Security your team actually adopts
Hoefel Security builds risk-based security governance programmes and prepares the people who will sustain them. From policy to practice.
- people trained
- 2,500+
- security policies authored
- 30+
- secure-dev adoption
- 20→70%
01 · What we do
Most companies don’t fail for lack of policy. They fail because policy never becomes behaviour
We work side by side with technology companies to analyse, plan and implement security around the risks of each client’s business model. There is no fixed package: what we deliver depends on what is actually at stake for your operation.
We write the policy, build the control and train the people. Governance, engineering and human behaviour belong in the same stream of work.
Training follows the same principle. Each team learns to recognise threats like phishing and ransomware through examples from their own daily work, in plain language.
The result: employees who act as the first line of defence, and governance that auditors, clients and insurers accept.
Governance designed for adoption. Adoption sustained by training.
- secure-development adoption at a national telecom operator, without mandate
- 20→70%
- security policies authored across telecom, SaaS and integrator environments
- 30+
- people trained, in person and online
- 2,500+
- from zero to 19 policies, with secure delivery running, at a SaaS company
- 4 months
Founder’s career figures, verified 07/2026.
02 · Services
Five service lines, one promise: security that sustains itself
From assessment to ongoing leadership. Each line solves a concrete problem and lays the ground for the next.
Governance & Compliance (GRC)
A governance foundation your clients, auditors and insurers accept
Learn more →Security Awareness & Training
Security behaviour that shows up in the metrics
Learn more →Secure Development
A product that passes enterprise security review
Learn more →vCISO · Security Leadership
A CISO's judgement without a CISO's payroll
Learn more →Regulatory Consulting
Regulation translated into workable implementation
Learn more →
03 · How we work
Fixed scope, weekly status, delivery in your own tools
- 01
Discovery call
We understand your context, your risks and what is blocking the business.
- 02
Scoped proposal
Short, with fixed deliverables and a fixed price. No open-ended hours.
- 03
Delivery
Execution with weekly status notes and direct access to the consultant.
- 04
Executive readout
Results presented to leadership, with a complete handover.
- 05
Optional retainer
Continuity through vCISO or a continuous training programme.
04 · About
Eduardo Hoefel
Cybersecurity specialist with experience across Brazil, Europe and Japan, working at the intersection of technology, governance and risk management.
On the technical side, he has worked on secure software development, vulnerability management and integrating security into the development lifecycle. On the regulatory side, he produced compliance evidence for ISO 27001, RVIT, ICOFR and NIS2 inside a European telecom operator and advised a government ministry in Japan on the review of its national telecom security policy.
He believes security starts with people, and that the work is only done when policy becomes practice.
- CISSP · Certified Information Systems Security Professional (ISC²)
- MSc Cyber Security · Radboud University & TU Eindhoven (dual degree)
- BSc Computer Science · PUCRS
- Portuguese and English · remote worldwide, on-site in southern Brazil
05 · Contact
Get in touch
Use whichever channel suits you. We reply as soon as we can.
Start with a discovery call
Thirty minutes, no strings attached. We look at your context and point to the shortest path, even if it isn’t with us.
Book a call