Skip to content

Robot with a glowing green face, an image associated with the Secnora cybersecurity partnership.

Cybersecurity with specialist delivery and local proximity.

Across Security Assurance and Testing, Cyber Incident Response, Security Training, Digital Forensics, Governance Risk & Compliance, Security Management and Managed Security Services.

We deliver cybersecurity services in Portugal through a local Shore team and specialist technical capabilities, with rigour, an operational framework and a single point of coordination.

  • Since 2007
  • ISO 9001:2015
  • 7 service families
  • Single point of coordination

Our services

We protect together

End-to-end support for information systems security, so you can operate with peace of mind. Seven service families, from offensive testing to managed operations — pick one to see what it covers.

11 services

Security Assurance and Testing

Assess before someone does it for you: penetration tests, audits and simulations that expose exploitable vulnerabilities — from applications and networks to cloud, code, smart contracts and LLM models.

Services

  • Penetration Testing Services
  • Vulnerability Assessments
  • Security Audits
  • Cloud Security Audit
  • Attack & Breach Simulations
  • Continuous Adversary Emulation
  • IT General Control Assessments
  • Source Code Review
  • Smart Contract Audit
  • LLM Security Audit
  • IOT Security

2 services

Cyber Incident Response

When an incident happens, the response is what counts: containment, investigation and recovery — and tabletop exercises so the team knows what to do before it is for real.

Services

  • Incident Response
  • Tabletop Exercises

1 service

Security Training

Cybersecurity enablement for technical and non-technical teams through specialist training programmes.

Services

  • Cybersecurity Training Academy

1 service

Digital Forensics

Digital forensic investigation: evidence preservation, analysis and documentation with chain of custody — for incidents, litigation and audits.

Services

  • Digital Forensics Services

7 services

Governance, Risk & Compliance

Governance, risk and compliance: from impact assessment to certification and regulatory readiness and follow-up — ISO 27001, GDPR, SOC 2, PCI DSS, HIPAA.

Services

  • ISO/IEC 27001
  • GDPR Compliance
  • GDPR Audit & Readiness Check
  • Data Protection Impact Assessment (DPIA)
  • SOC 2 Compliance
  • PCI DSS Compliance
  • HIPAA Compliance

4 services

Security Management

The management layer of security: strategy, security programme development, virtual CISO and third-party risk management.

Services

  • Cybersecurity Strategy
  • Security Program Development
  • Virtual CISO Consulting
  • Third Party Risk Management

5 services

Managed Security Services

Continuous security operations as a managed service: detection and response, vulnerability management, SIEM and SOC, cloud security and phishing simulations.

Services

  • Managed Detection & Response (MDR)
  • Endpoint Detection & Response (EDR)
  • Managed SIEM & 24/7 SOC
  • Vulnerability Management
  • Managed Cloud Security & Phishing Simulations

Core pillars

Our expertise

Three pillars sustain the delivery: the people who execute, the processes that frame the work and the technology that supports it.

  1. 01

    People

    Extensive technical competence, supported by a qualified team certified by the leading bodies, including ISACA, ISC2, ISO 27001, CREST, Offensive Security, SANS Institute, EC-Council and eLearnSecurity.

    • ISACA
    • ISC2
    • ISO 27001
    • CREST
    • Offensive Security
    • SANS Institute
    • EC-Council
    • eLearnSecurity
  2. 02

    Processes

    Adherence to global best practices (ITIL, ISO 27000, COBIT, PCI DSS), combined with superior management and technical reporting capabilities.

    • ITIL
    • ISO 27000
    • COBIT
    • PCI DSS
  3. 03

    Technology

    Reference Governance, Risk Management and Compliance (GRC) and security solutions, supported by partnerships with sector vendors.

    • GRC
    • Security Platforms

Available profiles

Cybersecurity specialists

Twenty-four profiles across six areas — from offensive security to leadership. Search by role or technology, or filter by area.

4 profiles found

  • Offensive Security

    4 profiles

    Testing like an attacker: intrusion, red team and vulnerability research.

    • Penetration Tester

      • OWASP
      • Burp Suite
      • Metasploit
      • Kali Linux
    • Red Team Operator

      • Cobalt Strike
      • C2 Frameworks
      • Social Engineering
      • Evasion
    • Ethical Hacker

      • Web App Testing
      • Network Pentesting
      • API Security
      • Mobile Security
    • Vulnerability Researcher

      • Reverse Engineering
      • Exploit Development
      • Fuzzing
      • CVE Analysis

Need to reinforce your team?

Contact us to discuss your needs — a single profile or a full team.

For reinforcing teams with specialists under your management, in other IT areas, see also IT Skills & Talent

Talk to a specialist

Our partners

Cybersecurity solutions

We work with reference platforms in identity protection, autonomous pentesting and data security.

  • Identity Protection

    Semperis

    Active Directory security and recovery platform: protection against identity-based attacks, threat detection and disaster recovery for hybrid AD environments.

  • Autonomous Pentesting

    Horizon3.ai

    Autonomous pentesting platform that runs automated penetration tests to identify exploitable vulnerabilities across networks, cloud environments and Active Directory.

  • Data Security

    Cohesity

    Unified data security and management platform: ransomware protection, backup and recovery, threat detection and regulatory compliance.

These are partner platforms, implemented and operated within the services described above — the choice depends on each organisation’s environment and problem.

Victim of an attack?

Talk to our security consultants.

If you are dealing with an active incident, do not describe sensitive technical detail by email — leave only your contact and availability, and we will call.