



Internal ThreatAmeaça InternaInterne Bedrohung
The Computer Security Bible of the Interior
A Bíblia da Segurança Informática Interna
Die Bibel der Computersicherheit des Innenministeriums
Available in 3 languages
“O perímetro morreu. A confiança é a nova superfície de ataque. Comecemos.”
- Pages
- 729 pages
- ISBN
- ISBN 979-8181526044
- Published
- Formats
- Kindle and paperback
- Pages
- 745 pages
- ISBN
- ISBN 979-8181479180
- First published
- Formats
- Kindle and paperback
- Pages
- 825 pages
- ISBN
- ISBN 979-8192641217
- Published
- Formats
- Kindle and paperback
About the book
Text published with the English edition (Amazon).
I've worked in information security for over three decades. I started at a time when the discipline didn't even have that name: we called it "computer security," and it essentially boiled down to antivirus software, passwords, and a firewall at the network's edge. The enemy was out there—a curious teenager, an opportunistic criminal, later an organized group or a state. Our mission was clear: build the highest possible wall and guard the gate.
It took me years to accept what I now consider the most uncomfortable truth of my profession: most of the serious damage I witnessed throughout my career didn't come from the outside. It came from within. It came from people with badges, valid credentials, and photos on the intranet. It came from the disillusioned administrator who took the keys to the kingdom with him, from the exemplary employee who clicked on the wrong connection on a mundane Tuesday, from the trusted supplier whose credentials were stolen without anyone noticing, from the technical staff who patiently copied things they shouldn't have for months. None of them had to "go in"—they were already there.
Technical literature has been slow to keep pace with this reality. For years, insider threats were treated as a footnote: a short chapter at the end of manuals, a slide in annual training sessions, a line in the risk matrix to which no one allocated a budget. Meanwhile, the numbers accumulated in the opposite direction. The benchmark annual reports—the same ones that the reader will find cited, scrutinized, and contextualized throughout this work—show, with stubborn consistency, that incidents originating from or involving internal human activity are among the most expensive, the slowest to detect, and the most devastating to the trust of customers, regulators, and markets. The external attacker steals data; the internal one also steals the certainty that we can trust our own people and our own processes. This second theft is the most difficult to repair.
It is in this context that the book the reader now holds in their hands emerges—and I say, without reservation, that it fills a real void in the bibliography in the Portuguese language, and not only that.
I am well acquainted with the "cybersecurity manual" genre. There are excellent works on cryptography, networks, incident response, and compliance. What was practically nonexistent was a work that addressed the insider threat for what it is: a total problem that permeates technology, psychology, law, management, and organizational culture—and which, therefore, cannot be solved by any of these disciplines in isolation. Hermínio Cerqueira understood this and had the rare ambition to write the entire book: from the historical foundations to the technical architecture, from the insider's mind to the letter of the regulation, from the Snowden case to the automated response playbook, from the principle of least privilege to a documented policy ready for adaptation.
Three qualities of this work deserve highlighting.
The first is intellectual honesty. This is not a fear-mongering book, nor a product catalog disguised as doctrine. The author rejects sensationalism with the same firmness with which he rejects comfort. When the data is solid, he cites its source; when it is uncertain or disputed—and in our field many numbers circulate for years without anyone verifying their origin—he states so openly. In a discipline saturated with orphaned statistics and marketing disguised as research, this methodological discipline is invaluable...
Excerpt
Há mais de três décadas que me preocupo com a segurança da informação. Comecei numa época em que a disciplina nem sequer tinha esse nome: chamávamos-lhe «segurança informática» e ela resumia-se, no essencial, a antivírus, palavras-passe e uma firewall na fronteira da rede. O inimigo estava lá fora — era um adolescente curioso, um criminoso oportunista, mais tarde um grupo organizado ou um Estado. A nossa missão era clara: construir o muro mais alto possível e vigiar o portão.
Demorei anos a aceitar aquilo que hoje considero a verdade mais incómoda da minha profissão: a maioria dos danos graves que testemunhei ao longo da carreira não veio de fora. Veio de dentro.
— Ameaça Interna
Original text in Portuguese.
Editorial note
Source: publisher’s description of the Portuguese edition (Amazon).
Index of editions
English edition:
Internal Threat
729 pagesKindle and paperback
Portuguese edition:
Ameaça Interna
745 pagesKindle and paperback
German edition:
Interne Bedrohung
825 pagesKindle and paperback
- In the Amazon stores, each link uses the edition’s own code (ASIN); availability in each country is managed by Amazon.
- In Portugal, buy from Amazon Spain: there is no Portuguese Amazon store.
Critical reading — “A Obra Comentada” (2026)
Original text in Portuguese.
Depois de três livros a olhar para o adversário externo, Ameaça Interna executa o gesto que o próprio texto descreve como «o mais difícil e mais necessário da disciplina: virar o olhar para dentro». A tese cabe numa frase que o autor destaca: «num mundo sem perímetro, a confiança não verificada é a superfície de ataque mais extensa de qualquer organização — e a gestão dessa confiança é a disciplina central da segurança moderna». O subtítulo expandido — "De Edward Snowden ao Zero Trust" — anuncia o arco: do administrador de sistemas que exfiltrou da NSA cerca de 1,5 milhões de documentos sem quebrar uma única firewall, até à arquitectura que abandona a presunção de confiança pela máxima nunca confiar, verificar sempre.
A estrutura, em oito partes e vinte e seis capítulos, segue um movimento declarado — compreender, localizar, detectar, prevenir, gerir, aprender, antecipar, agir — que faz da obra simultaneamente tratado e manual: dos fundamentos históricos e da psicologia do insider (motivações, burnout, liderança tóxica, a saída mal gerida) à arquitectura técnica (identidade, UEBA, SIEM/SOAR, forense interna), da governação e do enquadramento jurídico-laboral europeu aos casos históricos (Snowden, Pelton, Manning, Target — a intrusão que entrou «pela porta dos fornecedores») e a um manual de acção final com checklists faseadas e modelo de política pronto a adaptar. O aparelho de evidência é exemplar e datado com rigor: o Cost of a Data Breach 2025 da IBM (o insider malicioso como vector mais caro, 4,92 milhões de dólares por violação), o Ponemon/DTEX 2025 (17,4 milhões de dólares de custo anual médio, 55% dos incidentes por negligência), o Verizon DBIR 2025 (elemento humano em 60% das violações; 29% de origem interna na EMEA) — e, num gesto de probidade rara, a estatística que parece contrariar a tese, os 0,8% da ENISA, é analisada para ensinar o leitor a interrogar o que cada métrica mede.
Os referenciais doutrinários são precisos: o relatório fundador de John Kindervag na Forrester (No More Chewy Centers, 2010), a formalização do Zero Trust no NIST SP 800-207, o RGPD e a transposição da NIS2 pelo Decreto-Lei n.º 125/2025, as normas ISO/IEC 27001 e 27005. Digno de nota crítica: o método de validação de fontes que o livro propõe — autoridade, evidência, actualidade, consistência — é exactamente o protocolo metodológico que o autor declara para toda a sua obra de não-ficção, o que faz deste volume uma espécie de autodemonstração; e, singularidade editorial dentro do eixo, o texto adopta a grafia do Acordo Ortográfico ("deteção", "arquitetura"), ao contrário dos três volumes irmãos, escritos em norma pré-acordo.
No conjunto da obra, Ameaça Interna fecha o Eixo 2 pelo interior: se a Guerra Cibernética mapeia os Estados e o Manual Quântico blinda a matemática, este livro trata do elo que nenhuma criptografia protege — a pessoa com credenciais válidas. O encerramento condensa-o com eficácia de manifesto: «O perímetro morreu. A confiança é a nova superfície de ataque. Comecemos.»
Quotations from the book
“num mundo sem perímetro, a confiança não verificada é a superfície de ataque mais extensa de qualquer organização — e a gestão dessa confiança é a disciplina central da segurança moderna”
“o mais difícil e mais necessário da disciplina: virar o olhar para dentro”
Other expressions quoted from the book
“pela porta dos fornecedores”
Source: «A Obra Comentada» (Sintra, Julho de 2026) — comentário crítico
Book details
- Genre
- Essay
- Axis of the work
- Cyber Defense and the Quantum Era
- First published
- Pages
- 729 (English edition)
- Formats
- Kindle e-book · Paperback
- Languages
- 3 — Portuguese, English, and German
- ISBN
- 979-8181526044





