Summary
- Nomios has completed the acquisition of Porto-based Orbcom, which employs around 80 people and reports roughly €15 million in annual revenue.
- The deal gives Nomios its first Portuguese operation and expands its Southern European security-services footprint.
- European security-services consolidation is combining local engineering capacity with larger managed-service, consulting, and vendor ecosystems.
Pan-European security provider Nomios has acquired Portuguese cybersecurity and infrastructure specialist Orbcom, establishing its first operation in Portugal and extending a consolidation strategy across the European services market.
Orbcom has around 80 full-time equivalent staff and approximately €15 million in annual revenue, according to Nomios. Founded in 2002 and headquartered in Porto, it also operates from Braga, Lisbon, and Lamego and supports more than 250 customers across sectors including energy, healthcare, automotive, retail, and education.
The company specialises in secure network infrastructure and cybersecurity and holds partner relationships with Palo Alto Networks, Netskope, Infoblox, Arista, and Cisco. Nomios said Orbcom will continue operating under the leadership of founder Hélder Costa, who becomes Nomios managing director for Portugal.
Financial terms were not disclosed. The transaction completed during September.
The acquisition gives Nomios a local base in a market where enterprise security increasingly combines product integration, consulting, and continuously operated services rather than one-off deployments. Nomios organises its wider business around consulting, professional services, and managed security and network operations.
That model has become increasingly common across Europe as customers attempt to manage a growing collection of security technologies while facing shortages of specialist engineering and operational staff. Managed detection, network security, secure access service edge, privileged access, and exposure management often require ongoing integration work in addition to the underlying licences.
Orbcom’s relationships are particularly concentrated around network and cloud security. Nomios cited SASE, extended detection and response, network security, and privileged access management among the segments in which it expects Portuguese demand to grow.
The deal also continues Nomios’ wider expansion. The group operates across multiple European markets and has used acquisitions to add capabilities as well as geography. In 2025, it acquired identity and access management specialist Intragen, broadening a portfolio that already covered security architecture, networking, managed services, and operational support.
Services consolidation can simplify access to expertise for organisations operating across borders, but it also changes the dependency picture. As customers concentrate more security operations with fewer strategic providers, questions around service continuity, subcontractors, skills retention, access privileges, and incident escalation become part of supplier governance.
That is especially relevant as NIS2 and DORA place increasing attention on third-party dependencies and the resilience of outsourced technology functions. The regulatory obligations vary by sector and arrangement, but the wider direction is towards greater visibility of the suppliers supporting critical operations.
Orbcom’s local management and staff are being retained, while Costa and several members of the management team will become shareholders in the wider Nomios group. The structure gives Nomios a Portuguese platform without replacing the acquired company’s local technical organisation.
For the European cybersecurity market, the deal is another example of scale being built through combinations of local engineering depth, vendor relationships, and managed-service capacity. The commercial rationale is expansion, but the resulting providers are also becoming more embedded in the infrastructure and security operations their customers depend on.





