In Brazil, where credit cards are one of the main forms of payment and digital data has a value comparable to cash, the risks of online fraud are becoming increasingly prevalent, requiring heightened vigilance from both consumers and businesses.
To give an idea of the scale of the problem, four out of ten Brazilians have already been victims of scams and financial fraud in the country, representing 42% of Brazilians. This data comes from the "Digital Identity and Fraud Report 2024," a survey conducted by Serasa Experian.
Another study, this time by the National Confederation of Retail Leaders (CNDL) and the Credit Protection Service (SPC Brasil), in partnership with Sebrae, shows that approximately 8.4 million consumers reported fraud at financial institutions in the last 12 months. Among the scams, credit and debit card cloning is the main type of fraud.
Although approximately 70% of Brazilians own three or more credit cards, according to Serasa, the perception of risk is still low. Around 69% of Brazilians continue to underestimate the danger of registering financial data on websites and apps, leaving a huge portion of the population exposed to digital scams and cyberattacks.
Amid growing concerns about digital security, good news is emerging: new initiatives and technological advancements are making the online environment safer every day.
Recently, the PCI Security Standards Council (PCI SSC) proposed new guidelines for the continued development and improvement of security standards, applicable to companies that store, process, or transmit payment data, as well as developers and manufacturers of software and devices used in transactions. PCI is a global organization that brings together key players in the payments industry to drive the use of resources for secure transactions.
“As threats and technology evolve, PCI DSS standards also update. Therefore, it is necessary to pay attention to the new requirements and make the necessary adjustments,” warns Wagner Elias, CEO of Conviso, a developer of application security solutions.
Among the updates are those to the Payment Card Industry Data Security Standard (PCI DSS), created to protect the entire value chain of card payments. Its compliance requirements cover everything from the storage of cardholder data to secure access to sensitive payment information.
"In short, it is necessary to strengthen the protection of customer data by implementing additional measures to prevent unauthorized access," says the expert.
Therefore, companies will need to adapt and invest in new technologies. To give you an idea, some of these solutions are capable of providing a complete view of the risks related to each application. "These tools integrate different systems, centralizing information and assisting in prioritizing actions, all in a continuous way," explains the CEO of Conviso, regarding its Conviso Platform Application Security Posture Management (ASPM) platform, launched in 2010.
However, the expert points out that many companies still adopt a reactive stance regarding the security of their systems, only prioritizing the issue after suffering an attack. This behavior, according to him, is worrying, as security breaches can lead to significant financial losses and irreparable damage to the organization's reputation, which could be avoided with preventive measures.
According to him, when considering the creation of new software, it is essential that the company incorporates security at every stage of the creation cycle, from requirements gathering (the first phase that analyzes what the app will do) to deployment (production and final delivery).
“To avoid these risks, the key difference is adopting Application Security practices from the very beginning of the new application's development. This ensures the inclusion of protection measures at all stages of the software lifecycle. Besides being significantly more economical than remedying damage after an incident, investing in preventative security is much more effective. This allows you to prevent attacks, protect sensitive data, ensure compliance with laws and guidelines, and guarantee that the application is secure and reliable for users from the start,” says the expert.
Wagner explains that the company develops solutions that integrate security with DevOps, allowing each line of code to be developed with protection practices, in addition to services such as penetration testing and vulnerability mitigation. "Performing continuous security analysis and test automation allows companies to meet standards without compromising efficiency," Wagner emphasizes.
In addition to implementing robust technologies, the CEO of Conviso emphasizes the importance of specialized consulting firms, which help companies adapt to the requirements of PCI DSS 4.0 and other regulations. Offensive services such as Penetration Testing, Red Team, and third-party security assessments promote a proactive and comprehensive security approach, identifying and correcting vulnerabilities before they can be exploited.
Investments should accelerate
This transformation in digital security not only reinforces consumer confidence in a secure online environment, but also keeps pace with the accelerated growth of the application security market, which is expected to expand from US$11.62 billion in 2024 to US$25.92 billion by 2029, according to Mordor Intelligence. "Implementing cutting-edge technology marks a turning point in digital protection and reinforces confidence in a market that depends, more than ever, on security to thrive," concludes Wagner.
Check out the list of 12 PCI DSS requirements that compliance verification 4.0 must meet:
- Installing and maintaining a firewall
- Remove the default vendor configuration
- Protect the stored cardholder data
- Encrypting payment data transmission
- Update your antivirus software regularly
- Implementing secure systems and applications
- Restrict access to cardholder data as needed
- Assign user access identification
- Restricting physical access to data
- Track and monitor network access
- Continuously test processes and systems for vulnerabilities
- Create and maintain an infosec policy
The implementation of the PCI DSS 4.0 guidelines is being done in two phases:
- The first phase, with 13 new requirements, had a deadline of March 31, 2024.
- The second phase, with 51 additional requirements, must be implemented by March 31, 2025.



