What Can Brazil Learn from Global Cybersecurity Regulation?

Photo of Davi de Oliveira Gomes

Davi de Oliveira Gomes Follow

Reading time: 5 min

This is the second and final article on the lessons Brazil can draw from the cybersecurity regulatory initiatives being adopted in other countries. In this second part, we examine the challenges that still persist in these regulatory frameworks and the lessons that can be learned to avoid them when designing the Brazilian model.

Avoiding Regulatory Fragmentation

The United States is the most visible example. Without a single federal law, the country has accumulated dozens of sector-specific notification requirements, each with different deadlines and definitions. A 2023 government study conducted by the Office of the National Cyber Director identified 52 reporting requirements coexisting within the same ecosystem.

Regulatory fragmentation also manifests itself through the multiplication of reporting points for the same incident, a risk of particular relevance for Brazil. The country already combines the obligation to report to the National Telecommunications Agency (Anatel) under Resolution 740/2020, notification to the National Data Protection Authority (ANPD) when personal data are involved, activation of the Government Cyber Incident Prevention, Treatment and Response Center (CTIR Gov), and additional sector-specific obligations in finance and energy.

The impact is measurable and likely greater than isolated figures suggest. According to the World Economic Forum, 76% of companies report that regulatory fragmentation undermines both their ability to maintain compliance and the effectiveness of their security measures. The delay in the final implementation of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) also illustrates a recurring challenge in complex regulatory agendas: the gap between creating a legal obligation and putting it into practice effectively.

Chile illustrates a different version of the same problem. The country approved a technically sound law, established its cybersecurity agency in record time, and now faces the challenge of overseeing 915 essential or critical operators with a workforce that is still being developed. The global cybersecurity workforce gap is estimated at between 2.8 and 4.8 million professionals. The Chilean experience therefore serves as a reminder that creating new legal obligations must be accompanied by the capabilities and conditions required to make them effective.

Cybersecurity Risks Extend Beyond the Most Regulated Sectors

The cybersecurity bill currently under consideration in the United Kingdom has been criticized for failing to cover Marks & Spencer and Jaguar Land Rover, two companies, a major retail chain and a luxury vehicle manufacturer, respectively, that suffered significant cyberattacks in 2025 with substantial economic consequences. Although neither belongs to a sector classified as critical infrastructure, the effects of these incidents demonstrate that the economic and social impact of cyberattacks can reach far beyond sectors previously defined by regulation.

Cost-Benefit Analysis

One aspect that remains underestimated in the debate is the relationship between the cost of regulatory obligations and their ability to reduce risk. In the United Kingdom, the Office of Communications (Ofcom) estimated that ensuring just one hour of backup power for the mobile network would cost between £900 million and £1.8 billion, excluding maintenance costs. The telecommunications sector already allocates 7.3% of its IT budget to security, compared with a global average of 5.6% and 4.6% for local and regional public administrations. Additional requirements may generate only limited marginal benefits if they are not guided by risk assessment and cost-benefit analysis, supported by an appropriate funding strategy. The regulatory challenge is to prioritize measures capable of delivering the greatest risk reduction per unit of investment.

Educating Citizens

The low level of digital maturity among the general population also remains insufficiently addressed. The four countries analyzed prioritize the training of cybersecurity professionals through initiatives such as the United Kingdom’s CyberFirst program, U.S. public service scholarship schemes, and Australia’s goal of training 1,900 professionals annually. Basic digital literacy among citizens receives far less attention and is often limited to awareness campaigns, despite the growing prevalence of social engineering fraud, which demonstrates that cybersecurity also depends on users’ ability to recognize and avoid threats.

Brazil Can Resolve This Dilemma

A common pattern across all four jurisdictions deserves attention. Regulation almost always begins, and frequently remains concentrated, in sectors that are already highly regulated: telecommunications, energy, banking, and healthcare. These sectors typically have clearly designated teams or officers responsible for responding to regulatory requirements and interacting with authorities, as well as well-established compliance cultures. This tends to represent the path of least regulatory resistance, though not necessarily the most effective way to reduce risk across the broader digital value chain.

The problem is that the evidence points beyond these sectors. More than half of cybersecurity incidents originate from third parties. Fewer than a quarter of small and medium-sized enterprises carry cyber insurance, compared with 75% of large organizations. Vulnerabilities therefore tend to emerge outside the most protected environments, at other points within an increasingly interconnected digital value chain.

Given this scenario, five questions should be considered during the design phase of Brazil’s cybersecurity law:

– Does the law apply to organizations that contract with the public sector, or only to operators of critical infrastructure?

– Is every new obligation accompanied by a cost-benefit assessment and an identified source of funding?

– Is there a single point of contact, or can the same incident still require three separate notifications?

– Is there a simple, low-cost pathway for small and medium-sized enterprises to demonstrate compliance?

– How can Brazil invest in effective digital literacy beyond traditional awareness campaigns?

Conclusion

Digital security must be a shared responsibility. It depends on a regulatory framework that is light-touch, proportionate, risk-based, and evidence-driven, developed in partnership with the private sector from the outset rather than only during the final public consultation stage. It also depends on an economically sustainable and resilient telecommunications sector, which constitutes essential infrastructure upon which all other sectors of the economy operate and pursue digital transformation.

The challenge, therefore, is not simply to impose greater requirements on already regulated sectors, but to strengthen security across the entire digital value chain, particularly where its most vulnerable points are located.

The difference between these two scenarios is being written in Brazil today.

Share it on your social networks


Communication

Contact our communication department or requests additional material.