The firewall you bought three years ago is not a SOC. It is a door with a lock — useful, but no one is looking at the camera when someone tries to get in at 3am on a Sunday. This guide gives you the criteria to decide between buying more boxes or hiring someone to keep watch 24/7, and a decision matrix you can take into tomorrow's meeting.
The uncomfortable thesis: most Portuguese industrial SMEs already have sufficient perimeter protection. What they don't have is detection. A firewall blocks what it recognises. A SOC catches what got through — the lateral movement, the odd login at 4am, the encryptor that has started tampering with the files on the production server. In 2024 CERT.PT recorded 2,758 incidents in Portugal, up 36% on 2023, with around 78% in private entities.1 The question is no longer if, it's when you notice.
What you need on the table before you decide
No one chooses between perimeter and monitoring blindly. Before the meeting, gather six things — and not the polished version, the real one. First, the inventory of critical assets: the ERP servers, the shop-floor PLCs, the NAS where the collections live, the domain controllers. Then the up-to-date network diagram — not the 2019 one pinned to the wall of the IT office, the current one, with the production VLAN separated from the administrative one (or, more likely, not).
Third, the honest list of active remote accesses: VPNs, exposed RDP, that connection the finishing-machine supplier left open in 2021 and no one ever closed. Fourth, the backup policy with the date of the last real restore test — not the date the backup software was installed. Fifth, a named internal contact, with name and mobile number, to make decisions out of hours. And, finally, the regulatory framing: check whether you fall within the scope of NIS2 before the decision is no longer yours to make.
One detail the textbook checklists never mention: negotiate the maintenance window with production before choosing the solution. Installing monitoring sensors on an ERP server in the middle of the February campaign — when the international buyers of women's footwear have already confirmed their visit — doesn't happen. And if the SOC needs agents on machines that never stop, that changes the whole schedule.
Perimeter and SOC are not the same layer
Confusing the two is the mistake we see in almost every first conversation. They are different functions, at different moments in the attack.
| Dimension | Perimeter protection | SOC / monitoring |
|---|---|---|
| When it acts | Before — blocks known entry | During and after — detects what got in |
| Base technology | Firewall, email filtering, segmentation | SIEM, EDR, log correlation |
| Needs people? | Initial configuration + rules | Analysts watching 24/7 |
| Typical failure | Forgotten permissive rule, outdated firmware | Alerts with no one reading them |
| Covers insider threat? | No | Yes — anomalous login, exfiltration |
The firewall does not see an employee whose credentials have been stolen downloading 40 GB of footwear collections at 2am. The SOC does. In SMEs, ransomware was present in 88% of the breaches analysed, against 39% in large organisations2 — precisely because the box is there, but no one is looking at the alerts. The attacker knows this better than management: the industrial SME is a disproportionate target precisely because it invested in the lock and never hired the guard.
Decision matrix: buy a box or hire surveillance
Score each criterion from 0 (no) to 2 (yes, fully). Add them up. Interpret the result at the end.
| Criterion | Points (0-2) |
|---|---|
| Do we have someone reading security logs every day? | |
| Do we know, within minutes, if a server is being encrypted? | |
| Have we tested a backup restore in the last 90 days? | |
| Are our suppliers' remote accesses monitored? | |
| Do we fall within the scope of NIS2 (critical sector, size)? | |
| Is there a written incident response plan? |
0-4 points: perimeter protection is giving you false confidence. You need detection before more firewalls. 5-8 points: you have foundations, but you depend on internal heroes — unsustainable the day that hero goes on holiday or changes jobs. 9-12 points: mature; focus on automation and response time.
Don't buy the most expensive box. Buy the certainty that someone notices the attack before you find it in the ransom bill.
A scenario from the Vale do Ave
Imagine a textile factory of ~90 employees, ERP on the server, a dye house with temperature sensors connected to the network. A decent firewall, bought with COMPETE funds. One Saturday, an encryptor gets in through exposed RDP on a finishing machine. Monday morning, the batch traceability server is encrypted — and the client brand demands compliance with the EU Strategy for Sustainable Textiles, which relies on that data. No batch, no proof of origin. No proof, the order is held up.
The firewall did its job: it blocked everything it recognised. It did not recognise this. A SOC would have seen the RDP login at 2am from a Romanian IP and would have isolated the machine within minutes. The difference between a scare and three days of stopped production is measured in detection time — not in euros of hardware. Organisations that used AI and automation extensively in prevention saved, on average, USD 2.2 million per breach.3 In the Portuguese SME context these aren't millions — they are the working days the parent company doesn't forgive and the fine the tax authority doesn't waive.
Common mistakes and how to avoid them
Five patterns repeat from factory to factory, and none of them is sophisticated. The first is buying a SIEM and having no one to operate it. A SIEM without analysts is a warehouse of logs gathering digital dust — hire the managed service or don't buy the licence. The second is leaving the production network flat: separate the PLC VLAN from the administrative one, because the encryptor that gets in through an administrative worker's email should not have a clear path to the plastic injection line.
The third is the most lethal and the least discussed: backup on the same domain. Ransomware encrypts the network-connected backup as easily as it encrypts the production server. Insist on a replicated and offline copy, and test the restore on a Saturday before you need it on a Monday. The fourth is RDP exposed to the Internet — the most commonplace vector there is. Close it, put it behind a VPN, enable MFA, and then confirm that you really did close it, because half the factories swear they closed it and didn't.
The fifth is treating NIS2 as paperwork. The Directive requires real technical controls, not a policy in a PDF in the IT drawer. NIS2 (Directive (EU) 2022/2555, transposed by Decree-Law No. 65/2025) extends cybersecurity obligations to medium and large companies in 18 critical sectors, industry included.4 When the auditor knocks at the door, the PDF neither isolates machines nor logs incidents.
How INFOS brings the two layers together
INFOS Cybersecurity does not sell a box. It operates on five fronts: risk and maturity assessment, implementation of defences, SOC and monitoring, training and awareness, and incident response. The foundation includes replicated backup, perimeter security and secure email, with GDPR and ISO 27001 compliance as a starting point.
For those with a critical ERP — the MULTI ERP running textile, footwear or metal/plastic production — the advantage is operational: the SOC knows where the data that cannot stop is located. Watching the traceability server is not the same as watching any old laptop. Read also the silent cybersecurity risks for the context most managers still underestimate.
The question the matrix forces you to answer
The global shortfall of cybersecurity professionals was around 4.76 million people in 2024.5 Translated into the reality of an industrial SME in the Lousada/Paços corridor: you are not going to hire a full-time security analyst, and even if you found one, you wouldn't have them staring at the screen at 2am on a Sunday. That is the sum the matrix forces you to do.
Perimeter protects you from what is already known. Monitoring catches what isn't yet. The decision between the two stops being instinct once you score the six criteria with your internal IT — because the result, high or low, stops lying about how long your factory takes to notice an attack that is already inside.
Sources
- CNCS — Centro Nacional de Cibersegurança / CERT.PT, Cybersecurity in Portugal Report, 2024.
- Verizon, Data Breach Investigations Report (DBIR), 2025.
- IBM, Cost of a Data Breach Report, 2024.
- Directive (EU) 2022/2555 (NIS2), transposed in Portugal by Decree-Law No. 65/2025.
- ISC2, Cybersecurity Workforce Study, 2024.
Frequently asked questions
What is the difference between a firewall and a SOC?
A firewall blocks known threats before they enter the network — it acts in prevention. A SOC (Security Operations Center) detects attacks that have already got past the firewall, monitoring anomalous behaviour, odd logins and lateral movements within the network. The firewall is the door; the SOC is who keeps watch 24/7.
Does a Portuguese SME really need a SOC?
Yes. Most industrial SMEs have sufficient perimeter protection, but detection is missing. In 2024, CERT.PT recorded 2,758 incidents in Portugal, 78% in private entities. Ransomware was present in 88% of breaches in SMEs, precisely because the lock exists but no one looks at the alerts.
What is the real cost of not having 24/7 monitoring?
It is not just the ransom. An encryptor that gets in over a weekend and is discovered on Monday can bring production to a halt for days. For an industrial SME, the loss of operation, regulatory fines and reputational damage far outweigh the cost of a managed SOC. Detection time defines the difference between a scare and a catastrophe.
Can I use a SIEM without hiring analysts?
No. A SIEM without analysts is a warehouse of logs accumulating valueless data. It is recommended to hire the managed service (SOC as a Service) or not to invest in the licence. The tool alone detects nothing — it needs people to read, correlate and react to the alerts.
How do I know if I need a SOC or just to improve the firewall?
Use the decision matrix: score 0-2 on six criteria (daily log reading, encryption detection time, backup testing, remote access monitoring, NIS2 framing, incident plan). Score 0-4: you need detection urgently. 5-8: you have foundations but depend on internal heroes. 9-12: you are mature.
Does NIS2 require SMEs to have a SOC?
It does not explicitly require a SOC, but it does require incident detection and real-time response. If your SME falls within the scope of NIS2 (critical sector, size above 50 employees), a managed SOC is the most practical way to meet these requirements without creating dependence on a single internal employee.
What is the most common mistake I see in industrial SMEs?
Backup on the same network domain. Ransomware encrypts the network-connected backup as easily as it encrypts the production server. Insist on a replicated and offline copy, with real restore tests (not just software installation dates). Without a secure backup, there is no recovery.
