Why MSPs Must Take a Proactive Role in Cybersecurity Planning
MSPs are no longer called when something breaks or if a password needs to be reset. MSPs act as trusted advisors or business partners that provide clients with strategic guidance on how to reduce risk, allocate budget effectively, and build long-term cybersecurity success roadmaps.
Building a cybersecurity roadmap begins with a full understanding of the client’s existing infrastructure and technologies, the number of endpoints, and business-critical assets at the highest risk of exposure. The most binary way to present these key findings to your client is by conducting a thorough risk assessment of all assets, endpoints, applications, and users. A risk assessment is your starting point of reference.
Once you’ve inventoried all business-critical assets, endpoints, applications, and users within your client’s organization and perimeter scope, you’ll have better visibility into the level of threat exposure to build a sustainable cybersecurity plan and roadmap.
Your client will be surprised by what you discover, as they’re likely unaware of just how many unmanaged devices or shadow IT applications are circulating freely within their network. Then we have the issue of third parties, with unrestricted access to cloud environments, lingering around. These are the details you need to consider when planning the assessment. Cover every possible attack scenario unique to the client’s current security posture. This is where you get to showcase your expertise as a trusted security partner and advisor.
The risk assessment and planning stage is where your clients can set aside a budget based on anticipated risk reduction and revenue generated from cybersecurity initiatives. As a trusted security advisor, you must demonstrate those estimated cost-saving opportunities. This can be done in the form of threat exposure KPIs, which can be attributed to measurable outcomes and benchmarked as part of quarterly business review (QBR) discussions.
4 Key Components of a Winning Cybersecurity Roadmap
Focus on ROI-Driven Threat Metrics: Threat exposure metrics tied to business-driven objectives, such as a lower Mean Time to Resolution (MTTR) or number of endpoints secured MoM, help quantify the effectiveness of your cybersecurity investments. 50 additional endpoints secured can significantly reduce the attack surface. Other threat exposure metrics to focus on include phishing click rate, percentage of users enrolled in MFA, and incident closure rate. Fewer incidents. Fewer support tickets. More time for strategic projects. Better allocation of IT resources and measurable ROI that your clients can actually see. These metrics are highly valuable when justifying security budgets.
Cyber Insurance Optimization:Cyber insurance isn’t optional; it’s mandatory. Every business must have cyber insurance coverage. Save your clients the time, guesswork, and frustration by aligning your cybersecurity roadmap with their unique business needs and attack surface posture. This means having the right security controls in place to prevent potential attacks, such as ransomware, which many insurance providers either won’t cover or may partially cover. A potential ransomware attack could cost your clients more if they need to reach into their pockets due to denied claims, coverage gaps, or high deductibles. Comb through the exclusions and limitations, and make sure the fine print matches the cybersecurity roadmap you’re building for your clients.
Cost-Saving Opportunities: Imagine if you could optimize unused cloud storage, reduce the amount of licenses your client pays for, and automate certain processes, such as threat detection and response. Budget planning is a key consideration for clients to sign off on the POC and provide you with sustainable business for the foreseeable future.
Other areas for cost-saving opportunities include negotiating vendor contracts for better pricing, consolidating tools, and offering complementary security training awareness for employees. No additional investment needed. Because if a single employee falls for a phishing campaign, you could be saving your client millions. Your clients would be greatly appreciative and reward you with long-term loyalty and business.
These are also golden opportunities to upsell or cross-sell advanced services, introduce bundled packages, and experiment with tiered pricing models that align with your cybersecurity roadmap. Take the initiative here. Shop around and compare vendors to give your clients the best offer. Let them know that you’re looking out for their best interests. This forward-thinking will help deepen the trust level and position you as a value-driven partner, rather than just “another IT provider.”
Tool Consolidation: Does your client know the number of security tools they have or use? Probably not. A study found that companies can have between 60 to 75 security tools installed on average, with larger enterprises typically deploying more than double the number of tools.
Shadow IT becomes a big concern, especially for remote employees who may have an entire ecosystem of unapproved apps, tools, and cloud services running on personal or unmanaged devices. By the way, your clients might not even know how many identities are being granted access to these tools, or if the tools are even being used at all. Oh, and let’s not forget the added threat risk exposure for those unused tools waiting to be exploited by an attacker at any given moment.
Then we have the cost factor.
More tools translate to more users, more licensing fees, extra maintenance, dedicated support teams, and vendor lock-in, where clients become stuck with contracts for tools they no longer use or need. Cost aside, tool sprawl can create many bottlenecks and data silos across departments.
Tool consolidation helps organizations reduce management complexity and improve visibility by centralizing data and workflows into a single pane of glass, which is what Guardz does.
Building a Winning Cybersecurity Client Roadmap with Guardz
Cybersecurity roadmaps and client budgets require a lot of strategic planning. The Guardz unified platform provides MSPs with a holistic view of all assets, identities, endpoints, and applications from a holistic aggregated view. Consolidate your security controls and demonstrate real value to your clients while building a winning roadmap and game plan for the long run. Protect your clients’ most business-critical assets with AI-powered threat detection and response.
About Guardz Guardz is on a mission to create a safer digital world by empowering Managed Service Providers (MSPs). Their goal is to proactively secure and insure Small and Medium Enterprises (SMEs) against ever-evolving threats while simultaneously creating new revenue streams, all on one unified platform.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
Data lakes have evolved. Once treated as passive storage archives, they’re now becoming active components of enterprise risk management. The driver? Selective retrieval — the ability to park large data volumes in cold storage and later retrieve targeted slices for forensic or compliance needs.
This shift matters. According to 2025 data from Cybersecurity Insights Group, 73% of enterprises report that SIEM ingestion costs are limiting their real-time analysis capacity. At the same time, 62% of security leaders say forensic readiness is a top priority for compliance and post-incident response.
Here are five ways selective retrieval strategies are helping CISOs address both challenges without sacrificing visibility.
5 Selective Retrieval Strategies in Action
1. Focus Real-Time Analytics on High-Signal Data
Not every log needs immediate analysis. Modern pipelines now allow teams to route high-signal logs, like authentication failures or denied firewall requests, directly to SIEM tools for real-time analysis. Lower-signal data, such as successful logins or benign file accesses, can be sent directly to a central data lake.
The advantage is cost control without loss of coverage. When investigations require it, teams can retrieve dormant logs selectively, analyzing only the relevant portions.
In 2025, 58% of organizations report shifting non-critical data to cold storage to optimize real-time detection capacity. Selective retrieval operationalizes that shift without losing forensic traceability.
2. Improve Forensic Readiness While Reducing Always-On Costs
Maintaining hot access to all historical data is financially impractical. Enterprises using selective retrieval can store 12 to 24 months of logs affordably in cold storage and retrieve subsets for investigations as needed.
One European engineering firm reported a 45% reduction in SIEM licensing fees after adopting selective retrieval, while simultaneously extending their log retention period from six months to two years.
This approach separates storage from processing, giving security teams access to necessary data without ongoing analysis overhead.
3. Balance Security Priorities with Compliance Mandates
Compliance teams often require long-term data retention, but this should not dictate analytics workflows. By tagging data on ingest, teams can store all logs for audit readiness while restricting active analytics to data supporting detection priorities.
In 2025, 69% of financial services organizations reported using metadata tagging to manage regulatory and operational log requirements separately. This ensures compliance reporting needs are met without compromising security team efficiency.
4. Retain Full Visibility Across Noisy Data Sources
Firewall logs are a prime example of high-volume, low-actionability data. Many teams historically chose between retaining denied requests or successful connections due to storage and processing constraints.
Selective retrieval removes that tradeoff. Both denied and accepted traffic logs can be stored without analysis, preserving full visibility. When a post-incident review demands it, analysts can retrieve only the relevant data window to answer specific questions.
In regulated sectors like healthcare and manufacturing, 64% of security teams now cite selective retrieval as essential for supporting internal investigations without expanding real-time infrastructure.
5. Treat the Data Lake as an Operational Asset
Data lakes are no longer passive archives. Modern architectures support preview-before-ingest capabilities and conditional retrieval triggers, transforming data lakes into active security resources.
Instead of analyzing everything or ignoring large datasets, teams can treat stored logs as a reservoir to be accessed precisely when needed — whether for compliance audits, insider threat detection, or incident response.
The result is not just cost savings. It is operational flexibility. In 2025, 71% of CISOs surveyed by TechTarget acknowledged that selective retrieval had directly improved their team’s investigative efficiency.
Looking Ahead
Selective retrieval represents a practical shift in how CISOs manage data growth, security visibility, and compliance obligations. By separating storage from analysis, security leaders can cover more risk scenarios without overextending budgets or infrastructure.
As data volumes continue rising, adopting selective retrieval is becoming less of a niche strategy and more of an operational standard.
Graylog supports these strategies with flexible ingestion, metadata tagging, and retrieval pipelines, enabling CISOs to protect, retain, and investigate without adding unnecessary drag to daily detection operations.
Ready to stop paying for data you’re not actively using? Learn how Graylog’s selective retrieval unlocks forensic readiness and compliance flexibility—without overwhelming your SIEM or your budget. See how it works.
About Graylog At Graylog, our vision is a secure digital world where organizations of all sizes can effectively guard against cyber threats. We’re committed to turning this vision into reality by providing Threat Detection & Response that sets the standard for excellence. Our cloud-native architecture delivers SIEM, API Security, and Enterprise Log Management solutions that are not just efficient and effective—whether hosted by us, on-premises, or in your cloud—but also deliver a fantastic Analyst Experience at the lowest total cost of ownership. We aim to equip security analysts with the best tools for the job, empowering every organization to stand resilient in the ever-evolving cybersecurity landscape.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
Penta Security Achieves ‘Triple Crown,’ Named Frost & Sullivan’s WAF Company of the Year for Third Consecutive Year
Recognition highlights the market leadership of Penta Security’s advanced WAAP solutions, WAPPLES and Cloudbric WAF+.
For the third straight year, global research firm Frost & Sullivan has named Penta Security the 2025 South Korea Company of the Year in the Web Application Firewall (WAF) Industry. This prestigious award recognizes sustained excellence in leadership, technological innovation, and customer value.
Frost & Sullivan, a firm with over 60 years of history, conducts deep analysis to identify companies at the forefront of their industries. Penta Security was recognized for delivering robust and secure solutions that meet the diverse needs of customers in the rapidly evolving cloud security market.
This consistent recognition is driven by our commitment to next-generation web security, embodied by our two flagship solutions:
WAPPLES (Intelligent WAAP for the Enterprise): An evolution of traditional WAFs, WAPPLES is an advanced Web Application and API Protection (WAAP) solution built on a cloud-native architecture. Its proprietary intelligent detection engine, COCEP, provides real-time defense against emerging attack patterns. WAPPLES has held the #1 market share in the Korean WAF sector for 17 consecutive years.
Cloudbric WAF+ (Accessible All-in-One Web Security): As Korea’s first Security-as-a-Service (SECaaS) platform, Cloudbric WAF+ offers instant deployment via DNS redirection. It consolidates WAF, bot mitigation, DDoS protection, and more into a single, intuitive platform for businesses of all sizes.
This award demonstrates that Penta Security’s technology is not only a domestic leader but also globally recognized for its innovation. We remain committed to building a safer future, backed by trusted security performance and proven quality.
About Penta Security
Penta Security takes a holistic approach to cover all the bases for information security. The company has worked and is constantly working to ensure the safety of its customers behind the scenes through the wide range of IT-security offerings. As a result, with its headquarters in Korea, the company has expanded globally as a market share leader in the Asia-Pacific region.
As one of the first to make headway into information security in Korea, Penta Security has developed a wide range of fundamental technologies. Linking science, engineering, and management together to expand our technological capacity, we then make our critical decisions from a technological standpoint.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
The ESET PROTECT cybersecurity platform has been crowned a Leader in the prestigious G2 Summer 2025 Grid® Report for Extended Detection and Response (XDR) Platforms. This accolade stands as a testament to ESET PROTECT’s outstanding customer satisfaction, earning the highest score in this category, and its strong market presence.
ESET PROTECT outperformed XDR-first vendors like CrowdStrike and SentinelOne. An impressive 97% of users have rated it 4 or 5 stars, with 89% believing it’s on the right track. Furthermore, a remarkable 91% of users are likely to recommend ESET PROTECT to others.
In the Summer 2025 Grid® Report for XDR Platforms ESET PROTECT is rated #1 for Data Security, the highest-rated feature with a 99% rate, Data loss Prevention, Workflow Automation, and Governance. It has been awarded various unique badges in the XDR Platforms category, including “Most Implementable”, “Best Results” for mid-market, “Best Estimated ROI” and “Fastest Implementation” for enterprise, and more.
Users have praised ESET PROTECT for its outstanding ability to meet business requirements and its ease of platform setup and use. Dive into the full report to discover why ESET PROTECT is the go-to choice for businesses worldwide.
About ESET For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
The latest Pandora FMS version presents key improvements to the SIEM, module, designed to enhance security event detection and management. These new features are available starting with Feature Release 782, allowing for optimized log analysis, report generation, and rule validation in distributed IT environments. The SIEM module enables organizations to work with security events that are enriched and generated through log collection and other monitoring data sources. By applying custom correlation rules, it allows you to visualize critical data to detect threats and anomalies. This feature is essential for organizations that require advanced infrastructure monitoring, integrating security event analysis as part of their cybersecurity strategy.
The SIEM processes events in two main phases: log and monitoring event decoding, and the generation of structured events enriched with security information, applying predefined rules in a process called decoding. This architecture makes it possible to integrate data from IDS and IPS systems and detect vulnerabilities following the CVE standard. OpenSearch works as the storage and search engine, ensuring high performance even under heavy workloads.
Once raw and encoded data is collected, correlation is performed using specific SIEM rules that allow for time-window evaluation of relationships between different rules for the same event, or correlation between multiple different events. Pandora includes thousands of default rules, though the true power of a SIEM lies in its ability to easily define custom rules or import/convert rules from similar systems for use within Pandora.
Pandora’s multi-layer architecture allows for data distribution and filtering across five levels: endpoint, collection, decoding, SIEM rule, and visualization.
Dynamic filters have been added to the event viewer to enable advanced searches by event type, agent, or log message, simplifying incident management.
Log Parsing from the Command Line
The parse_siem_log command allows you to evaluate log lines directly from Pandora FMS CLI and preview the events generated. This tool is essential for validating decoders and rules before deployment, optimizing detection and reducin false positives. Log parsing also simplifies integration into orchestration and automated response (SOAR) processes.
Usage example:
Extended Support and Performance Optimization
The SIEM supports logs in CEF (Common Event Format), allowing the integration of data from third-party systems and devices without additional adjustments. This compatibility simplifies the centralization of security logs in heterogeneous environments. Additionally, the rule engine has been optimized to improve efficiency in event evaluation, reducing processing time and ensuring smoother performance in systems handling large data volumes.
SIEM Use Cases in Pandora FMS
The Pandora FMS SIEM enables centralized data collection and analysis from multiple sources: network devices, servers, endpoints, security systems, and applications. It detects abnormal behavior patterns, generates automatic alerts for threats, and allows for real-time quick response. It simplifies incident investigation through detailed history logs and helps meet security regulations and compliance policies. Log parsing through CLI helps validate decoders and rules before deployment, improving threat detection efficiency. These capabilities strengthen protection in distributed environments, simplify security management, and optimize incident response. The SIEM is a key component within Pandora FMS’s security architecture, which integrates advanced monitoring, log analysis, event correlation, and response tools. This combination allows organizations to adapt their environments to today’s cybersecurity challenges.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes. Of course, one of the things that Pandora FMS can control is the hard disks of your computers.
This article presents a detailed analysis of one of the most severe cybersecurity incidents ever to impact Brazil’s Payment System (Sistema de Pagamentos Brasileiro – SPB), which occurred in June and July of 2025. The breach was directly linked to C&M Software, a major Information Technology Services Provider (PSTI) for the national banking sector. This incident exposed, for the first time at this scale, the critical role PSTIs play within the financial ecosystem, and how internal vulnerabilities can reverberate systemically, compromising the integrity of financial operations across hundreds of banks and institutions.
The Brazilian Financial System (Sistema Financeiro Nacional – SFN) serves as the infrastructure enabling the circulation of money, credit, and payments throughout the country. It involves the Central Bank, banks, fintechs, credit cooperatives, payment institutions, and specialized technology providers, such as PSTIs. Through the SPB and the Instant Payments System (SPI), the SFN ensures fast, secure, and traceable settlement of fund transfers between institutions, thereby upholding trust and maintaining market functionality.
This cyberattack was facilitated through the compromise of C&M Software’s internal IT environment. A malicious insider—an employee of the PSTI—was recruited by a cybercriminal group and, in exchange for financial compensation, granted privileged access to internal systems, passwords, and sensitive institutional certificates. That access allowed attackers to manipulate the credentials and private keys of several C&M clients, primarily banks and fintechs, including BMP Money Plus. From there, attackers generated fraudulent transactions, signed in proper compliance with SPI’s cryptographic and procedural standards, allowing them to be instantly settled by the Central Bank. As these operations were technically valid, they were automatically debited from the reserve accounts of the victim institutions.
Because C&M Software acted as a core technical hub for hundreds of institutions, the breach had a wide-reaching and magnified impact. Not only did BMP Money Plus suffer substantial financial losses, but at least five other institutions were also compromised. The siphoned funds were immediately funneled through accounts held by mules, then quickly transferred to cryptoasset exchanges for conversion into Bitcoin and USDT, effectively complicating their traceability and recovery.
Due to its central role, C&M was at the center of the response efforts: alerted by affected institutions, C&M notified the Central Bank, implemented emergency containment measures, and had its operations within the SPB suspended until robust new controls could be enforced. The incident underscores how shortcomings in governance, privilege management, and certificate protection can result in systemic consequences. This analysis underscores the necessity of key security measures, including behavioral monitoring, automated credential management, just-in-time access control, and strict separation of client secrets to prevent similar events within such a highly interconnected financial environment like the SFN.
1. Introduction
In a financial system built on trust and speed, a single insider can bring the entire network to a halt.
Over the last two decades, Brazil has emerged as a global reference in financial innovation and infrastructure modernization. Its Financial System (SFN) stands out for its level of digital maturity, robust regulatory framework, and ability to integrate multiple market actors, fostering inclusion, efficiency, and large-scale security. One of the latest milestones in this evolution is the Instant Payment System (SPI), which, in tandem with PIX, has positioned Brazil ahead of many global markets in terms of speed and ubiquity of electronic fund transfers.
PIX/SPI has become the financial backbone for transactions involving individuals, businesses, fintechs, and banks, processing billions of transfers with near-immediate settlement across accounts belonging to different institutions. This orchestration is made possible not just by the Central Bank but by a network of specialized providers—the Information Technology Services Providers (PSTIs)—who perform critical functions in clearing, settlement, and interconnection for traditional banks, credit unions, payment institutions, and digital platforms. The advent of open finance has further intensified reliance on these technical intermediaries, expanding both the number and diversity of participants and interfaces within Brazil’s digital financial ecosystem.
However, this growth also brings new and complex challenges. As digitalization progresses and integrations multiply, so too do points of exposure to cyber threats, fraud, governance failures, and supply chain vulnerabilities. With operations distributed across many players—often with unequal security maturity—an isolated breach has the potential to jeopardize the confidentiality, integrity, and systemic availability of services that individuals and businesses rely on daily. Additionally, given the growing use of APIs, outsourced operations, and the sharing of institutional secrets, new attack surfaces are created for insiders, cybercriminals, and advanced persistent threat (APT) actors.
The case examined in this article offers a stark exemplification of the risks and critical weak points in Brazil’s so-called “chain of trust.” By analyzing a real-life breach involving a central PSTI supporting banks and fintechs, we highlight the root causes, technical and institutional impacts, and practical recommendations to strengthen system resilience, privileged access management, and behavioral security controls within a complex and highly interconnected financial environment.
2. Understanding Brazil’s Financial System
The SFN operates via multiple interconnected components to ensure fast and secure interbank settlements. The Central Bank of Brazil (BACEN) serves as both the top regulator and operator of the Brazilian Payment System (SPB), which includes banks, payment institutions, technology providers (PSTIs), and cryptocurrency exchanges.
Reserve Accounts
A cornerstone of the SPB is the reserve account, maintained by each financial institution with the Central Bank. These accounts power SPI (Instant Payment System), enabling irreversible, real-time transaction settlements via PIX.
Banking-as-a-Service (BaaS)
BaaS platforms like BMP Money Plus enable fintechs, funds, and digital platforms to leverage full banking infrastructure, maintain reserve accounts, and facilitate payments through the SPB.
Role of Exchanges
Cryptocurrency exchanges such as SmartPay and Truther bridge traditional finance and the crypto world, playing an essential role in transaction traceability and regulatory compliance at scale.
Caption:The client initiates a purchase via SmartPay/Truther. BMP, using its BaaS model, processes the PIX transaction and routes it to the SPI/SPB via C&M Software (PSTI). The payment moves from BMP’s reserve account at BACEN to the recipient’s institution, with instant settlement. The process concludes with confirmation back to the client.
3. Incident Description
At 4:00 a.m. on June 30, 2025, a senior executive at BMP Money Plus—a fintech specializing in banking-as-a-service (BaaS) solutions—received an unexpected call from CorpX Bank, alerting him to an unauthorized transfer of R$18 million from BMP’s reserve account. As the person responsible for managing those reserves with the Central Bank, the executive quickly identified that other similarly unauthorized PIX transactions were actively underway at that moment. BMP’s internal team immediately launched containment efforts and, by around 5:00 a.m., officially reported the incident to C&M Software, their critical payment processing service provider.
Initial investigations and information published in the media indicated that the attack originated from an internal compromise at C&M Software—one of the leading PSTIs in Brazil’s Payment System (SPB). An internal facilitator, allegedly motivated by financial gain, provided privileged credentials to cybercriminals and assisted in executing malicious commands within company systems. Possessing privileged access and the digital certificates of C&M’s financial institution clients—including BMP itself and at least five other institutions—the attackers were able to inject fraudulent PIX orders directly into the SPI/SPB infrastructure. Because the transactions were digitally signed using valid institutional certificates, the Central Bank’s core systems processed them as legitimate, immediately debiting funds from the reserve accounts of the victim institutions.
It is estimated that approximately R$400 million was siphoned from BMP’s reserve account alone, with R$160 million later successfully recovered. Following the breach, stolen funds were swiftly transferred to accounts held by third parties at smaller banks and payment institutions, particularly cryptoasset platforms integrated with PIX, including exchanges, gateways, and swap platforms. Most of the stolen funds were quickly converted into USDT or Bitcoin, further complicating traceability. However, in at least one case, an exchange that detected a high volume of suspicious activity froze the settlement and immediately notified BMP, thereby preventing the dispersion of a portion of the stolen funds.
Given the magnitude of the attack and in order to prevent further losses, the Central Bank ordered an emergency suspension of C&M Software’s systems from the SPB—affecting PIX operations across more than 300 financial institutions that relied on its services. Despite the substantial financial damage, BMP Money Plus publicly emphasized that no end-customer funds were affected and that institutional guarantees fully covered the stolen amounts. Meanwhile, the Federal Police, activated by the Central Bank, opened a formal investigation to examine potential crimes such as criminal conspiracy, fraud-related theft, unauthorized system intrusion, and money laundering. The case remains under active investigation.
4. Incident Timeline
Below is the timeline of key events related to the incident—from initial compromise to response—based on information available at the time.
June 30, 2025 – 12:18 AM: Exchanges such as SmartPay and Truther detect unusually high transaction volumes in Bitcoin/USDT and alert executives at financial institutions.
June 30, 2025 – 4:00 AM: A BMP Money Plus executive is informed of an unusual PIX transfer totaling R$18 million; multiple unauthorized transactions are identified.
June 30, 2025 – 5:00 AM: BMP executives report the incident to C&M Software.
June 30, 2025: The Central Bank orders the emergency disconnection of C&M Software from the SPB.
July 1, 2025: News portal Brazil Journal publishes an in-depth report on the cyberattack.
July 2, 2025: BMP Money Plus issues an official statement acknowledging the breach.
July 3, 2025: The Central Bank announces the partial restoration of C&M Software’s operations and confirms the arrest of an employee involved in the incident.
July 4, 2025: Authorities confirm the detention of a staff member suspected of aiding the cybercriminal operation.
5. Technical Analysis of the Incident
The incident that unfolded between June 29 and July 4, 2025, may represent one of the largest systemic frauds ever recorded within Brazil’s Payment System (SPB), involving a wide range of actors—from external cybercriminals and internal insiders to financial institutions, technology service providers, and regulatory authorities. Below is a technical, chronological breakdown of the attack’s modus operandi, the mechanisms exploited, the money flow, and institutional responses.
1. Initial Compromise: Insider Threat and Privilege Escalation
The first step in the incident was an internal compromise at C&M Software, an authorized and mission-critical Information Technology Services Provider (PSTI) within Brazil’s financial ecosystem. According to official investigations and media reports, an employee at C&M—referred to here as the “Facilitator”—was recruited by a cybercriminal group. Motivated by financial incentives, the insider shared administrative credentials and, following external instructions, executed strategic commands that enabled the attackers to operate undetected within the company’s internal environment.
This privileged access was essential. It allowed the attackers to discover and retrieve cryptographic keys and digital certificates belonging to C&M’s client institutions, enabling the group to digitally impersonate those financial institutions. In many financial environments, inadequate segregation of secrets management (keys, certificates, and credentials) between clients and tech providers makes these attacks exponentially more dangerous.
2. Injection of Fraudulent Orders and Automated Settlement
Once in possession of the original digital credentials and certificates belonging to compromised institutions—particularly BMP Money Plus and at least five others—the attackers began fabricating and injecting PIX payment orders directly into SPI (Instant Payment System) and SPB. Since the digital signatures were valid and the requests followed standard cryptographic formats, the Central Bank’s settlement infrastructure processed and executed them as legitimate. The SPI system, by design, presumes the authenticity of requests from verified participants.
During the night of June 29 to June 30, these operations were carried out in bulk, automated fashion, outside of business hours—when manual oversight tends to be minimal. The reserve accounts of the victim institutions—held with the Central Bank for interbank operations—were systematically debited without triggering any SPI anomalies.
3. Rapid Dispersion and Chain Effect
The next step involved the immediate dispersion of stolen funds. Large amounts—often sent in batches—were moved to “mule accounts” and smaller payment institutions (PIs), many of which featured less stringent KYC, onboarding, and compliance protocols. Funds were then transferred to cryptoasset service providers such as exchanges, OTC platforms, and swap apps. There, they were converted into Bitcoin and USDT and moved to wallets held by the attackers—often split into many small transactions to evade tracing.
This sequence underscores the attackers’ operational sophistication:
Exploiting supply chain links between the PSTI (C&M) and multiple banks/fintechs;
Leveraging scripts and automation to submit dozens of transactions in succession;
Executing the fraud during off-peak operational hours.
4. Timeline of Actions, Detection, and Response
🕛 June 30, 2025 – 12:18 AM: Initial Detection by Exchanges SmartPay and Truther exchanges were the first to detect suspicious activity. Their monitoring systems flagged abnormal transaction volumes and unusual purchases of Bitcoin/USDT made via PIX, triggering alerts to internal compliance teams and associated financial institutions.
🕓 June 30, 2025 – 4:00 AM: BMP Executives Flag the Incident Prompted by exchange alerts and transaction analysis, a BMP Money Plus executive was contacted by a CorpX Bank representative regarding an extraordinary PIX transfer of R$18 million originating from BMP. This kicked off an internal audit that revealed several unauthorized SPI transactions debiting BMP’s reserve account.
🕔 June 30, 2025 – 5:00 AM: Incident Escalation BMP formally notified C&M Software, reporting the breach and requesting urgent assistance from the provider responsible for part of the institution’s interbank infrastructure. By this point, the breadth of the attack suggested a systemic compromise affecting multiple C&M clients.
⚠️ June 30, 2025: Regulatory Response — Central Bank Intervention With converging reports from exchanges, BMP, and other affected financial institutions, the Central Bank was officially notified of a potential systemic breach. As an emergency measure, it ordered the precautionary suspension of C&M Software’s connections to SPB—halting PIX operations across all institutions that interfaced through its platform. This action aimed to prevent further fraud and maintain system liquidity, despite triggering operational interruptions for hundreds of banks, fintechs, and payment entities.
📰 From July 1, 2025 Onward: Public Disclosure, Analysis, and Partial Recovery In the days that followed, national media widely covered the breach, and official statements from BMP, C&M Software, and the Central Bank confirmed that no end-user funds had been affected. BMP reported that, of the R$400 million initially stolen, approximately R$160 million had been recovered through rapid collaboration with crypto exchanges, court orders, and financial tracing efforts.
Later, the Central Bank authorized the partial reactivation of C&M’s services—only after new control mechanisms and stricter access segregation were implemented. Amid the ongoing investigation, authorities confirmed the identification and arrest of the “facilitator”, the insider who enabled the breach. The Federal Police continues to investigate charges related to unauthorized access, banking fraud, and money laundering.
5. Operational Roles Across the Attack Chain
Cybercriminals: Strategized and executed the attack, exploiting both human and technical vulnerabilities. Used automation to scale operations and reduce execution time.
Insider (Facilitator): Served as the human vulnerability, granting “legitimate” access to core systems. Illustrates the danger of excessive privilege and lack of behavioral monitoring.
C&M Software (PSTI): Due to the absence of strong access segregation and behavioral controls, acted as the point of compromise that exposed its entire client base.
Victim FIs: Banks and fintechs whose reserve accounts were debited, suffering direct financial loss and reputational impact.
SPI/SPB: The infrastructure processed all digitally signed payment orders as expected—highlighting the limitations of automated controls against insider-originated attacks.
Mule Accounts / Payment Institutions (PIs): Weak onboarding and due diligence processes made them attractive channels for laundering and dispersing stolen funds.
Exchanges: A key positive aspect—proactive exchange-based compliance systems successfully detected, contained, and reported portions of the fraud, helping reduce total impact.
Below, you’ll find a step-by-step visualization of the incident flow:
6. MITRE ATT&CK Mapping
The attack on C&M Software’s environment demonstrates a well-defined chain of techniques documented in the MITRE ATT&CK Framework (Enterprise v17). Mapping these techniques supports threat hunting, incident response, and the enhancement of internal security controls across financial institutions and PSTI providers.
Below, we highlight the main tactics and techniques involved, referencing specific examples from the 2025 incident.
7. APT Groups: Exploratory Assessment
It is important to highlight that, as of now, none of the groups listed below have any confirmed connection to the attack under investigation. These references are intended primarily to inform threat intelligence efforts and assist in shaping strategic defense planning.
Although there has been no formal attribution to any internationally recognized Advanced Persistent Threat (APT) groups, the technical analysis of the attack on C&M Software reveals multiple operational similarities with campaigns previously carried out by sophisticated threat actors. These actors vary in motivation, technical breadth, and focus—often targeting critical financial infrastructures.
The purpose of this mapping is to help place the Brazilian incident within the context of global cyber threat trends, supporting the early identification of attack patterns and contributing to more proactive and intelligence-driven defense strategies.
The groups outlined below demonstrate common Tactics, Techniques, and Procedures (TTPs) seen in supply chain compromises, banking intrusions, ransomware campaigns, and money-laundering-driven data exfiltration:
Notable Examples
Plump Spider – Known for leveraging the Clop ransomware, this group has been involved in systemic attacks on global financial institutions. Its operations often combine supply chain compromise, large-scale data and confidential information exfiltration, and laundering of proceeds via cryptoasset mixer services.
TA505 – Specializes in malspam-driven campaigns, frequent use of Cobalt Strike for post-exploitation, and targeted attacks on banks and fintechs. Notable for its ability to rapidly convert and disperse illicit funds.
FIN7 / Carbanak – With an established reputation for social engineering and persistent access to banking environments, FIN7 is known for extended campaigns that leverage legitimate infrastructure and internal credentials to facilitate stealthy data exfiltration and fund diversion.
LAPSUS$ – Gained notoriety for its highly visible and theatrical attacks on major enterprises, with a particular focus on social engineering, privileged access acquisition, and the public exposure of stolen data. While the group is not a direct fit for this incident, which centers on financial operations, some alignment remains in terms of initial access and insider exploitation tactics.
8. Mitigation Strategies
Given the context and the vulnerabilities exposed by the incident, we propose a set of mitigation measures focused on behavioral security, automated credential management, and strong governance across the digital supply chain:
Behavioral Analytics: Real-time detection of anomalous privileged access; automatic blocking based on deviation patterns, with correlation by geolocation, time of access, and other indicators.
Just-in-Time Access: Grant privileged access strictly for specific tasks or timeframes, thereby reducing exposure windows to insider threats.
Credential Rotation (triggered by anomalous behavior): Credentials are automatically refreshed or revoked upon detection of any suspicious activity.
Secrets and Token Management for APIs and Supply Chain: Deployment of secure vaulting tools to safely isolate and manage third-party integrations and secrets.
Certificate Management and Rotation: Continuous monitoring and automated renewal of digital certificates used in critical financial operations.
Third-Party Access Control: Implementation of Zero Trust policies for partners, with strict onboarding and offboarding processes.
Reference Architecture: A recommended visual design illustrating an integrated security model for PSTIs, financial institutions, and the Central Bank (suggested as a flowchart or architecture diagram).
9. Conclusion
The attack that impacted C&M Software and multiple institutions connected to Brazil’s Payment System (SPB) underscores the critical role of behavioral cybersecurity and credential control in safeguarding financial ecosystems. This event exposed significant weaknesses in privileged access management, particularly within trust relationships between financial institutions and their technology service providers. It clearly demonstrates that traditional paradigms—relying solely on logical perimeters, firewalls, and network segmentation—are insufficient to defend against insider threats, supply chain compromise, and sophisticated attacks enabled by the misuse of valid credentials and seemingly legitimate but unauthorized operations.
The incident revealed that insider actions, improper certificate usage, and the absence of behavioral monitoring allowed fraudulent activity to flow through automated systems without triggering alarms across various points in the chain. Additionally, it reinforced the importance of traceability, real-time threat intelligence, and collaborative defense among key ecosystem players including fintechs, banks, exchanges, and regulatory bodies.
From the lessons learned, the following mitigation strategies stand out:
Continuous Behavioral Analytics: Monitor privileged user behavior in real time, generating alerts and automated blocks when anomalies are detected—such as unusual access times, organizational changes, or abnormal geolocation data.
Just-in-Time Access & Least Privilege: Minimize the time during which sensitive credentials remain active. Grant access strictly for specific tasks and timeframes, with comprehensive logging and traceability.
Credential Rotation Triggered by Anomalies: Implement mechanisms for the automatic replacement of passwords, tokens, and certificates whenever suspicious behavior is detected—preventing persistence or reuse of compromised access.
Secure Management of Secrets, Tokens, and Digital Certificates: Centralize the lifecycle control, usage auditing, and periodic renewal of these assets—especially across integrations between financial institutions, PSTIs, and APIs—to mitigate leakage and misuse risks.
Zero Trust Policies and Tight Third-Party Controls: Define robust procedures for granting, monitoring, and revoking access to partners, vendors, and external teams. Ensure consistent due diligence and oversight.
Ultimately, the case highlights that operational resilience, rapid intelligence sharing, transparent communication, and the integration of technical and procedural controls are foundational pillars for the systemic defense of the national financial environment in the face of evolving and sophisticated threats.
Speak to Our Experts To learn how Segura® can support your organization in behavioral cybersecurity, privileged access management, and fraud-resistant architecture, contact us for a personalized strategic assessment.
About Segura® Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
More efficiency, more optimization, more reliability: IT workflow automation is at the center of the scene for these simple and crucial reasons… which, in turn, reflect the demands of the market and of every company.
In a context that we could define as one of “permanent digital transformation,” leveraging automation means reducing costs, increasing productivity, and enabling IT departments to focus on more strategic areas. It’s not just a matter of speed and savings; it’s a fundamental tool for improving IT performance and ensuring that business processes are always aligned with the growing expectations of the market.
2025 Gartner®Market Guide for ITSM Platforms
Get the latest ITSM insights! Explore AI, automation, workflows, and more—plus expert vendor analysis to meet your business goals. Download the report now!
But what exactly are we talking about, more concretely?
In short: IT workflow automation consists of automating repetitive manual tasks and processes using increasingly advanced and “intelligent” technological tools. Activities that used to require direct intervention from dedicated teams—such as ticket management or resource allocation—are now simplified and managed automatically, with error margins that grow smaller every day.
The Role of AI in Optimizing IT Workflows
Automation and artificial intelligence are naturally closely linked. We can say that AI adds an additional level of sophistication to IT workflow automation, allowing systems to “learn from experience” based on the input and data collected, and to make decisions autonomously.
Thanks to AI, companies can not only automate processes but also predict and resolve problems in advance, further improving efficiency and reducing downtime.
In short, there’s a vast field in front of us to explore, with the right attention, but also by moving ahead of the competition to gain a competitive advantage.
2. Key Areas for IT Automation
Automation of Service Desk Operations
Automation can be applied to different areas of the IT department, each of which can benefit significantly from the reduction of manual workloads and the optimization of processes.
One of the most important areas is certainly the service desk, which is often the first point of contact for users needing IT support.
Automating operations such as ticket creation, prioritization, and handling of repetitive requests brings very tangible benefits and is something that can be achieved with great ease by relying on specialized solutions like those from EasyVista Service Manager.
Incident and Problem Management Enhanced by AI
Here’s another key area. Automation and AI systems can transform incident and problem management, identifying causes precisely and suggesting solutions in a timely manner.
But the approach is no longer just reactive. With the use of machine learning algorithms, it is possible to predict the occurrence of incidents, reducing response times, mitigating the negative impacts on business operations, and embracing a more effective proactive approach.
Automation of Workflows in IT Asset Management
The IT assets of a company—large, small, or medium—multiply, need constant updating, must be secured, and need to function like a well-coordinated orchestra. To achieve this, once again, automation comes to our aid.
Automating asset management processes, such as inventory, software updates, disposal of obsolete devices (and much more), is essential. It’s a matter of efficiency, security, but also compliance.
3. How AI Improves IT Workflows
AI for Predictive Maintenance and Monitoring
The IT infrastructures of companies are becoming increasingly extensive and “elastic.” Therefore, they need to be constantly and in real-time monitored, identifying potential anomalies before they turn into serious problems. This predictive maintenance approach is one of the very tangible advances that AI systems have already brought.
The benefits? Downtime is minimized, resource utilization is optimized, and the costs associated with extraordinary repair interventions can be avoided.
Smart Ticket Routing and Prioritization
Smart routing is a key element of ticket management. It’s the process that allows requests or tickets to be automatically routed within the service desk to the most appropriate team or technician, based on predefined criteria such as the type of request, priority, staff availability, or required skill level.
Once again, the benefits are many, including the optimization of response times and workloads, the reduction of manual errors, and, once more, an overall improvement in efficiency.
AI-Based Self-Service Solutions
Another crucial strategy to optimize request management and avoid overloads is to implement self-service solutions.
Integrating AI-powered chatbots and virtual assistants into self-service portals allows users to solve common problems without IT staff intervention.
This not only reduces the workload of the service desk but also improves the end-user experience, providing quick and accurate responses to their requests. The dynamic, in short, is perfectly win-win.
4. Implementing AI and Automation in IT Workflows
Steps to Automate IT Workflows
Automating IT workflows brings a significant chain of benefits. However, it requires a coherent and efficient implementation strategy.
There’s no one-size-fits-all recipe; much depends on the structure of the individual company and the context in which it operates. But there are some key steps to consider in any case:
Set clear objectives for this transition;
Identify the areas with the greatest potential for automation;
Choose the right tools (a point we’ll return to in the next paragraph);
Integrate new solutions with existing systems;
Continuously monitor results to make improvements;
Pay close attention to staff training.
Tools for Workflow Automation and AI Integration
The tools that facilitate IT workflow automation and AI integration are diverse and continuously growing; among them, IT Service Management (ITSM) platforms, business process management (BPM) software, and AI-focused solutions for monitoring and analysis play a central role.
Automation is at the heart of all EasyVista solutions and products, designed for companies of any size, with a strong emphasis on ease of implementation and use.
Overcoming the Challenges of AI and Automation Implementation
There’s no doubt: implementing automation and AI systems offers great advantages and enormous opportunities, still largely to be explored. But every innovation brings challenges that must be addressed.
In this case, the challenges involve change management, data security, and integration with existing systems. Therefore, it is essential to plan an adoption strategy for advanced systems that includes careful employee training, adjustments to company policies, and the implementation of advanced and constantly updated security measures.
5. The Benefits of AI and Automation in IT Workflows
As we near the conclusion, let’s summarize the main benefits of AI and automation in IT workflows that we have already touched upon in the previous sections of this article.
Greater Efficiency and Productivity
Automating IT processes reduces execution times, minimizes errors, and allows teams to focus on higher value-added activities. In other words: it greatly improves efficiency and productivity.
Improved Employee and Customer Satisfaction
Greater efficiency also means greater employee satisfaction, as they are not overwhelmed by sudden workloads, often involving boring and repetitive tasks. All this positive impact, finally, is reflected on end customers. And we know how crucial this is in today’s business world.
Reduction of Operating Costs
Not only greater efficiency. Optimizing IT workflows also leads to a significant reduction in costs, thanks to reduced downtime, optimized resource use, and fewer manual activities.
6. Conclusion
The Future of IT Workflow Automation
The future of IT workflow automation is closely linked to the development of new AI-based technologies and integration with increasingly advanced IT management tools. In front of us, we have vast opportunities, and—as always—the most attractive opportunities will be seized by those who know how to move ahead.
AI and Automation as Strategic Resources in IT Management
Let’s conclude with one certainty: we must think of AI and automation systems not just as technological tools, but as true strategic resources for IT management, capable of transforming operational efficiency and even the “mindset” of a company.
The end result? The creation of a lasting competitive advantage.
About EasyVista EasyVista is a leading IT software provider delivering comprehensive IT solutions, including service management, remote support, IT monitoring, and self-healing technologies. We empower companies to embrace a customer-focused, proactive, and predictive approach to IT service, support, and operations. EasyVista is dedicated to understanding and exceeding customer expectations, ensuring seamless and superior IT experiences. Today, EasyVista supports over 3,000 companies worldwide in accelerating digital transformation, enhancing employee productivity, reducing operating costs, and boosting satisfaction for both employees and customers across various industries, including financial services, healthcare, education, and manufacturing.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
Cast your mind back to May 2018. Remember that flurry of privacy policy updates hitting your inbox?
That was the grand entrance of the General Data Protection Regulation (GDPR). And if you thought it was just a fleeting trend, or something that would eventually fade like dial-up internet or fidget spinners, guess again!
Fast forward to today, and GDPR isn’t just sticking around – it’s stronger, more influential, and more vital than ever. Said another way: GDPR isn’t just a suggestion, it’s the law. If your business interacts with any personal data of individuals living in the European Union (EU) or the European Economic Area (EEA), you absolutely must comply. It’s the primary legal framework to ensure the millions of people living across the EU and EEA have fundamental rights over their digital footprints.
GDPR’s staying power is having an even wider impact on our global perspective of trust, privacy, compliance, and the commitments we make to one another about how we handle and process personal data. This article dives into that far-reaching impact, and showcases how GDPR’s success is an investment in trust.
Let’s dive in!
The Impact of GDPR Is Real (And Can Be Really Expensive)
GDPR is not a distant threat. Data Protection Authorities (DPAs) across Europe have demonstrated their willingness to levy hefty fines for noncompliance. Remember that eye-watering $1.3 billion fine Meta received in 2023 for data transfers to the US?
That wasn’t just a slap on the wrist; it was a loud, clear message.
Regulators are scrutinizing everything, from how transparent companies are about their data practices to whether they’re truly respecting individuals’ rights (like asking for your data back or requesting it be deleted). Enforcement is becoming more sophisticated and far-reaching, which means companies of all sizes need to be sure their systems and policies are compliant.
And while GDPR may directly apply to Europe, it’s far from a European idea. GDPR kicked off a wave of similar, robust data privacy laws across the globe. From California’s CCPA/CPRA to Brazil’s LGPD and South Africa’s POPIA, these regulations often share GDPR’s core principles and intent.
What does that mean for you?
If you’re doing a great job with GDPR compliance, you’re likely already building a fantastic foundation for meeting other international privacy requirements. If not, you’ll find that your efforts to improve your handling of private data will generally apply across the board.
AI’s New Frontier: GDPR’s Guiding Hand
The world may be buzzing about AI and Generative AI. But what is often lost in the conversation is that they bring a whole new set of questions about how our personal data is used, especially when it comes to training these powerful models.
The good news? GDPR’s foundational principles are incredibly robust and adaptable. They’re helping us navigate critical discussions around:
Lawful Basis: Is it okay to use my data to train an AI? What’s the legal reason?
Transparency: How do these AI models make decisions? Can I understand why an AI gave me a certain outcome?
Bias: Is the data used to train AI fair and unbiased?
And while the EU AI Act is on its way, it’s designed to work hand-in-glove with GDPR, not replace it. This shows just how forward-thinking and resilient GDPR’s framework truly is.
Ready to Be a GDPR Champion?
Becoming GDPR compliant (and staying that way!) is an ongoing journey, not a one-time checkbox. Here are some tips to get you on the path to being a GDPR pro:
Become a Data Detective: Time to map out all the personal data your company holds – from names and emails to IP addresses and even sensitive health info. Ask yourself:
Where does it live?
Who has access to it, both inside and outside your company?
Why are you collecting it in the first place?
Understanding “what you have” is step one!
Find Your “Why”: For every piece of personal data you process, you need a clear, legal reason (a “lawful basis”) under GDPR. Ask yourself:
Are you collecting it because someone consented?
Is it part of a contract?
Is it part of a legal obligation?
Pinpointing your “why” keeps you on the right side of the law.
Empower Your Users’ Rights: Make it easy for people to:
Know what data you’re collecting
Access their data
Correct any mistakes
Erase their data (“the right to be forgotten”)
And even move their data elsewhere (data portability)
Boost Your Security Game: You need strong defenses to protect personal data from unauthorized access, accidental loss, or anything that could compromise it.
Master the Breach Response: If a data breach occurs, you need a clear plan to detect, investigate, manage, and report it quickly – often within 72 hours! Being prepared is half the battle.
Bake Privacy In (By Design!):Data Protection by Design and by Default means thinking about privacy from the very beginning when you’re designing new systems, products, or services. And by default, ensure the strictest privacy settings are active and you only collect the data you truly need.
Mind Your Global Transfers: If you’re sending personal data across borders (especially outside the EU/EEA), make sure you’re doing it legally! There are specific mechanisms, like Standard Contractual Clauses, that help ensure data remains protected wherever it travels.
The Bottom Line: Invest in Trust
GDPR isn’t just a complex set of rules; it’s a fundamental pillar of global data privacy that’s built on trust.
Its influence continues to shape how businesses worldwide handle sensitive information. Ignoring GDPR doesn’t just invite hefty fines; it risks your reputation and the trust of your customers – something no organization can afford to lose in today’s digital age.
JumpCloud and GDPR
JumpCloud takes security and privacy seriously and complies with the EU privacy regulation GDPR to protect personal data. You can check out our JumpCloud GDPR Compliance online documentation for more information. Our safeguards for personal data include, but are not limited to:
Encrypting all data at rest and in transit
Training employees in security awareness and performing appropriate background checks
Maintaining access controls
Actively monitoring JumpCloud user logins and privileged commands
Monitoring logs
If you have questions about GDPR, or how JumpCloud can help you become GDPR-compliant, please contact us at sales@jumpcloud.com.
Prioritizing GDPR compliance isn’t just a cost; it’s a smart, critical investment in your company’s future and your relationship with your users. So, let’s embrace it and build a more privacy-conscious world together!
About JumpCloud At JumpCloud, our mission is to build a world-class cloud directory. Not just the evolution of Active Directory to the cloud, but a reinvention of how modern IT teams get work done. The JumpCloud Directory Platform is a directory for your users, their IT resources, your fleet of devices, and the secure connections between them with full control, security, and visibility.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
ESET Research has released insights into the landscape of AsyncRAT, a remote access tool (RAT), and its numerous variants.
The analysis uncovers their unique interconnections, and documents how these variants can be distinguished.
The widespread availability of frameworks such as AsyncRAT significantly lowers the barrier of entry for aspiring cybercriminals.
PRAGUE, BRATISLAVA — July 15, 2025 — ESET Research is releasing its analysis of AsyncRAT — a remote access tool (RAT) designed to remotely monitor and control other devices. Over the years, AsyncRAT has cemented its place as a cornerstone of modern malware and as a pervasive threat that has evolved into a sprawling network of its variants and forks (customized and improved versions of the original tool). The published analysis provides an overview of the most relevant forks of AsyncRAT, drawing connections between them and showing how they have evolved.
AsyncRAT, an open-source RAT, was released on GitHub in 2019 by a user going by the name of NYAN CAT. It offers a wide range of typical RAT functionalities, including keylogging, screen capturing, credential theft, and more. Its simplicity and open-source nature have made it a popular choice among cybercriminals, leading to its widespread use in various cyberattacks.
“AsyncRAT introduced significant improvements, particularly in its modular architecture and enhanced stealth features, making it more adaptable and harder to detect in modern threat environments. Its plug-in-based architecture and ease of modification have sparked the proliferation of many forks, pushing the boundaries even further,” says ESET researcher Nikola Knežević, author of the study.
Ever since it was released to the public, AsyncRAT has spawned a multitude of new forks that have built upon its foundation. Some of these new versions have expanded on the original framework, incorporating additional features and enhancements, while others are essentially the same version in different clothes. The most popular variants for the attackers, according to ESET telemetry, are DcRat, VenomRAT, and SilverRAT.
DcRat offers a notable improvement over AsyncRAT in terms of features and capabilities, while VenomRAT is packed with further additional features. However, not all RATs are serious in nature, and this applies equally to AsyncRAT forks. Clones like SantaRAT or BoratRAT are meant to be jokes. Despite this, ESET has found instances of real-world malicious usage of these in the wild.
In its analysis, ESET Research has cherry-picked some lesser-known forks, too, as they enhance AsyncRAT’s functionality beyond the features included in the default versions. These exotic forks are often the work of one person or group, and they make up less than 1% of the volume of AsyncRAT samples.
“The widespread availability of frameworks such as AsyncRAT significantly lowers the barrier to entry for aspiring cybercriminals, enabling even novices to deploy sophisticated malware with minimal effort. This development further accelerates the creation and customization of malicious tools. This evolution underscores the importance of proactive detection strategies and deeper behavioral analyses to effectively address emerging threats,” concludes Knežević.
About ESET For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.
About Version 2 Limited Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.