Cybersecurity services in Portland.
Secuur provides security testing to Portland, Oregon organisations across manufacturing and supply chain, software and SaaS, retail, e-commerce and payments. Oregon requires breach notification 45 days, and OCPA is in force. Every engagement includes an A–F post-quantum readiness grade.
The Portland risk profile
Portland is a semiconductor and advanced-manufacturing corridor with a growing software and consumer brand presence. Security work here is shaped by that mix more than by anything generic about company size or headcount.
Manufacturing and supply chain
Manufacturing combines high downtime cost with long-lived equipment and a deep supplier network, which is an unusually attractive combination. Ransomware operators price the ransom against a production line, and the same flat networks that make plant operations simple make lateral movement trivial once a foothold exists.
Software and SaaS
For a software company the security boundary is the product itself. Multi-tenant isolation, authorisation logic, SSO and OAuth flows, webhook handlers and the CI/CD pipeline that ships all of it are where real findings live — and none of them are visible to a scanner that only checks for known CVEs. Broken object-level authorisation remains the single most common serious finding in modern application testing.
Retail, e-commerce and payments
The cardholder data environment is the obvious target, but the more common breach path now runs through the web front end: a compromised third-party script skimming a checkout page, an exposed admin route, or an API that trusts a client-side price. Digital skimming succeeds precisely because it does not touch the systems most monitoring is pointed at.
What Oregon law expects of you
Security testing is not a compliance exercise, but in Oregon the legal clock is what turns an unnoticed weakness into a reportable event with a deadline attached. Knowing the timeline in advance is what lets you decide how fast findings need to be remediated.
| Obligation | Requirement in Oregon |
|---|---|
| Consumer notification deadline | 45 days |
| Regulator notification | AG notice within 45 days when 250+ residents are affected. |
| Comprehensive privacy statute | Oregon Consumer Privacy Act (OCPA) — in effect |
The 30-day right to cure expired on 1 January 2026.
The practical consequence for Portland businesses is straightforward: a breach you discover on a Friday starts a clock that runs in calendar days, not business days. Testing exists to find the exposure before that clock ever starts — and to give you documented evidence of diligence if it does.