Skip to content
← Learn

Geography

Penetration testing in Brazil

Penetration testing for Brazilian companies: what the market asks, what Bacen requires of licensed institutions, and what the LGPD does not name. Proposed scope, not a brochure.

Brazil does not buy pentesting for fashion: it buys it because someone upstream demanded it — an enterprise client, a post-incident board, or the supervisor if the firm sits under Bacen. The useful question is not “do we need a test?”. It is “is this a mandate or evidence of diligence?”.

What the market asks

Serious buyers no longer accept the scanner PDF. They ask for validated findings with exploitation proof, business impact and retest of the critical items. The differentiator is not the logo: it is the report your team can reproduce without asking again.

Mandate and diligence

The LGPD does not name pentesting. It requires security measures and the ability to prove them (Law 13.709/2018, accessed 2026-09-17). A pentest is evidence of that diligence, not a ritual the statute lists. Bacen’s perimeter is different: CMN Resolution 5.274/2025 requires annual, independent intrusion tests for institutions within the scope of CMN 4,893/2021. The detail is in LGPD vs Bacen.

How it is done properly

A serious engagement starts with written rules of engagement: what gets attacked, what does not, when, and who authorizes each intrusive action. Agents sweep surface and propose paths; a person validates, exploits and signs. Every finding carries a reproducible PoC. Failed attempts are documented with their limitations; they do not by themselves establish that a control works. The delivery window is fixed in the contract, not on this page.

Mistakes when buying

Buying on price and receiving a scan with report formatting. Accepting “anything with a public IP” without prioritization. Agree on risk-reduction measures without absolute continuity guarantees. And treating the annual report as an LGPD checkbox: the statute does not name it; the value is what an attacker can actually do. In Brazil the cybersecurity partner is Lexart. Rekon signs the pentest. What a penetration test is or write to us with context: we answer with proposed scope.

Before commissioning from Brazil

Confirm Portuguese communication and reporting availability, contracting entity, currency, taxes and evidence channel in the proposal. This page does not imply a Brazilian office. For Web/API, prepare roles, tenants, integrations and test environments; do not send credentials through the form. Regulatory scope must be reviewed for the institution type: CMN 4,893 does not apply identically to every supervised entity.

Straight answers

Does the LGPD mandate a pentest?

No. Law 13.709/2018 arts. 6(VII) and (X), and 46 to 50 require technical and administrative security measures and proof they are observed. They do not name pentest, penetration testing or intrusion testing (text accessed 2026-09-17 at planalto.gov.br).

Does Bacen require an annual independent pentest?

For institutions within the scope of CMN 4,893/2021, yes: CMN Resolution 5.274/2025 (18 Dec 2025) inserted art. 22-A into 4.893/2021. Intrusion tests must be at least annual, independent and impartial, performed by a contracted person or firm, with documented results. It is not a generic duty for every Brazilian company.

Does Rekon operate in Brazil?

Yes. Rekon runs the pentest with an explicit human gate. In Brazil the cybersecurity partner is Lexart (lexart.tech). We answer with proposed scope, not a brochure.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn