- Accueil
- / Publications
- / Articles
- / When Confidence Outpaces Capability: Closing Brazil’s Incident Response Gap
Closing Brazil’s Incident Response Gap
When Confidence Outpaces Capability
-
août 03, 2026
-
In the event of a cyber incident, there is a dangerous mismatch between perception and reality when it comes to response capabilities in Brazilian organizations. As noted in our introductory article, The Illusion of Readiness: Understanding the Cyber Landscape in Brazil,1 only 30% of companies regularly conduct training or structured simulations for cyber incident response. Meanwhile, 45% report having never engaged in cyber crisis education, and only 56% report full or institutionalized Lei Geral de Proteção de Dados (“LGPD”) compliance. For the remaining 44%, a cyber incident involving personal data creates an operational crisis and an immediate regulatory obligation. These findings come from the latest Digital Risks Index,2 published by the Markets Innovation & Technology Institute (“MiTi”), a study of Brazilian organizations conducted with the support of FTI Consulting.
These findings are not simply isolated metrics; together they reflect a structural problem in how organizations understand preparedness itself, conflating the presence of security controls with the far more demanding capability of coordinated response under pressure. Closing the readiness gap requires an honest assessment of what genuine incident response readiness looks like in practice and the cost of allowing capability and confidence to remain misaligned.
The data suggests this challenge is widespread across Brazilian organizations rather than confined to any single industry. Still, it is addressable, and with the average reported cost of an incident reaching USD 31.99 million in 2025, closing that gap should be a priority as attacks grow more sophisticated and regulations evolve to impose greater legal and financial liability.
The Danger of the Middle
Brazil is not facing this overestimation problem alone. Cisco’s annual report on cybersecurity readiness found that 63% of executives globally have an inflated view of their organization’s preparedness for an event.3 What makes Brazil’s version of this phenomenon particularly instructive is that the MiTi data allows us to see precisely where the gap lives: in the space between having controls on paper and having tested, integrated response capabilities that work under pressure.
Viewed in isolation, a 58% maturity score and a 44% average cyber risk level suggest meaningful organizational progress. And in important respects they do: governance structures have been established, LGPD compliance frameworks have been adopted and cybersecurity has moved up the organizational agenda in ways that were not true a decade ago. But, intermediate maturity carries a specific danger that low maturity does not: it can generate false confidence. An organization at the early stages of its security journey knows it is exposed, but an organization sitting at 58% maturity has enough architecture in place to feel protected. The problem is that feeling protected and being resilient are not the same thing, and the difference only becomes visible during an actual incident.
The distinction that matters here is between controls and capability: a control is a policy, a tool, a governance committee, a compliance certification; a capability is an organization’s ability to execute when those elements are activated simultaneously, with incomplete information and competing organizational priorities. The MiTi data reveals that Brazilian organizations have made genuine progress on the control side of this equation. Year-over-year, maturity has improved incrementally, moving from 53% in 2024 to 58% in 2025. Yet, gaps in simulation exercises, cross-functional integration and regulatory compliance suggest that the capability side remains largely untested. Organizations feel protected by their existing controls but are not able to respond effectively when those protections are challenged. That is the confidence gap, and it is not a failure of intention. Rather, it is a structural consequence of building the form of readiness without yet establishing the substance behind it.
What Incident Response Actually Requires
One of the most consequential misconceptions in enterprise risk management is viewing a cyber incident as only a technical problem to be solved in a silo by the IT or security team. This narrow view is why so many organizations fall short when a situation demands tested incident response. A cyber incident should be seen as an organizational crisis with a technical origin, and this distinction should determine how it is managed.
A defensible incident response capability operates across at least five simultaneous dimensions, each of which must function and coordinate with the others in real time.
- Technical containment: Isolating affected systems, preserving forensic evidence and stopping the spread of compromise; this is the dimension most organizations have at least partially planned for.
- Legal and regulatory notification: Under Brazil’s LGPD, organizations must notify the ANPD (Brazil’s national data protection authority) of incidents involving personal data within a reasonable timeframe, with specificity about the nature of the breach, data affected and remediation strategy. Delays or deficiencies in notification may create regulatory exposure and reveal organizational dysfunction that could be scrutinized in subsequent enforcement action or litigation.
- Internal communications: Organizations without pre-established protocols to alert the board, update the C-suite or inform affected employees will find that the absence of clear guidelines creates its own form of organizational disruption running in parallel with the technical crisis.
- Executive decision-making: The choices made in the first 24 to 72 hours, often with incomplete information, time pressure and significant downstream consequences, are among the highest-stakes decisions leadership will face. Without pre-established decision rights and escalation protocols, leaders may be forced to make critical decisions without clearly established authority or escalation procedures.
- External stakeholder engagement: Customers, regulators, media, investors and partners will all require communication. Reputational consequences are shaped less by the incident itself than by the quality and speed of the organization’s public response. A poorly managed communication strategy can transform a contained technical incident into a sustained reputational crisis.
The need to coordinate across these dimensions is becoming increasingly apparent. In a separate FTI Consulting survey, nearly a third of general counsel reported that incident response is placing growing demands on the legal function, suggesting that many organizations still treat legal involvement as a response requirement rather than an integrated component of preparedness.4 The question for organizations is whether legal, communications, IT and executive leadership are genuinely integrated into response planning or operating in silos that will fracture under pressure.
Beyond internal coordination, layered across all five dimensions is the question of third-party risk. Fewer than half of Brazilian organizations – just 45% – conduct any form of supplier compliance audits. This finding reflects a widespread failure to internalize a fundamental principle of modern cyber risk: in an interconnected supply chain, the vulnerabilities of trusted third parties increasingly become your own. Effective incident response therefore requires pre-established protocols for managing third-party involvement in an incident, including contractual notification obligations, joint response procedures and accountability for forensic investigation across organizational boundaries.
The Cost of Unpreparedness
The financial stakes of the readiness gap are clear, but the whole of what an organization actually loses in a cyber incident is often determined by the quality of its response. Organizations with mature, regularly tested incident response capabilities are generally able to contain incidents faster, limit data exposure, satisfy regulatory notification requirements and preserve the evidentiary record needed to support insurance claims and litigation. For organizations in Financial Services, Healthcare and Energy – where incident costs exceed the average significantly – a poorly managed response adds regulatory penalties and litigation exposure on top of direct financial losses.
What makes the cost calculus particularly striking is that 72% of respondents rate reputational damage as more critical than financial loss. Reputational damage is disproportionately driven by the speed, coherence, credibility and transparency of its communications, not merely by the fact that an incident occurred. In many cases, those outcomes are shaped long before an incident takes place through advanced planning, defined decision rights and practiced response procedures.
From Architecture to Muscle
Closing the readiness gap is less about acquiring new tools than about building the organizational muscle that makes existing capabilities function under pressure. Four priorities stand out as foundational to that effort and, taken together, constitute an integrated program that must be practiced, refined and owned at the executive level to be genuinely effective.
- Cross-functional simulation exercises: Conduct tabletop exercises and live simulations that bring legal, communications, IT and executive leadership into the same room to work through realistic scenarios in real time. This is the most direct mechanism for closing the gap between controls and capability as it surfaces coordination failures, unclear decision rights and communication breakdowns.
- Escalation protocols and decision rights: Establish clear answers to the questions that will matter most under pressure – who has the authority to take systems offline, who approves the regulatory notification, who speaks to the media in the first hour. Document these in frameworks that have been reviewed, tested and understood by everyone with a role in the response.
- Pre-approved communication frameworks: Develop internal and external communication templates, pre-cleared with legal and leadership, that allow the organization to move quickly and consistently when pressure is high. This removes the friction that slows communication when speed and credibility are paramount.
- Continuous review tied to the evolving threat landscape: Stress-test existing frameworks regularly against emerging attack vectors, incorporating lessons learned from both internal exercises and external incidents across the sector. AI-enabled attacks are changing the speed, sophistication and targeting precision of cyber threats in ways that make previous playbooks potentially inadequate.
- Pre-established external response resources: Identify and retain key external advisors, including forensic investigators, outside counsel and crisis communications specialists, before an incident occurs so they can be engaged immediately when needed. Establishing these relationships in advance helps reduce delays in the critical early stages of an incident and supports a more coordinated response.
Before the Crisis
The confidence gap documented in the MiTi data is not a story about negligence; it is a problem of untested assumptions. It is difficult to accurately self-assess a capability that is rarely tested under real conditions, and the controls Brazilian organizations have built are sophisticated enough to make the assumption of readiness feel reasonable. Closing the gap requires a deliberate shift from a compliance posture that asks, “Do we have the right policies in place?” to an operational posture that asks, “Have we proven, under simulated pressure, that those policies translate into a coordinated action?” Organizations that make that shift will survive incidents more effectively, emerge with institutional credibility intact, preserve regulatory relationships and reinforce stakeholders’ trust rather than erode it.
Footnotes:
1: FTI Consulting, “The Illusion of Readiness: Understanding the Cyber Landscape in Brazil” (24 July 2026).
2: Unless otherwise indicated, the data cited in this article is drawn from Markets Innovation & Technology Institute (“MiTi”), “Digital Risks 2025” (6 May 2026), an annual assessment of cybersecurity, data governance and AI maturity among Brazilian organizations, sponsored by FTI Consulting.
3: Cisco, “2025 Cisco Cybersecurity Readiness Index” (7 May 2025).
4: FTI Consulting and Relativity, “The Seventh Annual General Counsel Report” (18 February 2026).
Related Insights
Related Information
Date
août 03, 2026
Contacts
Senior Director