Back to the radar Cybersecurity

CISO Advisor e Pimenta Comunicação organizam evento de cyber

Cybersecurity

O CISO Advisor e a Pimenta Comunicação organizaram, na última quarta-feira (19 de agosto) em São Paulo, o Identity & Business Day da Veridas, um encontro que reuniu líderes do setor financeiro e de segurança para debater autenticação digital, biometria e prevenção a fraudes.

O CISO Advisor e a Pimenta Comunicação organizaram, na última quarta-feira (19 de agosto) em São Paulo, o Identity & Business Day da Veridas, um encontro que reuniu líderes do setor financeiro e de segurança para debater autenticação digital, biometria e prevenção a fraudes.

Em contexto

  • Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
  • Fonte: CISO Advisor
  • Publicado: 21/08/2026

Continuar lendo na fonte original →

Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.

Why it matters

Every time I read a case like this I think the same thing: security is not bought, it is operated. You can own every tool on the market and remain exposed if nobody reviews the alerts, if patches get applied when there is time, or if the backup was never tested by actually restoring it.

My way of reading these cases is to ask what failed in the process, not what failed in the machine. Behind nearly every incident there is a reasonable decision taken under pressure: granting a permission to unblock somebody, postponing an update because it was month-end. That is where the lesson lives.

What usually goes wrong

The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.

What to watch

  • Whether third parties or suppliers were in the chain, because the perimeter now includes partners.
  • How long it took to detect, usually the most revealing metric in the whole case.
  • Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.

How I read this entry

If this happened near an organisation I advise, the conversation I would force is not about tools. It is about the rehearsal. How many times the incident was simulated, who calls whom, what gets said to customers and when. A plan never rehearsed is not a plan, it is a document.

The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Share

Living through this in your own team?

Open the chat and tell me how you're handling it. I'm interested in comparing notes.

Keep reading

More entries from the radar

See all
Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.