Brazil’s New Financial Cybersecurity Rules Align to Global Standards
A significant regulatory shift is occurring in the financial sector to support operational resilience. Sitting at the very heart of institutional stability, accountability for cybersecurity risks is transitioning from a technical concern in IT departments to a critical issue addressed at boardroom level.
Paulo Baldin, CISO and Managing Partner of Cybersecurity at CLA Brazil explores what this means for organizations globally. Including how the frameworks and continuous validation cycles recently introduced in Brazil align to internationally recognized financial cybersecurity standards.
Historically, the financial sector treated cybersecurity as an IT responsibility, relying on patches and firewalls to address threats. This reactive approach resulted in quick technical fixes rather than proactive solutions.
Now, the industry is rapidly moving away from depending solely on written compliance statements. Instead, organizations are expected to provide operational evidence that demonstrates their cybersecurity controls are not only established but also function effectively.
‘Govern’ Function Formalizes Leadership Risk Responsibilities
Many new governance frameworks, including the NIST Cybersecurity Framework 2.0 have started to roll out a dedicated ‘Govern’ function. This decision-making structure formalizes a board’s legal and direct responsibility for risk management and incident response.
Specifically, these frameworks mandate that accountability starts at the top, requiring leadership to define risk appetite. As well as ensuring objective risk oversight, this decouples information security from IT to ensure there is no conflict of interest.
Paulo Baldin explains: “These shifts in accountability help to ensure that security integrity is not compromised. This structural independence is now codified in recent, harmonized mandates including Brazil’s CMN Resolution No. 5,274/2025, BCB No. 538/2025, the EU’s Digital Operational Resilience Act (DORA) and US Securities and Exchange Commission (SEC) rules.
“The hierarchy is now much clearer. Financial leaders are no longer regarded as passive observers of cyber risks. Rather, legally and directly accountable for management and how organizations respond to incidents,” expands Paolo.
Evidence Based Regime
Brazil’s regulatory landscape is indicative of this pivot toward an evidence based standard. Designed to align with the US and EU rules, the CMN Resolution No. 5,274/2025 and BCB Resolution No. 538/2025 were issued by the Central Bank of Brazil and the National Monetary Council (CMN) in December 2025.
Organizations are no longer evaluated on their stated intentions or ‘good practice’ declarations. Instead, they are expected to provide continuous, testable and auditable evidence.
Within Brazil’s framework, Penetration Testing (Pentesting) has evolved from a periodic technical exercise into a mandatory pillar of governance.
Additionally, the new standard requires a continuous compliance cycle, emphasizing ‘traceability of controls’ and ‘practical validation’. Multi-Factor Authentication (MFA), robust encryption protocols, network segmentation and digital certificate management are the other controls that must be monitored continuously to avoid regulatory action.
Collectively, these measures ensure greater resilience and can help organizations to recover quicker from significant operational disruptions. In addition to internal risks, this level of diligence should extend to increasingly complex external digital supply chains.
Adapting to AI Threats
Given the hyper-connected financial ecosystem, systemic risks often originate via a complex web of Cloud and SaaS providers.
Again, regulators have made the regime guidance extremely clear. The responsibility of security does not automatically transfer to the outsourced service. This means organizational leaders can be held accountable for vendor vulnerabilities.
Robust contractual clauses, the mandatory right to audit, evidence of vendor resilience and effective exit mechanisms are all needed to help ensure that a failure at a single service provider does not trigger a systemic outage across an entire financial system.
To maintain digital trust, firms must regularly test their defenses. For example, frontier AI introduces machine-speed vulnerabilities and threats such as data poisoning which could severely compromise the underlying logic of an automated system.
Global regimes are closing this security loop. Leadership Boards must now ensure their security teams are continuously evaluating systems against these evolving AI capabilities. The scale of these risks has also led supervisory authorities, such as the Bank of England and the FCA, to exercise direct oversight of major cloud providers.
Global Harmonization Unites Standards
The global financial sector is undergoing a fundamental transition toward unified operational standards. The strategic convergence of frameworks in the UK, EU, US and now Brazil confirms that cybersecurity is no longer considered a localized regulatory hurdle for financial firms.
According to Paulo, the level of maturity required to satisfy individual regulators is swiftly becoming the global standard. The benchmark for maturity is now set by the ability to provide operational, auditable evidence of compliance, rather than mere assertions or policy statements.
This shift presents a critical challenge for executives across the financial sector. Rather than simply questioning whether their organization is compliant, senior leaders must now ask "Can we demonstrate our compliance through operational evidence, and are we prepared for an immediate test of our systems?"
For further information
Paulo Baldin
CISO and Managing Partner of Cybersecurity, CLA Brazil
https://www.linkedin.com/in/paulobaldin/
The information contained herein is for general informational purposes only and is not intended, and should not be construed, as legal, auditing, accounting, investment, or tax advice or opinion provided by CLA Global or any of its individual member firms to the reader. No client, advisory, fiduciary, or other professional relationship is established or implied between the reader and CLA Global or any of its member firms through the presentation of the information contained herein. The reader is cautioned that this material may not be applicable to, or suitable for, the reader’s specific circumstances or needs, and may require consideration of a number of other factors if any action is to be contemplated. Accordingly, the information presented herein should not be considered a substitute for the reader’s independent investigation and sound technical business judgment, and the reader is advised to contact his or her CLA Global member firm or other tax or professional advisor prior to taking any action based upon said information. Neither CLA Global nor any of its member firms assume any obligation to inform the reader of any changes in tax laws or other factors that could affect the information contained herein.