Attacks on technology organizations have started arriving through the service supply chain, according to Cássio Campos, cybersecurity leader. In his assessment, this movement placed third-party evaluation at the center of risk strategy and began integrating commercial calculations for corporate buyers, insurers, and institutional investors.
The analysis comes from audits conducted at technology companies, financial services, and regulated sectors. The book that compiles it, titled "The Paradox of Technology Leadership," will be released in September 2026 at the Rede Líderes headquarters in São Paulo.
Campos reports that, during the audits, security questionnaires that were previously presented only at the contract closing phase started being required in the middle of the sales cycle. Contracts began including audit clauses, and negotiation timelines extended without changes to the product offered.
The specialist highlights that the conflict between speed and security is real in the symptom and false at the source, indicating that the change in risk approach represents a structural transformation in commercial relationships within the technology sector.




