Cybersecurity and Compliance

Cybersecurity and compliance to protect what keeps the company running.

For companies with 50 to 500 employees that need to reduce the risk of attacks and data leaks and demonstrate compliance to clients, auditors and regulators. Risk management, LGPD and PCI DSS compliance, environment protection and incident response — sized to your operation.

What's included

Cybersecurity and compliance, in practice

We prioritize by the real risk to your business, not by a vendor's shopping list.

Risk managementMap of assets, threats and vulnerabilities, with risks prioritized by impact and a treatment plan with an owner and a deadline.
LGPD complianceData inventory, legal bases, policies, contracts with processors and the security measures the law requires.
PCI DSSDefining the cardholder data environment, reducing scope, controls and evidence for the assessment.
Environment protectionHardening, network segmentation, vulnerability management and ransomware-protected backups.
Incident responseResponse plan, playbooks, exercises with leadership and support with containment, investigation and communication when something happens.
Policies and awarenessReadable security policies and people training, including phishing simulations.
References

Standards and reference frameworks

LGPD — arts. 46 to 49The controller must adopt security measures capable of protecting personal data and notify the ANPD (Brazil's data protection authority) and data subjects of any incident that may cause significant risk or harm, within the deadline set by ANPD regulation.
PCI DSS v4Mandatory for anyone who stores, processes or transmits card data. Version 4 introduced new requirements that became fully effective in 2025.
ISO/IEC 27001:2022Information security management system and the Annex A control set. It serves as a foundation even for those who don't plan to get certified.
CIS ControlsA prioritized list of technical controls, useful for deciding where to start when the budget is limited.

Want to measure where your company stands before we talk? The AI governance checklist has 12 items and takes about 15 minutes.

How we start

Four stages, with a concrete deliverable in each one.

Short cycles, a defined timeline and a goal stated before we begin. You know what you get and when.

01

Assessment

Maturity assessment, vulnerability scanning and gap analysis against the standard that matters to you.

2 to 3 weeks
02

Treatment plan

Prioritized risks, actions with owners and deadlines, and a cost estimate.

1 to 2 weeks
03

Implementation

Technical controls, policies, contracts and evidence, in short cycles starting with the greatest risk.

8 to 16 weeks
04

Ongoing operations

Vulnerability management, risk review, exercises and audit support.

ongoing
What you get

Deliverables, not slide decks.

  • Maturity assessment and gap analysis against the LGPD, PCI DSS or ISO/IEC 27001
  • Risk matrix with a treatment plan, owners and deadlines
  • Security and privacy policies ready for approval
  • Incident response plan with playbooks and an exercise
  • Vulnerability report with prioritized fixes
  • Evidence package for audits, clients or regulators
Frequently asked questions

What people ask before getting started.

Where should a mid-sized company start with security?
With inventory, MFA, protected backups and vulnerability management. These four reduce most of the ransomware risk and usually cost less than a new tool.
Do you handle full LGPD compliance?
We handle the security and process side and work together with your legal team, or the law firm that serves you, on the points that require legal analysis.
Do I need ISO/IEC 27001 certification?
Only if clients or contracts require it. Even without certification, the standard is the best roadmap for organizing security — and it leaves the path ready if the requirement comes.
What should we do if we are under attack right now?
Isolate the affected systems without shutting everything down, preserve evidence and bring in whoever will lead the response. Contact us on WhatsApp: an ongoing incident gets priority.
Is employees' use of AI a security risk?
Yes, above all because of data leaks through free tools. We address this in AI governance, which complements the security program.
Contact

Let's talk about security and compliance for your company.

Describe your situation in a few lines. We reply within one business day with a proposal for an initial conversation — free and with no commitment.

Request a free assessment

Tell us a little about your challenge. We will get back to you with a proposal for an initial conversation.

Please enter your name.
Please enter a valid email.
Please select a topic.
Please write a short message.
You must accept the privacy policy.
Chat on WhatsApp