Back to the radar Cybersecurity

Quando a cibersegurança fala difícil, o conselho decide mal

Por Gabriel Vieira e Robson Costa A cibersegurança tem um espaço cada vez mais relevante nas agendas estratégicas das empresas. Mas uma pesquisa recente do Gartner mostrou que 90% dos conselheiros acreditam que a cibersegurança atual não entrega o nível correto de proteção, evidenciando uma lacuna entre os investimento…

Por Gabriel Vieira e Robson Costa A cibersegurança tem um espaço cada vez mais relevante nas agendas estratégicas das empresas. Mas uma pesquisa recente do Gartner mostrou que 90% dos conselheiros acreditam que a cibersegurança atual não entrega o nível correto de proteção, evidenciando uma lacuna entre os investimento…

Em contexto

  • Tema: Ciberseguridad — Riesgo, identidad, respuesta a incidentes y cumplimiento.
  • Fonte: IT Forum
  • Publicado: 27/08/2026

Continuar lendo na fonte original →

Trecho publicado automaticamente pelo radar do site. O texto completo pertence ao veículo e está vinculado acima.

Why it matters

In security the story is rarely the attack. It is the time between the intrusion and somebody noticing. That number says more about an organisation than any certificate hanging on the reception wall.

My way of reading these cases is to ask what failed in the process, not what failed in the machine. Behind nearly every incident there is a reasonable decision taken under pressure: granting a permission to unblock somebody, postponing an update because it was month-end. That is where the lesson lives.

What usually goes wrong

The most expensive blind spot is usually the supplier. The organisation hardens its own perimeter and grants broad access to a third party that has half those controls. A good share of the incidents I have seen in this region came in that way, and the contract said nothing about it.

What to watch

  • How long it took to detect, usually the most revealing metric in the whole case.
  • Whether initial access came from a legitimate account handled badly, which is the most frequent pattern.
  • What could be restored and how fast — a backup that was never tested does not count.

How I read this entry

I would use it for a conversation with the board, not with the technical team. The question you must be able to answer there is how long the business can operate without its systems and what each day of that outage costs. With that number, the security budget gets discussed differently.

The original story is published in another language; the excerpt is quoted as the publisher delivers it and the commentary is written in English.
Share
Source. IT Forum

Living through this in your own team?

Open the chat and tell me how you're handling it. I'm interested in comparing notes.

Keep reading

More entries from the radar

See all
Darinel Ortega Online · I reply during the day
Today
Hello. I'm not selling anything here: this is for exchanging knowledge about technology.
Write whatever you like — you can send text, images or documents. Messages reach my console and I reply from there.

An open conversation to share knowledge. Messages reach my console and I reply from there.

Let us book a conversation

Pick the day and time that work for you. Thirty minutes, no sales pitch.

Video call

For a video call, just ask for one here and I'll send you the session link.