Skip to content

Security your team actually adopts

Hoefel Security builds risk-based security governance programmes and prepares the people who will sustain them. From policy to practice.

people trained
2,500+
security policies authored
30+
secure-dev adoption
20→70%

01 · What we do

Most companies don’t fail for lack of policy. They fail because policy never becomes behaviour

We work side by side with technology companies to analyse, plan and implement security around the risks of each client’s business model. There is no fixed package: what we deliver depends on what is actually at stake for your operation.

We write the policy, build the control and train the people. Governance, engineering and human behaviour belong in the same stream of work.

Training follows the same principle. Each team learns to recognise threats like phishing and ransomware through examples from their own daily work, in plain language.

The result: employees who act as the first line of defence, and governance that auditors, clients and insurers accept.

Governance designed for adoption. Adoption sustained by training.

secure-development adoption at a national telecom operator, without mandate
20→70%
security policies authored across telecom, SaaS and integrator environments
30+
people trained, in person and online
2,500+
from zero to 19 policies, with secure delivery running, at a SaaS company
4 months

Founder’s career figures, verified 07/2026.

03 · How we work

Fixed scope, weekly status, delivery in your own tools

  1. 01

    Discovery call

    We understand your context, your risks and what is blocking the business.

  2. 02

    Scoped proposal

    Short, with fixed deliverables and a fixed price. No open-ended hours.

  3. 03

    Delivery

    Execution with weekly status notes and direct access to the consultant.

  4. 04

    Executive readout

    Results presented to leadership, with a complete handover.

  5. 05

    Optional retainer

    Continuity through vCISO or a continuous training programme.

04 · About

Eduardo Hoefel

Cybersecurity specialist with experience across Brazil, Europe and Japan, working at the intersection of technology, governance and risk management.

On the technical side, he has worked on secure software development, vulnerability management and integrating security into the development lifecycle. On the regulatory side, he produced compliance evidence for ISO 27001, RVIT, ICOFR and NIS2 inside a European telecom operator and advised a government ministry in Japan on the review of its national telecom security policy.

He believes security starts with people, and that the work is only done when policy becomes practice.

  • CISSP · Certified Information Systems Security Professional (ISC²)
  • MSc Cyber Security · Radboud University & TU Eindhoven (dual degree)
  • BSc Computer Science · PUCRS
  • Portuguese and English · remote worldwide, on-site in southern Brazil

05 · Contact

Get in touch

Use whichever channel suits you. We reply as soon as we can.

Start with a discovery call

Thirty minutes, no strings attached. We look at your context and point to the shortest path, even if it isn’t with us.

Book a call