Portugal's biggest telecoms operator was knocked over three times in one night by a DDoS attack
MEO says the outages were a distributed denial-of-service attack and that no data was accessed. Under the cybersecurity regime in force since April, the operator now owes a 24-hour notification, a 72-hour update and a final report within 30 working days.
If your internet and television dropped out three separate times between Monday night and Tuesday morning, that was not a fault on the line. MEO’s own technical analysis points to a distributed denial-of-service attack aimed at its infrastructure, with enough traffic thrown at it to congest the network and degrade service temporarily.
The operator was precise about two things. Nobody got into the data, its own or its customers’. And the instability in BGP routing that the technical community spotted first, and that looked like the origin of the trouble, was a consequence of the attack rather than its cause. Service is stable again, and the incident has been reported to the National Cybersecurity Centre.
Which is where a bad night turns into a calendar.
The regime that changed the maths in April
Before 3 April this year, an operator hit by a DDoS mainly had to fix it and face its customers. Since then Portugal has been running the cybersecurity legal regime that transposes the EU’s NIS2 directive, and it treats electronic communications companies as essential entities — the most demanding category the law has.
For those entities a significant incident does not close with a press line. Article 42 requires an initial notification without undue delay and within 24 hours of the company concluding that a significant incident exists. An update follows within 72 hours, carrying an initial assessment of severity and impact. When the significant impact ends, article 43 allows another 24 hours to say so. Then comes the final report.
Thirty working days, which is not thirty days
That final report is the deadline almost everyone miscounts. Article 44 does not say thirty days. It says 30 working days, and it starts the clock from the end-of-impact notification rather than from the incident itself. If MEO filed that notification this week, as the stabilisation suggests, the report falls due in late October — weekends and the 5 October public holiday push it well past where a quick reading of “30 days” would land.
It is worth knowing what has to be in it, because that is the difference between a statement and an account: the date and time the incident became significant, the date and time it stopped being significant, the impact, the threat type and likely cause, and the mitigation applied.
And who actually receives it
The intuitive answer is the CNCS, and that is what MEO says it did. The law is a little tidier than that. Article 15 creates sectoral cybersecurity authorities and hands electronic communications and postal services expressly to ANACOM — the same regulator that already wants operators to pay you back when a switch leaves you offline, now holding cybersecurity supervision as well.
What sits at the far end of a missed deadline is real money. For an essential entity, the most serious offences run from €2,000 to €10 million or 2% of worldwide annual turnover, whichever is higher. The tier below tops out at €5 million or 1%.
None of which says MEO has failed at anything. It says that in a country where nearly half of all fixed lines now run at 1 Gbps, the conversation about a night without a network no longer ends the next morning. It has dates on it now.
By Oliver Grant
Photo: MarcoTangerino / Wikimedia Commons (public domain)