Cybersecurity risks, DevSecOps challenges, and emerging security priorities: An empirical study across Brazilian organizations
Edna Dias Canedo, Stefano Luppi Spósito, Laerte Peotta de Melo, Rafael Rabelo Nunes, Marcelo Ladeira · Computers & Security · 2026
Context: Cybersecurity has become increasingly intertwined with organizational resilience, digital transformation, and regulatory pressure. Yet, many institutions still struggle to assess their structural risks, integrate secure-by-design practices, and prepare for emerging technologies such as AI-enabled cyber operations. Goal: This study aims to examine how Brazilian organizations perceive their cybersecurity posture across three dimensions: (i) infrastructure and governance risks, (ii) secure software development and DevSecOps challenges, and (iii) strategic priorities for emerging cybersecurity research and innovation. Method: We conducted a mixed-method survey with 88 practitioners from public, private, and critical infrastructure sectors. The instrument combined Likert scale assessments, multiple choice questions, and open-ended items. Quantitative data were analyzed using descriptive statistics, and qualitative responses were examined using inductive coding and thematic analysis. Results: Organizations report structural vulnerabilities linked to supply-chain dependencies, legacy systems, governance gaps, insider threats, and insufficient patch and vulnerability management. Challenges in secure development center on data exposure, limited security culture and training, insufficient security automation within Continuous Integration and Continuous Deployment (CI/CD) pipelines, and fragmented compliance integration. Emerging priorities include adversarial machine learning, AI security, cloud and hybrid architecture protection, cyber resilience, Governance, Risk, and Compliance (GRC) modernization, and Zero Trust adoption. Conclusion: Findings reveal systemic cybersecurity weaknesses and uneven DevSecOps maturity across sectors, underscoring the need for stronger governance, continuous workforce development, and resilience oriented security architectures. The study also identifies strategic research directions particularly in AI security, supply-chain defense, and cloud resilience that can guide national cybersecurity capacity building and policy making initiatives. This study also provides an evidence-based foundation to guide capability building programs, governance modernization, and future research collaborations across the Brazilian cybersecurity ecosystem.