Cyberattacks: scattered data is an entry point

Scattered data, disconnected systems and overly broad access open the door to attacks. Learn how to protect company data and measure your exposure.

In short

  • Attackers choose companies by how easy they are to access, not by revenue, so disorganized data and broad access make any company a likely target.
  • Spreadsheets with sensitive data, disconnected systems and excessive privileges are gaps created by the operation itself and don't need a sophisticated attack to be exploited.
  • Centralizing data in a single source, controlling access by role and using single sign-on with two-factor authentication reduces what is exposed in a breach.
  • Indicators such as users with broad access, time to block access for people who left and exports outside the systems show whether the company is actually less vulnerable.

In 2025, Brazil recorded 315 billion attempted cyberattacks.

That's 84% of everything that happened in Latin America.

The easiest target isn't the biggest. It's the least organized.

The logic of cyberattacks has changed. Criminals no longer pick targets by revenue size. They pick them by ease of access.

And the easiest access point in a company is exactly what most still treat as normal: data scattered across spreadsheets, systems without proper authentication, teams with far too much access to things they don't need to see.

This isn't theory. In July 2025, an attack on C&M Software, a company that processes Pix transactions for financial institutions, led to more than R$ 1 billion being diverted. The way in was a compromised credential. A password. With access to the wrong system.

The problem wasn't the technical sophistication of the attack.

The problem was disorganized data.

Three vulnerabilities every operations manager needs to know

1. Scattered data is exposed data

Spreadsheets with sensitive information shared by email, customer databases outside the main system, exported reports sitting on someone's desktop — each of these points is a door.

According to Sophos, 91% of cloud accounts operate with excessive privileges. In plain terms: most people in companies have access to far more than they need to do their jobs.

2. Disconnected systems create invisible gaps

When billing, operations and customer data live in different systems that don't talk to each other, the company loses visibility into what's happening in real time.

And what the company can't see, the attacker finds.

Exploitation of vulnerabilities grew 34% as an initial access vector into systems in 2025. Most of these vulnerabilities weren't new; they were ignored.

3. Without governance, LGPD (Brazil's data protection law) becomes an active risk

The ANPD (Brazil's data protection authority) published a new regulatory agenda for 2025-2026. Pressure is growing on companies that can't demonstrate control over their data.

Fines for data breaches are no longer hypothetical. They're a risk line item in planning.

And SMBs? They're at the center of the problem.

Accounting for seven out of ten formal jobs in Brazil, small and mid-size businesses have moved quickly on digitalization, but not always at the same pace on governance and protection.

The average cost of recovering from an attack in Brazil already reaches millions of reais. For many SMBs, that's more than their entire annual revenue.

A successful attack doesn't just paralyze the system.

It paralyzes operations. It paralyzes trust. Sometimes it paralyzes the company.

Cybersecurity is a consequence. The problem starts earlier.

Here's what nobody says openly: most successful attacks don't win through technical sophistication. They win by finding what was already a mess.

Data without a clear owner. Systems without integration. Access without control. Reports that leave the system and never come back.

Organizing your operational data isn't just about efficiency. It's the first layer of protection.

When data is integrated, traceable and access-controlled, an attack has fewer places to hide. And the company finds out faster when something is out of place.

Three concrete actions to start now:

  • Map where your sensitive data lives: systems, spreadsheets, uncontrolled exports
  • Review who has access to what: excessive privilege is a vulnerability, not a convenience
  • Integrate what's disconnected: real-time visibility is the difference between detecting and finding out too late

How to organize data to reduce exposure

Mapping data, reviewing access and integrating systems take care of the start. For protection to become routine, and not a one-week cleanup sprint, the way data is structured has to change.

  • Single source: operational data lives in a central database, fed by integrations with ERP, CRM and other systems, instead of copies in spreadsheets.
  • Role-based access: each team sees only what it needs. In Power BI dashboards, this is done with row-level security (RLS).
  • Single sign-on: users log in with Microsoft Entra ID or Google, with two-factor authentication, so all access can be blocked at once when someone leaves.
  • Dashboards instead of exports: whoever needs a number checks a dashboard with controlled access, without downloading a file.
  • Usage logs: knowing who accessed what and when helps spot unusual behavior.

None of this replaces security tools such as antivirus, firewall, backup and monitoring. But it reduces what is exposed and makes it easier to notice when something is off.

Common mistakes that leave the door open

Many breaches don't come from one big failure. They come from small shortcuts that become habits because nobody looks at the risk.

  • Logins shared by several people, which makes it impossible to know who did what.
  • Access for former employees and vendors that was never removed.
  • Admin rights for everyone, so work doesn't get stuck.
  • Passwords and integration keys stored in spreadsheets, scripts or emails.
  • Copies of the production database used for testing, without the same access control.

None of these points requires a sophisticated attack to be exploited. One credential in the wrong place is enough. Fixing them rarely requires new technology. It requires someone responsible for reviewing this list regularly.

How to measure whether your company is less vulnerable

What isn't measured gets messy again. A few simple indicators show whether data organization is moving forward or stayed on paper.

  • Number of spreadsheets and exports with sensitive data circulating outside the systems.
  • Share of users with admin rights or broad access.
  • Time between a person leaving the company and all of their access being blocked.
  • Share of systems with single sign-on and two-factor authentication.
  • Number of integrations that still depend on manually sent files.

These numbers can sit in a dashboard that management reviews every month, next to operational indicators. That way, security stops being an IT-only topic and is tracked like any other business risk.

Is your data organized enough to withstand an unauthorized access attempt?

Wolkee connects systems, organizes databases and gives you real visibility into what's happening in your operations. No complexity, no delays.

Tell us about your situation. Wolkee knows how to unlock it.

Frequently asked questions

How do you protect a company's data?

Start by finding out where sensitive data lives and who has access to it. Then centralize information in a single source, grant access by role, use single sign-on with two-factor authentication and eliminate spreadsheets circulating outside the systems. Antivirus, firewall and backup are still necessary, but they work better when data is already organized.

Why are small and mid-size businesses targeted by cyberattacks?

Because they tend to be easier to break into. Many SMBs digitized their operations quickly, but without the same attention to access control, system integration and governance. Shared passwords, access that is never reviewed and data scattered across spreadsheets make entry easier. For an attacker, easy access is worth more than a big target.

What is excessive access privilege?

It is when a person or system has access to more data and functions than it needs to do its job. If that credential is stolen, the attacker inherits everything it could see and do. The fix is to apply the principle of least privilege: each role accesses only what is necessary, and access is reviewed periodically.

What does the LGPD require in case of a data breach?

The LGPD (Brazil's data protection law) requires companies to notify the ANPD and the data subjects of security incidents that may cause relevant risk or harm. The law also calls for adequate security measures to protect personal data and the ability to demonstrate them. Deadlines and notification format follow ANPD regulations, so it is worth involving the company's legal team or data protection officer.