Continuous penetration testing for LGPD and Banco Central programs

Threat emulation schedule with dates, sources, statuses, and a vulnerabilities list with severity and fix status.

LGPD article 46 obliges data processing agents to adopt technical and administrative security measures capable of protecting personal data, and the Banco Central framework sets cybersecurity policy and testing expectations for regulated institutions. Strike's continuous pentesting produces the technical evidence those programs ask for — real vulnerabilities, validated by experts, with reports that support audit and compliance programs. Sources and access dates below.

For DPOs and security leaders answering to BACEN

DPOs and privacy leaders who must show LGPD article 46 security measures are real, tested, and backed by evidence — not just written into policy.

Security and compliance teams at regulated Brazilian institutions building cybersecurity programs that support Banco Central and CMN expectations.

Risk and audit leaders who need continuous, documented validation they can put in front of regulators, auditors, and the board with confidence.

User interface with sections titled 'Strikers assigned' showing two profile pictures and their details, and an 'Export' panel with options to include Findings Summary, Assessment Updates, and Compliance Checklist, with a Download button.
[ LGPD & BACEN ]

What the rules ask for — and how a pentest answers

The LGPD and the Banco Central point to the same practice: test your systems continuously and prove the controls work. Continuous pentesting turns that into evidence that supports audit and compliance programs — real vulnerabilities, validated by experts, documented for your DPO, auditors and regulators.

LGPD (Art. 46): the Lei Geral de Proteção de Dados requires organizations to adopt technical and administrative measures that protect personal data from unauthorized access and incidents. Continuous pentesting validates those measures as your systems change and documents evidence for the ANPD.

Banco Central and CMN: Resolution CMN 4.893/2021, as amended by Resolution CMN 5.274/2025, sets cybersecurity policy expectations for supervised institutions, covering independent penetration testing, vulnerability management and incident response. Strike's continuous testing supports and strengthens that policy. See the sources below.

A pentest is not a compliance seal. It is the core technical evidence of a security program — proof that controls actually work. Strike does not certify compliance; it gives your auditors, DPO and regulators validated findings, remediation guidance and retest results.

Program requirement
What the auditor or regulator expects
How Strike supports it
Periodic security testing
Regular, independent penetration tests
Continuous testing, with retest results according to the subscribed scope
Vulnerability management
Identify, prioritize and remediate vulnerabilities
Validated findings with severity and remediation guidance
Documented evidence
Reports auditors and regulators can review
Reports that support audit programs, updated continuously
Incident prevention
Reduce the risk of breaches and data leaks
Real exploitation caught and fixed before attackers
Personal data protection (LGPD)
Technical measures that protect personal data
Testing of the systems and APIs that handle personal data
Continuity under change
Security kept current as systems evolve
Testing that runs as you ship, exposure window in days
[ FAQ ]

Pentest for LGPD and BACEN, answered

Does the LGPD require a pentest?

The LGPD does not mandate a specific test, but Art. 46 requires appropriate security measures to protect personal data. Continuous penetration testing is a recognized way to validate those measures and to produce evidence that controls work if the ANPD or an auditor asks.

What does the Banco Central expect regarding penetration testing?

Resolution CMN 4.893/2021, as amended by Resolution CMN 5.274/2025, sets out cybersecurity policy and testing expectations for institutions supervised by the Banco Central do Brasil, including independent penetration testing, vulnerability management and incident response. Strike's continuous testing and reporting support those programs. See the sources and access dates below, and confirm the current obligations that apply to your institution with your own legal or compliance counsel.

Sources, accessed 29 July 2026. LGPD: Lei nº 13.709/2018, art. 46 (Planalto). Banco Central do Brasil, CMN cybersecurity rules: Resolution CMN 4.893, of 26 February 2021, as amended by Resolution CMN 5.274, of 18 December 2025. For payment institutions: Resolution BCB 85, of 8 April 2021, as amended by Resolution BCB 538, of 18 December 2025, and by Resolution BCB 552, of 3 March 2026. This page summarises publicly available regulation and is not legal advice; confirm the obligations applicable to your institution with your own counsel.

Does a Strike pentest work as audit evidence?

Yes. You get validated findings with proof of exploitation, clear remediation guidance, retest results according to the subscribed scope, and reports that support audit and compliance programs, which you can share with auditors, your DPO and regulators.

How often should we test for LGPD and Banco Central programs?

Resolution CMN 5.274/2025 brought intrusion testing explicitly into the framework of Resolution CMN 4.893/2021, alongside vulnerability management and incident response. Continuous testing is the stronger option: it validates security after every significant change and keeps your exposure window in days instead of months, with evidence that stays current.

What role does Strike play for LGPD and BACEN?

Strike does not certify compliance. Strike provides continuous testing with expert human validation and the documented evidence your auditors, DPO and regulators need to demonstrate that controls work.

How much does a pentest cost, and how is it contracted?

Strike works as a continuous subscription scoped to your attack surface rather than a one-off project, so cost follows scope. Onboarding is quick — connect your scope — so you can produce validated findings and evidence that supports audit programs before a deadline, and keep it current with continuous testing.

Boost your experience with Hybrid Testing Booster

Continuous Hybrid Testing

Emulated, deep stealth-based attacks executed by creative, unconventional security experts. Find out how real attackers would breach your systems, and stop them before they do.

Testimonial

Trusted by security teams that lead

"Product was great! The team was exceptional when addressing our sense of urgency with regards to an important timeline, and they were able to deliver effectively and finding important vulnerabilities within our systems."

Head of Engineering
Banking · Gartner Peer Insights review

"Good option for agile testing, especially if GTM timelines are tight. This is especially important when the release train comes with a lot of new products and releases, making it hard to keep the pace in a traditional ad-hoc business model."

Product Security Leader, Cybersecurity
Hardware · Gartner Peer Insights review

“Strike provides continuous pentesting for our critical web and mobile features. Each month they help us validate new functionalities in production, delivering relevant vulnerabilities and strong value for money. We are very satisfied with their innovative and customer-centric approach.”

Chief Information Security Officer
Retail · Gartner Peer Insights review

"Strike team was fast and provided the exact solution we needed for our use case. We decided to go for Strike because they provide a pen-testing suite that fits the way we work in terms of speed and communication. Highly recommended!"

Gartner review
Chief Technical Officer
Banking · Gartner Peer Insights review

"We greatly value our partnership with Strike. Their exceptional penetration testing services and effective communication have significantly enhanced our cybersecurity, ensuring the safety and trust of our customers' financial information."

Information Security Officer
Strike customer

"The management of communication channels and the centralization of interactions with the team made the experience much more agile and effective. Having everything in one place was a huge advantage and allowed us to complete the pentest within just a few weeks."

CTO
Horizon

“Working with Strike is extremely important to us, especially because they deliver quality work over our products in a continuous way, and provide constant follow-up when it comes to managing the already found vulnerabilities. Moreover, they are constantly making improvements in their SaaS platform so we can have the best experience possible. In case we have a problem, they listen and help us. That’s invaluable.”

Sr AppSec Red Team
NaranjaX

“Working with Strike was an excellent experience for us. We were able to create our own pentests and change their scope each month. The Strikers are world-class professionals who provide us with relevant findings quickly and efficiently. Also, automated tools like Phishing Monitor are really interesting for our company, because they help us spot fake domains trying to impersonate our brand.”

CISO
Strike customer

“For us, security is the most important aspect, not only on the surface but throughout our entire product. When we reached out to Strike, we were looking for someone that could test & find vulnerabilities across our entire stack. We are very happy that we have found the right partner to achieve that, and we are looking forward to continuing this important work together.”

CEO & CTO
Strike customer

Human expertise.
AI power.
Superior security.

Whether you’re scaling fast, closing enterprise deals, or just tired of noisy reports, we’ll help you build a security stack that moves faster than your threats.

Book a Demo