Skip to content
Conference

State of the Art in Critical Infrastructure Protection and Resilience in Portugal: Governance, Incidents, and Gaps

Jul 2026 · 2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET) · pp. 1-7 · 0 citations · 13 references

Abstract

Portugal is expanding its portfolio of recognized critical infrastructures from approximately 150 to more than 400 entities across twelve strategic sectors, reflecting increasing cross-sector interdependence and exposure to hybrid disruptions. Critical infrastructure governance is coordinated by the National Security Office and the National Cybersecurity Center and has been reinforced since 2024 through the establishment of the National Unit for the Protection of Critical Entities. Despite these advances, persistent challenges remain, including fragmented institutional mandates, uneven integration of cyber and physical resilience practices, skills shortages, and dependence on external technological providers. This paper examines how Portugal's critical infrastructure protection and resilience governance is evolving in response to the European Critical Entities Resilience (CER) and NIS2 frameworks. Its novelty lies in combining legal-institutional analysis, incident-based cross-case comparison, and a resilienceassurance framework tailored to CER/NIS2-aligned governance assessment. The study applies a structured review of legal instruments, national strategies, regulatory publications, and publicly documented incidents between 2011 and 2026 in order to synthesize sectoral scope, governance roles, disruption patterns, and assurance gaps across sectors. Findings highlight three recurring governance weaknesses: fragmented institutional coordination, incomplete cyber-physical integration in resilience practices, and the absence of comparable resilience metrics and assurance artifacts. The paper contributes a compact analytical synthesis of Portugal's critical infrastructure governance and proposes a minimal roadmap and assuranceoriented framework to support CER/NIS2-aligned resilience evaluation and continuous improvement.

View source

Similar papers

Review Open access Jul 2026

A Critical Integrative Review of Technology Assurance for Operational Resilience in U.S. Regulated Organizations

Technology assurance practices have become central to efforts aimed at strengthening operational resilience across U.S. regulated sectors, including finance, healthcare, and critical infrastructure. This integrative review examines how audits, compliance mechanisms, governance frameworks, and emerging-technology controls are discussed in the recent peer-reviewed literature. Drawing on a synthesis of recent peer-reviewed studies, the analysis reveals recurring attention to traditional compliance-oriented approaches alongside growing interest in adaptive practices and data-protection balances. Studies consistently identify resource constraints, static checklists, and dynamic threats as barriers that limit the translation of assurance activities into sustained resilience. In financial and healthcare contexts, audits and regulatory implementation show promise for risk mitigation but frequently lack integration with broader operational strategies. Similar patterns appear in utility-sector discussions of cyber-physical threats and in examinations of AI governance, where qualitative reviews emphasize ethical and compliance balances without extensive empirical outcome data. Disclosure quality and framework application are linked to market or organizational responses, yet long-term quantitative evaluation remains underdeveloped. Overall, the literature suggests alignment around the identification of barriers and the need for adaptive cultures, while remaining fragmented on consistent linkages to resilience outcomes and silent on cross-sector empirical validation. These insights point to practical implications for regulated organizations seeking to move beyond compliance checklists toward more responsive assurance systems. The review contributes a grounded perspective on current evidence and highlights targeted areas for future inquiry.

Matilda Konotey, Daniel Bamfo, G. Apaflo · 0 citations
Review Open access Jul 2026

Fragmentation and Harmonization of Cybersecurity and IT Control Frameworks: An Integrative Review of U.S. Governance Practices

Cybersecurity and information technology control frameworks in the United States exhibit significant fragmentation arising from overlapping regulatory mandates and duplicated controls. Audits and compliance activities in financial institutions and critical infrastructure sectors identify vulnerabilities but reveal limitations when applied as static mechanisms rather than adaptive processes. Mapping exercises between National Institute of Standards and Technology Cybersecurity Framework, Control Objectives for Information and Related Technology, and International Organization for Standardization 27001 consistently document both shared requirements and gaps that widen with the introduction of artificial intelligence and machine learning. Federal harmonization efforts have produced initial coordination yet face persistent barriers from agency-specific mandates and scarce longitudinal outcome data. Governance practices navigate these tensions through sector-specific applications that balance operational demands against systemic interoperability needs. The empirical studies highlight the need for continued attention to framework alignment, regulatory coordination, and empirical validation if resilience is to match evolving threats. Effective integration of controls requires addressing both practical implementation challenges and broader policy structures that shape cybersecurity governance across regulated industries. These dynamics underscore the importance of reducing unnecessary duplication while preserving essential specialization to support more resilient national cybersecurity posture. Ultimately, achieving meaningful harmonization will depend on sustained policy coordination and the development of robust evidence on post-alignment outcomes. This review synthesizes cross-sector evidence to identify structural, operational, and technological barriers to harmonization, while proposing an integrative governance perspective grounded in recent empirical and policy literature.

William Asare Yirenkyi, G. Apaflo, Matilda Konotey et al. · 0 citations
Review Open access 2026

Cybersecurity Risks in Digitized Capital Markets: A Comparative Regulatory Analysis of Operational Resilience, Disclosure, and Market Integrity

The digitization of capital markets has increased efficiency, connectivity, and innovation, but it has also transformed cybersecurity from an institution-specific technical concern into a systemic threat to market integrity and financial stability. This study evaluates the adequacy and coherence of cybersecurity regulation in digitized capital markets. It employs qualitative policy analysis, doctrinal review, and comparative analysis of the United States Securities and Exchange Commission framework, the European Union’s Digital Operational Resilience Act, and IOSCO/CPMI-IOSCO standards. Regulatory documents and scholarly evidence covering 2020–2026 are assessed through directed content analysis and a comparative matrix spanning governance, incident reporting, disclosure, resilience testing, third-party risk, business continuity, enforcement, and systemic resilience. The findings reveal partial regulatory convergence but persistent structural fragmentation. The United States prioritizes disclosure and investor protection; the European Union adopts a broader operational-resilience model; and international standards emphasize financial-market infrastructures, coordination, and systemic stability. Major deficiencies include weak integration between disclosure and resilience requirements, uneven oversight of critical technology providers, inconsistent incident definitions and reporting timelines, limited cross-border enforcement, and inadequate treatment of contagion and market outages. The study proposes a multilayered regulatory model that aligns entity-specific obligations with harmonized reporting, proportionate disclosure, direct oversight of critical third parties, coordinated recovery planning, and market-wide resilience testing. Such integration is essential for protecting investors, preserving market continuity, and containing systemic cyber risk.

A. F. Olugbenga · 0 citations
Open access Aug 2026

Adaptive Governance of Disaster and Systemic Risks in Critical Energy Infrastructure: A Complex Adaptive Systems Perspective

Critical energy infrastructure operates in an increasingly complex environment characterized by disaster risks, systemic risks, interdependencies, and uncertainty. Traditional approaches emphasizing regulatory compliance and technical protection are no longer sufficient to explain how infrastructure resilience is achieved under rapidly changing conditions. Drawing on Complex Adaptive Systems Theory, this study examines how adaptive governance contributes to managing disaster and systemic risks within critical energy infrastructure. A qualitative instrumental case study was conducted in Naftna Industrija Srbije (NIS), using semi-structured interviews with ten experts responsible for corporate security and critical infrastructure protection, complemented by document analysis. Data were analyzed through reflexive thematic analysis. The findings identify four interrelated governance dimensions: institutional coordination, public-private collaboration, adaptive organizational learning, and governance adaptation. Building on these findings, the study develops the Adaptive Governance Capacity Framework, conceptualized as the collective capability of interconnected public and private actors to coordinate, learn, exchange knowledge, and adapt governance processes in response to evolving disaster and systemic risks. The study contributes to the literature by integrating Critical Infrastructure Theory, Disaster Risk Governance, Collaborative Governance, Organizational Resilience, and Complex Adaptive Systems Theory into a coherent conceptual framework. The findings also provide practical implications for policymakers, infrastructure operators, and emergency management authorities responsible for strengthening resilience in complex critical infrastructure systems.

Nevena Gavrić, Dragan Trivan · 0 citations
Review Open access Jul 2026

From Risk Reporting to Resilience: A Narrative Integrative Review of Cybersecurity Governance Practices in Organizations

Cybersecurity has moved from a peripheral technical function to a core pillar of organizational governance, driven by the escalating frequency and cost of digital intrusions, tightening disclosure regulation, and growing recognition that technical controls alone cannot guarantee continuity of operations. This narrative integrative review synthesises contemporary academic literature on cybersecurity governance, tracing its evolution from a compliance-oriented, risk-reporting paradigm toward an integrated model of organizational cyber resilience. The review examines governance structures and board oversight arrangements, the integration of cybersecurity into enterprise risk management, the conceptual architecture of organizational cyber resilience, the human and cultural determinants of governance effectiveness, sector-specific and supply-chain vulnerabilities, financial and insurance mechanisms for risk transfer, the regulatory and standards landscape, and approaches to measuring governance maturity. Findings indicate that although disclosure obligations and formal oversight structures have proliferated, substantive board-level expertise remains scarce, enterprise risk management integration is uneven, and resilience-building efforts are frequently undermined by fragmented accountability and inconsistent measurement practices. The review argues that a durable shift from reactive risk reporting to genuine organizational resilience requires coherent alignment across governance structures, cultural investment, supply-chain oversight and outcome-based metrics. Directions for future research and the practical implications of these findings for boards, risk officers and regulators are discussed.

William Asare Yirenkyi, Apaflo Godson Teye, Matilda Konotey et al. · 0 citations
Open access Jul 2026

Governance linkages in national security: A new analytical framework

The growing interdependence of geopolitical, economic, technological, and informational risks has challenged traditional approaches to national security that are primarily organized around threat identification and defensive responses. As contemporary security environments become increasingly characterized by systemic complexity and cascading disruptions, national security is evolving from a problem of managing individual threats into a problem of sustaining the continuity of state strategic action.This article reconceptualizes national security as a strategic governance problem rather than a threat-centered security problem. Drawing on strategic reading, governance analysis, and comparative interpretation, the study examines the limitations of conventional threat-based approaches, analyzes the characteristics of Mongolia’s contemporary security vulnerabilities, and explores the implications of ongoing transformations in the international strategic environment.The findings suggest that Mongolia’s principal national security vulnerabilities are less closely associated with the magnitude of threats, levels of risk, or resource constraints than with weaknesses in the governance linkages connecting strategic analysis, planning, implementation, evaluation, and continuity. When these linkages deteriorate, strategic discontinuities accumulate and progressively deepen systemic vulnerability. Based on this analysis, the article develops a National Security Governance Linkage Analysis Model and interprets strategic discontinuity as a manifestation of governance-linkage failure.The study concludes that the central challenge of national security is shifting from threat management toward the preservation of continuity in state strategic action. Under conditions of uncertainty, the effectiveness of national security depends less on the nature of threats themselves than on the quality, coherence, and resilience of the governance linkages that connect the strategic functions of the state. The article contributes to the national security literature by introducing governance linkage as an analytical unit for examining security vulnerability and by proposing a governance-linkage-based analytical framework for national security analysis. Үндэсний аюулгүй байдлын удирдлагын холбоос: Стратегийн шинжилгээний шинэ хандлага ХураангуйЭрсдэлийн огтлолцол гүнзгийрч, геополитик, эдийн засаг, технологи, мэдээллийн орчны дарамтууд харилцан хамааралтай болсон нөхцөлд үндэсний аюулгүй байдлыг аюул заналын ангилал болон хамгаалалтын хариу арга хэмжээний хүрээнд тайлбарладаг уламжлалт хандлага хүрэлцээгээ алдаж эхэлжээ. Ийм нөхцөлд аюулгүй байдлын асуудал нь аюулын шинж чанарын асуудлаас илүү төрийн стратегийн ажиллагааны тогтвортой байдлын асуудал болон өөрчлөгдөж байна.Энэхүү өгүүлэл үндэсний аюулгүй байдлыг аюул төвтэй уншлагын хүрээнээс гарган, төрийн стратегийн ажиллагааг тасралтгүй уялдуулах удирдлагын логик байдлаар дахин тайлбарлахыг зорив. Судалгаанд стратегийн уншлага, удирдлагын шинжилгээ, харьцуулсан тайлбарын аргыг ашиглан орчин үеийн стратегийн орчны өөрчлөлт, аюул төвтэй логикийн хязгаар, Монгол Улсын үндэсний аюулгүй байдлын эмзэг байдлын шинжийг нэгтгэн шинжилсэн болно.Шинжилгээний үр дүнгээс харахад Монгол Улсын үндэсний аюулгүй байдлын эмзэг байдал нь аюул заналын хүч, эрсдэлийн хэмжээ, эсвэл нөөцийн хомсдолд бус, харин стратегийн шинжилгээ, төлөвлөлт, хэрэгжилт, үнэлгээ, залгамжийг холбож байдаг удирдлагын холбоосууд сулралтай илүү нягт холбоотой байна. Эдгээр холбоосын доголдлоос үүдэлтэй стратегийн тасалдал хуримтлагдах үед эмзэг байдал тогтолцооны түвшинд гүнзгийрдэг болохыг тогтоов. Үүний үндсэн дээр үндэсний аюулгүй байдлын удирдлагын холбоосын шинжилгээний загварыг санал болгож, стратегийн тасалдлыг уг холбоосын доголдлын илрэл болгон тайлбарлав.Энэхүү судалгаа нь үндэсний аюулгүй байдлын төв асуудал аюулын удирдлагаас төрийн стратегийн ажиллагааны тасралтгүй байдлыг хангах асуудал руу шилжиж буйг харуулж, аюулгүй байдлын бодит шалгуур нь аюулын шинж чанарт бус удирдлагын холбоосын чанарт оршдог гэсэн онолын гаргалгаанд тулгуурлан “удирдлагын холбоос” ойлголт болон түүний шинжилгээний загварыг санал болгож байна. Түлхүүр үгс: Стратегийн удирдлага; стратегийн эмзэг байдал; стратегийн шинжилгээ; бодлогын уялдаа; стратегийн залгамж; нэгдсэн удирдлагын логик

Tuvshintugs Adiya · 0 citations