ETERSHIELD | THE COMPLETE GUIDE | ETER GROWTH
v1.6 · 2026-07-22 | PUBLIC
Eter Growth — Product Document

EterShield — The Complete Guide

Organisational Security Knowledge Platform for European Businesses
Version
1.6 — July 22, 2026
Author
Eter Growth
Target Audience
European SMEs
Platform
v2.2
"Compliance is not a destination. It is the by-product of an organisation that knows exactly what it has, what is at risk, and what it has decided to do." — Eter Growth
Table of Contents
PART I Context and Vision
01 The Regulatory Landscape in 2026
The Regulatory Storm That Reached SMEs

For years, cybersecurity and privacy regulation was seen as a problem for large organisations. GDPR, in 2018, was the first sign that this was changing: all organisations that process personal data of European citizens were covered, regardless of size. But it was between 2022 and 2025 that regulatory pressure became truly democratised.

NIS2 extended cybersecurity obligations to many more sectors. DORA imposed stringent requirements on the financial sector, including IT suppliers. The EU AI Act introduced obligations for organisations using high-risk AI systems. CSRD made sustainability reporting mandatory for a growing number of companies. In Portugal, Decree-Law 125/2025 transposed NIS2 with ANACOM as the competent authority.

The Cost of Non-Compliance
RegulationMaximum FineApplication Condition
GDPR€20M or 4% global turnoverPersonal data breach, lack of legal basis
NIS2€10M or 2% global turnoverInadequate measures, notification failure
DORAPer national authorityInsufficient operational resilience
EU AI Act€35M or 7% global turnoverHigh-risk AI systems without compliance
The Problem of Institutional Memory

Many organisations respond to regulatory pressure in the most obvious way: they hire a consultant, conduct an assessment, produce documentation, and pass an audit. A year later, the consultant is gone, the person who coordinated the process has moved to another company, and the organisation starts from scratch.

This is the problem EterShield was designed to solve. It is not a problem of lacking tools — it is a problem of knowledge that disappears. Every decision taken, every risk assessed, every policy approved should be a growing asset of the organisation.

The Market Gap

The market has responded with solutions at the extremes: Enterprise GRC (OneTrust, IBM OpenPages) with prices of €50,000–€500,000 annually and implementations taking months; or isolated tools (Eramba, spreadsheets) with no integration or AI. The gap is clear: no affordable solution preserves organisational knowledge, integrates multiple European frameworks in Portuguese, and uses contextual AI — all in a single product for SMEs.

02 What Is a vCISO Platform and Why It Matters
Definition

A vCISO (Virtual Chief Information Security Officer) externalises the function of strategic security leadership. A vCISO platform is the technological evolution: software that structures, automates, and systematises the functions of a CISO in an interface that any IT or compliance manager can operate — without being a security specialist.

EterShield is a vCISO platform, but goes further: it is an organisational security knowledge management system that collects and structures everything the organisation knows about its own security, uses AI to transform that knowledge into actionable assessments and policies, and accumulates value over time.

Core Functions
KNOWLEDGE COMPLIANCE RISK OPERATIONS ─────────── ──────────── ───── ────────── Entity profile Assessments Risk register Incidents Knowledge Base Gap analysis Monte Carlo/FAIR Audits AI Policies Evidences Treatment CAPA History Cross-framework Vendors Calendar
Implementation Models
ModelDescriptionSuitable for
Self-managedOrganisation uses the platform directlySME with a dedicated IT manager
AssistedEter Growth operates the platform with the organisationSME without internal technical capacity
Full vCISOEter Growth assumes the vCISO roleOrganisations with no security resources whatsoever
MSP / partnerConsultancy uses EterShield for multiple clientsMSSPs, compliance consultancies
03 EterShield — Vision, Mission and Value Proposition
Value Proposition
For the CEO / Board
NIS2, GDPR, and ISO 27001 compliance documented and demonstrable, without hiring a CISO. Always know what is at risk and how much it costs in euros.
For the IT / Compliance Manager
Replaces spreadsheets and emails to consultants. AI generates assessments, analyses vendors, and quantifies risks — in minutes, not weeks.
For the External Auditor
Documented, traceable, and exportable evidence. Immutable Audit Trail. Cross-framework mapping an ISO 27001 control to the corresponding NIS2 requirement.
For the vCISO Consultancy
Multi-client dashboard to manage 10 organisations with the effort of one — automatic PDF reports, per-client audit portals, AI that accelerates analysis.
Five Design Principles
  • Knowledge that stays — unlike an external consultant, when the person who led the certification leaves the company, the knowledge remains in the platform with all its justification.
  • AI that reads the real context — before suggesting a policy or analysing a gap, the AI reads the organisation's Knowledge Base. A logistics company receives different suggestions from a health clinic.
  • European regulatory by design — NIS2, DORA, GDPR, EU AI Act were designed for the European context. EterShield was built from the start in Portuguese, with data in the EU, with ANACOM and CNCS as references.
  • Single scope for a complete IMS — ISO 27001, ISO 9001, ISO 45001, GDPR, CSRD integrated in a single platform, eliminating silos and data duplication.
  • Progressive modularity — pay for what you use — not every organisation needs everything at once. The base plan includes the GRC core (compliance frameworks, risk, TPRM, audits); the operational modules (ISO 9001, OH&S, HR Security, ESG/CSRD, BCM, Fleet, Facilities, NetworkAlerts) and additional frameworks are activated individually, as the organisation grows or when a specific regulatory requirement arises. There is no need to upgrade the plan to access a single additional module.
PART II Features
04 GRC and Compliance — The Platform Core
Chapters 4 to 10 describe all features available on the platform. Access depends on the plan and add-on configuration. Professional and Enterprise plans include all operational modules. Lite and Starter plans include the GRC core; operational modules are available as individual add-ons or in a bundle (Operations Pack).
Supported Frameworks 994 Controls
FrameworkScopeControls
ISO 27001:2022Information Security93 (complete Annex A)
NIST CSF 2.0Cybersecurity Framework106 subcategories
GDPR (2016/679)Data Protection57
ISO 42001:2023AI Management57
EU AI Act (2024/1689)High-Risk AI Systems54
ISO 9001:2015Quality52
ISO 31000:2018Risk Management47
ISO 22301Business Continuity43
NIS2 (2022/2555)Cybersecurity41
DORA (2022/2554)Digital Resilience40
MITRE ATT&CKThreat Modelling38
SOC 2Security and Availability38
ISO 20000-1IT Service Management37
CIS Controls v8Security Baseline (IG1)72 safeguards
HIPAA Security RuleHealthcare Data Security65 safeguards
PCI DSS v4.0Payments29
Cyber Resilience Act (2024/2847)Products with Digital Elements29
AMLD6 (2018/1673)Anti-Money Laundering23
ISO 23894AI Risk Management22
MITRE CTID FraudFraud and Abuse16
ISO 45001:2018Health and Safety13
ISO 14001:2015Environmental Management12
OWASP Top 10Application Security10
23 frameworks active in the catalogue, 994 controls in total. Framework activation per entity managed by the super-admin. Starter and higher plans include all GRC frameworks; Lite includes 1 base framework. Additional frameworks available as add-ons. NIST CSF 2.0, CIS Controls v8, and HIPAA Security Rule are add-on frameworks with 89 crosswalks to ISO 27001, letting an organisation already working ISO 27001 answer most of the equivalent US-market or sector requirement without duplicate effort. New framework 2026-07: Cyber Resilience Act (Regulation (EU) 2024/2847), 29 controls, with 18 crosswalks to ISO 27001 and 22 to NIS2.
AI Gap Analysis and Automatic Score

Instead of going through 93 ISO 27001 controls manually, the user activates the AI Gap Analysis. Based on the organisation's profile and accumulated Knowledge Base, the AI automatically identifies the most likely gaps, suggests remediation priority, and proposes response texts for each control. The compliance score (0–100%) updates in real time by category and by framework.

Cross-Framework — Work Without Duplication

An ISO 27001 control can simultaneously satisfy NIS2 and DORA requirements. An organisation working ISO 27001 in parallel with NIS2 and DORA can have 60–70% of DORA controls already answered by the work done on ISO 27001. No duplicate questions, no redundant effort.

AI-Generated Policies

The policy repository generates contextualised drafts — not generic templates. Based on the organisation's profile, sector of activity, and active frameworks, the AI creates a policy that references the specific reality of the company. Full versioning with revision history, approvals, and next scheduled review.

05 Risk Management with Financial Quantification
Monte Carlo / FAIR — Risk in Euros

Most risk tools stop at coloured matrices. EterShield quantifies risks financially using the FAIR model (Factor Analysis of Information Risk) with Monte Carlo simulation: 10,000 simulations produce an annual expected loss (ALE) distribution with P10, P50, and P90 percentiles in euros.

Risk (example)Median ALE (P50)ALE P90
Ransomware on a Windows endpoint€78,000€310,000
Unauthorised access to customer database€45,000€180,000
Critical cloud vendor failure€25,000€95,000
AI Parameter Estimation

FAIR quantification requires parameters that few IT managers know how to estimate. The AI proposes frequency and magnitude parameters with justification based on benchmarks from DBIR (Verizon), ENISA, and CNCS, presenting a TransparencyBadge with the complete reasoning and sources used.

Control ROI

For each implemented security control, EterShield automatically calculates the risk reduction in euros — allowing investments to be prioritised by financial return, not intuition. Each risk enters a formal treatment plan with milestones, owners, approval, and linkage to the compliance calendar.

Complete Risk Chain
Asset → Threat (MONARC/ISO 27005 catalogue) → Vulnerability → Risk → Treatment → Plan Integrated MONARC catalogue: ├── 50 threats in 9 categories (physical, technical, social engineering, malware…) └── 41 vulnerabilities in 6 categories (hardware, software, network, human…)
06 Third-Party Management (TPRM)
Adaptive Questionnaire

EterShield uses an adaptive TPRM questionnaire with 33 questions distributed across 5 modules, activated automatically based on the vendor's profile. An office supplies vendor answers 8 questions. A personal data processor with direct CRM access answers all 33.

ModuleActivated whenQuestions
Information SecurityAlways8
Data ProtectionVendor processes personal data7
Business ContinuityVendor critical to operations6
Technical SecurityVendor with access to systems7
ComplianceVendor in a regulated sector5
Public Portal with Unique Token

The vendor does not need to create an account. They receive an email with a unique token link, access a secure public page, respond, and submit. The token expires after submission or deadline. All interaction is tracked and audited.

AI Analysis and Decision Workflow

After submission, the AI analyses each response: score 0–100, red flags identified with reasoning, and overall recommendation (Approve / Conditional / Reject / Defer). The responsible party records the formal decision with a justification note — direct evidence for ISO 27001 and NIS2 auditors.

07 Personnel Security (HR Security)
JML Lifecycle — Joiners, Movers, Leavers

The access lifecycle tracks Joiners (new employees with a provisioning checklist), Movers (role changes with access review), and Leavers (departures with a revocation checklist). Each event generates an assigned task with a deadline and completion confirmation.

Access Reviews, Background Checks and Disciplinary

Automated periodic access reviews: a cron job schedules the review, the responsible party receives the access list, approves or revokes each entry, all recorded with a timestamp. Background checks with status and validity. Disciplinary process with PII fields encrypted in AES-256-GCM (GDPR Art. 9).

Data Subject Requests (DSR)

GDPR Art. 15–20 requests with entry date registration, 30-day legal countdown, status tracking (Received → Under review → Responded), and complete history for compliance demonstration.

08 Quality (ISO 9001)
Six ISO 9001 Modules
ModuleDescription
Document ControlQMS with version, revision date, approval owner, and automatic alert
Customer ComplaintsFull cycle: reception, root cause analysis, action plan, effectiveness verification
Equipment CalibrationRecords with calibration dates and automatic alert before recalibration deadline
Supplier AuditsISO 9001 checklists by category, non-conformance records
SPC Control ChartsX-bar, R and p charts for statistical process monitoring
CAPA 8DStructured resolution following 8 Disciplines (D1–D8) with evidence chain
ISO 9001 + ISO 27001 integrated: audits, CAPA, evidence, and documentary records share the same infrastructure on the platform — no separate tools, no data duplication.
09 Health, Safety, Fleet and Facilities
OH&S / ISO 45001

Accident records with root cause analysis and automatic ACT report; hazard register with risk assessment and controls; PPE management per employee; documented worker consultation (clause 5.4 ISO 45001 requirement).

Facilities Management

Critical physical systems (HVAC, CCTV, alarms, sprinklers, UPS) registered as assets with preventive maintenance plans, inspection history, and imminent maintenance alerts. Direct linkage to ISO 27001 physical and environmental security controls.

Fleet Management

Vehicle and driver records, fuel tracking, maintenance history, and document expiry calendar (inspection, insurance, service). Fuel data feeds directly into the GHG Scope 1 emissions module.

10 Sustainability and ESG (CSRD)
Three ESRS Pillars
PillarStandardContent
GHG EmissionsESRS E1Scope 1/2/3 with IPCC factors; sync from fleet records; tCO₂e dashboard
Social IndicatorsESRS S1Workforce, gender, accidents, training, absenteeism, pay gap
GovernanceESRS G1Anti-corruption policy, whistleblower (AES-256), vendor assessment, fines

The CSRD report editorial cycle follows a Draft → Under Review → Approved → Published flow. The report is generated from records already existing on the platform — no manual re-entry of data.

11 Artificial Intelligence — Transparent Trust and AI Security
The Transparency Package

All AI in EterShield is auditable. Every generated result includes a TransparencyBadge visible to the user — relevant for organisations subject to the EU AI Act.

FieldContent
ModelLanguage model (version and provider identified)
Tokens consumedInput + Output
Estimated costIn euros (cost control)
LatencyResponse time in ms
OperationE.g.: "Gap Analysis ISO 27001 Annex A.8"
ReasoningExposed model reasoning
SourcesBenchmarks or frameworks referenced
AI Components
ComponentUsage
Internal AI GatewayInternal proxy that intermediates all requests to the AI model — ensures isolation, auditability, and cost control
Claude (Anthropic)Single production LLM backend — Gap Analysis, TPRM, Monte Carlo, EtherFlow, Cook/Sparks, response suggestions, profile prefill
Semantic searchKnowledge Base — context retrieval by entity, optimised for European Portuguese
GRC knowledge graphVera's structured context injected into prompts — at no additional cost per call
Knowledge Base — The AI That Knows the Organisation

EterShield's deepest differentiator: a per-entity Knowledge Base system with contextual semantic search in four phases.

Phase A
Entity Profile

6-step wizard (identification, business, systems, regulation, team, maturity). Completeness score 0–100%. AI suggests frameworks and identifies the competent NIS2 authority (ANACOM, BdP, CNCS) based on the sector.

Phase B
CISO Validation Queue

Any free text (meeting minutes, email, report) is processed by the AI, which extracts structured knowledge in 7 categories. The CISO approves, edits, or rejects each item before it enters the database.

Phase C
Active Semantic Search

Approved items are indexed and made available for semantic search optimised for European Portuguese. At each AI call, the most relevant Knowledge Base items are retrieved and injected into the prompt. The AI responds with the organisation's real context.

Phase D
Document Upload

PDFs, DOCX, and TXT files up to 20MB are processed, fragmented into chunks, and integrated into the Knowledge Base. Existing policies, audit reports, contracts — all enrich the AI context.

EtherFlow — Meetings That Feed the System

The meeting ingestion pipeline: the transcript is sent via API or uploaded manually; the AI extracts risks, gaps, tasks, and decisions; items appear in an approval inbox; approved items go directly into the corresponding modules and the Knowledge Base. A 2-hour meeting produces 15 structured entries in 10 minutes.

AI Security — Agentic Risk Assessment ARIA

With the proliferation of AI systems in business processes, AI risk management has become a formal requirement (EU AI Act, ISO 42001). EterShield includes a set of specialised modules for organisations that develop or use AI systems.

The ARIA Framework (Agentic Risk Intelligence Assessment) is a proprietary agentic AI risk assessment methodology structured in 7 phases, aligned with NIST AI RMF, MITRE ATLAS, MAESTRO, OWASP AIUC-1, and AIVSS. It covers 15 risk vectors: A1–A8 (agentic system risks: objective manipulation, planning hallucination, privilege escalation, context exfiltration, reasoning loop, tool abuse, irreversible impact, malicious coordination) and D Series D1–D7 (development phase threats, OWASP AI Exchange: data poisoning, backdoors, model attacks, inversion, extraction, adversarial evasion, dependency injection).

ModuleDescription
ARIA AssessmentComplete 7-phase assessment — score per phase, A1–A8 risks + D Series, assessment history, and mitigation plan
AI IncidentsAI behavioural incidents — 7 types (hallucination, bias, prompt injection, data leak, jailbreak, misuse, unexpected behaviour); EU AI Act Art. 72 flag
Model CardsEU AI Act Art. 13 technical fact sheet — intended use, training data, limitations, bias, ethics, human oversight; formal approval with record
Red Team SchedulerRed teaming campaigns on AI systems — pre-defined OWASP AIUC-1 tests by category (prompt injection, jailbreak, data exfiltration)
EU AI Act AssessmentCompliance assessment with 33 EU AI Act obligations per AI system; risk classification (UNACCEPTABLE / HIGH / LIMITED / MINIMAL); automatic seed of applicable obligations
12 Governance, Audits and Operations
Incident Management with NIS2/GDPR Countdowns
ObligationDeadlineTrigger
CNCS notification (NIS2)24 hoursIncident with significant impact
DPA notification (GDPR)72 hoursPersonal data breach
BdP/ANACOM notification (DORA)4 hoursMajor ICT incident

ANACOM routing automatically identifies the competent authority based on the sector and Decree-Law 125/2025 — eliminating manual research during a crisis.

Internal Audits, CAPA, and Evidence Management

Formal internal audit planning with audit team, agenda, findings, and non-conformance classification (Major / Minor / Observation). CAPAs with structured root cause, owner, deadline, status, and effectiveness verification. Evidence with automatic OCR — text extracted from any PDF or image, searchable and linked to the control it supports.

Evidence Automation — Freshness, Coverage and Google Drive Livesync

Automated evidence (e.g. a connector-collected screenshot or an OCR-extracted document) carries a freshness / TTL flag: once validity expires, the evidence is marked stale and the control it supports drops out of the "fresh" bucket until re-collected. A continuous coverage view shows, per framework, the split between fresh, stale, and manual evidence — giving the CISO a single screen to answer "what still needs a human this week." Google Drive Livesync links a Drive folder directly to a control: files added to that folder are picked up automatically and attached as evidence, with no manual upload step.

Auditor Portal

Dedicated portal for external auditors with controlled access to assessments, evidence, and reports — without access to platform configuration or data from other modules. Revocable access, with all queries recorded in the audit trail.

Transfer Impact Assessment (TIA) & DPF Watch

The TIA module addresses the GDPR obligation to assess the impact of international personal-data transfers, as established in GDPR Art. 44–49, grounded in the Schrems II judgment (CJEU C-311/18) and EDPB Recommendations 01/2020 on supplementary measures.

Regulatory trigger: Following the collapse of the EU–US Data Privacy Framework (DPF) on 29 June 2026 (Trump v. Slaughter), transfers based on that adequacy decision lost their legal basis. Organisations relying on the DPF must now use an alternative mechanism — Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or Art. 49 derogations — and, in any case, conduct a formal Transfer Impact Assessment whenever there is a risk of access by authorities in third countries.

Field / FeatureDetail
Transfer mechanismAdequacy Decision | SCCs | BCRs | DPF | Art. 49 Derogations
LifecycleDRAFT → UNDER_REVIEW → APPROVED / REJECTED / NEEDS_REVISION; mandatory periodic review date
Surveillance riskAssessment of the legal and surveillance environment of the destination country
Supplementary measuresEncryption, pseudonymisation, contractual clauses, technical restrictions
Residual riskLOW / MEDIUM / HIGH / CRITICAL with decision and rationale
Optional linksData Flow, RoPA entry, Vendor, or DPA — no data duplication
Access controlADMIN / MANAGER / AUDITOR / SUPER_ADMIN; fully multi-tenant
Route/dashboard/transfer-impact-assessments

DPF Watch is a dashboard card that auto-derives — with no manual data entry — all Data Flows and DPAs in the tenant that involve a DPF-based or adequacy-based transfer to the US and have no associated approved TIA. When uncovered flows exist, the card displays a red alert listing the affected transfers, ensuring that no high-risk transfer goes undetected after a legal-framework change such as the collapse of the DPF in June 2026.

Wave 2 roadmap (FUTURE — not yet shipped): AI scoring of transfer risk based on country profile and transfer mechanism; exposure of approved TIAs in the public Trust Center for auditor review.
Automated Regulatory Watch

A weekly job polls RSS feeds from EU regulatory sources — the European Data Protection Board (EDPB) and the European Commission's Digital Strategy publications — and runs each new item through AI classification: which framework it affects, likely impact, and any inferable compliance deadline. Classified items land in a human review queue, where a CISO or compliance officer publishes or rejects each one before it reaches end users. Published items are pushed straight into the tenant's regulatory calendar, alongside internal read-time deadlines, so a new EDPB guideline or Commission proposal shows up next to the organisation's own compliance milestones — no manual trawling of regulatory websites.

PART IV Market Comparison
13 GRC / vCISO Solutions Landscape
GRC/vCISO SOLUTIONS ON THE MARKET ┌──────────────────────────────────────────────────────────────┐ │ ENTERPRISE GRC │ │ OneTrust · IBM OpenPages · ServiceNow GRC · RSA Archer │ ├──────────────────────────────────────────────────────────────┤ │ COMPLIANCE AUTOMATION (SaaS) │ │ Drata · Vanta · Sprinto · Tugboat Logic │ ├──────────────────────────────────────────────────────────────┤ │ vCISO / MSSP PLATFORMS │ │ Cynomi · Defendify · Balbix · Kaseya 365 Security │ ├──────────────────────────────────────────────────────────────┤ │ OPEN SOURCE GRC │ │ Eramba · OpenGRC · Heimdall │ ├──────────────────────────────────────────────────────────────┤ │ ETERSHIELD │ │ European SME · Integrated IMS · Contextual AI · Native PT │ └──────────────────────────────────────────────────────────────┘ COST: ████████████████████████████████░░ LOW OneTrust (€100k+) EterShield (From €209/month (PT) )
14 EterShield vs. Eramba
CriterionErambaEterShield
ModelSelf-hosted (free) or SaaS (€800+/month)Managed SaaS — immediate access
Installation4–8 hours for self-hostedZero — trial in 5 minutes
Native AINoneContextual AI with RAG per entity
NIS2 / DORAManual (customisation)Native PT-PT frameworks
TPRMBasic moduleAdaptive questionnaire + AI + public portal
HR SecurityNoneJML, Access Reviews, Disciplinary (AES-256)
ISO 9001 / ISO 45001NoneComplete modules
ESG / CSRDNoneNative ESRS E1/S1/G1
Monte Carlo / FAIRNone10,000 simulations, ALE in euros
LanguageEnglishNative PT-PT + EN
DataDepends on client's deploymentEU always
When to choose Eramba: senior GRC technical team that wants full infrastructure control, zero budget, no need for AI or modules beyond the GRC core. When to choose EterShield: SME without an internal CISO, NIS2/DORA is a requirement, wants value within days, needs an integrated IMS.
15 EterShield vs. OneTrust
CriterionOneTrustEterShield
Target audienceLarge companies (500+ employees) with a dedicated DPOSMEs and mid-sized companies (10–500 employees)
Price€50,000 – €200,000+/yearFrom €209/month (PT)
Implementation3–6 months with consultantsDays (trial → production)
GDPR / RoPAMarket referenceComplete module
NIS2 / DORAConfigurable with effortNative, PT-PT
Generative AILimited to some modulesIntegrated across the whole platform
Data in the EUConfigurableAlways
ISO 9001 / OH&SNoneNative modules
ESG / CSRDEnterprise onlyIncluded in Starter

OneTrust is irreplaceable for multinationals operating across multiple jurisdictions. For the Portuguese SME market, the cost is prohibitive and the complexity excessive.

16 EterShield vs. Drata / Vanta
CriterionDrata / VantaEterShield
Target marketUSA / UK, SaaS startupsEurope (PT, ES, EU), traditional SMEs
FrameworksSOC 2, ISO 27001, HIPAA, PCI DSS29 frameworks incl. NIS2, DORA, GDPR, ISO 9001, ISO 45001, CSRD, NIST CSF 2.0, CIS Controls v8, HIPAA Security Rule, Cyber Resilience Act, IFS Food v8, FEDIAF, FSSC 22000 v7, ISO 26000:2010, IT Service Management — modern ITSM practices, TISAX® (VDA ISA 6.0) (ISO 55001 and ISO 56001 code-ready, not yet activated in production)
GDPR / NIS2 / DORANo real supportNative
NIDS / Network AlertsNoneProprietary network NIDS; CRITICAL → automatic Incident
Integrations100+ (GitHub, AWS, GCP, Slack)Internal SIEM, GLPI, EterScan, Gophish, webhooks
AIBasic automationContextual AI with RAG per entity
Price$1,000 – $5,000+/monthFrom €209/month (PT)
DataUSAEU
LanguageEnglishPT-PT + EN

Drata/Vanta are excellent for English-speaking startups focused on SOC 2. For a European SME that needs NIS2, DORA, ISO 27001, and ISO 9001 in Portuguese with data in the EU — EterShield is the natural choice.

17 EterShield vs. Cynomi
CriterionCynomiEterShield
Sales modelExclusively MSPs (B2B2B)Direct to SME + MSP/vCISO channel
PriceCustom, ~$500–$2,000+/monthFrom €209/month (PT)
AIAI CISO (automatic reports)Generative AI + RAG per entity
Frameworks~8 (ISO 27001, SOC 2, NIS2, HIPAA)23 frameworks
OH&S / Fleet / FacilitiesNoneIntegrated modules
NIDS / Network AlertsNoneProprietary network NIDS; CRITICAL → automatic Incident
HR SecurityNoneJML, disciplinary, Access Reviews, DSR
Audit Trail → SIEMNoneAutomatic forward to internal SIEM
WhistleblowerNoneNative (AES-256-GCM)
Knowledge Base / FTSNoneComplete system per entity
PT marketNoneNative PT-PT + CNCS + ANACOM routing
18 Cost-Benefit Analysis
Comparison Table
Eramba SaaSOneTrustDrata/VantaCynomiEterShield
Annual SME cost€9,600+€50,000+€12,000–60,000€6,000–24,000€2,508–8,388 ¹
Integrated IMS
Native NIS2/DORA PTPartial
Contextual AI (RAG)PartialPartialPartial
HR SecurityPartial✓ ²
ISO 9001 / Quality✓ ²
ESG / CSRDEnterprise✓ ²
NetworkAlerts (NIDS)✓ ²
Monte Carlo / FAIR
WhistleblowerEnterprise
Portuguese language
Guaranteed EU dataDependsConfigurablePartial
¹ Lite €209 – Professional €699/month PT (base plan). Operational modules and additional frameworks available as add-ons — see pricing.  ² Included in Professional/Enterprise. Available as add-on for Lite/Starter (individually or in Operations Pack).
Total Cost of Ownership (5 years, 50-employee SME)
SolutionYear 1Years 2–5 (average)5-year Total
OneTrust€60,000€55,000/year€280,000+
Drata (Professional)€20,000€18,000/year€92,000
Cynomi (MSP)€15,000€12,000/year€63,000
Eramba SaaS€10,000€9,600/year€48,400
EterShield (Starter + Operations Pack)€7,400€6,800/year€34,600
EterShield (Starter, GRC core)€5,500€5,000/year€25,500

Starter + Operations Pack = €419 + €149/month PT — all operational modules without upgrading to Professional.

ROI — Three Scenarios
  • NIS2 Compliance: typical SME fine for non-compliance: €100,000. EterShield provides technical and documentary evidence of compliance. Positive ROI from the first avoided compliance event.
  • ISO 27001 Certification: external consultants cost €15,000–50,000 and take 6–18 months. With EterShield, the process is accelerated by AI and already-structured evidence. Consultancy cost reduction: €10,000–30,000 per cycle.
  • Knowledge that stays: an SME that depends on an external consultant pays €2,000–5,000/month. When the consultant leaves, the knowledge disappears. EterShield preserves that knowledge — the next person in charge starts where the previous one left off.
PART V Implementation
19 Requirements and Prerequisites
Access Requirements

EterShield is SaaS — no software installation, no servers to configure. A modern browser (Chrome 120+, Firefox 120+, Safari 17+), an internet connection, and an email address.

For Advanced Features
FeaturePrerequisite
SSO SAML 2.0Configuration on the IdP (Okta, Entra ID, Google Workspace)
SIEM IntegrationNetwork connectivity between the SIEM and EterShield infrastructure
GLPI IntegrationGLPI API active with access token
API EtherFlowAPI key generated on the platform; accessible endpoint
Subscription Plans (June 2026)
PlanPT PriceUsersEntitiesAI / month
TrialFree (14 days)5120
Lite€209/month · €2,090/year31
Starter€419/month · €4,190/year201200
Professional€699/month · €6,990/year503500
EnterpriseNegotiatedUnlimitedUnlimitedUnlimited

PT prices with a 30% discount for organisations headquartered in Portugal (valid NIF).

20 The Onboarding Model
Phase 1
Activation
Day 1
  • Account created (14-day trial, no card required)
  • Entity profile wizard (6 steps, ~15 min)
  • Active frameworks selected
  • AI suggests NIS2 authority and high-priority gaps
Phase 2
First Assessments
Week 1
  • Start assessment of the main framework
  • Activate AI Gap Analysis
  • Create risk register with the first 10–15 risks
  • Add critical assets to the inventory
Phase 3
Data and Knowledge
Weeks 2–4
  • Upload existing documentation to the Knowledge Base
  • Use EtherFlow in compliance meetings
  • Add first vendors and launch TPRM
  • Configure SIEM integration (if applicable)
Phase 4
Operationalisation
Month 2+
  • Launch first internal audit cycle
  • Activate compliance calendar
  • HR Security module for JML and Access Reviews
  • Prepare evidence for external audit
21 Evolution Roadmap
Current State — July 2026
23
Frameworks and methodologies
994
Controls mapped
~85
Operational modules
2.2
Platform version
Live
www.etershield.com
The platform is live with: GRC core, Risk (Monte Carlo/FAIR), TPRM, HR Security, ISO 9001, OH&S, ESG/CSRD, BCM, Fleet, Facilities, Audits, Evidence (with freshness/TTL, continuous coverage view, and Google Drive Livesync), Network Alerts (EterSOC) — proprietary network NIDS, real-time network alerts, automatic escalation to Incidents — AI Security: ARIA Assessment, AI Incidents, Model Cards/AI Register, Red Team Scheduler, and EU AI Act Assessment — TIA / DPF Watch: Transfer Impact Assessments with DPF Watch auto-detection (triggered by DPF collapse, 29 June 2026) — Automated Regulatory Watch: weekly EDPB/European Commission RSS ingestion, AI classification, human review queue, tenant regulatory calendar — and Remediation Sync: per-integration Jira push (signature-verified webhook), new ServiceNow connector, alongside GLPI. Active add-on model: frameworks and operational modules individually activatable on any base plan; Operations Pack available for Starter.
Planned Developments
PriorityFeatureImpact
HighMaturity Benchmarks by sectorAnonymous comparison with organisations in the same sector
HighDORA RTS for financial entitiesDORA report templates for BdP
MediumOpenCTI IntegrationSector-contextualised threat intelligence
MediumMulti-language (ES, FR)Expansion to Iberian and Francophone markets
FutureNative Mobile App (iOS / Android)Push notifications, full mobile access
FutureAutonomous AI AgentAgent that proposes and executes remediations with human approval
PART VI Use Cases and Playbooks
22 Real-World Compliance Scenarios
SCENARIO 01 Logistics SME Pursuing ISO 27001 Certification

Situation: a logistics company with 120 employees needs ISO 27001 certification as a requirement from a customer in the automotive sector. No CISO. The IT Manager has other responsibilities.

  • Profile wizard automatically identifies 34 high-priority controls for the logistics sector
  • Knowledge Base loaded with existing policy (outdated Word document) — AI extracts already-implemented controls
  • AI Gap Analysis identifies 27 gaps ordered by impact; generates policy draft for 20 of them in <2 hours
  • Evidence uploaded with OCR; auditor accesses the Auditor Portal
  • Result: certification cycle reduced from 12 to 6 months; consultancy cost reduced by 40%
SCENARIO 02 Ransomware Incident with NIS2 Obligation

Situation: a health clinic (NIS2 PT) detects ransomware on 3 servers. It is 14:30 on a Friday.

  • Incident created → countdowns activated: 23h30 for CNCS and 71h30 for DPA (CNPD)
  • ANACOM routing identifies: CNCS + DPA/CNPD (health personal data affected)
  • The internal SIEM imports technical alerts as incident evidence
  • At 22:30: notification to CNCS sent within 24 hours; record on the platform with timestamp
  • Result: legal compliance demonstrated with evidence; GDPR fine avoided
SCENARIO 03 vCISO Consultancy Managing 8 Clients

Situation: a cybersecurity consultancy manages 8 SME clients with different maturity levels and frameworks.

  • Multi-client dashboard: 8 entities in a single panel with compliance scores
  • AI uses each organisation's specific Knowledge Base — contextualised suggestions per client
  • Automatic PDF reports per client generated monthly for management
  • Auditor Portal: when a client needs an audit, the auditor accesses without seeing the other 7
  • Result: consultancy manages 8 clients with the quality of a dedicated internal CISO, at 30% of the cost
SCENARIO 04 Financial Company under DORA

Situation: an asset management company with 200 employees, subject to DORA, in a remediation process.

  • Cross-framework: 14 of the 24 DORA controls already have a partial response from existing ISO 27001 work
  • DORA critical functions: mapping of business functions and contracts with ICT vendors
  • ICT incidents: automatic countdown (4 hours for major DORA incidents)
  • Result: DORA compliance documented in 8 weeks instead of the expected 6 months
23 Operation Playbooks
PB-01 Monthly Compliance Cycle 2–4 hours / month
  • Review dashboard — compliance score and trend
  • Check compliance calendar — events for the next month
  • Review overdue tasks — reassign or renegotiate deadlines
  • Process EtherFlow inbox — approve/reject items from the monthly meeting
  • Review vendor alerts — assessments expiring in the next 60 days
  • Review pending access reviews — approve or revoke access
  • Check for missing evidence for critical controls
  • Update risks with new developments (new systems, new vendors)
PB-02 Onboarding a New Critical Vendor 3–5 days
  • Create vendor record in EterShield with risk profile
  • Launch TPRM questionnaire — send link to vendor (deadline: 5 business days)
  • Review AI analysis: score, red flags, recommendation
  • If red flags: request additional clarifications
  • Record CISO decision: Approve / Conditional / Reject
  • If Conditional: create CAPA with remediation deadline
  • Schedule next reassessment (6 or 12 months)
  • Associate with ISO 27001 control A.5.19 (supplier relationships)
PB-03 Preparation for External Audit 4–6 weeks prior
Weeks -6 to -4
  • Run AI Gap Analysis for the framework under audit
  • Create remediation tasks for each gap; prioritise by criticality
Weeks -4 to -2
  • Upload missing evidence — screenshots, logs, approvals
  • Check policy versioning — all approved and within validity?
  • Document non-conformances with associated CAPAs
Week -1 and audit day
  • Create access for external auditor in the Auditor Portal
  • For each control questioned: show linked evidence in EterShield
  • Immediately record identified non-conformances as CAPAs
PB-04 Response to a GDPR Data Breach 72 hours + follow-up
First 24 hours
  • Create incident — type: "Personal Data Breach"; DPA/CNPD countdowns (72h) activated
  • Identify: affected data, categories, volume, data subjects
  • Activate immediate containment: revoke access, isolate systems
Hours 24–72
  • Assess risk to data subjects (low / medium / high)
  • Draft and submit notification to the DPA (CNPD) within 72 hours
  • Record submission with reference number
Post-incident
  • CAPA: root cause, corrective measures, deadline
  • Review relevant ISO 27001 / GDPR controls — update evidence
  • Incident report for the board (automatic Board Report PDF)
CONCLUSION EterShield as a Strategic Asset
Conclusion

Security compliance has moved from a peripheral concern to a strategic factor in competitiveness. Organisations that build real security management capability — not just pass audits — gain access to larger clients, public contracts, cyber insurance with lower premiums, and partnerships that require certifications.

EterShield was built for a specific reality: the European SME facing growing regulation without resources for an internal CISO, without budget for enterprise platforms, and without patience for tools that don't speak their language.

23
Frameworks and methodologies
994
Controls in the database
€209
Starting from / month (PT)
What EterShield is not: it is not a solution that guarantees certification; it does not replace human judgement in critical decisions; it does not eliminate the need for external auditors.

What EterShield is: the difference between starting each certification cycle from scratch or with two years of structured knowledge. The difference between discovering a NIS2 incident at 15:00 on a Friday not knowing what to do, or having a workflow that counts the hours and tells you exactly who to notify. The difference between a consultant who takes the knowledge when they leave, and an organisational asset that stays.
G Glossary
TermDefinition
vCISOVirtual Chief Information Security Officer — the CISO function outsourced to a partner or platform
GRCGovernance, Risk and Compliance — set of processes for managing governance, risk, and compliance
IMSIntegrated Management System — a management system that combines multiple standards (ISO 27001, ISO 9001, ISO 45001…)
RAGRetrieval-Augmented Generation — AI technique that injects relevant context into prompts for precise and contextualised responses
FAIRFactor Analysis of Information Risk — financial quantification methodology for cyber risk
ALEAnnualised Loss Expectancy — expected annual financial loss, the output of the FAIR/Monte Carlo model
TPRMThird-Party Risk Management — management of risks associated with vendors and third parties
JMLJoiners, Movers, Leavers — the access lifecycle of employees
DSRData Subject Request — a request by a data subject under GDPR (access, rectification, erasure…)
CAPACorrective and Preventive Action — plan of corrective and preventive actions for non-conformances
NIS2Network and Information Security Directive 2 — European cybersecurity directive (2022/2555)
DORADigital Operational Resilience Act — European digital resilience regulation for the financial sector (2022/2554)
CSRDCorporate Sustainability Reporting Directive — European sustainability reporting directive (2022/2464)
ESRSEuropean Sustainability Reporting Standards — CSRD sustainability reporting standards
CNCSCentro Nacional de Cibersegurança (Portuguese National Cybersecurity Centre) — national cybersecurity authority in Portugal
CNPDComissão Nacional de Protecção de Dados (Portuguese Data Protection Authority, DPA) — data protection authority in Portugal
ANACOMAutoridade Nacional de Comunicações (Portuguese National Communications Authority) — NIS2 competent authority for specific sectors in Portugal
MONARCMethod for an Optimised aNAlysis of Risks — ISO 27005 threat catalogue under CC0 licence
AI SparksIntelligent form prefill — automatic AI content suggestion based on gap or entity context
SPCStatistical Process Control — statistical process control (ISO 9001)
RBACRole-Based Access Control — access control by user role
RoPARecord of Processing Activities — Register of Processing Activities (GDPR Article 30)
BIABusiness Impact Analysis — business impact analysis (ISO 22301)
ARIAAgentic Risk Intelligence Assessment — proprietary agentic AI risk assessment methodology in 7 phases
AIVSSAI Vulnerability Scoring System — vulnerability scoring system for AI systems, analogous to CVSS
TIATransfer Impact Assessment — formal assessment of the impact of international personal-data transfers required by GDPR Art. 44–49 and Schrems II
DPFData Privacy Framework — EU–US adequacy decision (invalidated 29 June 2026, Trump v. Slaughter); replaced by SCCs, BCRs, or Art. 49 derogations
DPAData Processing Agreement — contract required under GDPR for sub-processors handling personal data on behalf of a controller
SCCsStandard Contractual Clauses — pre-approved GDPR transfer mechanism for transfers to countries without an adequacy decision