Blog

Articles on Compliance

What we publish on Compliance for CISOs, IT and compliance teams in LATAM.

Articles on how an awareness program turns into compliance evidence: PCI DSS 12.6, ISO/IEC 27001 (control A.6.3), LGPD and local AML/CFT rules. We cover what each standard asks for on phishing and training, what record format an external auditor expects, and why "we ran a course" isn't a sufficient answer. If your compliance team needs to show annual review, coverage by role and exportable evidence, this category collects the concrete cases: what each standard controls, what auditors ask, and how the report gets built without a manual spreadsheet.

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)
PCI DSS, audit
Apr 2, 2026By Federico Hombre

PCI DSS 12.6: what the auditor wants to see (and what an annual course doesn't prove)

The requirement asks for a formal awareness program that includes phishing and social engineering. The evidence isn't a screenshot.

Read more

Want to see this in your organization?

Book a demo. We will look at how to measure human risk in your team and what to change first.

Book a demo