CCT debate marco legal da cibersegurança – 30/6/26

CCT debate marco legal da cibersegurança – 30/6/26

22ª Reunião da Comissão de Ciência, Tecnologia, Inovação e Informática

Abertura da Reunião

  • A reunião é declarada aberta pelo presidente, com a presença de um número regimental de participantes.
  • O evento ocorre em 30 de junho de 2026, durante a quarta sessão legislativa ordinária da 57ª Legislatura.

Estrutura da Reunião

  • A reunião será dividida em duas partes: uma deliberativa e uma audiência pública interativa.
  • O foco inicial é a deliberação do Requerimento 50/2026 da CCT.

Leitura do Requerimento

  • O requerimento visa instruir o PL 4752, que estabelece o marco legal da cibersegurança e cria o Programa Nacional de Segurança e Resiliência Digital.
  • Convidados para a audiência incluem especialistas em cibersegurança e representantes de instituições relevantes.

Votação do Requerimento

  • O requerimento é colocado em votação; os senadores que concordam permanecem como estão. Aprovado por unanimidade.
  • Com isso, conclui-se a parte deliberativa da sessão antes de iniciar a audiência pública sobre o PL 4752/2025.

Apresentação dos Convidados

  • Diversos especialistas são convidados para participar presencialmente ou via videoconferência, incluindo diretores e presidentes de associações relacionadas à cibersegurança.
  • É enfatizada a importância das contribuições dos convidados para enriquecer as discussões sobre o projeto em pauta.

Interatividade na Audiência Pública

  • A reunião será interativa e transmitida ao vivo, permitindo participação do público através do portal e-Cidadania ou telefone.
  • Um relatório completo com todas as manifestações será disponibilizado no portal após a reunião.

Discussões sobre Legislação

  • O relator do projeto destaca que não se trata apenas de apresentar um projeto já existente, mas sim colher sugestões construtivas para aprimorá-lo conforme as necessidades atuais.
  • Há um reconhecimento das críticas recebidas anteriormente sobre o projeto, ressaltando sua natureza sensível devido à rápida evolução dos temas relacionados à cibersegurança.

Importância da Flexibilidade Legislativa

  • O relator menciona que o projeto deve ser dinâmico e adaptável às mudanças constantes no cenário tecnológico e social relacionado à segurança digital.
  • Ele enfatiza que é crucial equilibrar sugestões com os princípios fundamentais do projeto durante sua tramitação legislativa.

Limites Temporais nas Contribuições

  • Para otimizar o tempo disponível para discussão entre os participantes, foi sugerido um limite máximo de três minutos por fala.
  • Essa abordagem visa garantir que todos tenham oportunidade de contribuir sem prolongar excessivamente as intervenções.

Introduction to the Cybersecurity Discussion

Opening Remarks

  • The session is led by a senator who emphasizes politeness and aims to gather suggestions from participants. Each speaker is allotted three minutes for their contributions.
  • Contributions will alternate between in-person and remote participants, with parliamentary members allowed to ask questions or make comments afterward.

Presentation by Jacir Barbosa Jr.

  • Jacir Barbosa Jr., representing the Cyber Defense Command of the Ministry of Defense, begins his presentation, clarifying that he is not from the Army's command but rather from the broader Ministry of Defense structure.
  • He expresses gratitude for the opportunity to discuss cybersecurity, highlighting its significance in contemporary defense strategies globally.

Importance of Cybersecurity Legislation

Legislative Context

  • Barbosa stresses that cybersecurity is a pressing concern worldwide and within Brazil's defense framework, indicating urgency in advancing relevant legislation.
  • He believes that the proposed law addresses a significant gap in Brazilian legal frameworks and aligns with global best practices in cybersecurity legislation.

Nature of Cyber Attacks

  • Emphasizes that cyber attacks often stem from financial motivations but can also target industrial secrets or state secrets, leading to social chaos. This highlights diverse motivations behind cyber threats beyond mere financial gain.
  • Notes that when cyber incidents affect essential services or critical infrastructure, they become defense issues requiring specialized attention from national security entities.

Key Considerations on Proposed Legislation

Differentiation Between Concepts

  • Highlights a lack of clear differentiation between "cybersecurity" and "cyber defense," which could lead to significant implications regarding responsibilities among various actors involved in cybersecurity efforts.
  • Points out potential ambiguities in competencies among different authorities proposed under this legislation, stressing the need for clarity to avoid operational conflicts during incidents.

Information Sharing Concerns

  • Stresses that effective cybersecurity relies heavily on information sharing; however, there are concerns about exposing vulnerabilities through mandatory information exchanges outlined in the proposal. This could jeopardize critical infrastructure security if not handled carefully.

Defining Security vs Defense Issues

Incident Classification Proposal

  • Proposes establishing objective indicators distinguishing between security problems and those escalating into defense issues; without such guidelines, there may be overlaps leading to jurisdictional conflicts among agencies involved in response efforts.
  • Suggestion includes categorizing cyber incidents based on severity levels—from technical issues manageable by IT staff to crises necessitating state-level intervention due to impacts on national resilience or sovereignty threats.

Emerging Technologies and National Interests

Addressing Technological Advancements

  • Advocates for explicit inclusion of emerging computational technologies and quantum technologies within legislative discussions as these have become state matters internationally; regulation here could enhance national interests significantly concerning technological autonomy and development capabilities.

Collaborative Platforms for Threat Sharing

  • Recommends creating neutral platforms for threat information sharing among stakeholders as an essential step towards improving collective cybersecurity posture while ensuring secure communication channels are established for sensitive data exchange related to threats faced by critical infrastructures across sectors.

Ongoing Initiatives in Cybersecurity

Current Activities

  • Discusses ongoing initiatives like "Guardião Cibernético," which has been running simulations focused on strategic impact scenarios related specifically to essential services over nearly ten years—highlighting institutional improvements alongside technical enhancements achieved through these exercises annually conducted across multiple cities including Brasília this September 2023 event invitation extended publicly at this forum gathering attendees' interest further engagement opportunities ahead!

Construção de Legislação sobre Cibersegurança no Brasil

Compromisso com a Elaboração do Relatório

  • O orador, embora temporariamente licenciado, continua comprometido com a construção da legislação e elaboração do relatório.

Importância do Diálogo e Colaboração

  • A criação de uma legislação sólida requer diálogo, responsabilidade e a capacidade de integrar diferentes visões. O projeto é um esforço colaborativo.

Desafios na Criação de um Marco Legal

  • O objetivo é criar um marco legal que proteja a infraestrutura e contemple a cibersegurança sem impedir a inovação. Este é um grande desafio enfrentado por diversos senadores.

Consultas e Contribuições para uma Legislação Viva

  • Há consultas em andamento com a consultoria legislativa do Senado para garantir que a legislação seja dinâmica e adaptável às novas ameaças cibernéticas.

Integração de Frameworks Internacionais

  • A proposta inclui incorporar frameworks internacionais como NIST, ISO 27000, entre outros, para evitar que a legislação se torne obsoleta frente às ameaças futuras.

Aprendizados com Outras Nações

Análise das Legislações Estrangeiras

  • Outros países já aprovaram legislações semelhantes; o Brasil está atrasado, mas pode aprender com os erros cometidos por essas nações.

Modernização da Legislação Brasileira

  • Estudo dos exageros nas leis europeias, asiáticas e americanas visa modernizar a legislação brasileira para torná-la mais eficaz e abrangente.

Impacto da Transformação Digital

Riscos Crescentes em Cibersegurança

  • A transformação digital trouxe avanços significativos, mas também aumentou os riscos cibernéticos enfrentados por órgãos públicos e empresas.

Soberania Nacional em Jogo

  • A cibersegurança é agora uma questão de soberania nacional, afetando o desenvolvimento econômico e proteção dos dados dos cidadãos.

Envolvimento das Instituições na Discussão

Importância da Audiência Pública

  • A audiência pública é crucial para o processo legislativo. As contribuições escritas serão bem-vindas para enriquecer o debate sobre cibersegurança.

Compromisso com Resultados Democráticos

  • O orador reafirma seu compromisso em conduzir o trabalho com diálogo responsável, buscando resultados que beneficiem todo o Brasil.

Reflexões sobre Segurança Cibernética

Complexidade do Tema

  • O senador Marcos Pontes destaca que segurança cibernética é um assunto extenso que afeta diversas esferas da sociedade brasileira.

Necessidade de Flexibilidade Legislativa

  • É essencial que as leis sejam flexíveis e adaptáveis às rápidas mudanças no cenário tecnológico e nas ameaças emergentes.

Interconexão entre Segurança Cibernética e Outras Áreas

  • Há uma relação direta entre segurança cibernética, inteligência artificial e proteção de dados; todos devem ser abordados conjuntamente na nova legislação.

Discussing the Impact of AI and Cybersecurity

The Role of AI in Modern Systems

  • The integration of various AI applications is becoming increasingly prevalent across systems, leading to the creation of millions of agents operating without control.
  • These agents can lead to significant data exposure, as individuals unknowingly share their information with them, raising concerns about privacy and security.

Global Implications and Challenges

  • The discussion highlights the global nature of these challenges, emphasizing that data flows across borders, complicating regulatory efforts.
  • There is a caution against allowing fear to hinder technological development; overly restrictive laws could harm both progress and security.

Importance of Cybersecurity Education

  • Emphasizes the need for collective effort in cybersecurity; education at all levels is crucial to mitigate risks associated with careless online behavior.

Legislative Efforts in Cybersecurity

Commitment to Support Cybersecurity Initiatives

  • Acknowledgment of years spent working on technical systems and now contributing to legislative efforts aimed at enhancing cybersecurity frameworks.

Urgency for National Policy Development

  • Representation from the National Cybersecurity Committee stresses the urgency for a cohesive state policy regarding cybersecurity.
  • Highlights previous discussions that underline the importance of merging proposed regulations with existing frameworks for better governance.

Key Messages on Digital Sovereignty

Cibersegurança as a Pillar of Digital Sovereignty

  • A message from Brazil's Court of Accounts emphasizes that cybersecurity is one of three critical dimensions necessary for digital sovereignty.

Need for Improved Governance

  • Despite being a leader in digital government services, Brazil faces high rates of cyberattacks; improved governance is essential for protecting its digital economy.

Recent Incidents Highlighting Vulnerabilities

Notable Cyber Incidents

  • Discussion includes serious incidents like IPEM's attack and a major denial-of-service incident affecting civil defense services, showcasing vulnerabilities within current systems.

Monitoring Emerging Technologies

Focus on Artificial Intelligence Regulation

  • Attention drawn towards monitoring 35 technologies including AI; countries are urged to align regulatory bodies with cybersecurity efforts rather than solely focusing on data protection agencies.

Future Directions in Quantum Computing

Advancements in Quantum Technology

  • Mentioned initiatives by other nations (e.g., U.S. plans for quantum sensors by 2027), indicating an urgent need for Brazil to enhance its own capabilities in quantum technology and post-quantum cryptography.

Proposed Framework for National Cybersecurity Governance

Establishing Essential Services and Regulatory Bodies

  • Proposal includes designating certain organizations as essential services under national regulation, aiming to create a comprehensive framework involving multiple regulatory authorities.

Proposta de Centro Nacional de Cibersegurança

Importância da Segurança Cibernética

  • A criação de um centro nacional de cibersegurança é proposta como operador responsável pela segurança, monitorando ataques em tempo real e controlando funções essenciais.
  • A manutenção dessa proposta é considerada crucial, conforme apresentado pelo senador Espiridão e colegas da Frente Parlamentar, visando um programa voluntário para adesão.

Estrutura do Programa

  • O programa incluiria órgãos obrigatórios devido à importância dos serviços prestados e infraestruturas críticas, além de permitir a adesão voluntária por outros interessados.
  • O orador encerra sua apresentação oferecendo contato para mais informações sobre a fusão proposta.

Apresentação do Sr. Demi Getschko

Introdução ao NIC.br

  • Demi Getschko inicia sua fala agradecendo a oportunidade e se apresenta como diretor-presidente do Núcleo de Informação e Coordenação do Ponto BR (NIC.br).
  • O NIC é uma entidade privada que gerencia o domínio .br sem recursos públicos, mantendo uma gestão sensata desde 1989.

Gestão do Domínio .br

  • O domínio .br é amplamente adotado no Brasil; o NIC mantém o segundo nível fechado para garantir semântica no processo, evitando confusões com domínios semelhantes.
  • O CERT-BR, parte do NIC, tem uma longa trajetória na área de emergências informáticas e oferece cursos regulares sobre tratamento de incidentes.

Desafios da Cibersegurança

Temática Multifacetada

  • A cibersegurança deve ser tratada como um tema colaborativo devido à sua complexidade; as abordagens variam entre defesa institucional e proteção ao cidadão comum contra fraudes.
  • É essencial coletar denúncias sobre problemas na segurança para gerar conselhos eficazes às potenciais vítimas; a identidade dos denunciantes deve ser protegida para garantir essa coleta.

Legislação e Educação

  • A legislação deve avançar cautelosamente; experiências passadas mostram que alguns países tiveram que recuar após legislações apressadas. A frase "festina lente" ilustra a necessidade de agir com cuidado enquanto se avança rapidamente nas soluções propostas.
  • Um foco importante é aumentar o letramento em cibersegurança entre cidadãos e empresas, enfatizando que todos devem estar constantemente reconfigurando suas defesas contra ameaças móveis.

Papel do CEPESC na Segurança Cibernética

Introdução ao CEPESC

  • Rodrigo Pereira Pacheco apresenta-se como diretor substituto do Centro de Pesquisa e Desenvolvimento para a Segurança das Comunicações (CEPESC), parte da Agência Brasileira de Inteligência (Abin).
  • O CEPESC possui 44 anos de experiência em segurança da informação, sendo pioneiro no Brasil nesse campo específico.

Soberania Nacional e Infraestruturas Críticas

  • A discussão atual transcende a cibersegurança convencional; envolve também a preservação da soberania nacional e proteção das infraestruturas críticas diante das complexidades geopolíticas atuais no ciberespaço.
  • Governança em cibersegurança requer articulação com atividades de inteligência e uso avançado de criptografia estatal para mitigar riscos relacionados à ciberespionagem e cibersabotagem.(3780)

A Centralidade do CEPESC e da ABIN na Inteligência Cibernética

Pilar 1: Inteligência Cibernética como Função de Estado

  • A inteligência cibernética é uma área temática essencial da inteligência de Estado, coordenada pelo Sistema Brasileiro de Inteligência (SISBIM), que inclui mais de 40 órgãos parceiros.
  • Esta atividade está formalmente prevista na doutrina da atividade de inteligência e responde a ameaças prioritárias desde a Política Nacional de Inteligência, iniciada em 2016.

Pilar 2: Conexão com a Cibersegurança

  • A inteligência cibernética serve como suporte à cibersegurança, atuando como camada de governança para garantir políticas de resiliência que atendam aos padrões exigidos para proteger segredos nacionais.

Pilar 3: Múltiplas Fontes e Inteligência de Ameaças

  • Para cumprir sua missão estratégica, a inteligência cibernética utiliza diversas fontes, incluindo a análise tática e operacional da inteligência de ameaças, que examina dados sobre incidentes cibernéticos.

Pilar 4: Missão do CPSC-ABIM

  • O CPSC-ABIM se dedica ao enfrentamento de APTs (Ameaças Persistentes Avançadas) e pesquisa em desenvolvimento tecnológico avançado para neutralizar ameaças à administração pública.
  • Monitoramos o impacto das tecnologias emergentes, como IA e computação quântica, antecipando novas dinâmicas de risco introduzidas por essas inovações.

Desenvolvimento Tecnológico no CPSC

Algoritmos Proprietários e Criptografia Pós-Quântica

  • O CPSC lidera pesquisas em segurança tecnológica focadas na criação de algoritmos com criptografia pós-quântica para proteger comunicações críticas contra futuras capacidades computacionais.

Comparações Internacionais em Segurança Digital

Exemplos Globais

  • Referências globais como o Reino Unido (National Cyber Security Center), EUA (NSA e CISA), e Espanha (Centro Criptológico Nacional) demonstram que a inteligência civil é fundamental para a resiliência digital dos países.

Importância do Papel do CPSC-ABIM

Ativos Indispensáveis para Resiliência Digital

  • O know-how acumulado pelo CPSC é vital para assegurar que o Brasil atue proativamente na era digital, evitando ser um mero espectador reativo às ameaças cibernéticas.

Introdução ao Senhor Rony Weishoff

Importância do Tema da Cybersegurança

Participação no Senado

  • Rony destaca seu orgulho em representar entidades empresariais na audiência sobre cybersegurança no Senado, evidenciando o grande público presente como sinal da relevância do tema.

Proposta Legislativa PL 4752

Urgência da Aprovação

  • Ele ressalta a importância do PL 4752 e sua conexão com as propostas discutidas no Comitê Nacional de Cybersegurança (CNCiber), enfatizando a necessidade urgente dessa legislação para mitigar riscos econômicos relacionados à segurança digital.

Custos dos Incidentes Cibernéticos

Impacto Financeiro

  • Os custos anuais relacionados a fraudes cibernéticas podem chegar até US$10 trilhões globalmente; no Brasil, esses custos são estimados em R$100 bilhões anualmente apenas por golpes digitais.

Vulnerabilidades Tecnológicas

Desafios Emergentes

  • Com o avanço das tecnologias como IA, vulnerabilidades podem ser exploradas rapidamente; menos de 1% das vulnerabilidades conhecidas foram corrigidas efetivamente até agora.

Necessidade por um Órgão Centralizado

Proposta Legal

  • O TCU alertou sobre a falta de uma organização oficial capaz de zelar pela maturidade da segurança cibernética no Brasil; propõe-se um marco legal com um órgão centralizado para coordenar esforços nesse sentido.

Coordenação Nacional em Cybersegurança

Abordagem Baseada em Risco

  • É necessário evitar sobreposição sancionatória nas ações relacionadas à cybersegurança; deve haver foco na avaliação contínua da maturidade organizacional.

Conclusão sobre Colaboração Legislativa

Complementariedade entre Propostas

  • As propostas legislativas devem se complementar visando fortalecer as bases legais necessárias à transformação digital segura no Brasil.

Opening Remarks by Rodrigo Jonas Fragola

Introduction to the Confederação Acesp

  • Rodrigo Jonas Fragola introduces himself as the Vice-President of Political Articulation at the Confederation of Brazilian Information Technology Companies (Confederação Acesp), representing 3,500 companies in software development, particularly small and medium-sized enterprises.

Professional Background

  • Fragola shares his credentials: a bachelor's degree in computer science from the University of Brasília and specialization in cyber policy and strategy from the Escola Superior de Guerra. He has 30 years of experience in Cyber Security.

Importance of Cybersecurity

  • He emphasizes the significance of mastering technology that ensures national security, highlighting three critical points for evaluation regarding cybersecurity initiatives.

The Role of Collaborative Projects

Union of Initiatives

  • Fragola stresses that combining two specific projects will enable effective action towards enhancing national security, aligning with earlier comments made by Marcelo and Rony.

Holistic Risk Management

  • He argues that cybersecurity risks are now shared across entities, necessitating a mature agency capable of evaluating and improving overall market security rather than focusing solely on individual risks.

National Sovereignty Concerns

Technology Development Necessity

  • Fragola warns against investing heavily in foreign products without developing local technology autonomy, stating that such investments are futile if they do not enhance national sovereignty.

Espionage Risks

  • He highlights concerns over using products from nations known for espionage practices, arguing that security measures must be rooted in domestic capabilities to be effective.

Regulatory Challenges for Private Enterprises

Impact of Fines on Businesses

  • Fragola expresses concern about excessive fines imposed on private companies involved in critical infrastructure, advocating for penalties to be applied judiciously and only in cases of negligence.

Supportive Role of ANSIBER

  • He calls for ANSIBER's role to focus on guidance rather than punitive measures, enabling private sector contributions to improve cybersecurity efforts collaboratively.

Legislative Contributions

Need for Legislative Text

  • Fragola suggests presenting legislative text based on his extensive experience to aid lawmakers effectively during discussions about cybersecurity legislation.

Call for Formal Feedback

Importance of Presentations

  • Acknowledging valuable presentations made during the session, he urges participants to formalize their insights into written opinions or reports to contribute meaningfully to ongoing legislative processes.

Engaging Experts

Collaboration with Recognized Entities

  • The session aims to gather input from qualified individuals and organizations within government and industry sectors to compile comprehensive feedback on proposed legislation addressing cybersecurity challenges.

Introduction by Luiz Henrique Barbosa

Overview of Telcomp Association

  • Luiz Henrique Barbosa introduces himself as President Executive at Telcomp, representing telecommunications service providers across Brazil’s connectivity landscape including submarine cables and data centers.

Cybersecurity Vulnerabilities

  • Barbosa notes that all member companies face cybersecurity threats due to their roles as connectivity providers; thus emphasizing the importance of robust legal frameworks addressing these vulnerabilities amid digital transformation trends.

Importance of Legal Framework in Data Responsibility

Overview of Responsibilities in Data Handling

  • The legal framework emphasizes that responsibility for data handling extends beyond telecommunications to all entities involved in capturing, processing, and storing data.
  • It is crucial that obligations are proportional to the risks posed by different actors within the data ecosystem, rather than imposing uniform requirements.

Cooperation Between Sectors

  • Effective resolution of cybersecurity issues requires collaboration between public and private sectors; neither can tackle these challenges alone.
  • There is a need for secure reporting mechanisms for threats detected by private entities before they escalate to state-level awareness.

Crisis Management and National Coordination

  • Media coverage during crises can lead to reputational damage and direct economic impacts on organizations involved.
  • Establishing a national agency for coordination is vital for protecting those affected by crises, especially when they have taken necessary precautions.

Legislative Opportunities for Cybersecurity in Brazil

Integration and Harmonization Efforts

  • The proposed legislation aims to integrate various regulatory efforts while avoiding duplication of oversight among agencies, ensuring clear responsibilities are defined.
  • This legal framework represents a historic opportunity for Brazil to adopt an integrated approach towards digital transformation across its ecosystem.

Insights from Luca Belli on Cybersecurity Regulation

Background and Expertise

  • Luca Belli introduces himself as a professor with extensive experience in digital technology regulation and cybersecurity over the past 20 years.

Essential Elements for Cybersecurity Framework

  • In his recent publication, Belli outlines five essential elements needed to build effective cybersecurity: regulatory framework, agency establishment, multistakeholder council, system integration, and industrial policy support.

Current Challenges in Brazilian Cybersecurity Landscape

  • Despite advancements in regulations over the last five years, Brazil faces significant challenges including high rates of cyberattacks (356 billion attempts reported).
  • The country suffered substantial financial losses due to cyber incidents (100 billion reais), highlighting the urgent need for skilled professionals—over 700 thousand positions remain unfilled.

Paradoxical Progression in Cybersecurity

  • Belli describes Brazil's situation as a "Schrödinger's cat" scenario where progress coexists with setbacks; while some regulations advance cybersecurity efforts, many sectors lack prioritization or coordination.

Recommendations for Future Action

  • He advocates that effective communication and regulatory coordination are critical components of any new legislative measures aimed at enhancing cybersecurity resilience.

Introduction and Context

Opening Remarks

  • The speaker emphasizes that the books in the FGV library are for knowledge dissemination, not for sale.
  • Belisario Contreiras expresses gratitude for the invitation to speak and congratulates Brazil on its recent victory over Japan.
  • Acknowledges key figures in cybersecurity leadership, including Senator Amin and others.

Focus of Presentation

  • The main focus is on online child protection as a significant public policy challenge in the region.
  • Highlights increasing digital technology use among children in Latin America, which brings both opportunities and risks.

Challenges in Online Child Protection

Risks Faced by Children

  • Recent reports identify growing risks such as online grooming, sexual exploitation, cyberbullying, harmful content exposure, privacy violations, algorithmic amplification of harmful content, and challenges from emerging technologies like AI.

Policy Gaps

  • The report outlines critical gaps in public policies addressing these issues while also suggesting practical solutions.

Key Recommendations for Cybersecurity Legislation

Central Conclusions

  • Protecting children online should not compromise privacy or freedom of expression.
  • Collaboration among various stakeholders (government, private sector, civil society, educators, parents) is essential to tackle these challenges effectively.

Successful Models

  • International experiences show that successful models combine security with privacy protections and risk-based regulations.

Brazil's Current Position and Legislative Recommendations

Existing Strengths

  • Brazil has valuable assets like data protection institutions and initiatives such as Cefernet to enhance cybersecurity capabilities.

Specific Legislative Suggestions

  • Emphasizes clarity in governance structures and institutional responsibilities within cybersecurity legislation.

Future Directions for Cybersecurity Agency

Institutional Independence

  • Advocates for an autonomous National Cybersecurity Agency with technical independence to ensure effective coordination without federal subordination.

Risk-Based Approach to Cybersecurity

Proportional Obligations

  • Calls for cybersecurity obligations proportional to actual risks presented by services like cloud computing.

Defining Responsibilities

Shared Responsibility Model

  • Legislation should clearly define responsibilities among providers, operators, and users reflecting current technological realities.

Conclusion: Opportunities Ahead

Regional Leadership Potential

  • Brazil has a chance to become a regional leader in child protection online while establishing a modern framework for cybersecurity that balances security with fundamental rights.

Transition to Luana Tavares Diniz

Introduction of New Speaker

  • Luanas thanks everyone present at the hearing while introducing herself as representing the Multisectoral Alliance for Cybersecurity.

Overview of Multisectoral Alliance

Composition of Alliance

  • Luana details the diverse organizations involved in the alliance including FEComércio de São Paulo and FEBRABAN among others.

Collaborative Efforts

Ongoing Contributions

  • Expresses pleasure at collaborating on legislative processes since inception through initial drafts leading up to this audience discussion.

Discussion on Cybersecurity Legislation and Vulnerable Citizens

Integration of Responsibilities in Cybersecurity

  • The importance of cooperation among various entities such as IPF, Civil Police, Public Ministry, Judiciary, and Intelligence is emphasized to clarify responsibilities and enhance integration.

Focus on Vulnerable Citizens

  • A suggestion is made to address the needs of vulnerable citizens—such as the elderly and children—during discussions about legal frameworks. This highlights a need for national coordination and clearer regulations.

Education and Emerging Technologies

  • There is a call for special attention to digital education for vulnerable groups, including proposals to integrate this into the national curriculum. Additionally, emerging technologies should be considered in legislative discussions.

Documenting Contributions for Legal Framework

  • A document summarizing contributions from various stakeholders will be shared to facilitate progress in drafting legislation that addresses critical societal issues effectively.

Closing Remarks by Luana de Brito Tavares Diniz

  • Luana expresses gratitude for the opportunity to contribute to the process and offers support from her organization, INCC. She emphasizes collaboration among senators and consultants present at the meeting.

Insights from Patrícia Peck on Cybersecurity

Acknowledgment of Key Figures

  • Patrícia thanks key senators involved in cybersecurity discussions, highlighting their representation in addressing these crucial topics within Brazil.

Experience in Technology Law

  • With 25 years of experience in technology law and numerous publications, Patrícia shares her expertise related to artificial intelligence and cybersecurity during her presentation.

Importance of Diversity in Cybersecurity

  • Emphasizing diversity, she advocates for increased female participation in cybersecurity fields from an early age. This reflects a broader commitment to inclusivity within technological sectors.

Addressing Cybersecurity Gaps

  • Patrícia points out significant gaps in Brazil's cybersecurity landscape that need urgent attention. She stresses that true state sovereignty requires both digital and quantum sovereignty amidst rising cyber threats.

Complementary Legislative Proposals

  • She clarifies that proposed bills (PL 4752 & CNCIBER draft) are not competitors but rather complementary efforts aimed at improving Brazil's cybersecurity framework over time.

Technical Perspectives on Cyber Risk Management

Transitioning Towards Risk Management Culture

  • The discussion highlights a shift from reactive responses towards proactive risk management strategies as essential for enhancing digital resilience across society.

Role of Insurance Market

  • The effectiveness of laws should be measured by societal adherence rather than strictness; thus, the insurance market can play a vital role by providing necessary resources for implementation efforts.

Economic Viability of Digital Inclusion

  • Addressing high costs associated with operational structures is crucial; insurance can facilitate economic viability especially for small-medium enterprises (PMEs), aiding their compliance with regulations.

Certification Induction through Insurance Policies

  • The proposal includes incentivizing proactive certification practices through insurance policies which would require basic governance standards before coverage can be obtained.

Cybersecurity Insurance and Its Role in National Resilience

The Importance of Cybersecurity Insurance

  • Cybersecurity insurance can serve as a complementary tool for indirect state supervision, ensuring compliance with legal frameworks.
  • The low technical maturity of Brazilian industries affects their response times to cyber incidents, highlighting the need for improved resilience.
  • Beyond financial losses, cybersecurity insurance provides immediate responses and qualified panels to manage incidents effectively.

Mitigating Economic Impacts

  • Stakeholders share responsibility in mitigating consequences from cyber incidents, enhancing the state's response capabilities and minimizing economic impacts.
  • The insurance market generates valuable data on cyber realities, including attack vectors and incident monitoring, contributing to better preparedness.

Benefits for Society and Governance

  • For society and the state, cybersecurity insurance leads to regulatory efficiency, cost reduction in oversight, and increased national resilience.
  • It aims to minimize incident impacts while ensuring service continuity and fostering digital trust within the economy.

Legislative Framework and Market Integration

  • Legislative projects aim to establish a modern system that relies on effective induction tools for implementation.
  • Insurers should integrate into national cybersecurity structures (SNCiber), recognizing cybersecurity insurance as a strategic public policy tool.

Current State of Cybersecurity Insurance in Brazil

Market Overview

  • There is still low adoption of cybersecurity insurance in Brazil despite available products across various sectors.
  • Current offerings include policies specifically designed for digital protection against fraud beyond just malicious hacker actions.

Comparison with Global Markets

  • Brazil's market has approximately 300 million reais in premiums compared to 10 billion dollars annually in the U.S., indicating significant room for growth.
  • Effective incentives are necessary for broader adoption of cybersecurity measures that encompass governance frameworks alongside risk transfer.

Adapting Products for SMEs

  • Many small and medium enterprises struggle with lengthy application processes; however, simplified products have been developed recently.
  • New offerings allow access starting at one thousand reais annually, reflecting an understanding of SMEs' roles within larger corporate ecosystems.

Insights from Palo Alto Networks on Cybersecurity Legislation

Acknowledgment of Key Contributors

  • Patrick Aron Rinsky expresses gratitude towards senators involved in legislative efforts aimed at strengthening Brazilian digital sovereignty.

Challenges Ahead

  • As Brazil undergoes digital transformation, it must ensure that new laws lead to tangible improvements in cyber resilience rather than mere compliance checks.

Need for Dynamic Approaches

  • Static compliance can create false security; real-time threat detection is essential given adversaries' rapid operational capabilities.

Learning from Global Practices

  • Brazil should adopt continuous risk management practices seen globally (e.g., EU regulations), focusing on proactive incident reporting rather than bureaucratic processes.

Cybersecurity Approaches in the U.S. and U.K.

Evolving Strategies in Cybersecurity

  • In the United States, there is a shift towards greater executive accountability, dynamic metrics usage, and frameworks like NIST Cybersecurity.
  • The United Kingdom adopts a results-based approach, focusing less on specific technologies and more on risk limits, operational failures, and innovation protection.
  • The focus has shifted from merely detecting breaches to how quickly they are identified, contained, and remediated.

Legislative Recommendations for Cybersecurity

  • Legislation should be technology-neutral, emphasizing operational outcomes rather than static compliance; continuous visibility culture is essential for monitoring digital environments.
  • Latin America faces significant challenges in early threat detection within critical environments; attackers often remain undetected for extended periods.

Importance of Objective Indicators in Cybersecurity

Metrics and Intelligence Sharing

  • Objective indicators such as MTTD (Mean Time to Detect) and MTTR (Mean Time to Respond), along with effective attack interruption measures, are crucial.
  • Incident response centers should evolve into a national immune system for cybersecurity threats.

Role of National Authority

  • A future national authority must go beyond oversight to coordinate efforts among government entities, private sectors, academia, and society.

Data Sharing Protocols

Automation in Threat Response

  • Data sharing protocols need to be machine-readable; manual processes are insufficient given the speed of threats.

Dynamic Definition of Critical Infrastructure

  • The definition of critical infrastructure should be dynamic and based on systemic risk rather than just current essentials.

Modernizing Identity Management

Continuous Identity Posture Management

  • There is a need to modernize identity management systems; traditional authentication methods like SMS are inadequate against sophisticated attacks.

Automated Containment Measures

  • Security systems must automate the isolation of compromised assets to reduce attack propagation risks.

Protecting Artificial Intelligence Systems

Real-Time Monitoring Mechanisms

  • Specific protective mechanisms for AI systems must monitor model behavior to identify misuse and halt malicious activities instantly.

Urgency in Digital Defense

Analogies with Airspace Protection

  • An analogy is drawn between national airspace defense using radars and fighters acting immediately against hostile aircraft versus delayed responses in digital security contexts.

Transitioning Towards Proactive Cybersecurity Strategies

Moving from Reactive to Preventive Measures

  • By adopting result-based metrics and automated containment strategies, Brazil can shift from reactive postures toward coordinated preventive approaches that enhance resilience.

Building a Resilient Digital Nation

  • This legislation aims not only at law approval but also at establishing the backbone of a resilient digital nation capable of thriving without fear. Contributions from Palo Alto Networks were offered for enhancing cybersecurity legal frameworks.

Discussing National Entities and Market Competition

The Impact of Favoring National Entities

  • Prioritizing national entities can hinder the development of know-how, new products, and genuine competition in the market.
  • WEG is highlighted as a successful national company that competes globally due to its quality rather than sector-specific benefits.

Regulatory Concerns for Small Businesses

  • Automatic cloud regulation poses significant challenges for businesses of all sizes, particularly small ones.
  • Concerns were raised about how stringent regulations could push smaller players out of the market, leading to potential monopolies.

Digital Sovereignty and Data Control

Defining Digital Sovereignty

  • A clear definition of digital sovereignty is essential; it should be established by the state rather than individual governments.
  • Emphasis on knowing where data is stored and who has access to it is crucial for maintaining control over digital assets.

Cybersecurity Basics

  • Basic cybersecurity measures, such as regularly changing passwords, are vital yet often overlooked.
  • The need for operational resilience through layered security measures is emphasized as critical for Brazil's cybersecurity landscape.

Legislative Developments in Technology

Current Legislative Initiatives

  • A proposed Digital Market Act aims to create a framework that may lead to censorship within regulatory bodies like CAD.
  • Positive developments include legislation on stablecoins and financial market infrastructure that could enhance digital interoperability.

Caution Against Retrogression

  • There’s a strong call to avoid regression in technological advancements while ensuring careful legislative processes similar to tax reforms.

Innovation vs. Regulation

Balancing Innovation with Regulation

  • Brazil's AI law was passed before generative AI became prevalent; caution is needed not to stifle innovation with outdated regulations.
  • Active participation in the market is necessary for progress; historical context from the 1980s highlights risks associated with excessive regulation.

Systemic Approaches Needed

Interconnected Solutions Required

  • Addressing issues requires an interconnected system rather than relying solely on one agency or approach.

Inclusion Efforts

  • The importance of including diverse groups (e.g., women and elderly individuals in digital inclusion efforts), emphasizing systemic approaches for effective implementation.

Infrastructure Development Challenges

Urgency in Infrastructure Projects

  • Delays in critical projects like Redata are causing economic losses; there’s an urgent need for these initiatives to move forward.

Historical Context on Telecommunications

  • Past experiences during 5G auction preparations highlight concerns regarding foreign technology dependencies, especially from China.

Private Sector Collaboration

Importance of Private Sector Involvement

  • Collaboration between public and private sectors is essential; adversarial relationships do not yield positive outcomes.

Conclusion on Legislation Impact

  • Laws must be crafted carefully to support national interests without hindering necessary innovations.

Opening Remarks and Acknowledgments

Introduction to the Meeting

  • The speaker commends Senator Amin for his democratic approach in gathering suggestions and acknowledges attendees, including international participants.

Project Presentation

  • The speaker clarifies that while he is a signatory of the project, it is a collective effort with contributions from various partners over time.

Legislative Process and Responsibilities

Role of the Rapporteur

  • Emphasizes the importance of the rapporteur's role in legislative work, highlighting collaboration with consultancy to ensure thorough law-making.

Addressing Criticism

  • Critics acknowledge that the proposed law does not stifle creativity or innovation, which are essential in today's fast-paced world.

Current Technological Landscape

Speed of Change

  • The rapid pace at which technology evolves is noted, suggesting that traditional measures may struggle to keep up with advancements like AI and quantum computing.

Urgency for Legislative Progress

Importance of Timely Approval

  • The speaker expresses hope for swift progress on the report due to an atypical election year, stressing its significance for Senate committees and subsequent discussions in the Chamber of Deputies.

Commitment to Inclusivity

Engagement with Stakeholders

  • Acknowledges diverse representation from public and private sectors at the meeting, reinforcing commitment to addressing national interests through collaborative efforts.

Responsibility as Rapporteurs

Dedication to Comprehensive Legislation

  • The rapporteurs commit to carefully considering all contributions received during consultations both domestically and internationally, ensuring legislation reflects broad concerns.

Conclusion of Public Hearing

Summary of Discussions

  • Concludes by recognizing that today’s discussions enriched understanding of Bill 4752/2025, emphasizing cybersecurity as a matter beyond technology—pertaining also to sovereignty and citizen protection.

Gratitude Expressed

  • Thanks all participants for their contributions and engagement throughout the hearing process.
Video description

A Comissão de Ciência, Tecnologia, Inovação e Informática (CCT) realiza audiência pública para instruir o PL 4.752/2025, que institui o Marco Legal da Cibersegurança, cria o Programa Nacional de Segurança e Resiliência Digital e altera a Lei 13.756/2018. O debate reúne representantes do governo, da academia e do setor produtivo para discutir estratégias de proteção digital, prevenção a ataques cibernéticos e fortalecimento da segurança das redes no Brasil.  Nossas páginas: TV Senado (https://www12.senado.leg.br/tv#) Senado Federal (https://www12.senado.leg.br/hpsenado) Inscreva-se no nosso canal do YouTube: (http://www.youtube.com/channel/UCLgti7NuK0RuW9wty-fxPjQ?sub_confirmation=1) #TVSenado #SenadoFederal #Senado2026