Key Takeaways
- Brazil’s average cybersecurity maturity rose to 58 % in 2025 (up from 53 % in 2024) but still lags behind global peers, leaving companies at an intermediate level of sophistication with notable gaps in consistency and governance.
- The maturity score translates to an average current risk level of 44 % (medium), meaning that while a baseline of digital controls exists, uneven implementation creates significant exposure to breaches, operational disruption, fraud, and regulatory sanctions.
- Cyber threats are growing in sophistication, driven by generative AI and intelligent agents, yet only 56 % of firms report full or institutionalized compliance with Brazil’s LGPD, and regulatory readiness remains a top future challenge for 26 % of respondents.
- Financially, a significant cyber incident costs an estimated USD 31.99 million on average, with the most exposed sectors (Financial Services, Telecommunications, Industry, Retail) facing losses between USD 70.87 million and USD 98.43 million; 72 % of executives view reputational damage as even more critical than the direct financial hit.
- Incident response preparedness is weak: only 30 % conduct regular training or simulations, while 45 % do none at all, creating a mismatch between perceived readiness and actual capability when attacks occur.
- AI adoption outpaces governance—just 22 % of organizations have a proactive cybersecurity strategy for AI systems, leaving 78 % with basic, limited, or no controls, raising risks of data misuse, IP loss, and compliance failures.
- Crisis communications are underdeveloped: merely 19 % possess a structured communications and stakeholder‑engagement plan for cyber events, leading to overly technical responses that neglect broader trust management.
- Building resilience requires coordinated shifts in governance, preparation, and communication, focusing on strengthening incident‑response capabilities, closing the AI‑governance gap, and integrating reputational considerations into crisis management.
Overview of Brazil’s Cybersecurity Maturity
Brazil’s digital environment is under increasing pressure, as reflected in the latest Digital Risks Index from the Markets Innovation & Technology Institute (MiTi). The average cybersecurity maturity of Brazilian companies stands at 58 %, a modest improvement from the 53 % recorded in 2024. Despite this uptick, the score still places Brazilian firms below the average maturity observed among global peers, signaling a persistent gap in their ability to defend against evolving digital threats. The index, sponsored by FTI Consulting, surveyed hundreds of organizations across artificial intelligence, cybersecurity, and data governance domains, measuring compliance readiness against the Lei Geral de Proteção de Dados (LGPD), Brazil’s foremost data‑protection legislation.
Interpreting the Maturity Score and Associated Risk
A maturity level of 58 % is characterized as intermediate sophistication: essential controls and practices exist, but their application is inconsistent, governance structures are often fragmented, and continuous execution lapses. The Digital Risks Index converts this maturity figure into an average current risk level of 44 %, classified as medium. This indicates that while Brazil maintains a foundational set of digital capabilities, companies remain significantly exposed to incidents that could impair operations, tarnish reputation, and erode financial performance—such as data breaches, service disruptions, fraud, regulatory sanctions, and legal or ethical liabilities. Importantly, the exposure is not uniform; it tends to arise where controls are present but unevenly applied rather than where they are entirely absent.
Threat Landscape: Sophistication, AI, and Regulatory Response
The disparity between maturity and actual resilience becomes most evident during high‑stakes cyber incidents. Cyber attackers are growing more sophisticated, increasingly leveraging generative artificial intelligence and intelligent agents to expand the attack surface and evade traditional defenses. In response, Brazil’s regulatory environment is tightening: stricter cybersecurity requirements are being imposed, and legal and financial liability for breaches is rising. However, LGPD compliance remains patchy, with only 56 % of surveyed companies reporting full or institutionalized adherence. Consequently, regulatory compliance ranks as a primary future challenge for 26 % of respondents, underscoring the difficulty of aligning evolving legal expectations with internal capabilities.
Financial and Reputational Consequences of Incidents
When a cyber incident materializes, the financial toll can be substantial. In 2025, the average estimated cost of a significant incident reached USD 31.99 million. For the sectors most exposed—Financial Services, Telecommunications, Industry, and Retail—the impact ranges from USD 70.87 million to as high as USD 98.43 million per event, reflecting the heightened asset criticality and regulatory complexity inherent to those industries. Although such financial losses command boardroom attention, a striking 72 % of respondents consider reputational damage even more critical than the direct monetary impact. Reputational harm, while harder to quantify, often amplifies financial downstream effects by eroding customer trust, deterring partners, and increasing long‑term recovery costs.
Gaps in Incident Response Preparedness and Training
A core weakness lies in incident response readiness. Across Brazilian organizations, only 30 % conduct regular training or structured simulations for cyber incident response, while a troubling 45 % undertake no such preparation at all. This disconnect creates a false sense of security: while many leaders believe they have adequate safeguards, the reality is that response capabilities frequently falter when tested by real‑world attacks. The Seventh Annual General Counsel Report from FTI Consulting and Relativity notes that data privacy and protection rank among the top five risks for general counsel, yet nearly one‑third say incident response now places growing demands on legal departments, and more than one‑third cite data breaches as a leading driver of organizational disputes and investigations. The volume and sophistication of cyber threats are outpacing the ability of most firms to mount an effective, coordinated response.
AI Adoption Outpacing Governance
The rapid adoption of artificial intelligence introduces a parallel exposure when governance lags behind innovation. While AI has become a business priority and many legal leaders express concerns about data privacy and security related to generative AI, only 22 % of MiTi survey participants report having a proactive cybersecurity strategy specifically for AI systems. The remaining 78 % rely on basic, limited, or no AI‑focused controls. Without robust governance, organizations risk misuse of personal data, intellectual‑property infringement or loss, and automated decision‑making that could violate laws, trigger compliance failures, or damage reputation. The gap between AI enthusiasm and oversight therefore represents a growing source of cyber risk that must be addressed urgently.
Crisis Communications and Stakeholder Engagement
When a cyber incident unfolds, the manner in which an organization communicates can shape its long‑term institutional and reputational trajectory. Yet MiTi data reveal a stark deficit in communications preparedness: only 19 % of Brazilian companies possess a structured communications process and stakeholder‑engagement plan for cyber events. In practice, response plans tend to be overly technical, focusing on system restoration while neglecting the broader perception of the organization as it moves from crisis to control. An integrated stakeholder engagement strategy—encompassing customers, regulators, employees, investors, and the media—is essential to maintain trust during turbulence. Simulation exercises that extend beyond technical response, encouraging coordination among departments with competing priorities, have proven effective in closing this readiness gap and ensuring that crisis management is both swift and socially aware.
From Risk to Resilience: Required Shifts in Governance, Preparation, and Communication
Moving from vulnerability to resilience demands deliberate changes across three interconnected dimensions. First, incident‑response capabilities must be strengthened through regular, realistic training, cross‑functional simulations, and clear escalation pathways that involve IT, legal, compliance, and executive leadership. Second, the governance gap surrounding AI adoption must be closed by instituting proactive AI‑specific cybersecurity policies, continuous monitoring, and accountability mechanisms that align innovation with risk management. Third, reputational considerations need to be embedded into crisis planning, ensuring that communication strategies are as rigorous as technical response plans and that stakeholder trust is preserved throughout the breach lifecycle. By addressing these areas—enhancing response readiness, governing AI responsibly, and integrating reputational safeguards—Brazilian companies can better navigate the current digital risk landscape and transform cybersecurity from a reactive cost center into a strategic asset that sustains long‑term value.

