technical report
Noise and fire
Security incidents detected in Uruguay tripled in a single year. Severe ones did not. This 11-page report explains what the official CERTuy series actually says, what we find across more than fifteen ISO 27001 certifications, and how that changes the way security should be managed.
- Pages
- 11
- Format
- Language
- English
- Cost
- Free
What it covers
- The full official CERTuy series 2024-2026, including the number almost nobody looks at: the share of severe incidents keeps falling while volume triples.
- What the volume is made of: the 69 % that is reconnaissance, the 1.64 % that did get in, and the category that grew the most this half-year.
- The seasonality of risk: why the peak lands in December, when the team is on leave.
- The four findings we see again and again across more than fifteen ISO 27001 certifications, and why none of them is solved by buying a product.
- The overlap between what goes unmanaged inside and what strikes from outside, drawn from our sectoral threat radar.
- What AI changed: the cost of reconnaissance, with the three 2026 cases that prove it.
- A ten-question self-assessment, five tasks for Monday and six budget lines for 2027.
Who it is for
- Boards that have to decide how much to invest in security and want to read the numbers without marketing in between.
- Information security and IT leads receiving more alerts than they can process.
- Certified organisations, or those on their way, preparing a surveillance audit or the 2027 budget.
