O CISO Advisor e a Pimenta Comunicação organizaram, na última quarta-feira (19 de agosto) em São Paulo, o Identity & Business Day da Veridas, um encontro que reuniu líderes do setor financeiro e de segurança para debater autenticação digital, biometria e prevenção a fraudes.
O CISO Advisor e a Pimenta Comunicação organizaram, na última quarta-feira (19 de agosto) em São Paulo, o Identity & Business Day da Veridas, um encontro que reuniu líderes do setor financeiro e de segurança para debater autenticação digital, biometria e prevenção a fraudes.
Em contexto
- Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Fonte: CISO Advisor
- Publicado: 21/08/2026
Continuar lendo na fonte original →
Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.
Why it matters
Every time I read a case like this I think the same thing: security is not bought, it is operated. You can own every tool on the market and remain exposed if nobody reviews the alerts, if patches get applied when there is time, or if the backup was never tested by actually restoring it.
My way of reading these cases is to ask what failed in the process, not what failed in the machine. Behind nearly every incident there is a reasonable decision taken under pressure: granting a permission to unblock somebody, postponing an update because it was month-end. That is where the lesson lives.
What usually goes wrong
The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.
What to watch
- Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
- How long it took to detect, usually the most revealing metric in the whole case.
- Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.
How I read this entry
If this happened near an organisation I advise, the conversation I would force is not about tools. It is about the rehearsal. How many times the incident was simulated, who calls whom, what gets said to customers and when. A plan never rehearsed is not a plan, it is a document.
The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.