Brazil introduces cyber maturity model and boosts telecom security compliance
The National Cybersecurity Committee (CNCiber) unveiled the CIMBRA (CiberMaturidade Brasileira) framework to assess cyber‑maturity across Brazil's public and private sectors. CIMBRA‑N measures the country's overall cybersecurity capability across eight thematic axes with six maturity levels, while CIMBRA‑I evaluates individual institutions using 14 axes tailored to service criticality. The goal is to create a national standard for identifying vulnerabilities, protecting critical infrastructure, and tracking digital security progress.
The National Telecommunications Agency (Anatel) reported rapid adoption of the R‑Ciber regulation, which mandates audited Cybersecurity Policies for telecom equipment suppliers. Within seven months, certified bodies rose 25%, audit attestations grew 23%, audited manufacturers increased 35%, and product categories covered expanded 28%. "The growth observed in just seven months shows the audit model is being absorbed by the supply chain," said CNCiber adviser Edson Holanda. Anatel also began monitoring telecom operators' own security policies to build an integrated view of supply‑chain risk, underscoring a shift from formal compliance to routine security governance.