Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert
Public sector

Cybersecurity for the public sector, with services online and data protected.

When a public body is attacked, it is the citizen who loses the service. We help federal, state and municipal bodies, courts, audit courts, public companies and mixed-capital companies prevent, detect and respond to incidents, and demonstrate what they do to oversight bodies.

Why the sector is a target

Essential services, data on millions of people and high exposure

Government holds citizen records, systems that cannot stop and highly visible portals. This combination attracts criminals and activists.

RansomwareEncrypted systems take citizen services, revenue collection, case processing and digital services offline.
Data leakExposed citizen and civil servant databases trigger notification duties and sanctions under the LGPD.
DefacementPortals defaced by attackers damage an institution's credibility within hours.
Oversight bodiesInternal control and audit courts require policy, risk management, and evidence of execution.
What regulation requires

A framework that now demands governance and response

O Decree 11.856/2023 established the National Cybersecurity Policy (PNCiber) and the National Cybersecurity Committee, chaired by GSI/PR. Its principles include preventing attacks on critical infrastructure and essential services and the resilience of public and private organizations. In August 2025, Decree 12.573 established the National Cybersecurity Strategy, which provides for contingency plans, tests and simulations in public bodies and entities.

In the federal administration, Decree 12.572/2025 established the new National Information Security Policy and revoked Decree 9.637/2018. Each body and entity must set up an information security committee, appoint a security manager, publish and review its policy in line with GSI regulations, assess compliance and allocate budget to the topic. Decree 10.748/2021 made participation in the Federal Cyber Incident Management Network mandatory for the direct, autarchic and foundational administration.

A LGPD applies to all of government. Processing must serve a public purpose (art. 23), security measures are mandatory (art. 46) and, under Resolution CD/ANPD No. 15/2024, incidents with relevant risk must be reported to the ANPD and data subjects within three business days.

Where we help

Each risk and the service that responds to it

24×7 SOC and MDR

Continuous monitoring to detect the attack before encryption, in an ISO/IEC 27001:2022 certified SOC.

Incident Response

Containment, investigation, and recovery, with the technical record required for notifying the ANPD and oversight bodies.

Vulnerability Management

Inventory and continuous scanning of exposed assets, with risk-based prioritization and remediation tracking.

Pentest

Penetration testing of portals, service systems and internal networks, with evidence of what an attacker could reach.

Cloud security

WAF to protect portals and APIs against defacement and exploitation, and DLP to contain data leaks.

GRC

Security policy, risk management, LGPD compliance and organized evidence for audits.

Who trusts us

Public bodies and companies that trust Network Secure

STJ, TCE-SP, BNDES, Caixa and Banco Central do Brasil are among the public bodies and companies served by Network Secure, which has worked in cybersecurity since 2002.

At CEDAE, the work began with vulnerability assessment and pentesting. In the words of Paulo Pompei: “Network Secure is our Information Security partner. With the vulnerability assessment and Pentest project, we were impressed by the information provided — it has become an ongoing and essential partner.”

Frequently asked questions

Common questions about cybersecurity in the public sector

Decree 11.856/2023 sets out national principles and objectives, including coordinated action among the Federal Government, states, the Federal District and municipalities, and among the three branches of government. It does not list mandatory technical controls. The details come from the National Cybersecurity Strategy (Decree 12.573/2025) and the National Cybersecurity Plan.

Under art. 52, § 3, of the LGPD, fines do not apply to public bodies and entities, but warnings, public disclosure of the violation, blocking, deletion of data and suspension of processing do. Public companies and mixed-capital companies operating under competitive conditions are treated as private companies (art. 24) and can be fined.

Under Resolution CD/ANPD No. 15/2024, three business days from the moment the controller learns that the incident affected personal data, both to the ANPD and to data subjects, when there is relevant risk or harm. Specific legislation may set a different deadline.

Not necessarily. Under Decree 10.748/2021, participation is mandatory for the direct, autarchic and foundational federal administration, and voluntary, by opt-in, for federal public companies, mixed-capital companies and their subsidiaries.

If your agency were attacked today, how long would the service be offline?

Talk to a specialist and see where the gaps are between your operations and what PNCiber, the LGPD, and oversight bodies expect.

Talk to an expert →