Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Convene: Boston | Cybersecurity & Human Risk Conference Aug 13 - 14, 2026

Brazilian CSIRTs Forum 2026

Type Conference
Organization NIC.br
Event Format Physical
Size 500+ approximate delegates
Registration Free
SPEAKING: FREE-TO-SPEAK

Search for other Cybersecurity Conferences in Brazil in 2026-2027.

Conference Description

Key Takeaways

  • Annual gathering for Computer Security Incident Response Teams (CSIRTs) and Security Operations Centre (SOC) professionals in Brazil
  • Technical focus on incident response, threat intelligence, malware analysis, and security automation
  • Includes dedicated MISP workshop for hands-on threat intelligence platform training
  • Addresses emerging challenges including AI-driven threats, ransomware, and regulatory compliance
  • Emphasises practical, non-commercial content with real-world case studies and operational strategies

Introduction

The Fórum Brasileiro de CSIRTs brings together cybersecurity professionals responsible for defending organisations against increasingly sophisticated threats. Held annually in São Paulo, this event serves incident responders, threat intelligence analysts, and security operations teams seeking practical knowledge and peer collaboration. The forum addresses critical operational challenges facing security teams today, from automating detection and response workflows to integrating threat intelligence across disparate systems. As organisations contend with ransomware campaigns, AI-enabled attacks, and evolving regulatory requirements, the event provides a venue for sharing methodologies that have proven effective in real-world incident scenarios.

About the Fórum Brasileiro de CSIRTs

The Fórum Brasileiro de CSIRTs functions as a community-driven gathering focused on organisational resilience in the face of cybersecurity incidents. Unlike vendor-dominated conferences, the forum explicitly prioritises practical, non-commercial content. Presentations centre on lessons learned from actual incidents, operational strategies that have been tested under pressure, and technical approaches that attendees can implement within their own environments.

The event takes place at the Amcham Business Center in São Paulo and combines traditional presentations with technical workshops, tutorials, and hands-on demonstrations. This format allows participants to move beyond theoretical discussions into applied learning. A notable component is the Workshop MISP, which provides intensive training on the Malware Information Sharing Platform, an open-source tool widely adopted by CSIRTs for structured threat intelligence exchange.

Incident Response and Threat Intelligence in Practice

The forum’s agenda reflects the operational realities facing modern security teams. Incident response remains the central theme, with sessions examining how organisations detect, contain, and recover from security breaches. This includes detailed examination of ransomware incidents, which continue to disrupt organisations across sectors, and the forensic techniques required to understand attacker methodologies.

Threat intelligence receives substantial attention, particularly the challenge of making intelligence actionable within security operations. The relationship between threat intelligence programmes and operational tools such as Security Information and Event Management (SIEM) platforms, Endpoint Detection and Response (EDR) solutions, and Network Detection and Response (NDR) systems forms a recurring discussion point. Effective intelligence sharing requires not only technical integration but also governance frameworks that enable organisations to contribute and consume threat data responsibly.

Malware analysis sessions provide technical depth for practitioners who need to understand adversary capabilities. The forum covers both commercial and open-source analysis tools, including IDA Free, Ghidra, JADX, and APKtool, giving analysts options regardless of budget constraints. These sessions typically progress from static analysis fundamentals through dynamic analysis techniques, equipping attendees with methodologies applicable to current threat samples.

Automation and Operational Efficiency

Security teams face persistent pressure to handle growing alert volumes with constrained resources. The forum addresses this through sessions on automation in security operations, examining how organisations can reduce manual effort in detection, triage, and response workflows. This extends beyond simple scripting into orchestration approaches that connect multiple security tools into coherent response processes.

Network telemetry analysis using NetFlow and IPFIX protocols represents another technical track. These flow-based monitoring approaches provide visibility into network behaviour patterns that complement traditional signature-based detection. When integrated with tools such as IVRE, Zeek, and Suricata, flow data enables threat hunting activities that can identify compromises missed by perimeter defences.

Vulnerability management at scale presents ongoing challenges for security teams, particularly in environments with diverse technology stacks and rapid deployment cycles. Forum sessions examine how organisations prioritise remediation efforts when facing thousands of identified vulnerabilities, balancing risk-based approaches against operational constraints and business requirements.

The MISP Workshop

The Workshop MISP operates as a distinct technical track within the forum, providing hands-on training with the Malware Information Sharing Platform. MISP has become a foundational tool for CSIRTs seeking to structure and share threat intelligence, offering standardised formats for indicators of compromise, threat actor profiles, and attack patterns.

Workshop content covers practical deployment and integration scenarios, including the use of PyMISP for programmatic interaction with MISP instances. Participants learn how to connect MISP with other security tools in their environment, creating automated workflows that enrich alerts with contextual intelligence. The workshop also addresses governance considerations, including how organisations can participate in sharing communities while managing sensitivity and attribution concerns.

Emerging Threats and Regulatory Developments

The forum acknowledges that the threat landscape continues to evolve in ways that challenge established defensive approaches. Sessions examine the security implications of artificial intelligence adoption, both as a tool that defenders can leverage and as a capability that adversaries are beginning to exploit. Secure AI adoption requires organisations to understand new attack surfaces introduced by machine learning systems while also considering how AI can enhance detection and response capabilities.

Financial sector fraud receives specific attention, reflecting the sophisticated attacks targeting banking and payment systems in Brazil. These sessions examine the intersection of cybersecurity and fraud prevention, areas that increasingly require coordinated response as attackers combine technical intrusion with social engineering and account manipulation.

Regulatory compliance forms another discussion thread, as organisations navigate requirements that mandate specific security controls, breach notification timelines, and data protection measures. The forum provides context on how compliance obligations intersect with operational security practices, helping teams align regulatory requirements with effective defence strategies rather than treating compliance as a separate exercise.

Who Should Attend

The Fórum Brasileiro de CSIRTs serves professionals with direct responsibility for security operations and incident management. This includes incident responders and SOC analysts who handle day-to-day detection and response activities, threat intelligence analysts who produce and consume intelligence products, and security engineers who build and maintain defensive infrastructure.

The event also addresses the needs of security leaders, including Chief Information Security Officers and IT managers responsible for security strategy. These attendees benefit from understanding operational challenges and emerging practices that inform resource allocation and programme development decisions. Sectors represented typically include finance, government, healthcare, telecommunications, and critical infrastructure, though the operational focus makes content applicable across industries.

Building Community Through Collaboration

Beyond formal sessions, the forum emphasises networking and community building among Brazilian security professionals. The challenges facing CSIRTs often benefit from collaborative approaches, whether through formal intelligence sharing arrangements or informal peer relationships that enable rapid consultation during incidents. The event creates opportunities for these connections to form, recognising that effective incident response frequently depends on relationships established before crises occur.

The forum’s emphasis on lessons learned reflects a maturity in the Brazilian security community, acknowledging that organisations benefit when peers share both successes and failures. This openness enables collective improvement in defensive capabilities, raising the baseline for incident response across participating organisations.