Skip to content
DM11AI TRUST & IT RISK PROTECTION
ProductsCase StudiesAbout UsContact
PTTalk to an expert
Carregando
DM11AI TRUST & IT RISK PROTECTION

ouvir. entender. resolver.

Trust to grow in the AI era. AI governance, IT GRC, cybersecurity and business continuity for companies that cannot stop.

Solutions

  • AI Trust
  • Governance, Risk & Compliance
  • Cybersecurity
  • Security Office
  • Business Continuity

Products

  • oitenta20®
  • Jigphish®
  • Ethical Hacker as a Service
  • DPO Backoffice®
  • All products

Company

  • About us
  • Case studies
  • FAQ
  • Contact

Contact

  • contato@dm11.com.br
  • +55 (11) 4837-5758
  • Av. Eng. Luís Carlos Berrini, 1140 – 7º andar, Brooklin, São Paulo/SP – CEP 04571-000

DM11 © 2026 · All rights reserved.

  • Privacy Policy
  • Cookies
  • Terms of use
  • Ethics and conduct
  • Anti-corruption
  1. Home
  2. Case studies

CASE STUDIES

Every industry has its risks. We know them all.

Over 5,300 projects in 17 years. We anonymized every story below, because the same discretion that protects these clients will protect you. Read them and you'll recognize your own industry, maybe your own board meeting.

IN THE WORDS OF OUR CLIENTS

Two clients who agreed to speak on the record

Every other case on this page keeps the client anonymous, as the contract requires. These two waived that. The passages below are translated from what they wrote.

DM11® has established itself as one of our main intelligence partners in information security, delivering high quality services to Tribanco. I would highlight in particular the Security Office as a service, which has been essential to protecting the integrity and confidentiality of our data.

Rogerio Marcos da Silva

Tribanco

A PARTNERSHIP OF MORE THAN 8 YEARS

Before this partnership we faced significant challenges in this area, because we lacked a reliable partner for critical GRC and cybersecurity work. We finally found a partner we can trust, one that understands our challenges and is fully equipped to take them on.

Leda Maria Angelis

NovaQuest

DIGITAL BANKS

The digital bank that grew too fast for its own controls

CHALLENGE
Three million accounts in two years, and a security team still sized for the original startup. The board knew what BACEN, Brazil's Central Bank, would ask at the next inspection. It also knew it lacked the answers.
SOLUTION
We aligned the bank with CMN Resolution 4,893 and BCB Resolution 85, ran continuous subscription-based pentesting across the app, APIs, and infrastructure, and reviewed the governance of the AI model behind credit decisioning.
RESULT
The regulator's inspection came and went without a single critical finding. The risk committee now reads a monthly dashboard the board understands, and the security team grew on a plan instead of in a panic.

INSURANCE CARRIERS

The insurer that found the leak before the regulator did

CHALLENGE
An alert about exposed credentials on a criminal forum named the company's domain. Nobody could say whether it was serious, stale, or fake. Every hour of uncertainty raised the odds of making the wrong call.
SOLUTION
We ran incident response with digital forensics: traced the source to a legacy broker portal, contained the access, established the true extent of exposure, and led the notifications to ANPD and SUSEP based on facts rather than guesswork.
RESULT
Exposure contained within 72 hours and regulatory notification filed on time, with a precisely defined scope. Six months later, the response plan born in that crisis went through a full simulation. This time, no real incident attached.

DEBT COLLECTION AND CREDIT RECOVERY

A full security office for a company that couldn't afford one

CHALLENGE
The credit recovery firm handled sensitive data on millions of debtors, and its contracting banks demanded a security operation its size couldn't support on its own payroll.
SOLUTION
We delivered IT GRC and cybersecurity through a Security Office as a Service: governance, vulnerability management, awareness training, and full support through the banks' audits, all under one flexible contract.
RESULT
The firm passed vendor approval with its three largest bank clients and renewed every portfolio. The structure now flexes with the business: senior when it has to be, lean when it can be.

INVESTMENT PLATFORMS

The platform that treated security like a product

CHALLENGE
After a competitor made headlines over account fraud, the executive committee asked the right question: if it happened to us, would we even know? The honest answer was no.
SOLUTION
We ran application and API pentesting focused on business-logic fraud, reviewed the authentication and onboarding flows, and set up monitoring of sector-targeted threats through cyber threat intelligence (CTI).
RESULT
We found two viable fraud chains and closed them before anyone could exploit them. The report became a board agenda item, and the security budget stopped living on a cost spreadsheet.

HOSPITAL NETWORKS

The hospital that rehearsed the crisis before it arrived

CHALLENGE
Brazilian hospitals sit among ransomware's favorite targets, so the network's board ran the numbers on a single day of downtime: surgeries suspended, medical records unreachable, lives at risk. It decided to prepare instead of wait.
SOLUTION
We built a business impact analysis (BIA) across clinical processes, a continuity plan ordered by clinical priority, and network segmentation to isolate legacy medical devices. Then we ran two crisis simulations with the executive team in the room.
RESULT
By the third exercise, simulated recovery time for critical systems dropped from days to hours. The network now knows what it would do at 2 a.m. on a Saturday, and who would call whom.

HEALTH INSURANCE OPERATORS

Health data: the number one target of the new ANPD

CHALLENGE
ANPD, Brazil's data protection authority, named health data an enforcement priority. The operator looked at its own privacy program, assembled in a hurry back in 2021, and knew it would not survive a real inspection.
SOLUTION
DPO Backoffice®: our multidisciplinary team rebuilt the data mapping, reviewed the legal bases for clinical data use, structured the data subject request process, and coached the in-house DPO to face the authority with confidence.
RESULT
An auditable privacy program with the evidence trail ready to go. When the routine inspection notice arrived, the response went out in days: complete, documented, and without a single all-nighter.

PHARMACEUTICAL INDUSTRY

Protecting research worth billions that can't wait for a patent

CHALLENGE
Clinical trial data and formulas in development moved between headquarters, partner CROs, and research centers. Each link applied a different standard of care. Nobody had central visibility.
SOLUTION
We built a third-party risk management program for the research ecosystem: assessment of every partner, contractual security clauses, and an audit trail over access to sensitive study data.
RESULT
Full visibility across the research chain within six months. Under contractual pressure, two critical partners raised their controls before any data ended up where it shouldn't.

PHARMACEUTICAL DISTRIBUTION

Two thousand pharmacies supplied, and none can wait for the system to come back

CHALLENGE
The distributor moved medicines to thousands of pharmacies and dozens of hospitals. A day of downtime wouldn't be an IT problem. It would be empty shelves, postponed surgeries, lost contracts. And distribution was already showing up on ransomware victim lists.
SOLUTION
We ran an impact analysis across the supply chain, built a continuity plan prioritizing orders, billing, and dispatch, put immutable backups under monthly restore tests, and set up vulnerability management across WMS, TMS, and manufacturer integrations.
RESULT
In the most recent recovery exercise, the simulated dispatch operation came back in under four hours, inside the window hospital contracts tolerate. Medicine logistics turned from a termination clause into a renewal argument.

AUTO PARTS (TIER 1)

No TISAX, no contract: a Brazilian supplier's race against the clock

CHALLENGE
The German automaker was polite but firm: without the TISAX label, the supplier was out of the next global platform. Deadline: one qualification cycle. The company had never even heard the acronym.
SOLUTION
We prepared the company for TISAX/VDA-ISA end to end: gap assessment, implementation of the required controls, protection of prototypes and engineering data, and hands-on support through the official assessment.
RESULT
Label secured within the qualification window. The contract survived and extended to a second product line. A competitor that failed to move was left out, a detail the board has not forgotten.

24X7 MANUFACTURING (OT/SCADA)

Pentesting a plant that can't stop for even a minute

CHALLENGE
Manufacturing had become one of the country's most attacked sectors, yet the plant director vetoed any testing: "nobody touches the SCADA." The fear was legitimate. The approach wasn't.
SOLUTION
We ran an OT security assessment with a methodology purpose-built for industrial environments: passive reconnaissance, controlled windows, off-production-line testing, and IT/OT segmentation based on the Purdue model and IEC 62443.
RESULT
We closed seventeen paths between the corporate network and the shop floor without one second of downtime. The plant director, once the most skeptical voice at the table, now requests the annual reassessment himself.

MEATPACKING AND AGRO-INDUSTRY

The meat exporter that refused to become a statistic

CHALLENGE
After watching an industry giant halt plants worldwide over ransomware, the group understood that an export shutdown caused by an attack wasn't a hypothesis. It was a matter of time and preparation.
SOLUTION
We ran our Cyber Antifrágil® program: identified the weaknesses that could stop production, built a prioritized mitigation plan, put immutable backups under test, and ran recovery exercises with IT and operations together.
RESULT
In the latest recovery drill, the simulated plant came back online in under one shift. Export licenses and international contracts remain intact, and the cyber insurance premium came down at renewal.

STEEL AND MINING

Security for a business that measures losses in idle blast furnaces

CHALLENGE
At the steelmaker, IT and industrial automation had lived in separate worlds for twenty years. Then a minor incident proved that, on the network, those worlds were far more connected than anyone believed.
SOLUTION
We ran an industrial security maturity diagnostic, built an OT asset inventory and a zones-and-conduits segmentation architecture (IEC 62443), and stood up a single cyber-physical risk committee bringing both sides together.
RESULT
Cyber-physical risk entered the corporate risk matrix with an owner and a budget. Internal audit had flagged the issue for three straight years. It finally closed the finding, the oldest one in the report.

CHEMICALS AND PETROCHEMICALS

Crisis management for operations where failure isn't an option

CHALLENGE
An unplanned shutdown at a chemical plant means more than lost revenue. It means environmental, regulatory, and community risk. The crisis plan existed on paper, but nobody had ever tested it against a cyber scenario.
SOLUTION
We integrated cyber risk into the crisis management plan: attack scenarios with physical consequences, decision protocols for safe shutdown, and a tabletop exercise with leadership, operations, legal, and communications at the table.
RESULT
The exercise exposed and fixed a critical gap: no one had formal authority to disconnect systems in an emergency. Now someone does. That kind of detail only surfaces before a crisis if somebody goes looking for it.

INDUSTRIAL AUTOMATION AND EQUIPMENT

The manufacturer that turned product security into a selling point

CHALLENGE
The company's connected equipment went into the plants of demanding customers, and those customers' security questionnaires began asking questions engineering had never considered.
SOLUTION
We brought security by design to the product line: code and firmware architecture review, pentesting of the equipment and its management platform, and a vulnerability response process for the installed base.
RESULT
The equipment datasheet now includes its security posture, and the sales team has learned to use it. In two years, the company has lost no deal to a failed customer technical assessment.

POWER DISTRIBUTION

Critical infrastructure, measured by the power sector's yardstick

CHALLENGE
Between the power sector's minimum cybersecurity controls and the reality of substations running three-decade-old technology, the utility needed to prove to the regulator, and to itself, that it was in control.
SOLUTION
We aligned the utility with the sector's operational cybersecurity requirements, inventoried and classified critical assets, designed a segmentation architecture between corporate and operations, and built a response plan for incidents affecting supply.
RESULT
The utility showed the regulator evidence instead of declarations. When a substation lost communications (an electrical fault, as it turned out, and no attack), the new diagnostic protocol saved hours of investigation.

WATER AND SANITATION

Clean water, protected data, a community at ease

CHALLENGE
Attacks on water treatment systems abroad set off alarms in the company's boardroom: what if someone remotely altered the chemical dosing at a treatment station? The answer had to be better than "unlikely."
SOLUTION
We assessed the stations' supervisory systems, integrated physical and logical access controls, segmented the industrial networks, and built a response plan with water safety protocols and public communication procedures.
RESULT
The remote manipulation scenarios were blocked and tested. The company brought the issue to its board with a plan in hand, before any regulator or journalist ever asked.

OIL AND GAS

From terminal to pump: security for a supply chain that can't leak, in any sense

CHALLENGE
At the fuel distributor, terminal automation coexisted with ever more integrated corporate systems. Its international major partners began demanding evidence of cyber-physical security across the entire chain, from intake to dispatch.
SOLUTION
We ran a cyber-physical risk assessment at the terminals with a methodology safe for live operational environments, segmented automation from corporate, set access controls for operators and carriers, and answered the international partners' due diligence with technical evidence.
RESULT
The distributor cleared the international counterparties' assessments with no imposed action plans. Operations leadership now reviews the cyber-physical risk map every quarter, the same way it reviews inventory and margin.

SAAS WITH GENERATIVE AI

The AI feature that almost shipped without brakes, then became a benchmark

CHALLENGE
The generative AI assistant was the bet of the year, but a week before beta an executive asked: what if it leaks one customer's data to another? Nobody had tested it. The launch stopped cold.
SOLUTION
We ran LLM application pentesting (prompt injection, context leakage, jailbreaks) against the OWASP Top 10 for LLMs, reviewed the RAG architecture with tenant isolation and sensitive-data guardrails, and delivered an AI policy with ISO/IEC 42001 readiness.
RESULT
Three critical isolation flaws fixed before beta. The launch shipped with an AI security whitepaper that marketing turned into a campaign, and enterprise customers turned into a reason to upgrade.

DATA CENTERS AND COLOCATION

The data center that sold trust and decided to prove it

CHALLENGE
Banking and healthcare clients kept asking about the data center's own certifications. The facility audited everyone but itself, and the irony was starting to cost contracts.
SOLUTION
We implemented ISO 27001 and SOC 2 Type II in parallel under a unified scope, using every control for both certifications, with our team driving the evidence all the way through the final audit.
RESULT
Two certifications in the same fiscal year, at half the internal effort forecast. The seals went straight into the sales deck, and the clients' uncomfortable question became the sales team's favorite slide.

MARKETPLACES AND PLATFORMS

Open APIs, a platform closed to fraud

CHALLENGE
The B2B marketplace grew by exposing APIs to integrators. Every new integration carried a commercial promise and a technical risk, and business-logic abuse fraud started surfacing in the reconciliations.
SOLUTION
We set up continuous API pentesting focused on authorization and business logic, a gateway with per-partner limits and monitoring, and a security qualification process for new integrators.
RESULT
API abuse losses hit zero within a quarter. Integrator qualification, once a bottleneck, became a badge: approved partners display the status and demand it from their competitors.

ISPS AND REGIONAL TELECOM

The regional ISP that became a target, then became a fortress

CHALLENGE
Route hijacking, DDoS attacks, and corporate clients demanding security SLAs: the ISP realized it had become the region's critical infrastructure without ever being built like it.
SOLUTION
We hardened the network infrastructure and core, set up risk-based vulnerability management and DDoS protection sized to the threat, and wrote a response plan that includes customer communication during incidents.
RESULT
The ISP absorbed two volumetric attacks the following year with no perceptible downtime. The security SLA became a product: the ISP now sells peace of mind along with the link, at a better margin.

SCALE-UPS AND STARTUPS

Series B due diligence: the day security was worth valuation

CHALLENGE
Mid-round, the international fund sent a 40-page technical questionnaire. The scale-up had traction, product, and team, and not one structured answer about security. The round's clock was ticking.
SOLUTION
We ran a pre-due-diligence readiness sprint: rapid assessment, remediation of the critical gaps, formalized policies, and our team fielding the technical questions alongside the founders on calls with the fund.
RESULT
Due diligence cleared with no security conditions precedent, which the fund itself remarked was rare. The round closed on schedule, and the startup came out of it with a grown-up security program.

LARGE-SCALE E-COMMERCE

Black Friday without surprises for an e-commerce giant

CHALLENGE
Rising fraud and a history of instability at peak dates had turned Black Friday into a war event. The operation made money, and leadership held its breath every November.
SOLUTION
We set up recurring intrusion testing across the platform and APIs, integrated SAST and DAST code analysis into the sprints, and ran a security war room alongside the NOC during peak weeks.
RESULT
Two consecutive Black Fridays without a significant incident and fraud under target. "War mode" became a procedure: trained, boring, and predictable, exactly what a critical operation should be.

BRICK-AND-MORTAR RETAIL CHAINS

Four hundred stores, one security standard

CHALLENGE
Aging POS terminals, heterogeneous store networks, and card data flowing through systems nobody documented anymore: the retail chain was, in practice, four hundred companies with four hundred levels of risk.
SOLUTION
We brought the chain to PCI DSS compliance with standardization across the store fleet, segmented the payment network, centralized monitoring, and wrote a repeatable security playbook for every new store opening.
RESULT
PCI certification achieved and sustained for three consecutive cycles. Opening a new store actually got faster: the playbook made security part of the expansion instead of an obstacle to it.

LOGISTICS OPERATORS

The gang knew every shipment's schedule. We found out how.

CHALLENGE
Cargo thefts far too surgical to be luck: the gang knew route, timing, and contents. Suspicion of an inside leak hung over the operation, and nobody knew where to start.
SOLUTION
Our digital forensic investigation identified compromised TMS credentials being sold. We then overhauled access management, set up anomaly monitoring on cargo queries, and ran an awareness program with phishing simulations.
RESULT
The leak channel closed and the pattern of surgical thefts stopped in the months that followed. The case, properly documented, held up in court and changed for good how the company treats credentials.

MOBILITY AND FLEET MANAGEMENT

Telemetry from thousands of vehicles, privacy for thousands of drivers

CHALLENGE
The fleet management platform collected location, behavior, and working-hours data from thousands of drivers. A union challenge over monitoring set off the alarm: the data was a labor liability and an LGPD liability at the same time.
SOLUTION
We reviewed the legal bases and the transparency of monitoring, minimized the data collected, pentested the platform and telemetry APIs, and wrote clear access and retention policies.
RESULT
A privacy program defensible on both fronts, regulatory and labor. The company answered the union challenge with documentation, and transparency became a contract clause with the platform's clients.

SCHOOL NETWORKS

Children's data: the most sensitive asset a school holds

CHALLENGE
With ANPD prioritizing children's and adolescents' data, the school network took a hard look at its systems (enrollment, academics, school health, photos) and realized it was guarding one of the most sensitive data collections there is.
SOLUTION
We mapped all student data, aligned legal bases and consents, implemented role-based access controls, trained educators, and set up a data subject channel that answers families in plain language.
RESULT
Demonstrable compliance on LGPD's most scrutinized front. In the enrollment seasons that followed, the privacy policy became part of the presentation to families, and an edge over the school across town.

STATE-OWNED COMPANIES AND PUBLIC AGENCIES

Public services that keep running, even under attack

CHALLENGE
Brazilian public bodies remain among ransomware's favorite targets, and the agency knew it could be next in line. Systems essential to citizens ran without a tested continuity plan.
SOLUTION
We ran a maturity assessment aligned with government frameworks, built a continuity plan for essential services, prioritized vulnerability management by social criticality, and trained the internal team.
RESULT
The five services most critical to citizens now have tested recovery plans. For the first time, the next administration inherited a security posture that is documented, auditable, and built to outlast the term.

AGRICULTURAL COOPERATIVES

The harvest doesn't wait for systems to restore from backup

CHALLENGE
At the peak of grain intake, a system failure took the cooperative down for six hours. No attacker was involved, yet the losses and the lines of trucks showed exactly how big the risk would be if someone had done it on purpose.
SOLUTION
We built an impact analysis around the agricultural calendar, a continuity plan prioritizing weighing, grading, and dispatch, and tested immutable backups, with crisis simulations scheduled for the off-season.
RESULT
In planning the next harvest, operational continuity joined weather and exchange rates on the cooperative board's agenda. The most recent recovery test brought critical systems back in 40 minutes.

LAW FIRMS

Attorney-client privilege in the age of the data leak

CHALLENGE
The firm handled billion-dollar M&A deals and realized the confidentiality guaranteed by professional ethics wasn't guaranteed by its infrastructure. A leak wouldn't cost just one client. It would cost the firm.
SOLUTION
We ran a confidentiality-focused health check, protected case repositories with matter-based access, pentested the client portal, and delivered anti-phishing training designed for lawyers, the favorite targets of spear-phishing fraud.
RESULT
In the due diligence reviews where international clients assess the firm, security is no longer a caveat. The managing partner puts it simply: "privilege is now a promise our technology can actually keep."

BPO AND CALL CENTERS

Thousands of agents, millions of records, zero tolerance for leaks

CHALLENGE
Running customer service for banks and retailers, the BPO handled data on millions of consumers and faced client audits growing ever tougher on access, call recordings, and internal fraud prevention.
SOLUTION
We implemented access controls and monitoring across agent workstations, prevented card data capture in recordings (PCI-aligned), ran a continuous awareness program, and built per-operation audit trails.
RESULT
The BPO passed the audits of its five largest clients in the same year. The security pipeline became an RFP argument, and the company started winning contracts by citing exactly what used to disqualify it.

CONSTRUCTION AND REAL ESTATE DEVELOPMENT

The email that almost paid R$ 2 million to the wrong supplier

CHALLENGE
A flawless email, with the right contract attached and the bank details swapped, nearly led the developer's finance team to wire millions to a fraudster. Luck stopped the scam: an employee thought the timing felt off.
SOLUTION
We ran incident response with forensics on the email compromise, rolled out DMARC and strong authentication, installed a dual-verification process for any change to bank details, and ran CEO fraud simulations with every team that moves money.
RESULT
In the following year's simulations, no fraudulent transfer got past the first control. Dual verification stopped two real attempts, now retold at onboarding as war stories.

PROPERTY MANAGEMENT

The fake invoice scam that stopped working on this portfolio

CHALLENGE
Managing thousands of lease and condominium contracts, the company watched fake payment slip scams against tenants keep climbing. Every fraud eroded the trust the business runs on, even through no fault of its own. And its records held income data, guarantees, and documents for thousands of families.
SOLUTION
We authenticated email and the billing pipeline (DMARC), created official verified channels for invoice reissue, pentested the tenant portal and app, and aligned the data lifecycle of tenants, guarantors, and residents with LGPD.
RESULT
Fraudulent invoices stopped passing as the company's: the next attempts failed at delivery. Partner real estate agencies received the anti-fraud communication kit and began referring the firm citing exactly that.

TOURISM AND HOSPITALITY

Guests entrust their card, their passport, and their sleep. The chain protects all three.

CHALLENGE
Between online bookings, a PMS integrated with OTAs, and card data at every front desk, the hotel chain had amassed data on millions of guests, across a systems estate that had grown without a security owner.
SOLUTION
We brought the payment flow to PCI DSS compliance, applied LGPD across the guest data lifecycle, pentested the OTA integrations, and trained front-desk staff against social engineering.
RESULT
Payment certification stays current, and the international franchisor approved the privacy program without reservations. That approval unlocked the brand for two new hotels.

MEDIA AND CONTENT PRODUCTION

The TPN assessment that opened the doors of the major studios

CHALLENGE
To produce content for global studios, the production company needed the Trusted Partner Network (TPN) assessment, the security standard of the film and TV industry. Without it, the scripts and masters simply never arrive.
SOLUTION
We prepared the company for the TPN assessment end to end: security across production and post environments, project isolation, physical and digital media controls, and compliance with the specific requirements of the MPA standard.
RESULT
TPN assessment completed, with contracts from two international studios following soon after. Pre-release content now moves through an environment the IP owner audits and approves.

NONPROFIT SECTOR

Data protection for the people who protect people

CHALLENGE
The foundation served vulnerable populations, and its records held stories that could never leak. It had an NGO's budget and a bank's responsibility.
SOLUTION
We built an essential security program sized for the nonprofit sector: protection of beneficiary records, access controls, secure backup, training for staff and volunteers, and proportionate LGPD compliance.
RESULT
The most sensitive data got the strongest protection, at a cost that fit the budget. Two international funders cited data governance in their grant renewals. One of them increased the funding.

HOLDINGS AND BUSINESS GROUPS

Seven companies, one family, one standard of IT and AI governance

CHALLENGE
The family group spanned seven operations in different industries, each with its own IT, its own risks, and its own appetite for AI. The patriarch asked the question the whole estate hinged on: who answers for the security of the entire group?
SOLUTION
We delivered corporate CISO as a Service with a holding-level view: a single security and AI-use policy, a minimum control baseline per company, a quarterly cyber risk committee with the boards, and AI Risk Assessments at the two operations already using AI in business decisions.
RESULT
For the first time, the holding's board sees the technology risk of all seven companies on a single dashboard: comparable, prioritized, and with a plan. The patriarch's question now has a name, a cadence, and a metric.

Your industry is here. Your story isn't, yet.

Bring your challenge to a DM11 specialist. The conversation is direct, technical, and commitment-free. And the discretion, as you've seen, is taken seriously.

Talk to a specialistRequest an assessment