technical report

Noise and fire

Security incidents detected in Uruguay tripled in a single year. Severe ones did not. This 11-page report explains what the official CERTuy series actually says, what we find across more than fifteen ISO 27001 certifications, and how that changes the way security should be managed.

Pages
11
Format
PDF
Language
English
Cost
Free

What it covers

  • The full official CERTuy series 2024-2026, including the number almost nobody looks at: the share of severe incidents keeps falling while volume triples.
  • What the volume is made of: the 69 % that is reconnaissance, the 1.64 % that did get in, and the category that grew the most this half-year.
  • The seasonality of risk: why the peak lands in December, when the team is on leave.
  • The four findings we see again and again across more than fifteen ISO 27001 certifications, and why none of them is solved by buying a product.
  • The overlap between what goes unmanaged inside and what strikes from outside, drawn from our sectoral threat radar.
  • What AI changed: the cost of reconnaissance, with the three 2026 cases that prove it.
  • A ten-question self-assessment, five tasks for Monday and six budget lines for 2027.

Who it is for

  • Boards that have to decide how much to invest in security and want to read the numbers without marketing in between.
  • Information security and IT leads receiving more alerts than they can process.
  • Certified organisations, or those on their way, preparing a surveillance audit or the 2027 budget.