Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

Cybersecurity, risk and compliance, explained for the people who have to decide.

Guides on ransomware, phishing, SOC, pentesting, ISO 27001, NIST CSF, LGPD, Brazilian Central Bank regulation and risk analysis — with the official source for every claim.

Threats and security operations

· 7 min read

Ransomware and RaaS: how to prepare your company

Ransomware is now an industry of affiliates and double extortion; preparing means prevention, detection, tested backups and a plan agreed before the crisis.

Cyber risk

· 4 min read

Risk appetite: from sentence to number

A statement approved in the minutes does not tell an analyst what to do. How to turn appetite into a limit, and a limit into acceptance criteria.

· 5 min read

ISO 27005: the risk assessment 27001 demands

The standard you get audited against demands a risk assessment and does not say how to run one. ISO 27005 answers that — and it changed in 2022.

· 20 min read

CROC: when detecting threats is no longer enough

Companies have security data to spare. What they lack is a way to turn it into risk decisions. The CROC is the layer that builds that bridge — without replacing the SOC.

Standards and frameworks

Vulnerabilities and exposure

· 5 min read

48,000 CVEs a year: where to start

Nobody fixes 48,000 vulnerabilities a year. The question is not how many you close but which — and CVSS alone answers that badly.

Regulation and third parties