{"id":30649,"date":"2025-10-30T19:00:48","date_gmt":"2025-10-30T19:00:48","guid":{"rendered":"https:\/\/www.caiadoguerreiro.com\/?p=30649"},"modified":"2025-10-30T19:04:36","modified_gmt":"2025-10-30T19:04:36","slug":"cyberattacks-and-civil-liability-who-is-responsible-for-the-damages","status":"publish","type":"post","link":"https:\/\/www.caiadoguerreiro.com\/en\/cyberattacks-and-civil-liability-who-is-responsible-for-the-damages\/","title":{"rendered":"Cyberattacks and Civil Liability: Who Is Responsible for the Damages?"},"content":{"rendered":"<p data-start=\"166\" data-end=\"525\">Cyberattacks have ceased to be a hypothetical and marginal risk and have become a strategic threat to Portuguese companies. According to the <em data-start=\"311\" data-end=\"347\">Hiscox Cyber Readiness Report 2025<\/em>, more than half (54%) of Portuguese SMEs suffered at least one attack in the past year \u2014 including data loss, DDoS (Distributed Denial of Service) attacks, or financial fraud.<\/p>\n<p data-start=\"527\" data-end=\"856\">Among the companies affected by cyberattacks, 41% experienced denial-of-service (DDoS) attacks, and around 40% incurred financial losses resulting from fraud (i.e., payment diversions through fraudulent emails). There have also been reports of cryptocurrency mining incidents, as well as loss of encrypted data.<\/p>\n<p data-start=\"858\" data-end=\"1095\">In addition to the direct consequences of cyberattacks, there are collateral impacts related to greater difficulty in acquiring new clients and the inadvertent breach of third-party partners\u2019 data, reported by 30% of companies.<\/p>\n<p data-start=\"1097\" data-end=\"1317\">Indeed, beyond direct losses, the repeated impact of such incidents is strategic: loss of clients, damage to brand reputation, and a substantial increase in costs associated with notifications and recovery efforts.<\/p>\n<p data-start=\"1319\" data-end=\"1484\">After a company suffers a cyberattack, with all the resulting strategic and financial consequences, the central question arises: who is liable for the damages?<\/p>\n<p data-start=\"1486\" data-end=\"1732\">Under the applicable legislation, organisations that fail to demonstrate appropriate technical and organisational measures may be held civilly liable for losses suffered by clients or partners, as well as being subject to significant fines.<\/p>\n<p data-start=\"1734\" data-end=\"1937\">The only possible ground for exemption from liability lies in proving that the attack was unforeseeable and unavoidable, and that all implemented security best practices were duly verified.<\/p>\n<p data-start=\"1939\" data-end=\"2151\">Beyond the technical response, this reality requires companies to undergo a paradigm shift: cybersecurity is no longer merely a protective measure \u2014 it has become a governance and compliance obligation.<\/p>\n<p data-start=\"2153\" data-end=\"2523\">The adoption of clear internal policies, regular audits, and incident response plans now constitute essential elements of legal and commercial defence. In a time when reputation is as valuable an asset as capital, compliance has become the new line of corporate defence. In digital litigation, prevention remains the most effective form of defence.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyberattacks have ceased to be a hypothetical and marginal risk and have become a strategic threat to Portuguese companies. According to the Hiscox Cyber Readiness Report 2025, more than half (54%) of Portuguese SMEs suffered at least one attack in the past year \u2014 including data loss, DDoS (Distributed Denial of Service) attacks, or financial [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":30109,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-30649","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sem-categoria","areas-litigation","areas-technology"],"acf":[],"jetpack_featured_media_url":"https:\/\/www.caiadoguerreiro.com\/wp-content\/uploads\/2025\/10\/CEF-SJ-WEBSITE-SJ-MRR-MPS-2.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/posts\/30649","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/comments?post=30649"}],"version-history":[{"count":3,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/posts\/30649\/revisions"}],"predecessor-version":[{"id":30652,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/posts\/30649\/revisions\/30652"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/media\/30109"}],"wp:attachment":[{"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/media?parent=30649"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/categories?post=30649"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.caiadoguerreiro.com\/en\/wp-json\/wp\/v2\/tags?post=30649"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}