< Back to all clusters
[TECHNOLOGY] · Brazil · 2 sources

started · updated

Cybersecurity maturity remains low among Brazilian companies

Brazilian companies are facing significant challenges in cybersecurity maturity, often prioritizing the purchase of tools like firewalls and antivirus software over comprehensive risk diagnosis. According to the Cisco Cybersecurity Readiness Index 2025, only 5% of Brazilian companies have reached a mature level of cybersecurity, a figure that remains unchanged from previous studies.

Even publicly traded companies listed on the B3 exchange show a lack of maturity, receiving an average score of 4.9 out of 10 in a survey by Abrasca and the Security Design Lab. This suggests that increased spending on security technology is not translating into improved protection due to a lack of structured processes to map specific vulnerabilities.

Furthermore, legal uncertainty in Brazil complicates information security management. The lack of clear regulatory frameworks for modern security practices, such as bug bounty programs, often leads to lengthy legal reviews that delay critical security updates. While laws like the LGPD and Central Bank regulations exist, the absence of specific guidance for emerging security models creates friction between technical teams and legal departments.

Entities

ABRASCA · ANPD · B3 · Cisco