IBLISS Digital Security
IBLISS Digital Security is a Brazilian cybersecurity consultancy founded in 2009, serving 500+ organizations including Fortune 500 firms with multidisciplinary services spanning penetration testing, managed security, compliance, AppSec/DevSecOps, and security awareness across Brazil.
- Company typePrivate
- Founded2009
- HeadquartersBela Vista, Brazil
- Headcount51–100
- GTM typeB2B
- OfferingServices
What IBLISS Digital Security does
IBLISS Digital Security (legal name: IBLISS Segurança Digital LTDA.) is a Brazilian cybersecurity consultancy founded in 2009 and headquartered in São Paulo (Bela Vista). The firm delivers multidisciplinary cybersecurity services across six pillars — cybersecurity consulting, penetration testing (Pentest), security awareness and culture, compliance and governance, managed security services (MSS), and AppSec & DevSecOps — supplemented by proprietary methodologies such as the Security Essentials 360° diagnostic and a dedicated HaaS (Hacker as a Service) offensive security team. The technology stack integrates partner platforms (Tenable, Veracode, Imperva, KnowBe4, Vicarius) with internally developed open-source tools (WebDiscover, Octopus) and the spun-off GAT (Get Ahead of Threats) vulnerability management platform, now operating independently at gat.digital.
The company serves a broad base of more than 500 organizations across financial services, government, healthcare, insurance, retail/e-commerce, technology, and SMBs, including Fortune 500 firms and Brazilian majors such as SulAmerica Seguros and Bradesco Seguros (referenced in joint LGPD events). IBLISS is ISO/IEC 27001:2013 certified, recognized as a top Brazilian Information Security consultant by ISG Lens for two consecutive years, and a Great Place to Work for four consecutive years. Go-to-market combines direct enterprise sales (led by CRO Guilherme Serra and Head of Customer Success Alexandre Trentini) with strategic channel partnerships — notably IT-ONE (digital transformation, jointly serving 1,000+ clients) and INVIRON (digital media) — and content-led demand generation through its Minuto Proteção blog, e-books, vulnerability bulletins, and webinars.
Revenue is generated through project-based professional services engagements (consulting, pentest, compliance), recurring managed security services (MSS, PtaaS, vulnerability remediation, WAF/API protection, Security Champion), subscription-style awareness and culture programs, and the spun-off GAT platform. The business remains privately held under founder and CEO Leonardo Militelli, with the September 2024 appointment of a CRO and Business Executive signaling a transition toward more formalized, CTEM-focused (Continuous Threat Exposure Management) go-to-market.
IBLISS Digital Security firmographics
Firmographics- Name
- IBLISS Digital Security
- Legal name
- IBLISS SEGURANÇA DIGITAL LTDA.
- Website
- https://ibliss.com.br
- Company type
- Private
- Founded year
- 2009
- Operating status
- Operating
- Headcount range
- 51–100 employees
- Short description
- IBLISS Digital Security is a Brazilian cybersecurity consultancy founded in 2009, serving 500+ organizations including Fortune 500 firms with multidisciplinary services spanning penetration testing, managed security, compliance, AppSec/DevSecOps, and security awareness across Brazil.
- Ownership category
- akta.pro rank
IBLISS Digital Security industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621), Computer Systems Design and Related Services (54151), Custom Computer Programming Services (541511)
- SIC
- Services-Detective, Guard & Armored Car Services (7381), Services-Computer Programming Services (7371)
- akta.pro primary industry
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG)
- akta.pro secondary industries
- Vulnerability Management & Penetration Testing Services (BPAEADAD), Cybersecurity & Identity Consulting (BPAHAEAG)
Keywords
Where IBLISS Digital Security is headquartered
LocationHeadquarters
- HQ city
- Bela Vista
- HQ country
- Brazil
- HQ region
- Latin America
Offices1 record
Markets served
IBLISS Digital Security business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Cybersecurity Consulting Services: Professional services across cybersecurity consulting, penetration testing (Blackbox/Greybox/Whitebox, Network, Cloud, Mobile, Web & API pentests), AppSec & DevSecOps, and compliance/governance advisory. Sold as project-based engagements to enterprise and mid-market clients.
- Managed Security Services (MSS): Recurring continuous service programs covering vulnerability management and patches, PtaS, baseline definition and management, Security Champion, vulnerability remediation, WAF and API protection. Proposed as ongoing outsourced security operations.
- Security Awareness & Culture Programs: Subscription-style awareness and training programs for end-user behavior change including workshops, anti-phishing campaigns, quizzes and educational videos, delivered as ongoing programs.
- GAT Platform (Spun Off): Vulnerability and threat management platform that originated inside IBLISS consulting and was spun off as a separate product, now operating under gat.digital. Likely sold via subscription or licensing model to enterprises.
Go-to-market motion3 records
Distribution channels5 records
Marketing channels10 records
IBLISS Digital Security product offering
Product offeringCore offering
IBLISS Digital Security provides multidisciplinary cybersecurity services for Brazilian organizations, organized into six pillars: strategic consulting, penetration testing, security awareness and culture, compliance and governance, managed security services (MSS), and AppSec/DevSecOps. The company delivers bespoke consulting engagements, continuous offensive security testing, regulatory gap analysis (LGPD, BACEN, PCI-DSS, ISO 27001), and outsourced security operations, leveraging its proprietary GAT (Get Ahead of Threats) vulnerability management platform and Security Essentials 360° diagnostic methodology.
Product overview
IBLISS Digital Security delivers a multi-disciplinary cybersecurity services portfolio organized into six core pillars — Consultoria em Cibersegurança, Teste de Intrusão (Pentest), Conscientização & Cultura, Compliance & Governança, Serviços Gerenciados (MSS), and AppSec & DevSecOps — supported by specialized offerings such as the Security Essentials 360° maturity assessment, the HaaS (Hacker as a Service) offensive security team, and the spun-off GAT vulnerability management platform. The Servicos Gerenciados bundle includes sub-modules such as Gestão de Vulnerabilidades e Patches, PtaaS (Pentest as a Service), Definição e Gestão de Baseline, Security Champion, Correção de Vulnerabilidades (built on Vicarius), and WAF e Proteção API (built on Imperva); the AppSec & DevSecOps pillar contains SAST/DAST analysis and ASVS security reviews; and the consultancy is reinforced by internally developed tools like WebDiscover and Octopus as well as the Sec4Kids awareness program for children. The architecture is service-led rather than a single SaaS product, but IBLISS integrates partner technologies (Tenable, Vicarius, Veracode, KnowBe4, Imperva, and its own GAT platform) and is ISO/IEC 27001:2013 certified.
Differentiator
Problem solved
Functional benefit
Brands
- GAT – Get Ahead of Threats: Vulnerability and threat management platform originated inside IBLISS and later spun off as a separate platform/company focused on Continuous Threat Exposure Management (CTEM).
Products and services
- Consultoria em Cibersegurança Strategic cybersecurity consulting providing intelligence for prevention, identification, and detection of risks and incidents, including computer forensic analysis, threat analysis, risk assessments, and penetration testing. Targeted at enterprise and mid-market clients in Brazil.
- Teste de Intrusão (Pentest) Penetration testing service delivered across Network, Cloud, Mobile, and Web/API modalities and Blackbox, Greybox, and Whitebox engagement approaches. Includes more than 10,000 testing hours per year, including the dedicated HaaS offensive security team.
- Conscientização & Cultura Security awareness and culture program sensitizing and engaging employees on information security and privacy, including workshops, anti-phishing simulations, educational quizzes and videos. Targeted at enterprises seeking to reduce human-factor security incidents.
- Compliance & Governança Compliance and governance advisory covering PCI-DSS, GDPR, ISO, NIST, LGPD, BACEN, CIS Controls, CONATRAN, and OWASP SAMM, including gap analysis, supplier evaluation, process definition, pre-audit for certification, and CISO/DPO support. For regulated Brazilian organizations.
- Serviços Gerenciados (MSS) Managed security services program providing continuous, proactive visibility of risks and threats, including vulnerability and patch management, PtaaS (Pentest as a Service), secure baseline definition, Security Champion program, vulnerability remediation (via Vicarius vRx), and WAF/API protection (via Imperva). Sold as outsourced recurring engagements.
- AppSec & DevSecOps Application security practice establishing best practices across the software development lifecycle, including SAST and DAST analysis and ASVS (Application Security Verification Standard) security reviews. For technology providers, startups, and enterprises building software products.
- Security Essentials 360° 360-degree maturity assessment that maps information security and privacy posture across people, processes, and technology pillars to identify gaps and inform an investment plan for a security program. For organizations beginning or refreshing a security program.
- GAT – Get Ahead of Threats Vulnerability and threat management platform providing integrated lifecycle management of vulnerabilities across the IT environment and an IBLISS Security Score; spun off from IBLISS and now commercialized via gat.digital.
- HaaS (Hacker as a Service) Specialized offensive security team delivering continuous penetration testing, red-team activities, exploit research, and open-source security tool development for Brazilian enterprises requiring deep offensive expertise.
Quantifiable outcome
- More than 10,000 hours of security testing per year delivered through HaaS team
- +4 more outcomes
Companies that use IBLISS Digital Security
Customer profileNamed customers5 records
Segments7 records
Ideal customer profiles4 records
IBLISS Digital Security technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration7 records
Feature6 records
IBLISS Digital Security partnerships and signals
Strategic signalPartnerships
Ten partnerships are on record, tiered moderate, flagship, core and minor.
- INVIRONmoderatePartnership announced on May 30, 2022, with INVIRON to enhance security criteria and requirements applicable to INVIRON's digital media publishing network. IBLISS brings 13+ years of information security and privacy expertise, ISO 27001:2013 certified.
- IT-ONEflagshipStrategic partnership announced in May 2022 to combine IT-ONE's digital transformation expertise with IBLISS's cybersecurity capabilities; combined client base exceeds 1,000 across Brazil. Initial offerings include Vulnerability Assessment, Gap Analysis LGPD, and User Awareness programs.
- GAT Security (Get Ahead of Threats)flagshipGAT originated inside IBLISS as an integrated vulnerability and threat management platform and was spun off as a separate product. The partnership enables IBLISS to leverage the GAT platform in client engagements while GAT independently commercializes the technology; IBLISS + GAT Security Score is also offered as a joint asset on the website.
- TenablecoreTenable is one of IBLISS's technology partners (logo displayed in the partners section). IBLISS and Tenable co-hosted a series of webinars on vulnerability prioritization for remote work, predictive prioritization, and other technical deep-dives, and jointly support vulnerability management programs for clients.
- ImpervacoreImperva is one of IBLISS's displayed technology partners, providing WAF and API protection capabilities that IBLISS offers to clients through its managed services and application security portfolio.
- KnowBe4coreKnowBe4 is featured as a strategic technology partner of IBLISS, supporting the company's security awareness and culture programs with phishing simulation and training capabilities.
- VeracodecoreVeracode is displayed as a technology partner, supporting IBLISS's AppSec & DevSecOps offerings with application security testing capabilities (SAST/DAST).
- VicariuscoreVicarius is a strategic partner of IBLISS, recognized by IDC as a leader in preemptive exposure management. The partnership enables IBLISS to deliver vulnerability remediation and preemptive exposure solutions to clients.
- Fundação AbrinqmoderateInstitutional partnership where IBLISS secures Fundação Abrinq's digital environment and Fundação Abrinq helps promote the SEC4KIDS social responsibility project. The collaboration combines cybersecurity protection with social impact focused on children and adolescents' internet safety.
- IBMminorIBM is referenced as a source for cybersecurity frameworks (NIST Cybersecurity Framework) and IBM Cost of a Data Breach Report that IBLISS cites in thought-leadership content; not a commercial partnership but a content reference.
Scale indicators10 records
Recent moves8 records
Expansion highlights5 records
IBLISS Digital Security competitors and assessment
Company assessmentBroad incumbents
- Mandiant (Google Cloud): Global incident response, threat intelligence, and cybersecurity consulting firm — comparable to IBLISS in offensive security and consulting capabilities, but serving a global enterprise customer base with substantially more resources.
- Secureworks: Global MSSP and security consulting provider offering managed detection, vulnerability management, and advisory services — comparable to IBLISS in MSS and consulting positioning, but at much larger scale and global reach.
- Trustwave: Global cybersecurity company offering MSS, consulting, penetration testing, and compliance services to enterprises — comparable to IBLISS in service portfolio, but operating globally with much larger headcount and managed services infrastructure.
- Stefanini Cybersecurity: Large Brazilian IT services group with a dedicated cybersecurity practice covering consulting, managed services, and compliance — a broad incumbent that competes with IBLISS on enterprise security engagements at significantly greater scale.
- Cipher (A Br company): Latin American cybersecurity consultancy (part of the Stefanini/A Br ecosystem) offering managed security, consulting, and offensive security to large enterprises across Brazil — comparable to IBLISS in services portfolio but operating at a larger scale with broader geographic reach.
- Logicalis Brasil (Security Practice): Global IT solutions and managed services provider with a Brazilian security practice spanning consulting, MSS, and compliance — comparable to IBLISS in services and customer base, but as part of a much larger multinational portfolio.
Direct peers
- Morphus (Sec4Way Group): Brazilian cybersecurity specialist focused on pentesting, red team, threat intelligence, and managed detection & response — comparable to IBLISS in offensive-security expertise and Brazilian enterprise/government customer profile.
- Clavis Segurança da Informação: Brazilian cybersecurity firm delivering consulting, vulnerability management, managed security, and compliance services to enterprise and government clients — closely comparable to IBLISS across service lines, certifications, and Brazilian enterprise customer base.
- Tempest Security Intelligence: Brazilian cybersecurity consultancy offering offensive security (pentesting, red team), managed detection, and security consulting to large enterprises — directly comparable to IBLISS in services portfolio, target customer (Fortune 500/large Brazilian corporates), and Brazilian market focus.
- H4rdw0rk: Brazilian offensive-security boutique delivering penetration testing, red team, and AppSec services to enterprise clients — a directly comparable niche peer to IBLISS's HaaS and pentest practices within the Brazilian market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
IBLISS Digital Security social profiles
Digital presenceIBLISS Digital Security compliance and trust
Trust signalCompliance3 records
IBLISS Digital Security financial estimates
Financial estimateRevenue estimate
Valuation estimate
IBLISS Digital Security leadership team
Management profileNumber of profiles
Profiles8 records
IBLISS Digital Security subsidiaries and ownership
Company hierarchySubsidiaries1 record
IBLISS Digital Security funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
IBLISS Digital Security M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about IBLISS Digital Security
What does IBLISS Digital Security do?
IBLISS Digital Security provides multidisciplinary cybersecurity services for Brazilian organizations, organized into six pillars: strategic consulting, penetration testing, security awareness and culture, compliance and governance, managed security services (MSS), and AppSec/DevSecOps. The company delivers bespoke consulting engagements, continuous offensive security testing, regulatory gap analysis (LGPD, BACEN, PCI-DSS, ISO 27001), and outsourced security operations, leveraging its proprietary GAT (Get Ahead of Threats) vulnerability management platform and Security Essentials 360° diagnostic methodology.
Is IBLISS Digital Security a public or private company?
IBLISS Digital Security is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was IBLISS Digital Security founded?
IBLISS Digital Security was founded in 2009. It employs 51 to 100 people.
Where is IBLISS Digital Security based?
IBLISS Digital Security is headquartered in Bela Vista, Brazil, in the Latin America region.
How does IBLISS Digital Security make money?
Four revenue lines are on record. Cybersecurity Consulting Services are the primary driver. The others are managed Security Services (MSS), security Awareness & Culture Programs and GAT Platform (Spun Off).
Who are IBLISS Digital Security's main competitors?
Broad incumbents on record are Mandiant (Google Cloud), Secureworks, Trustwave, Stefanini Cybersecurity, Cipher (A Br company) and Logicalis Brasil (Security Practice). Direct peers are Morphus (Sec4Way Group), Clavis Segurança da Informação, Tempest Security Intelligence and H4rdw0rk.
Does IBLISS Digital Security have an API?
No public API is recorded for IBLISS Digital Security.
What industry is IBLISS Digital Security in?
IBLISS Digital Security's product category is Cybersecurity Services. Its primary akta.pro industry code is BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing, with a secondary code of BPAEADAD, Vulnerability Management & Penetration Testing Services. Its NAICS code is 561621 and its SIC code is 7381.