Governance and compliance
Brazilian Central Bank resolutions
The cybersecurity policy the regulator expects to see.
What this work consists of
We bring your institution into compliance with the Central Bank of Brazil's cybersecurity resolutions. The first decision in the project is the classification: the applicable rule changes with the type of institution, and getting that reading wrong means meeting a requirement that is not yours or ignoring one that is.
A large share of the requirements falls on the contracting of cloud data processing and storage, and that is where most institutions discover gaps. We handle the cybersecurity policy, the incident response plan, the preparation of communications to the regulator, and the review of cloud contracts against what the resolution says they must contain.
On the institution's side, the project needs the current cloud contracts, the existing policies, access to the people accountable for technology and risk, and the involvement of whoever will take the policy to the board, because approval is an act of internal governance. You choose the depth: just the assessment with a prioritized plan, full remediation, or support through the audit, when the institution's size requires one.
How we conduct it, stage by stage
The stages and deliverables below describe the Full compliance work modality. The other modalities appear when you request the proposal.
Scope definition
We agree in writing what is in and what is out, and why. A badly defined scope is the most common cause of a project running over.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
Implementation
We stand the controls up together with your team, write down what needs to exist on paper and train the people who will operate them. Nothing counts as implemented until it works in practice and someone on your side can sustain it.
Evidence routine
We set out how each control proves it worked, with an owner and a frequency, so the audit does not turn into a scramble.
What is not included
- Formal communication with the Central Bank, which belongs to the institution itself: we prepare the content, you sign and send it
- Board approval of the policy, which is an act of internal governance: we deliver the document ready for that agenda
- The independent audit, when required by the institution's size
- Negotiating and signing cloud contracts: we review them and flag what is missing against the resolution, the institution does the contracting
- A formal legal opinion on regulatory classification, which belongs to your legal counsel: we work alongside them, not in their place
- Reporting a real incident to the regulator, which is an act of the institution's representative: the plan leaves the path and the templates ready
- Ongoing operation of controls and monitoring after implementation, which can be added as an ongoing service
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.