Por Gabriel Vieira e Robson Costa A cibersegurança tem um espaço cada vez mais relevante nas agendas estratégicas das empresas. Mas uma pesquisa recente do Gartner mostrou que 90% dos conselheiros acreditam que a cibersegurança atual não entrega o nível correto de proteção, evidenciando uma lacuna entre os investimento…
Por Gabriel Vieira e Robson Costa A cibersegurança tem um espaço cada vez mais relevante nas agendas estratégicas das empresas. Mas uma pesquisa recente do Gartner mostrou que 90% dos conselheiros acreditam que a cibersegurança atual não entrega o nível correto de proteção, evidenciando uma lacuna entre os investimento…
Em contexto
- Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
- Fonte: IT Forum
- Publicado: 27/08/2026
Continuar lendo na fonte original →
Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.
Why it matters
In security the story is rarely the attack. It is the time between the intrusion and somebody noticing. That number says more about an organisation than any certificate hanging on the reception wall.
My way of reading these cases is to ask what failed in the process, not what failed in the machine. Behind nearly every incident there is a reasonable decision taken under pressure: granting a permission to unblock somebody, postponing an update because it was month-end. That is where the lesson lives.
What usually goes wrong
The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.
What to watch
- How long it took to detect, usually the most revealing metric in the whole case.
- Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.
- What could be restored and how fast — a backup that was never tested does not count.
How I read this entry
I would use it for a conversation with the board, not with the technical team. The question you must be able to answer there is how long the business can operate without its systems and what each day of that outage costs. With that number, the security budget gets discussed differently.
The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Living through this in your own team?
Open the chat and tell me how you're handling it. I'm interested in comparing notes.