Attacks against Brazilian public agencies more than tripled in a single year. Notifications to the Institutional Security Office jumped from 1,500 per month in early 2025 to more than 4,600 in 2026. In the private sector the story is the same: data hostage-taking, leaks and fraud sit at the top of the threat list, and they hit companies of every size. Brazil closed out 2025 with roughly 60 billion attempted attacks over the year.
This piece is not here to scare you with numbers. It is here to answer the only question that matters for anyone running a business: what this scenario means for your company, in money and in risk, and what you can do about it today. At the end, we show how Steply treats security as part of the work, not as an optional item sold separately.
The most common attack, explained without the tech jargon
The main threat for companies of every size is called ransomware. In plain terms: a program breaks into your system, locks all your files with a password that only the criminal has, and demands a ransom to give them back. Imagine arriving at your company in the morning and finding out that every contract, invoice, customer record and financial spreadsheet is locked, and that to reopen them you have to pay whoever locked them. One third of companies worldwide have already been through this, according to a study by IDC.
And the ransom is the smallest part of the bill. The real cost comes from everything else: the days shut down with no way to operate, the data that never comes back even after you pay, the customers who lose trust when they learn about the leak, and the legal fine. Add it all up and the damage usually ends up at five to ten times the ransom amount. Whoever pays thinks they have solved it, and then finds out it was only the beginning.
The law turned security into an obligation, not a choice
Before, protecting data was a debate about "is it worth investing in this?". The LGPD, Brazil's data protection law, ended that conversation. Today, a company that lets a customer's personal data leak can be fined up to 2% of its gross annual revenue, capped at 50 million reais per violation. And the responsible authority is investigating and fining more every year.
Translated into cash flow: not protecting your data stopped being a way to save money. It became a debt with no due date you can see. The question shifted from "whether it is worth spending on security" to "how much to spend and who will take care of it". And that second question is where most companies get stuck, because there are not enough people.
The attack now has AI. The defense needs it too
Here is the turning point of 2026, and the one that gets ignored the most. The Google Cloud forecast report points out that criminals have started using artificial intelligence to attack with more speed, more reach and more effectiveness. In practice, the scam became cheaper to produce and harder to spot. The fake email that used to have grammar mistakes and an obvious scammy look now arrives flawless, personalized with your manager's name and the subject of your latest project.
This changes the game in a way that is simple to grasp: a defense built only on people and manual process can no longer keep up with the speed of an attacker using machines. To face an automated attack, you need a defense that also uses automation and AI in your favor. Anyone who treats AI as just a productivity tool, and ignores that it has already become a weapon on the other side, is defending a 2026 house with a 2015 padlock.
The hidden problem: there are not enough people to run the defense
The Brazilian market does not have enough professionals to handle this. Information security was named by Robert Half's 2026 Salary Guide as the skill that pushes salaries up the most in the technology sector, and nearly half of hiring managers say they are willing to pay above the market average for someone with certification in the field. When salaries spike, it is a sign that people are scarce.
For a business owner, this has a direct and uncomfortable consequence: building and keeping your own security team has become expensive and hard. You compete for a rare professional with banks, fintechs and hospitals, you pay a red-hot market salary, and even then you depend on a single person who could leave tomorrow. Security became critical at exactly the moment it got harder to hire the people who handle it.
How Steply protects your company
Most technology vendors deliver the system and treat security as an extra, a separate service you hire later, once the damage has already shown up. At Steply the logic is the opposite: protection is not a separate sale, it is part of how we build. Software that is born insecure has no cheap fix later. That is why defense goes in first, alongside the code, not on top of it.
In practice, this turns into things you can feel:
- Layered defense, not a single lock. Your most sensitive data sits behind several barriers, so that one failure alone does not open the whole house. When something goes wrong at one point, the damage stops there, it does not spread.
- Backup that actually comes back. Against data hostage-taking, the defense that matters most is having a clean, separate and tested copy. A backup that no one ever tried to restore is worthless. Ours is built to come back fast, so that paying a ransom is never your only way out.
- AI on both sides of the scale. We use AI to speed up the delivery of your product and, at the same time, to watch for anything abnormal in your system, at the same automated pace as the attacker. You gain speed in the build and do not inherit risk in the operation.
- Compliance that gets you out of the fine's line of fire. We handle personal data within what the LGPD requires from the start of the project, so that the law is a box already checked, and not a surprise when the auditors come knocking.
The message is direct. In 2026 the question is no longer whether your company will be a target. With 60 billion attempts a year in the country, it already is. The question is whether, when the attack arrives, you will be protected from the inside or finding out on the spot that security was just a promise in a contract. Steply builds software for the first scenario, and the conversation starts by understanding where your operation is exposed today.