Foursys is investing 2.1 million euros in Portugal and accelerating its expansion in Europe
Foursys has announced an investment of 2.1 million euros in Portugal as part of its...
sou ingles
lang: en
October is International Cybersecurity Awareness Month. The date exists because the figures continue to demand attention, and those for 2024 and 2025 are particularly hard to ignore.
In the first quarter of 2024, Brazilian organizations recorded an increase of approximately 38% in cyberattacks compared to the previous year. In parallel, 73% of companies in the country have already been victims of ransomware, the type of attack that blocks systems, exposes confidential data and demands a ransom to release access. The average cost of a data breach in Brazil reached R$7.2 million in 2025, up 6.5% on the previous year. And 32% of managers interviewed in recent surveys reported breaches associated with the use of artificial intelligence without adequate control.
There is a paradox in this scenario. Brazil is the second country in the Americas in terms of cybersecurity maturity, according to a report by the International Telecommunications Union. But maturity in the ranking has not prevented the volume and sophistication of attacks from continuing to grow. Defenses advance. Attacks are moving faster.
There is a lot of talk about external threats. The vector that increasingly worries experts, however, lies within the organizations themselves.
Shadow AI is the use of artificial intelligence tools by employees or business areas without approval, without supervision and outside of IT and security governance. It goes beyond traditional Shadow IT because the potential risk is proportionally greater: generative models processing sensitive data on third-party servers, prompts with strategic information feeding systems without auditing, and business decisions being made based on outputs that no security area has validated.
"If I, as CISO, am integrated into the use of AI but without having defined the limits, controls, governance and monitoring, I could be voluntarily or involuntarily creating tomorrow's attack within my own organization," warns Gabriel Loschi, CISO at Foursys.
The scenario is more common than it seems. Almost 75% of Brazilian companies say they plan to apply AI and machine learning to digital security. But planning controlled use and tolerating uncontrolled use are completely different things, and the latter is happening on a silent scale.
Visibility is not control. Having metrics showing an increase in attacks doesn't mean that the organization sees or blocks everything. It may just mean that noise is growing while part of the risk remains invisible. If Shadow AI governance is not structured, there is a surface of exposure that the dashboard simply doesn't show.
AI without guardrails becomes vulnerability. Using artificial intelligence for defense is necessary. Not using it is already a risk. But putting AI into operation without data security, testing, privacy and compliance controls in place turns the tool into a vector for the next incident. A concrete example: a marketing team that uses generative tools without curation to develop campaigns could be exposing competitive differentials that a competitor accesses before launch.
Governance, culture and third parties are the points of greatest failure. The HLB 2024 report indicates that 37% of organizations have suffered breaches through third parties, and 20% are unsure about the level of security of their partners. In the context of Shadow AI, this external risk is amplified: AI platforms and services that have not undergone a corporate security assessment create loopholes that don't always show up in conventional audits.
The transition from a reactive stance to a proactive approach requires concrete actions. Some of the most urgent:
Effective cybersecurity today is not only measured by the ability not to be attacked. Any sufficiently exposed organization will be targeted at some point. The relevant indicator is something else: the ability to recover quickly, with established governance and with learning incorporated into the process.
Brazil is advancing in security maturity. But it is advancing at a pace that has yet to keep pace with the sophistication of the threats. And the next big risk vector is probably already operating inside organizations, silently, in the form of an AI tool that nobody has approved.
This post was based on an opinion piece published on Crypto ID by Gabriel Loschi, CISO at Foursys, on the occasion of International Cybersecurity Awareness Month.
Foursys has announced an investment of 2.1 million euros in Portugal as part of its...
Artificial Intelligence is no longer a technological promise but a structural element of...
Financial institution strengthens regulatory governance with centralized monitoring of...
At Foursys, we connect strategy, innovation, digital engineering, data, AI, cybersecurity and organizational agility to build complete, secure and scalable solutions. We work from concept to sustained operation, helping companies modernize, accelerate delivery, make smarter decisions and generate continuous value across their digital transformation journey.
Av. Tamboré, 267 - Torre Norte
9º Floor |+55 (11) 4134-2222
Av. Paulista, 1912
15th Floor | +55 11 4861-8560
R. Comendador Araújo, 499
10th Floor | +55 (41) 2106-6709
Av. Pres. Vargas, 3131 - Suite 604
Cidade Nova, Rio de Janeiro
980 N. Federal Highway #110
Boca Raton, Florida 33432
Dedicated to Information Security and AI
Avenida da Liberdade, 110
1269-046 Lisboa, Portugal