Lisbon, Oct. 2, 2026 (Lusa) - In the first half of the year, Portugal ranked 19th in Europe amongst the markets where customers were most frequently affected by malicious cyber activity, according to the 7th edition of the Microsoft Digital Defence Report (MDDR) published on Friday.
The data shows that, in the first half of the year, «Portugal ranked 55th globally and 19th in Europe amongst the countries where customers were most frequently affected by malicious cyber activity», according to the report published by Microsoft.
Cyber risks «are becoming faster, more interconnected and harder to contain. In this context, organisations will need to focus their efforts not only on preventing attacks, but also on the ability to respond quickly and maintain business continuity when incidents occur».
Cybersecurity «has entered a new phase in which it is no longer enough simply to prevent attacks. Organisations need to be prepared to respond swiftly, protect their digital identities and ensure business continuity in a context where risks are increasingly interconnected», says Pedro Soares, national security director at Microsoft Portugal, quoted in a press release.
In this regard, «resilience has become a critical factor for the security and competitiveness of organisations», he concludes.
The Microsoft Digital Defence Report «concludes that AI is redefining the economics of cybersecurity, accelerating discovery, analysis, adaptation and automation for both attackers and defenders».
On the one hand, «it enables attackers to operate more quickly and on a larger scale. On the other, it is helping security teams to identify, investigate and disrupt threats more effectively», the report states.
Identity «remains the main point of entry for attackers».
Despite the growing sophistication of threats, «attackers continue to rely on compromised accounts and stolen credentials to gain access to organisations».
Phishing attacks accounted for «23% of intrusions observed in 2026, highlighting the ongoing importance of identity protection as the first line of defence against more widespread attacks».
Microsoft argues that organisations «must strengthen the protection of digital identities and ensure that critical accounts have adequate security measures in place, thereby reducing the risk of initial compromise and the spread of attacks».
The report also points out that governments and public services remain among the main targets of cyber threats this year, «accounting for 27% of the activity observed».
These organisations «are particularly attractive targets due to the sensitive information they store, the essential services they provide, and the fact that they are at the centre of networks involving public bodies, technology suppliers, service providers and critical infrastructure operators», the report states.
In an era marked by threats fuelled by artificial intelligence, «resilience no longer simply means the ability to recover from an attack. It means preparing for a context in which incidents spread more rapidly, affect more organisations and require a coordinated response to ensure the continuity of essential services», it points out.
October is considered Cybersecurity Month.
ALU/AYLS // AYLS
Lusa