SUSEP’s new cybersecurity manual for Brazilian insurers did not appear out of nowhere: it is the output of a working group created in August 2024, which held ten meetings across two thematic subgroups that same autumn — but it took regulators nearly two years to weave those findings into governance rules meant, until recently, only for mutualist and cooperative insurers. The manual now reaches across the market, from national reinsurers to capitalization companies, and it arrives with a recurring reporting duty attached.
From Working Group to Rulebook: How SUSEP Built the Manual
SUSEP’s manual traces back to a dedicated Insurance & Cybersecurity working group, formally created by Administrative Order (Portaria) No. 8,323 on August 26, 2024, and later extended by a second order, Portaria No. 8,348. The group did not linger: it held ten meetings between September and October 2024, organized across two thematic subgroups, comparing market practice against the direction international regulators were already taking on operational cyber risk.
The rationale SUSEP cites for moving beyond a single circular is largely a numbers argument. GFIA, the global federation of insurance associations, puts the worldwide cyber-risk protection gap at close to $944 billion a year, a figure the regulator’s own working-group report leans on to justify treating cyber exposure as a standing supervisory concern rather than a one-time compliance box to check.
Mutualist Reform Becomes the Cybersecurity Vehicle
The manual’s legal foundation is where the convergence story gets specific. SUSEP states that the document is grounded in CNSP Resolutions 416/2021, 491/2026 and 492/2026, together with SUSEP Circulars 638/2021 and 700/2024. Two of those five instruments did not exist a year ago, and neither was written with cybersecurity as its headline purpose.
CNSP Resolution 491 was adopted at an extraordinary session on May 4, 2026, establishing general rules for mutual patrimonial protection operations — the first dedicated regime for Brazil’s mutualist property-protection structures. Its companion measure goes further on governance: CNSP Resolution 492/2026 requires insurance cooperative boards to ensure the adequacy and effectiveness of their risk-management structure and internal controls, under Article 21, section X. Cybersecurity, in other words, entered the mutualist and cooperative segment through board-level risk governance — the same logic underpinning the EU’s incident-reporting framework for insurers.
The Fraud and Breach Numbers Behind the Rulebook
SUSEP’s own case leans on data rather than doctrine. Brazil’s average cost of a data breach reached $1.36 million in 2024, up from $1.22 million in 2023, according to IBM figures cited in the working group’s report. Fraud trends point the same direction.
Brazil recorded 3.7 million digital-commerce fraud attempts in 2023, totaling roughly $3.5 billion, per Clearsale data referenced in the same report, while claims-specific figures show fraud migrating deeper into the insurance value chain. Confirmed fraudulent insurance-claims notices reached R$1 billion combining the second half of 2023 and the first half of 2024, according to CNSEG, the national insurers’ confederation — the kind of trend line that turns a cybersecurity manual into a claims-fraud conversation as much as a data-protection one.
What Supervised Entities Must Now Do
Scope is broad by design. The manual applies to insurers, open pension entities, capitalization companies, local reinsurers, insurance cooperatives, and mutual-protection administrators, meaning the same baseline expectations now run across segments that previously sat under separate circulars.
The operational core of the new document is reporting. Supervised entities must prepare an annual report on the prevention and treatment of incidents and vulnerabilities, a recurring disclosure rather than a one-off certification.
None of this replaces existing rules. SUSEP Circular No. 638/2021 already set minimum cybersecurity requirements for supervised entities, five years before the new manual, and the manual folds that baseline into the wider architecture of Brazil’s National Cybersecurity Policy (PNCiber), instituted by Decree No. 11,856 in 2023. The manual lands alongside other structural changes reshaping how Brazilian carriers and brokers operate, including sweeping changes carriers and brokers must absorb under the country’s new insurance law, and follows a market separately building new risk-transfer instruments such as a record-setting reinsurance-linked structure priced for the local market this year.
Mini-FAQ
What prompted SUSEP to publish this cybersecurity manual?
Which types of insurance entities does the manual cover?
What new obligation does the manual create for insurers?
Sources: SUSEP, Insurance & Cybersecurity working group, SUSEP working group final report, CNSP Resolution 491/2026, official text, CNSP Resolution 492/2026, LegisWeb reproduction, Legismap coverage of the manual.