The United States, the United Kingdom, Australia, and Chile have adopted very different regulatory designs. Yet the underlying dilemma remains the same: how can the chain be strengthened up to its weakest link?
This article is the first of a two-part series examining the lessons Brazil can draw from cybersecurity regulatory initiatives being adopted around the world. In this first part, we compare the Brazilian draft cybersecurity law with emerging regulatory frameworks in the United States, the United Kingdom, Chile, and Australia.
The Brazilian Draft and Its International References
In December 2025, Brazil’s National Cybersecurity Committee finalized the draft General Cybersecurity Law and submitted it to the the Casa Civil, the coordinating office of the Presidency. The text was developed collaboratively, with contributions from government, industry, academia, and civil society. At the same time, Bill 4,752/2025, sponsored by Senator Esperidião Amin (PP/SC), began its legislative journey with a similar objective: establishing a legal framework for cybersecurity and creating a National Digital Security and Resilience Program.
When the draft legislation is compared with the frameworks adopted in the United States, the United Kingdom, Chile, and Australia, Brazil’s approach appears particularly close to Chile’s Law 21.663 of 2024, itself a Latin American adaptation of the European NIS2 directive. The similarities are evident across nearly all major elements.
What has not yet gained the same prominence in the Brazilian debate are several tools that have made a practical difference elsewhere: the use of government procurement to raise security standards without requiring new legislation, legal protections for those who report incidents in good faith, specific regulatory treatment for ransomware, and requirements that new obligations be accompanied by cost assessments and funding mechanisms.
Emerging Trends
The SolarWinds and Kaseya incidents in the United States beginning in 2020 demonstrated how a single compromised supplier can dramatically expand the global impact of a cyber incident, reinforcing a familiar principle: no chain is stronger than its weakest link. In the SolarWinds case, attackers compromised a software update used by thousands of organizations. In the Kaseya incident, a ransomware attack spread through the company’s IT management platform and affected numerous customers of managed service providers. Both events illustrated how a vulnerability at a single supplier can multiply across an entire supply chain. The regulatory response in the four countries examined was swift.
The United States began requiring software component inventories from companies supplying the federal government and, as of November 2025, incorporated the Cybersecurity Maturity Model Certification (CMMC) into Department of Defense procurement rules, extending requirements to subcontractors. Australia expanded the definition of critical assets to include storage systems containing sensitive operational data. The United Kingdom is bringing managed service providers and data centers within the scope of its cybersecurity regulatory framework.
Ransomware as a Separate Regulatory Category
This shift in scale is directly connected to a second international trend: ransomware is increasingly subject to its own reporting regime, separate from general incident notification requirements. The rationale is straightforward. Ransomware attacks combine the operational impact of a cybersecurity incident with a specific economic and criminal dimension. Payment of a ransom may ultimately finance organized criminal networks, even when victims act under coercion.
Australia has taken the most explicit approach. Organizations that pay a ransom must report the payment within 72 hours, including the amount, currency, and records of communications with the attacker. The law protects this information from being used against the victim in regulatory proceedings, except in cases of false statements.
The United States is moving in a similar direction through the Cyber Incident Reporting for Critical Infrastructure Act which establishes a 72-hour reporting deadline for ordinary cyber incidents and a separate 24-hour deadline for ransom payments. The United Kingdom has also addressed the issue in legislation currently under consideration.
Public Procurement as a Regulatory Lever
The third trend is perhaps the most surprising because it shifts the response away from the strictly legislative arena. If suppliers represent the most exposed link in the chain, public procurement may be one of the most effective tools available. Australia made the Essential Eight, a set of eight core cybersecurity controls ranging from tested backups to multi-factor authentication (MFA), mandatory for federal government entities and incorporated them into procurement requirements for IT suppliers. The United Kingdom adopted a similar strategy through Cyber Essentials. More than 60,000 certifications have already been issued, many of them to small businesses seeking to sell products and services to the public sector. The outcome is significant. Governments can use their purchasing power to raise cybersecurity standards across their supply chains without necessarily imposing new legislative obligations. In this case, no new law was required.
Cybersecurity Moves into the Boardroom
A notable development across all four countries is that responsibility for cybersecurity has moved up the corporate hierarchy. Cybersecurity is no longer viewed solely as a technical issue delegated to IT teams. Instead, it has become a formal responsibility of boards of directors and senior management. This trend echoes Brazil’s relatively advanced approach in the telecommunications sector, where regulations already require an internal governance structure, a designated executive, and board-level approval of a Cybersecurity Policy.
Legal Immunity to Encourage Reporting
A fifth trend involves legal protections for organizations that share information about cyber incidents. The United State’s Cybersecurity Information Sharing Act of 2015 and Australia’s Cyber Security Act of 2024 provide protections for entities that report incidents in good faith. These measures reduce incentives for organizations to withhold information out of fear of regulatory penalties. Reporting obligations can increase the volume of available cybersecurity information, but the usefulness of that information depends on adequate safeguards, governance arrangements, and proper data handling mechanisms.
The speed of regulatory adaptation completes this picture and may be the most difficult element to replicate. Australia has revised its critical infrastructure legislation several times within a relatively short period, often in response to specific incidents such as Optus, Medibank, and DP World.
The Optus breach exposed personal data belonging to millions of customers. The Medibank attack compromised highly sensitive healthcare information. The incident affecting DP World disrupted port operations across Australia. These three cases demonstrated that the consequences of cyberattacks can range from large-scale data exposure to the disruption of critical infrastructure and essential services.
Ultimately, international experience suggests that cybersecurity frameworks benefit from update mechanisms that keep pace with the evolving threat landscape. In technology-related fields, overly prescriptive legislation often becomes difficult to update, particularly when implementation occurs in an environment of rapid technical change.
Conclusions
International experience points to five major trends: Strengthening security throughout the entire supply chain, establishing specific rules for ransomware incidents, using public procurement as a regulatory instrument, elevating cybersecurity responsibility to senior management and boards of directors, protecting organizations that share cybersecurity information in good faith.
Rather than automatically importing foreign regulatory models, Brazil’s challenge will be to identify which instruments can strengthen its own cybersecurity framework without creating unnecessary complexity.
In the second part of this article, we will examine the challenges that remain within the regulatory systems analyzed and explore how those shortcomings can be avoided in the Brazilian context.
- Public Policy
- Cybersecurity
State of Play of the Digital Networks Act
Resilience in the DNA: Simplifying to Strengthen Security
Networks: Europe’s Digital Future. Is Voluntary Conciliation Enough?
Contact our communication department or requests additional material.
