
Events
From attack to systemic risk: the new challenges of cybersecurity
OPLIUM made its presence felt at Mind The Sec 2026, one of the largest cybersecurity events in Latin America.
On September 15, it moderated the panel “Modern Cyberattacks and Systemic Impact,” bringing together criminal investigation, banking defense, and corporate security. On the 16th, it took to the stage with the presentation “The New Cybersecurity Game: Attacks at Scale.” These two moments converged on the same understanding: the attack is no longer an isolated technical event but has become systemic, and if the risk is systemic, the defense must be as well.
Held in São Paulo, Mind The Sec brings together thousands of professionals, CISOs, and security leaders in hundreds of sessions spread across multiple stages. It was in this environment, filled with discussions about artificial intelligence and autonomous agents, that OPLIUM brought a less obvious and more structural lens: that of scale and systemic impact.
The panel: when the attack scales and becomes an institutional crisis
The debate on the 15th started from a realization: when we think of a cyberattack, we still imagine someone trying to breach a technological barrier. But the landscape has changed. Identity, cloud, SaaS, APIs, AI, personal devices, third parties, and even messaging apps have become part of the business environment, and on the other side, threat actors have professionalized, with specialization, automation, and monetization chains.
Adonias Filho, Chief Commercial Officer at OPLIUM and panel moderator, opened the conversation: “For years, we protected servers, networks, and endpoints. Today we protect data, identities, people, applications, and trust relationships, and these relationships do not stop at the border of a single company. That is why we brought investigation, banking, and the financial ecosystem to the same table.”

“If the attack has become systemic, the defense must be as well,” Adonias Filho, from OPLIUM.
From the perspective of those who investigate crime in the real world, the change is in nature, not just in degree. What was once seen as the action of isolated individuals is now organized as a structured economy.
Delegado Emerson Wendt, Civil Police Delegate of Rio Grande do Sul and OSINT researcher, observed: “What we see in investigations is no longer the lone hacker, it is a chain with division of labor: those who get access, those who carry out the scam, those who launder, and those who resell the information. And criminals cooperate faster than companies. Brazil moves forward when the private sector and public authorities exchange intelligence at the speed of the incident, and not weeks later.”

“Cybercrime has become a structured economy, and the attacker cooperates faster than the defender,” Delegado Emerson Wendt, from the Civil Police of RS.
If the attacker has changed, so has what we try to protect. The notion of perimeter, a clear boundary between inside and outside, was the first victim of this transformation.
Fernando Bruno, Cybersecurity Superintendent at Banco Bradesco, reflected: “The traditional perimeter is gone. When user, data, application, cloud, and third parties are distributed, defending the edge no longer protects what matters. The CISO's challenge is no longer to build walls, but to have visibility and governance over data wherever it is, including in the channels that the business itself has adopted.”

“The perimeter is gone; today we protect data wherever it is,” Fernando Bruno, from Banco Bradesco.
There is also a third dimension. Modern business, built on APIs, cloud, and partners, is, by definition, collective. A significant part of each company's risk is not under its direct control.
Thiago Cunha, Vice President of Corporate Security at Dock, summarized: “A business made of APIs, cloud, and partners is structurally collective, and in a financial ecosystem, technical attack and fraud are the same problem viewed from different angles. That is why we merged cybersecurity and fraud prevention into a single center, operating 24/7. Believing in individual security, in an environment that is collective, is an illusion.”

“Individual security, in an ecosystem that is collective, is an illusion,” Thiago Cunha, from Dock.
The conversation converged on the point that gives the panel its name: interconnected risk produces systemic impact. Attackers share tools, infrastructure, and knowledge much faster than defenders share intelligence. Effective defense, the panel concluded, requires technology, but also intelligence, data governance, and collaboration, including between private enterprise and public authorities.
The presentation: attacks at scale and the shift toward resilience
The panel diagnosed the problem; the presentation on the following day offered an answer. On the PS10 stage, OPLIUM presented what it called the “new game” of cybersecurity: driven by AI, automation, and complex digital chains, incidents no longer affect one company at a time but impact multiple organizations simultaneously.
OPLIUM demonstrated, with recent public cases, how a single compromised point propagates through dependencies, third parties, and technological concentration. In this scenario, artificial intelligence changes its role: it is no longer just another risk vector, but becomes a capability lever with correlation, automation, and response at the speed of the attack, increasing resilience instead of just expanding the surface.
George Chaves, Director of Innovation and New Business at OPLIUM, shared a reflection: “We have been watching companies full of AI initiatives, but without a clear strategy and governance, the technology ends up only optimizing our work, when it should be increasing our defense capacity. That is what we propose: using AI to transform the reading of risk into installed capacity, reduce the impact radius, test resilience, and support companies to be ready to continue operating even under attack.”

“You don't fight attacks at scale with artisanal risk management,” George Chaves, from OPLIUM.
OPLIUM's proposal: a resilience framework at scale
Cyber resilience begins by accepting that you cannot prevent every attack, but that it is possible to contain its propagation. And that is where the traditional risk matrix falls short: probability and impact tell you how likely and how severe, but they do not measure how far the event propagates. Therefore, risk gains a third dimension, the blast radius, the impact radius. This is what separates a contained incident from a systemic crisis.
Chaves showed, with recent public cases, how a single compromised point propagates through dependencies, third parties, and technological concentration. More than a concept, the blast radius can be applied as a key prioritization criterion, mapping how far the impact can reach across the entire supply chain and using that reading to decide where to invest. In this scenario, artificial intelligence changes its role: it is no longer just another risk vector, but becomes a capability lever with correlation, automation, and response at the speed of the attack, increasing resilience instead of just expanding the surface.
It was at this point that the presentation reached OPLIUM's proposal: a framework designed to contain the radius from end to end. Under a layer of risk governance and strategy, the model organizes defense into 5 capabilities that function as a continuous and adaptive cycle, increasing companies' resilience and reducing the impact radius, with artificial intelligence accelerating each of these capabilities, instead of operating as isolated initiatives.

Overview of the OPLIUM Cyber Resilience Framework
Between the panel and the presentation, OPLIUM's message at Mind The Sec 2026 was clear: the modern attack is distributed, specialized, and exploits trust relationships that go beyond the border of any company. Protecting, in this scenario, means seeing the data, reducing the impact radius, and building resilience with technology, intelligence, governance, and collaboration. Because, if the attack has become systemic, the defense must be as well.