Viriatus
Viriatus is an AI-driven cybersecurity platform from a Portuguese publisher that unifies attack surface management, GRC and a virtual CISO across nine modules, for NIS2-, DORA- and ISO 27001-bound organizations requiring European-controlled hosting. Sold by quotation only.
What is Viriatus?
Viriatus is an Attack Surface Management (ASM) and Governance, Risk & Compliance (GRC) platform deployed on controlled infrastructure, published by CyberS3C, a Portuguese company based in Loures. The home page announces nine integrated modules behind a single interface; eight are detailed on the platform page.
External Surface performs passive and active subdomain enumeration through Certificate Transparency, DNS, crawling and brute force, plus technology fingerprinting, WHOIS/DNS/SSL domain intelligence, geographic server mapping and a security score. Internal Surface builds an endpoint inventory with health scores, correlates CVEs against the software inventory, classifies assets on confidentiality, integrity and availability, and records agentless assets such as printers, CCTV, IoT, SCADA and medical devices. The Firewall module adds a threat dashboard, traffic analysis, user behaviour anomaly detection and an interactive network graph aimed at command-and-control traffic, exfiltration and lateral movement. Vulnerabilities correlates external and internal findings, scores them with CVSS v3.1, EPSS and CISA KEV, ranks them P1 to P4 and counts public exploits in Exploit-DB, Metasploit and GitHub proofs of concept. Incidents implements the ten-class CNCS taxonomy, a twelve-state lifecycle, a real-time War Room, automated playbooks, a four-phase NIS2 notification workflow, a public status page and blameless post-mortems. GRC carries a complete FAIR model — threat event frequency, threat capability, resistance strength, primary and secondary losses, annualized loss expectancy in euros — with Monte Carlo simulation over 10,000 iterations, VaR 95 and CVaR 95, sensitivity analysis, what-if scenarios, ISO 22301 business impact analysis, multi-framework compliance covering NIS2, GDPR, ISO 27001 and PCI DSS, and DORA supplier management. vCISO answers on the organization's real data through retrieval-augmented generation, in a structured format running from executive summary to prioritized recommendations, with cited sources and an automatic daily digest. Probus, announced in version 3.2 in April 2025, runs autonomous AI penetration testing around the clock with TTP simulation and PDF reporting.
The platform aligns with NIST CSF, MITRE ATT&CK, FAIR, ISO 27001 and CIS Controls v8, scans every ten minutes and deploys through Docker, PM2 and Nginx on CyberS3C infrastructure over VPN or on the customer's own servers. The product was called TYRSO until the VIRIATUS rebranding of March 2024 and was rewritten in version 3.0 in November 2024; the name comes from Viriathus, the Lusitanian leader who resisted Rome between 147 and 139 BC. It is not a SIEM replacement: the publisher presents it as a complement to existing detection tooling.
What it does
- Discover and map the external attack surface: subdomains, IP addresses, technologies, SSL/TLS posture and reputation.
- Inventory the internal estate through multi-vendor XDR/EDR integration, including agentless assets.
- Prioritize vulnerabilities with CVSS v3.1, EPSS and CISA KEV scoring into P1 to P4 tiers.
- Run continuous autonomous penetration testing with evidence-backed exploit validation.
- Quantify risk in euros with FAIR modelling and 10,000-iteration Monte Carlo simulation.
- Drive the CNCS/NIS2 incident notification workflow across four phases with automatic deadlines.
- Question an AI vCISO grounded in the organization's own data, with cited sources.
When to use Viriatus / When not to
A quick filter to help you decide if Viriatus is the right fit.
When to use Viriatus
- Organizations in scope of NIS2, DORA or Portugal's DL 65/2021 that must document compliance and notify incidents within statutory deadlines.
- Small IT and security teams — the publisher's public administration case study describes three people with no dedicated cyber training — that need external and internal coverage without extra headcount.
- Security and risk leaders who want exposure expressed in euros through FAIR modelling and Monte Carlo simulation rather than high/medium/low matrices.
- Public administration, healthcare, financial services, manufacturing, telecom and education bodies that require data to stay on European infrastructure or on their own servers.
- MSSPs, resellers and technology partners, through a partner programme with Authorized, Gold and Platinum tiers carrying up to 20% additional margin.
When not to use Viriatus
- Very small companies and independent professionals: there is no free plan and no announced trial, and the only public figure is an entry point from EUR 6,000 per year excluding VAT.
- Buyers who want to sign up and evaluate on their own: the only route in is a demo request or a sales conversation, with no self-service access.
- Teams looking to replace a SIEM: the publisher positions Viriatus as a complement focused on attack surface, vulnerabilities and GRC.
- Development or integration teams that need documented, supported APIs: no API documentation is published, only a changelog line announcing a REST API for external integrations.
- Users who need mobile apps or an interface beyond Portuguese and English: no iOS or Android application is offered and the site and documentation exist in those two languages only.
How to use Viriatus
A typical end-to-end flow, from setup to results.
- Request a demonstration or contact sales through the contact form: there is no self-service sign-up.
- Choose the deployment mode: hosted on CyberS3C infrastructure with VPN access, or deployed on your own infrastructure.
- Deploy the stack — Docker, PM2 and Nginx — with the VPN configured; the publisher announces a typical installation in under an hour.
- Configure the organization and connect the security tools, around fifteen minutes on the publisher's timeline; XDR/EDR integration is optional, since external surface, firewall and GRC can be used alone.
- Let external surface discovery run: first subdomain results are announced at around one hour.
- Build the internal endpoint inventory, announced at around two hours.
- Run the first vulnerability scan with CVSS, EPSS and KEV scoring, announced at around three hours.
- Configure the NIS2/CNCS notification workflow with its automatic deadlines, announced at around four hours.
- Read the first vCISO report at around eight hours and the first Probus penetration testing cycle at around twelve; the publisher claims full visibility at twenty-four hours.
- Train the team through the certification tracks if needed: VCA (8 h), VCP (16 h) and VCE (24 h), each with a 40-question exam, a 70% pass mark and two-year validity.
Pros & Cons
Pros
- Broad coverage in a single product: external and internal ASM, firewall analytics, vulnerabilities, incidents, GRC, vCISO and autonomous penetration testing.
- Risk quantified in euros through FAIR, Monte Carlo, VaR 95, CVaR 95, sensitivity analysis and what-if scenarios, where many tools stop at qualitative matrices.
- Built-in NIS2/CNCS regulatory workflow with four notification phases and automatic deadline calculation.
- Data sovereignty: hosting on European territory or on the customer's own infrastructure, with the AI engine executed locally.
- Explicit commitment that customer data is never used to train models.
- Multi-vendor integrations claimed for XDR/EDR tools and for firewalls from any manufacturer, through log ingestion and APIs.
- Fast start claimed — deployment in under an hour, scanning every ten minutes — and a subprocessor list published with locations and legal bases.
Cons
- No per-tier pricing: the three plans all display “Custom - Contact us for a quote”, and the only public amount comes from a home page comparison block.
- No free plan and no announced free trial; the only free access is a commercial demonstration.
- No public API documentation, although the changelog has announced a REST API for external integrations since March 2024.
- No data processing agreement published or offered, which is unusual for a regulated target audience.
- No legal notice page, and a company name that differs between the terms (“Viriatus, Lda.”) and the privacy policy (“CyberS3C - Cybersecurity Artisans, Lda.”).
- A single contact address, hello@cybersec.pt, for legal, GDPR and support requests, hosted on a third-party domain rather than viriatus.eu.
- Outcome figures such as 47 subdomains discovered, 89% faster response or 95% savings on external penetration tests are given without a named customer or methodology, home page counters read zero in the static HTML, and no Wayback capture exists to date the site.
Pricing & Plans
There is no free plan and no announced free trial; the only free access is a commercial demonstration. The pricing page lists three plans — Essencial, Avançado and Enterprise — each displayed as “Custom - Contact us for a quote” with a “Contact Sales” call to action, so no per-tier amount is public. The only published figure appears in the home page comparison block, which states an annual Viriatus cost from EUR 6,000; the same block sets it against an estimated annual cost above EUR 85,000 without the platform and external penetration tests at EUR 25,000 per year. The pricing page adds that all prices exclude VAT, are stated in EUR, and that annual billing carries a discount of up to 27%. Probus, the continuous penetration testing module, is presented as included at no extra cost.
- up to 50 assets
- 3 users
- 48-hour response SLA
- covering external surface and vulnerability management only. Price displayed as Custom.
- up to 100 assets
- 10 users
- 24-hour response SLA
- adding internal surface through XDR/EDR integration and incident management. Price displayed as Custom.
- unlimited assets and users
- 4-hour response SLA
- adding firewall analytics
- full GRC
- the AI vCISO
- FAIR with Monte Carlo simulation and the War Room. Price displayed as Custom.
- XDR/EDR integration
- endpoint inventory and internal vulnerabilities are absent from Essencial
- while firewall analytics
- the network graph
- the War Room
- FAIR/Monte Carlo and the vCISO are reserved for Enterprise. All three tiers are quoted individually.
Data, GDPR & hosting
A consolidated view of how Viriatus handles your data.
GDPR overview
GDPR implementation is documented in detail. The privacy policy is built on the regulation: fourteen sections, Article 6 legal bases (consent, legitimate interest, performance of the contract) and seven data subject rights — access, rectification, erasure, restriction, portability, objection and withdrawal of consent — with a stated 30-day response time through hello@cybersec.pt. The Portuguese supervisory authority, CNPD, is named. Subprocessors are listed with their locations: HubSpot in the EU1 region, Google Analytics 4 and reCAPTCHA v3, which may process on Google LLC servers in the United States under the EU-US Data Privacy Framework and standard contractual clauses. Security measures cited include HTTPS/TLS, CSP, HSTS, X-Frame-Options and Permissions-Policy headers, restricted access controls and regular vulnerability monitoring. No data protection officer is named, no Article 27 representative applies since the publisher is established in the EU, and no data processing agreement is mentioned anywhere on the site.
Who owns the data?
The privacy policy, last updated in April 2026, names CyberS3C - Cybersecurity Artisans, Lda., Passeio das Ilhas n.º3 Loja B, 2670-322 Loures, Portugal, as the data controller, while the terms of service attribute the platform's intellectual property to Viriatus, Lda. The publisher states that personal data is never sold, rented or shared with third parties for direct marketing purposes. The platform runs either on CyberS3C infrastructure reached over VPN or on the customer's own infrastructure, and in both cases data stays in European territory and is never shared with third parties. The policy covers the website only: it does not set out who owns or controls the customer data processed inside the platform.
Reuse rights
The published terms define the service and reserve the platform's intellectual property to Viriatus, Lda.; no clause found on the site grants or restricts the reuse of exported customer data, so that point remains contractual ground to settle with the publisher. What the site does document is how the publisher itself uses data. In the vCISO module, customer data is retrieved and injected into the query context through retrieval-augmented generation and is never used to train models; the AI engine runs locally on controlled infrastructure and does not retain data. Website data serves enquiry handling, CRM, web analytics, anti-spam protection, the newsletter and legal obligations, under consent (Art. 6(1)(a)), legitimate interest (Art. 6(1)(f)) and performance of the contract (Art. 6(1)(b)).
Data retention & training
Hosting summary
The privacy policy states that the website is hosted on infrastructure located within the European Union, without naming a country. The platform itself operates entirely on controlled European infrastructure, either on CyberS3C's own infrastructure reached over VPN or on the customer's infrastructure; in both cases the publisher states that data stays in European territory and is never shared with third parties. Among the declared subprocessors, HubSpot sits in the EU1 region, Google Analytics 4 in the EU/EEA with IP anonymization, and the cPanel host in the EU, while Google reCAPTCHA v3 is global. Analytics and reCAPTCHA may therefore process on Google LLC servers in the United States, covered by the EU-US Data Privacy Framework and standard contractual clauses. No hosting country is ever named, so only a regional commitment can be verified, not a country-level one. As a network observation outside the publisher's declarations, the domain resolves to 94.46.22.172, geolocated in Lisbon on AS24768 (Almouroltec).
Things to keep in mind
Risks and trade-offs to weigh before adopting Viriatus.
- The contracting entity is unclear: the terms name “Viriatus, Lda.” while the privacy policy names “CyberS3C - Cybersecurity Artisans, Lda.”. There is no legal notice page and no company registration number is displayed, so the signing entity should be confirmed before contracting.
- No data processing agreement is published or offered anywhere on the site, and the privacy policy covers the website only, not the customer data processed inside the platform — an awkward gap for NIS2, DORA, healthcare or public sector buyers who must document their processors.
- Pricing is opaque: per-tier amounts are not published and the single public figure of EUR 6,000 per year comes from a home page comparison block, not from the pricing page, so budget planning rests on a quotation you do not yet have.
- One address, hello@cybersec.pt, on a third-party domain, handles legal, GDPR and support requests alike — a single point of contact for a rights request, a support ticket and a breach notification.
- ISO 27001, NIST CSF, MITRE ATT&CK and CIS v8 are frameworks the platform covers and aligns with; the site claims no certification held by the publisher, and the distinction should not be blurred in an internal risk assessment.
- Claimed outcome figures — 47 subdomains discovered, 423 endpoints, 89% faster response, 95% savings on external penetration testing — come with no named customer and no methodology; home page counters display zero in the static HTML and the domain has no Wayback capture, leaving the site's track record undatable.
- Automation invites over-reliance: an AI vCISO answering from your own data inherits that data's blind spots, and an autonomous penetration tester can create a false sense of exhaustiveness. A three-person team that stops questioning a prioritization it did not perform loses the very judgement the tool is meant to support, so keep human review over P1 decisions and regulatory filings.
Setup & Integrations
Technical difficulty
Moderate to high, and never self-service: onboarding runs through the publisher. In hosted mode, CyberS3C operates the platform and the customer configures VPN access, integrations and the organization profile, which is largely administrative work. In self-hosted mode the customer runs the Docker, PM2 and Nginx stack, so system and network administration skills are required. Connecting XDR/EDR tools and firewalls through log ingestion and APIs assumes familiarity with those consoles. The publisher announces a typical installation in under an hour and full visibility within 24 hours, and offers VCA, VCP and VCE certification tracks of 8, 16 and 24 hours.
Deployment
Integrations
Behind Viriatus
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does Viriatus replace a SIEM?
Is a specific XDR/EDR solution required?
Where is the data hosted?
What separates the Essencial, Avançado and Enterprise plans?
Does the vCISO train models on customer data?
Is NIS2 supported?
How is the platform deployed?
Which firewalls can be integrated?
Is there a free plan or a free trial?
What is the entry price?
Should you pick Viriatus?
Viriatus is an unusually broad product for a small publisher: external and internal attack surface management, firewall analytics, vulnerability prioritization, incident response, GRC and an AI vCISO in one platform, with an openly European regulatory angle covering NIS2, DORA, GDPR and ISO 27001. Two elements stand out as verifiable on the site: risk quantified in euros through FAIR and Monte Carlo rather than colour-coded matrices, and an explicit commitment that customer data is never used to train models, with the AI engine running locally on controlled infrastructure. Portugal Digital Awards 2024 and INNCYBER 2024 distinctions are claimed on the same pages.
The counterweight is opacity and youth. All three plans are quoted individually, and the only public figure — from EUR 6,000 per year excluding VAT — comes from a home page comparison block rather than the pricing page. There is no free plan, no announced trial, no self-service route, no public API documentation despite a REST API announced in the March 2024 changelog, and no data processing agreement anywhere, which is unusual for a buyer base regulated by definition. Signs of youth accumulate: no Wayback capture for the domain, home page counters displaying zero, and a company name that differs between the terms and the privacy policy.
The platform suits regulated organizations with small security teams that need breadth and evidence more than depth in a single discipline, and those that require European hosting or self-hosting. Before committing, settle three points with the publisher: which legal entity signs the contract, whether a data processing agreement and platform-level retention terms can be provided, and what the real quotation is for your asset and user count. Note also that ISO 27001, NIST CSF and CIS v8 are frameworks the platform covers, not certifications the publisher claims to hold.
- Choosing a selection results in a full page refresh.
- Opens in a new window.