Cybersecurity in Brazil in 2023

For many years, concern about technological resources and digital security within companies was not a priority. However, cybersecurity has reached a level of extreme importance within companies, mainly due to the advancement of digital transformation. The number of scams and cyber threats suffered by companies of all sizes and segments is constantly growing in Brazil . This advancement demonstrated that investing in cybersecurity has become a priority for all businesses.

With increasingly efficient tools and complete resources that contribute to carrying out a company's day-to-day activities, businesses have been implementing solutions that help optimize the service and guarantee a prominent role in the market . Increased competition has meant that companies need to find ways to stand out and guarantee a competitive edge, especially when it comes to modernization and technological revolution.

However, at the same time as the tools that improve our activities and bring more practicality to everyday life, strategies used to divert confidential information, harm devices, and cause an immense negative impact on companies are also advancing.

We can see that, although government agencies and large companies constantly invest in solutions that help block these threats, this growth is not as significant in smaller companies. This lack of support for the technological resources of these companies makes them easy targets for cybercriminals, potentially compromising the confidentiality of their data and the privacy of customers, partners and employees.

In this material that we have prepared for you, we will address relevant topics, such as:

What is cybersecurity?

In a simplified way, cybersecurity consists of a set of techniques, strategies and methods used to protect technological resources, devices, networks and data against the actions of criminals. Through cybersecurity, the company can prevent the violation or leakage of this information.

Investments in cybersecurity have become essential for businesses that want to remain competitive in the market. This is because, in addition to a quality product and service, consumers also expect attention to the security of the information provided to companies. The more prepared your organization is to deal with this type of threat, the better your positioning and image will be in the market.

Companies that invest in cybersecurity are able to convey transparency and strengthen relationships and trust with their consumers. Among the strategies used to increase security within companies, we list the five main ones:

  1. Access monitoring: through this approach, the company is able to manage access permission and data traffic between employees and third parties, bringing greater confidentiality and security.
  2. Security guidance: it is essential that the company has clear objectives and goals regarding the protection of information, implementing cybersecurity resources in accordance with the company's demand and need for confidentiality.
  3. Encryption: the conversion of data that is stored and manipulated into encrypted codes allows only users who have permission and need to handle this information to gain access to this data.
  4. Backup strategy: we know that even with the implementation of all security tools available on the market, it is still not possible to guarantee that there will be no cyber attack. For this reason, it is essential that the company adopts a backup strategy to guarantee the continuity of its service even in the face of an attack .
  5. Software updates: Software updates are developed to ensure that these applications remain protected even in the face of the most modern threats available on the network . Performing these updates helps strengthen your cybersecurity strategy and keeps your data away from unauthorized users.

The evolution of cybersecurity in Brazil in 2023

In recent years, companies have become increasingly concerned about their digital security strategy , mainly due to the massive cyber attacks that have victimized businesses of all sizes. These attacks caused a lot of data to be made inappropriately available on the network and had a major negative impact on companies, which had their image damaged among consumers and their competition.

According to data from Fortinet, in 2022 alone Brazil suffered from 103.16 billion attempted cyber attacks . This data demonstrates an increase of 16% compared to the previous period, highlighting the need to be concerned with cybersecurity strategies that increase data security within companies.

Among these attacks, there are some approaches that deserve to be highlighted, such as ransomware attacks. This type of attack kidnaps confidential information and demands the payment of a sum, usually in bitcoins, so that this data can be returned. In addition to causing great financial loss, these attacks also demonstrate that the company is not prepared to deal with confidential information.

In 2022, ransomware attacks increased by 51% , placing Brazil in first place as the country that suffered the most cyber attacks in Latin America. In addition to this threat, a widely used strategy that also continues to claim victims is the phishing attack , which can be applied without sophisticated resources and cause immeasurable damage to users and companies.

In 2023, the main cybersecurity trend is the use of the security of technology resources used daily, such as cloud technology . It was also necessary to adopt protection tools, threat detection systems and network protection to guarantee an increasingly secure digital environment.

Developed to facilitate the adoption of efficient resources to protect information, the LGPD came into force in August 2021. This legislation provides specific rules regarding the collection, processing and storage of third-party information . Therefore, adapting to this legislation is one of the first steps for companies that wish to invest in cybersecurity and improve their positioning in the market.

The cyber threat landscape is constantly evolving. Cybercriminals seek every day to find new vulnerabilities both in company devices and networks and in the applications used . Because of this, it is essential to find solutions that help increase the security of your business and keep this information away from unauthorized access.

Main cybersecurity trends in Brazil and around the world

As we said previously, with more than 100 billion attempted cyber attacks in just one year in Brazil , national companies need to find more efficient ways to protect themselves. As a result, more complete tools were developed for an even more consolidated cybersecurity strategy.

These advances have delivered strategic solutions for companies of all sizes and segments, as we will see below:

Security for the internet of things

Currently, there are many devices that use the exchange of data and information to optimize our routine and bring more practicality, as is the case with the internet of things . These systems transmit information without the need for human intervention , so it was necessary to develop tools aimed at increasing protection during this transmission.

As a result, one of the main cybersecurity trends of 2023 is the monitoring of devices carried out through the internet of things. This monitoring is essential to evaluate not only performance but also the destination of the information that is constantly transmitted.

Security features for the home office

The pandemic caused several companies to adopt a home office in order to maintain their activities. Over time, many of these businesses noticed that this modality brought many benefits to both the company and the employee, and ended up definitively implementing the remote work regime.

However, since this device is connected far from the company's physical space, it has become essential to find tools to guarantee reinforced security , as is the case with Corporate VPN . With the help of these tools, it is possible to increase data protection and ensure that, even when working remotely, workers have all the protection resources necessary for their activity.

Artificial intelligence

Although artificial intelligence has become popular due to tools used to create photos and texts, this technology is much more complete than one might imagine. Following the growth of cyber attacks, artificial intelligence has been adding an additional layer of protection to provide a more efficient and secure operation.

The technology has been ensuring quick insights for more effective monitoring of possible vulnerabilities and attack attempts. Implemented in the access control and monitoring tools used by the company, Artificial Intelligence brought many benefits to the security strategy.

Global or local threats

When it comes to cybersecurity, 2023 was an extremely challenging year for businesses . The forecasts made available in the previous year already showed that it would be a phase of extreme vulnerability in relation to cyber attacks, highlighting the need to adopt more complete solutions.

The prediction made by the Cybersecurity Ventures report is that cybercrime has caused a cost of eight trillion dollars around the world, which could reach up to 10.5 trillion in 2025. Cybercrime has become not only a problem related to the confidentiality of information, but also a major financial threat to companies in all segments.

It is essential to remember that cyber threats can come from anywhere in the world and affect any company. There is no specific target audience in most cyber attacks, making it clear that cybersecurity strategies must be a priority for all businesses. In addition to adopting the best solutions available to increase your company's security, it is important that there is a change in your company's organizational culture focused on protecting information.

Discover the main cyber threats in Brazil

As mentioned above, there are countless cyber threats that can cause problems for your company. And in recent years, some of these attacks have gained prominence due to their massive application and the damage caused by them, as we will see below:


Ransomware is one of the cyber threats that scares companies and organizations the most. This is because, in addition to the kidnapping and the expectation of confidential information being leaked, the company may also suffer great financial loss.

This is because these cybercriminals improperly collect extremely confidential data and threaten its exposure unless the company pays a large amount. Generally this ransom payment must be made in Bitcoin, making it difficult to track and possibly identify the cybercriminal.

Security by obscurity

Although not exactly a cyber threat, this conduct can increase the risk of exposure for your business. This means that a lack of concern about possible vulnerabilities can expose your company to cyber attacks of enormous proportions.

To avoid this problem, in addition to implementing security tools, it is the company's responsibility to inform its employees about the risks and the best conduct to be adopted. The first step to strengthening your company's security is to assume that you cannot fully trust your current security strategy. Assuming that there is no risk of exposure is the main characteristic of obscurity security problems.

Theft of access credentials

Depending on your company's niche and the activity carried out, the access credential can be extremely valuable. Through it, criminals are able to access confidential data and misuse this information .

From this, the theft of credentials can encourage the application of other even more harmful scams, such as information leaks, ransomware and even the sale of data to illegal companies. All of these problems can have a major negative impact on your organization, especially on your consumers.


Phishing is a cyber problem that has been debated since the internet became popular. Through fake emails and links, cybercriminals can install malicious applications on your device , steal information or carry out other types of scams.

The main way to avoid this type of problem is to ensure that your employees are prepared to deal with possible difficult attempts, maintaining a constant education and awareness process. Anti-phishing training is essential, as your employees need to identify this type of scam to avoid the damage caused by it.

How local cybersecurity can be more effective

Cybersecurity is essential within a company that handles information and handles consumers' personal data . For this reason, it is essential to implement some actions that help increase protection against hackers and scammers.

To help you, we have put together some tips. Check it out below:

Conduct a complete assessment of your security

It will only be possible to implement more efficient solutions if managers have already mapped the current digital security situation and points of vulnerability within the company. Because, by evaluating the infrastructure, it is possible to identify possible points for improvement to avoid cyber threats.

The complete assessment can be carried out through a security audit and monitoring of the systems and applications used. To do this, you can count on more complete and efficient security tools, such as our security diagnosis and , completely free.

Team awareness

The team needs to be aware of good security practices that can help your company. Contrary to what many think, cybersecurity is not the exclusive responsibility of the IT sector.

In this sense, all employees in your company need to be aware of the best security practices to be implemented on a daily basis. Such as creating more robust passwords, avoiding opening suspicious links, knowing the best behavior on the internet, among others.

Systems update

Updates to systems and applications used by companies are developed to ensure that your business uses the most secure version of these products. Failure to carry out these updates could expose your company to vulnerabilities , as the application will not be prepared to deal with the most up-to-date threats.

Considering the constant advancement of strategies used by cybercriminals, failing to update applications and resources is a great risk. The company ends up creating points of vulnerability that are used by criminals in their invasion attempts.

Implementation of internet access policy

Contributing to the education process of your employees, the access policy must be developed based on all expectations and good practices that are expected by the company. All your employees must be informed about these practices so that they can be implemented in their daily lives.

This access policy must inform about the risk of accessing inappropriate pages during working hours, downloading files, improperly sharing information, and much more. The policy must be complete and take into account the company's needs and the reality experienced on a daily basis.

Considering that Brazilians are one of the biggest users of social networks in the world, spending around 3h 46m per day on these platforms , a large part of these accesses ends up being carried out during working hours, causing even more vulnerabilities for the company. Blocking certain types of access can help protect your company from multiple cyber scams.

Develop a response plan

As we mentioned, cyber threats evolve daily . For this reason, it is impossible to guarantee that no threat will be able to affect your organization, making it essential to develop a response plan.

This response plan must be developed based on all the protection measures that are used and the best way to deal with problems caused by cyber threats. This plan will help your company maintain its activities even if a problem occurs, such as unavailability caused by DDoS attacks.

How to protect yourself from cybercriminals in Brazil?

When it comes to cybersecurity, the first step to be mentioned is adapting to the LGPD . This legislation was specifically developed to ensure that the information stored and made available by companies remains confidential in accordance with the needs of the business and the respective holders of this data.

Since this legislation brings all the rules and paradigms to be followed to increase protection within companies, its adequacy is essential for businesses that wish to remain safer and more competitive in the market. This process will help protect yourself from cybercriminals and block possible vulnerabilities that affect your organization.

It is also equally important to be careful regarding user behavior. Creating weak passwords is one of the main vulnerabilities that can affect your organization, and it is essential to educate your employees about the importance of staying protected.

In the same sense, protecting access credentials is essential to prevent access by unauthorized users . Depending on the activity carried out by your business, there are accesses that must only be carried out by authorized personnel and the protection of these credentials is essential to increase your cybersecurity.

In addition to this, a strategy must be implemented to protect networks and devices. Since all data passes through these devices and is sent over the network, credential protection is a priority.

Count on complete tools that help your organization remain increasingly protected. Although there are numerous solutions on the market for protecting these devices and your network, it is essential to carry out intense research on the subject.

The tool to be used must be compatible with your needs and your company’s objectives. In addition to an intuitive, easy-to-use panel, this tool must have all the resources your company needs to maintain information protection.

National overview of cyber threats 

In Brazil, theft of accounts and access credentials accounts for 72% of frauds carried out in the country. This demonstrates how the digital environment has been used not only for everyday solutions but also for applying scams and traps.

Using sophisticated technology, fake emails, social engineering, among other strategies, cybercriminals have been stealing identities, diverting confidential information, carrying out financial scams, and much more. In addition to technology, lack of information is one of the main causes of creating points of vulnerability, causing users to expose confidential data and provide confidential information.

Current research shows that cyber scams are gradually increasing every year, making this type of threat increasingly worrying. In a country where investment in digital security is considerably low, we can understand how cybersecurity is neglected and why we suffer so many cyber attacks .

