enters a formal treatment plan with milestones, owners, approval, and linkage to the compliance calendar.
EterShield uses an adaptive TPRM questionnaire with 33 questions distributed across 5 modules, activated automatically based on the vendor's profile. An office supplies vendor answers 8 questions. A personal data processor with direct CRM access answers all 33.
| Module | Activated when | Questions |
|---|---|---|
| Information Security | Always | 8 |
| Data Protection | Vendor processes personal data | 7 |
| Business Continuity | Vendor critical to operations | 6 |
| Technical Security | Vendor with access to systems | 7 |
| Compliance | Vendor in a regulated sector | 5 |
The vendor does not need to create an account. They receive an email with a unique token link, access a secure public page, respond, and submit. The token expires after submission or deadline. All interaction is tracked and audited.
After submission, the AI analyses each response: score 0–100, red flags identified with reasoning, and overall recommendation (Approve / Conditional / Reject / Defer). The responsible party records the formal decision with a justification note — direct evidence for ISO 27001 and NIS2 auditors.
The access lifecycle tracks Joiners (new employees with a provisioning checklist), Movers (role changes with access review), and Leavers (departures with a revocation checklist). Each event generates an assigned task with a deadline and completion confirmation.
Automated periodic access reviews: a cron job schedules the review, the responsible party receives the access list, approves or revokes each entry, all recorded with a timestamp. Background checks with status and validity. Disciplinary process with PII fields encrypted in AES-256-GCM (GDPR Art. 9).
GDPR Art. 15–20 requests with entry date registration, 30-day legal countdown, status tracking (Received → Under review → Responded), and complete history for compliance demonstration.
| Module | Description |
|---|---|
| Document Control | QMS with version, revision date, approval owner, and automatic alert |
| Customer Complaints | Full cycle: reception, root cause analysis, action plan, effectiveness verification |
| Equipment Calibration | Records with calibration dates and automatic alert before recalibration deadline |
| Supplier Audits | ISO 9001 checklists by category, non-conformance records |
| SPC Control Charts | X-bar, R and p charts for statistical process monitoring |
| CAPA 8D | Structured resolution following 8 Disciplines (D1–D8) with evidence chain |
Accident records with root cause analysis and automatic ACT report; hazard register with risk assessment and controls; PPE management per employee; documented worker consultation (clause 5.4 ISO 45001 requirement).
Critical physical systems (HVAC, CCTV, alarms, sprinklers, UPS) registered as assets with preventive maintenance plans, inspection history, and imminent maintenance alerts. Direct linkage to ISO 27001 physical and environmental security controls.
Vehicle and driver records, fuel tracking, maintenance history, and document expiry calendar (inspection, insurance, service). Fuel data feeds directly into the GHG Scope 1 emissions module.
| Pillar | Standard | Content |
|---|---|---|
| GHG Emissions | ESRS E1 | Scope 1/2/3 with IPCC factors; sync from fleet records; tCO₂e dashboard |
| Social Indicators | ESRS S1 | Workforce, gender, accidents, training, absenteeism, pay gap |
| Governance | ESRS G1 | Anti-corruption policy, whistleblower (AES-256), vendor assessment, fines |
The CSRD report editorial cycle follows a Draft → Under Review → Approved → Published flow. The report is generated from records already existing on the platform — no manual re-entry of data.
All AI in EterShield is auditable. Every generated result includes a TransparencyBadge visible to the user — relevant for organisations subject to the EU AI Act.
| Field | Content |
|---|---|
| Model | Language model (version and provider identified) |
| Tokens consumed | Input + Output |
| Estimated cost | In euros (cost control) |
| Latency | Response time in ms |
| Operation | E.g.: "Gap Analysis ISO 27001 Annex A.8" |
| Reasoning | Exposed model reasoning |
| Sources | Benchmarks or frameworks referenced |
| Component | Usage |
|---|---|
| Internal AI Gateway | Internal proxy that intermediates all requests to the AI model — ensures isolation, auditability, and cost control |
| Claude (Anthropic) | Single production LLM backend — Gap Analysis, TPRM, Monte Carlo, EtherFlow, Cook/Sparks, response suggestions, profile prefill |
| Semantic search | Knowledge Base — context retrieval by entity, optimised for European Portuguese |
| GRC knowledge graph | Vera's structured context injected into prompts — at no additional cost per call |
EterShield's deepest differentiator: a per-entity Knowledge Base system with contextual semantic search in four phases.
6-step wizard (identification, business, systems, regulation, team, maturity). Completeness score 0–100%. AI suggests frameworks and identifies the competent NIS2 authority (ANACOM, BdP, CNCS) based on the sector.
Any free text (meeting minutes, email, report) is processed by the AI, which extracts structured knowledge in 7 categories. The CISO approves, edits, or rejects each item before it enters the database.
Approved items are indexed and made available for semantic search optimised for European Portuguese. At each AI call, the most relevant Knowledge Base items are retrieved and injected into the prompt. The AI responds with the organisation's real context.
PDFs, DOCX, and TXT files up to 20MB are processed, fragmented into chunks, and integrated into the Knowledge Base. Existing policies, audit reports, contracts — all enrich the AI context.
The meeting ingestion pipeline: the transcript is sent via API or uploaded manually; the AI extracts risks, gaps, tasks, and decisions; items appear in an approval inbox; approved items go directly into the corresponding modules and the Knowledge Base. A 2-hour meeting produces 15 structured entries in 10 minutes.
With the proliferation of AI systems in business processes, AI risk management has become a formal requirement (EU AI Act, ISO 42001). EterShield includes a set of specialised modules for organisations that develop or use AI systems.
The ARIA Framework (Agentic Risk Intelligence Assessment) is a proprietary agentic AI risk assessment methodology structured in 7 phases, aligned with NIST AI RMF, MITRE ATLAS, MAESTRO, OWASP AIUC-1, and AIVSS. It covers 15 risk vectors: A1–A8 (agentic system risks: objective manipulation, planning hallucination, privilege escalation, context exfiltration, reasoning loop, tool abuse, irreversible impact, malicious coordination) and D Series D1–D7 (development phase threats, OWASP AI Exchange: data poisoning, backdoors, model attacks, inversion, extraction, adversarial evasion, dependency injection).
| Module | Description |
|---|---|
| ARIA Assessment | Complete 7-phase assessment — score per phase, A1–A8 risks + D Series, assessment history, and mitigation plan |
| AI Incidents | AI behavioural incidents — 7 types (hallucination, bias, prompt injection, data leak, jailbreak, misuse, unexpected behaviour); EU AI Act Art. 72 flag |
| Model Cards | EU AI Act Art. 13 technical fact sheet — intended use, training data, limitations, bias, ethics, human oversight; formal approval with record |
| Red Team Scheduler | Red teaming campaigns on AI systems — pre-defined OWASP AIUC-1 tests by category (prompt injection, jailbreak, data exfiltration) |
| EU AI Act Assessment | Compliance assessment with 33 EU AI Act obligations per AI system; risk classification (UNACCEPTABLE / HIGH / LIMITED / MINIMAL); automatic seed of applicable obligations |
| Obligation | Deadline | Trigger |
|---|---|---|
| CNCS notification (NIS2) | 24 hours | Incident with significant impact |
| DPA notification (GDPR) | 72 hours | Personal data breach |
| BdP/ANACOM notification (DORA) | 4 hours | Major ICT incident |
ANACOM routing automatically identifies the competent authority based on the sector and Decree-Law 125/2025 — eliminating manual research during a crisis.
Formal internal audit planning with audit team, agenda, findings, and non-conformance classification (Major / Minor / Observation). CAPAs with structured root cause, owner, deadline, status, and effectiveness verification. Evidence with automatic OCR — text extracted from any PDF or image, searchable and linked to the control it supports.
Automated evidence (e.g. a connector-collected screenshot or an OCR-extracted document) carries a freshness / TTL flag: once validity expires, the evidence is marked stale and the control it supports drops out of the "fresh" bucket until re-collected. A continuous coverage view shows, per framework, the split between fresh, stale, and manual evidence — giving the CISO a single screen to answer "what still needs a human this week." Google Drive Livesync links a Drive folder directly to a control: files added to that folder are picked up automatically and attached as evidence, with no manual upload step.
Dedicated portal for external auditors with controlled access to assessments, evidence, and reports — without access to platform configuration or data from other modules. Revocable access, with all queries recorded in the audit trail.
The TIA module addresses the GDPR obligation to assess the impact of international personal-data transfers, as established in GDPR Art. 44–49, grounded in the Schrems II judgment (CJEU C-311/18) and EDPB Recommendations 01/2020 on supplementary measures.
Regulatory trigger: Following the collapse of the EU–US Data Privacy Framework (DPF) on 29 June 2026 (Trump v. Slaughter), transfers based on that adequacy decision lost their legal basis. Organisations relying on the DPF must now use an alternative mechanism — Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or Art. 49 derogations — and, in any case, conduct a formal Transfer Impact Assessment whenever there is a risk of access by authorities in third countries.
| Field / Feature | Detail |
|---|---|
| Transfer mechanism | Adequacy Decision | SCCs | BCRs | DPF | Art. 49 Derogations |
| Lifecycle | DRAFT → UNDER_REVIEW → APPROVED / REJECTED / NEEDS_REVISION; mandatory periodic review date |
| Surveillance risk | Assessment of the legal and surveillance environment of the destination country |
| Supplementary measures | Encryption, pseudonymisation, contractual clauses, technical restrictions |
| Residual risk | LOW / MEDIUM / HIGH / CRITICAL with decision and rationale |
| Optional links | Data Flow, RoPA entry, Vendor, or DPA — no data duplication |
| Access control | ADMIN / MANAGER / AUDITOR / SUPER_ADMIN; fully multi-tenant |
| Route | /dashboard/transfer-impact-assessments |
DPF Watch is a dashboard card that auto-derives — with no manual data entry — all Data Flows and DPAs in the tenant that involve a DPF-based or adequacy-based transfer to the US and have no associated approved TIA. When uncovered flows exist, the card displays a red alert listing the affected transfers, ensuring that no high-risk transfer goes undetected after a legal-framework change such as the collapse of the DPF in June 2026.
A weekly job polls RSS feeds from EU regulatory sources — the European Data Protection Board (EDPB) and the European Commission's Digital Strategy publications — and runs each new item through AI classification: which framework it affects, likely impact, and any inferable compliance deadline. Classified items land in a human review queue, where a CISO or compliance officer publishes or rejects each one before it reaches end users. Published items are pushed straight into the tenant's regulatory calendar, alongside internal read-time deadlines, so a new EDPB guideline or Commission proposal shows up next to the organisation's own compliance milestones — no manual trawling of regulatory websites.
| Criterion | Eramba | EterShield |
|---|---|---|
| Model | Self-hosted (free) or SaaS (€800+/month) | Managed SaaS — immediate access |
| Installation | 4–8 hours for self-hosted | Zero — trial in 5 minutes |
| Native AI | None | Contextual AI with RAG per entity |
| NIS2 / DORA | Manual (customisation) | Native PT-PT frameworks |
| TPRM | Basic module | Adaptive questionnaire + AI + public portal |
| HR Security | None | JML, Access Reviews, Disciplinary (AES-256) |
| ISO 9001 / ISO 45001 | None | Complete modules |
| ESG / CSRD | None | Native ESRS E1/S1/G1 |
| Monte Carlo / FAIR | None | 10,000 simulations, ALE in euros |
| Language | English | Native PT-PT + EN |
| Data | Depends on client's deployment | EU always |
| Criterion | OneTrust | EterShield |
|---|---|---|
| Target audience | Large companies (500+ employees) with a dedicated DPO | SMEs and mid-sized companies (10–500 employees) |
| Price | €50,000 – €200,000+/year | From €209/month (PT) |
| Implementation | 3–6 months with consultants | Days (trial → production) |
| GDPR / RoPA | Market reference | Complete module |
| NIS2 / DORA | Configurable with effort | Native, PT-PT |
| Generative AI | Limited to some modules | Integrated across the whole platform |
| Data in the EU | Configurable | Always |
| ISO 9001 / OH&S | None | Native modules |
| ESG / CSRD | Enterprise only | Included in Starter |
OneTrust is irreplaceable for multinationals operating across multiple jurisdictions. For the Portuguese SME market, the cost is prohibitive and the complexity excessive.
| Criterion | Drata / Vanta | EterShield |
|---|---|---|
| Target market | USA / UK, SaaS startups | Europe (PT, ES, EU), traditional SMEs |
| Frameworks | SOC 2, ISO 27001, HIPAA, PCI DSS | 29 frameworks incl. NIS2, DORA, GDPR, ISO 9001, ISO 45001, CSRD, NIST CSF 2.0, CIS Controls v8, HIPAA Security Rule, Cyber Resilience Act, IFS Food v8, FEDIAF, FSSC 22000 v7, ISO 26000:2010, IT Service Management — modern ITSM practices, TISAX® (VDA ISA 6.0) (ISO 55001 and ISO 56001 code-ready, not yet activated in production) |
| GDPR / NIS2 / DORA | No real support | Native |
| NIDS / Network Alerts | None | Proprietary network NIDS; CRITICAL → automatic Incident |
| Integrations | 100+ (GitHub, AWS, GCP, Slack) | Internal SIEM, GLPI, EterScan, Gophish, webhooks |
| AI | Basic automation | Contextual AI with RAG per entity |
| Price | $1,000 – $5,000+/month | From €209/month (PT) |
| Data | USA | EU |
| Language | English | PT-PT + EN |
Drata/Vanta are excellent for English-speaking startups focused on SOC 2. For a European SME that needs NIS2, DORA, ISO 27001, and ISO 9001 in Portuguese with data in the EU — EterShield is the natural choice.
| Criterion | Cynomi | EterShield |
|---|---|---|
| Sales model | Exclusively MSPs (B2B2B) | Direct to SME + MSP/vCISO channel |
| Price | Custom, ~$500–$2,000+/month | From €209/month (PT) |
| AI | AI CISO (automatic reports) | Generative AI + RAG per entity |
| Frameworks | ~8 (ISO 27001, SOC 2, NIS2, HIPAA) | 23 frameworks |
| OH&S / Fleet / Facilities | None | Integrated modules |
| NIDS / Network Alerts | None | Proprietary network NIDS; CRITICAL → automatic Incident |
| HR Security | None | JML, disciplinary, Access Reviews, DSR |
| Audit Trail → SIEM | None | Automatic forward to internal SIEM |
| Whistleblower | None | Native (AES-256-GCM) |
| Knowledge Base / FTS | None | Complete system per entity |
| PT market | None | Native PT-PT + CNCS + ANACOM routing |
| Eramba SaaS | OneTrust | Drata/Vanta | Cynomi | EterShield | |
|---|---|---|---|---|---|
| Annual SME cost | €9,600+ | €50,000+ | €12,000–60,000 | €6,000–24,000 | €2,508–8,388 ¹ |
| Integrated IMS | ✗ | ✗ | ✗ | ✗ | ✓ |
| Native NIS2/DORA PT | ✗ | ✗ | ✗ | Partial | ✓ |
| Contextual AI (RAG) | ✗ | Partial | Partial | Partial | ✓ |
| HR Security | ✗ | Partial | ✗ | ✗ | ✓ ² |
| ISO 9001 / Quality | ✗ | ✗ | ✗ | ✗ | ✓ ² |
| ESG / CSRD | ✗ | Enterprise | ✗ | ✗ | ✓ ² |
| NetworkAlerts (NIDS) | ✗ | ✗ | ✗ | ✗ | ✓ ² |
| Monte Carlo / FAIR | ✗ | ✗ | ✗ | ✗ | ✓ |
| Whistleblower | ✗ | Enterprise | ✗ | ✗ | ✓ |
| Portuguese language | ✗ | ✗ | ✗ | ✗ | ✓ |
| Guaranteed EU data | Depends | Configurable | ✗ | Partial | ✓ |
| Solution | Year 1 | Years 2–5 (average) | 5-year Total |
|---|---|---|---|
| OneTrust | €60,000 | €55,000/year | €280,000+ |
| Drata (Professional) | €20,000 | €18,000/year | €92,000 |
| Cynomi (MSP) | €15,000 | €12,000/year | €63,000 |
| Eramba SaaS | €10,000 | €9,600/year | €48,400 |
| EterShield (Starter + Operations Pack) | €7,400 | €6,800/year | €34,600 |
| EterShield (Starter, GRC core) | €5,500 | €5,000/year | €25,500 |
Starter + Operations Pack = €419 + €149/month PT — all operational modules without upgrading to Professional.
EterShield is SaaS — no software installation, no servers to configure. A modern browser (Chrome 120+, Firefox 120+, Safari 17+), an internet connection, and an email address.
| Feature | Prerequisite |
|---|---|
| SSO SAML 2.0 | Configuration on the IdP (Okta, Entra ID, Google Workspace) |
| SIEM Integration | Network connectivity between the SIEM and EterShield infrastructure |
| GLPI Integration | GLPI API active with access token |
| API EtherFlow | API key generated on the platform; accessible endpoint |
| Plan | PT Price | Users | Entities | AI / month |
|---|---|---|---|---|
| Trial | Free (14 days) | 5 | 1 | 20 |
| Lite | €209/month · €2,090/year | 3 | 1 | — |
| Starter | €419/month · €4,190/year | 20 | 1 | 200 |
| Professional | €699/month · €6,990/year | 50 | 3 | 500 |
| Enterprise | Negotiated | Unlimited | Unlimited | Unlimited |
PT prices with a 30% discount for organisations headquartered in Portugal (valid NIF).
| Priority | Feature | Impact |
|---|---|---|
| High | Maturity Benchmarks by sector | Anonymous comparison with organisations in the same sector |
| High | DORA RTS for financial entities | DORA report templates for BdP |
| Medium | OpenCTI Integration | Sector-contextualised threat intelligence |
| Medium | Multi-language (ES, FR) | Expansion to Iberian and Francophone markets |
| Future | Native Mobile App (iOS / Android) | Push notifications, full mobile access |
| Future | Autonomous AI Agent | Agent that proposes and executes remediations with human approval |
Situation: a logistics company with 120 employees needs ISO 27001 certification as a requirement from a customer in the automotive sector. No CISO. The IT Manager has other responsibilities.
Situation: a health clinic (NIS2 PT) detects ransomware on 3 servers. It is 14:30 on a Friday.
Situation: a cybersecurity consultancy manages 8 SME clients with different maturity levels and frameworks.
Situation: an asset management company with 200 employees, subject to DORA, in a remediation process.
Security compliance has moved from a peripheral concern to a strategic factor in competitiveness. Organisations that build real security management capability — not just pass audits — gain access to larger clients, public contracts, cyber insurance with lower premiums, and partnerships that require certifications.
EterShield was built for a specific reality: the European SME facing growing regulation without resources for an internal CISO, without budget for enterprise platforms, and without patience for tools that don't speak their language.
| Term | Definition |
|---|---|
| vCISO | Virtual Chief Information Security Officer — the CISO function outsourced to a partner or platform |
| GRC | Governance, Risk and Compliance — set of processes for managing governance, risk, and compliance |
| IMS | Integrated Management System — a management system that combines multiple standards (ISO 27001, ISO 9001, ISO 45001…) |
| RAG | Retrieval-Augmented Generation — AI technique that injects relevant context into prompts for precise and contextualised responses |
| FAIR | Factor Analysis of Information Risk — financial quantification methodology for cyber risk |
| ALE | Annualised Loss Expectancy — expected annual financial loss, the output of the FAIR/Monte Carlo model |
| TPRM | Third-Party Risk Management — management of risks associated with vendors and third parties |
| JML | Joiners, Movers, Leavers — the access lifecycle of employees |
| DSR | Data Subject Request — a request by a data subject under GDPR (access, rectification, erasure…) |
| CAPA | Corrective and Preventive Action — plan of corrective and preventive actions for non-conformances |
| NIS2 | Network and Information Security Directive 2 — European cybersecurity directive (2022/2555) |
| DORA | Digital Operational Resilience Act — European digital resilience regulation for the financial sector (2022/2554) |
| CSRD | Corporate Sustainability Reporting Directive — European sustainability reporting directive (2022/2464) |
| ESRS | European Sustainability Reporting Standards — CSRD sustainability reporting standards |
| CNCS | Centro Nacional de Cibersegurança (Portuguese National Cybersecurity Centre) — national cybersecurity authority in Portugal |
| CNPD | Comissão Nacional de Protecção de Dados (Portuguese Data Protection Authority, DPA) — data protection authority in Portugal |
| ANACOM | Autoridade Nacional de Comunicações (Portuguese National Communications Authority) — NIS2 competent authority for specific sectors in Portugal |
| MONARC | Method for an Optimised aNAlysis of Risks — ISO 27005 threat catalogue under CC0 licence |
| AI Sparks | Intelligent form prefill — automatic AI content suggestion based on gap or entity context |
| SPC | Statistical Process Control — statistical process control (ISO 9001) |
| RBAC | Role-Based Access Control — access control by user role |
| RoPA | Record of Processing Activities — Register of Processing Activities (GDPR Article 30) |
| BIA | Business Impact Analysis — business impact analysis (ISO 22301) |
| ARIA | Agentic Risk Intelligence Assessment — proprietary agentic AI risk assessment methodology in 7 phases |
| AIVSS | AI Vulnerability Scoring System — vulnerability scoring system for AI systems, analogous to CVSS |
| TIA | Transfer Impact Assessment — formal assessment of the impact of international personal-data transfers required by GDPR Art. 44–49 and Schrems II |
| DPF | Data Privacy Framework — EU–US adequacy decision (invalidated 29 June 2026, Trump v. Slaughter); replaced by SCCs, BCRs, or Art. 49 derogations |
| DPA | Data Processing Agreement — contract required under GDPR for sub-processors handling personal data on behalf of a controller |
| SCCs | Standard Contractual Clauses — pre-approved GDPR transfer mechanism for transfers to countries without an adequacy decision |