Brazil’s average cybersecurity maturity score climbed to 58% in the latest Digital Risks Index, up from 53% a year ago, according to new research from the Markets Innovation & Technology Institute (MiTi) sponsored by FTI Consulting. The improvement, published on July 24, 2026, reflects growing investment in security tools and governance frameworks across hundreds of surveyed organizations. Yet behind that headline number, the data reveals a troubling disconnect: most Brazilian companies remain dangerously unprepared for the moment a cyberattack actually hits.
The report’s most jarring statistic may be this: only 30% of surveyed organizations conduct regular training or structured simulations for cyber incident response, while a full 45% do no incident response training at all. Combined with the finding that just 19% have a structured crisis communications plan, the numbers paint a picture of businesses that have bought the alarms but never run a fire drill.
The Numbers That Should Worry Every Brazilian Executive
A maturity score of 58% represents intermediate sophistication: companies have established policies, deployed security tools, and adopted compliance processes. But a single score hides immense variation. Here are the key findings that every organization in Brazil needs to examine against its own operations:
- LGPD Compliance Plateau: Only 56% of companies report full or institutionalized compliance with Brazil’s General Data Protection Law, leaving nearly half exposed to regulatory risk and eroding customer trust.
- AI Governance Vacuum: Despite rapid adoption of generative AI, merely 22% of participants have a proactive cybersecurity strategy for AI systems. The remaining 78% cite basic, limited, or no management—a governance gap that practically invites data leaks and intellectual property exposure.
- Incident Practice Void: Already noted, but worth emphasizing: 30% run regular incident simulations; 45% do nothing. The rest may have ad hoc or incomplete exercises.
- Financial Exposure: The average estimated loss from a significant cyber incident reached US$31.99 million, with the hardest-hit sectors—financial services, telecom, industry, and retail—facing potential crisis impacts between US$70.87 million and US$98.43 million.
- Reputation Over Revenue: 72% of respondents consider reputational damage more critical than direct financial loss, underscoring the long-tail costs of a breach.
These numbers aren’t just academic. They translate directly into the likelihood that a ransomware attack, a data theft, or a business email compromise will spiral into a prolonged operational and legal crisis.
What a 58% Maturity Score Actually Means When an Attack Arrives
Maturity assessments measure whether controls exist. They do not measure whether controls work under stress. A company might check the box for multifactor authentication but still allow legacy accounts to bypass it. It might have endpoint detection deployed but fail to monitor alerts. It might back up data but never test restoration.
Cybercriminals don’t need every defense to fail. They need one unpatched VPN, one reused password, one employee tricked by a convincing AI-generated phishing email. And as attackers increasingly use generative AI to automate reconnaissance and craft personalized lures, the cost of finding that single weak point is falling fast.
For businesses running on Windows infrastructure—and that’s most Brazilian firms—the implications are immediate. If your Microsoft 365 tenant, Active Directory, or cloud workloads are protected in name only, you’re not protected at all. Maturity without resilience means your recovery plan may be untested, your privileged accounts may be shared, and your legal team may have no script for when customer data leaks.
Why the Gap Persists: Compliance Paperwork Doesn’t Stop Hackers
Brazil’s corporate culture around cybersecurity often equates purchasing tools and completing compliance documents with being secure. The FTI Consulting report suggests this is an illusion of readiness. In many organizations, security is still viewed as an IT cost center rather than a business continuity function.
This mindset shows up in the LGPD numbers. The law has been in force since 2020, yet only 56% of firms claim full compliance. Even that figure is suspect because true compliance requires not just privacy policies but technical enforcement: knowing where all personal data lives, restricting access, monitoring data flows, and being able to report a breach within the legal timeframe. A policy on a shelf doesn’t satisfy the ANPD (Brazil’s data protection authority) if a breach exposes a million customer records from an unprotected file share.
AI adoption widens the gap further. Employees are feeding company data into public chatbots, teams are deploying AI agents without security review, and automated decision-making systems are processing personal information without governance. Only one in five companies has a proactive strategy, meaning most are trusting luck over controls.
Concrete Steps: How to Move from Maturity to True Readiness
The path forward isn’t about buying more tools. It’s about building organizational muscle memory for crises. Whether you’re a small business owner, an IT manager at a mid-sized company, or a CISO at a large enterprise, here are the highest-impact actions you can take this quarter:
- Run a tabletop exercise this month. Select a plausible scenario—ransomware encrypting file servers, a compromised Microsoft 365 account exfiltrating emails—and bring together IT, legal, communications, and leadership. Don’t aim for a perfect outcome; aim to uncover who doesn’t know what to do.
- Lock down privileged identities. Enforce phishing-resistant MFA for all administrative accounts. Eliminate shared admin credentials. Review who has Global Admin in Microsoft Entra ID and every domain admin in Active Directory.
- Test your backups. Restore a critical production database or SharePoint site from backup to a sandbox. If you can’t do it within your recovery time objective, your backup strategy is a wish, not a plan.
- Inventory your AI usage. Ask department heads what AI tools their teams use. Then assess data classification: are employees entering customer data, source code, or financial reports into public services? Create simple, enforceable guidelines.
- Draft a crisis communications playbook. Not a long document. A one-page list of who speaks, who approves, and what channels you’ll use to notify customers, regulators, and employees in the first 24 hours.
- Make LGPD operational, not documentary. Map where personal data lives across your Windows endpoints, file servers, and cloud environments. Ensure you can quickly identify and quarantine affected data during an incident.
- Shift metrics from tool counts to performance. Track mean time to detect, mean time to contain, phishing-resistant MFA adoption rate, and percentage of critical vulnerabilities patched within SLA—not just the length of your tool list.
Outlook: The Next Six Months Will Define the Preparedness Curve
Brazil’s regulator, the ANPD, is expected to increase enforcement activity, and courts are becoming more receptive to data breach litigation. Meanwhile, attackers are refining AI-driven techniques that render traditional awareness training less effective. The window for closing the readiness gap is narrowing. Smart organizations will treat the 58% maturity score not as a passing grade, but as a warning that on-paper security is not the same as being ready for the exam that counts.