La Seguridad Comienza Con Conciencia

Explora lo último en ingeniería social, amenazas generativas de inteligencia artificial y estrategias de ciberseguridad para proteger lo que más importa: su equipo.
Blog post
Your EU AI Act Classification Is Complete. Shadow AI Isn't on the List.
The EU AI Act requires organizations to classify every AI system they run by risk level. That requirement assumes a complete list of systems exists. Gartner's own research says it usually does not: 69% of security leaders already suspect employees are using generative AI tools nobody approved, and Gartner expects more than 40% of enterprises to face a security or compliance incident tied to unauthorized shadow AI by 2030. This post argues that the real compliance gap is not legal — it is behavioral, and it is measurable before it becomes an incident.
¡Gracias! ¡Su presentación ha sido recibida!
¡Uy! Algo salió mal al enviar el formulario.
Blog post
Your EU AI Act Classification Is Complete. Shadow AI Isn't on the List.
The EU AI Act requires organizations to classify every AI system they run by risk level. That requirement assumes a complete list of systems exists. Gartner's own research says it usually does not: 69% of security leaders already suspect employees are using generative AI tools nobody approved, and Gartner expects more than 40% of enterprises to face a security or compliance incident tied to unauthorized shadow AI by 2030. This post argues that the real compliance gap is not legal — it is behavioral, and it is measurable before it becomes an incident.
Blog post
Your ISO 37001 due diligence file could be perfectly accurate, and still completely out of date
Most organizations treat third-party due diligence as a single gate: pass it once, and the relationship stays cleared. That approach assumes the vendor approved on day one is the same vendor a year later. ISO 37001 due diligence exposes what happens when that assumption breaks: ownership changes, a new intermediary enters the deal, the vendor expands into a market nobody reviewed, and nothing in most compliance programs notices. This is not a documentation failure or a reviewer's judgment call. It is a monitoring gap, and it is measurable before it becomes an incident.
Blog post
The compliance program that produces records but not decisions
Most compliance programs do exactly what they were designed to do: produce a record. Modules completed, policies acknowledged, certificates issued. What they do not produce is the decision that matters, when an employee faces a real vendor and a real relationship. 93% of employees say they would report misconduct; only 50% do when they actually witness it (Ethisphere, 2024 Ethical Culture Report). That gap is not a training failure. It is a design problem, and it takes a different architecture to close.
Blog post
The AI risks your compliance team has not modelled yet
Most security and risk leaders built their model of AI risk in 2023: hallucinations, data leaks, unsanctioned tools. That model is now incomplete. Three risks have moved from theoretical to operational: bias amplified at scale, inference from accumulated context, and an accountability gap with no audit trail. Today, 39.7% of workplace AI interactions involve sensitive data (Cyberhaven, 2026 AI Security Report). None of these three look like an AI problem when they surface, which is exactly why they go unmanaged.
Blog post
Your employees know AI hallucinates. They still don't verify.
Most AI literacy programs are awareness programs with a new label. They teach employees what the risks are. They don't change what employees do when those risks materialize under real work pressure. The gap between knowing AI can produce unreliable outputs and building the habit of verifying before acting is a behavior gap, not a knowledge gap. Closing it requires what works for any behavioral security program: repeated exposure, realistic scenarios, and reinforcement at the point of decision.
Blog post
Your employees pass the phishing test. 87.5% still fall for the attack.
Adding a single channel to a phishing attack multiplies the failure rate by six. That is what most security awareness programs are not measuring — and it is the gap where coordinated attacks succeed. This post argues that single-vector simulation produces readiness data that does not map to how attacks actually land, and examines what a testing methodology built for this reality looks like.
Blog post
Your Face Is Now a Weapon. Here's What That Actually Means
A finance employee at a global engineering firm joins a video call. He sees his CFO. He sees colleagues. Everyone looks real, sounds real, acts real. By the end of the call, he has wired $25 million to an account he'll never recover. Every person on that call was a deepfake. This wasn't a movie. It happened in February 2024, at Arup — one of the world's most respected engineering companies. And it's no longer an edge case.
Blog post
How attackers steal passwords through social engineering
Most compromised credentials aren't broken through brute force. They're obtained by convincing the person who holds them. Helpdesk vishing, MFA fatigue, and AI-personalized phishing are the active vectors — and the defence that works has to operate at the human layer.
Blog post
Suplantación de identidad por invitación al calendario: cómo un ataque a Google Calendar eludió todos los controles perimetrales
El 17 de marzo, un atacante envió una invitación a Google Calendar por un cargo de 399,77 dólares que no era real. No había ningún enlace en el que hacer clic ni ningún archivo adjunto en el que hacer estallar, y DKIM fue aprobado. La única parte del ataque que importaba era el número de teléfono. He aquí por qué fallaron todos los controles perimetrales y dónde vive realmente la defensa.
Blog post
AI social engineering in 2026: why phishing simulations built on last year's templates are the wrong defense
Targeted social engineering used to require hours of manual reconnaissance. AI removed that ceiling. Personalized, multi-channel attacks now take seconds to build — and most simulation programs still test only email.
Blog post
The architecture gap: why your security gateway and your training program have never shared a single data point
Your security gateway logs every threat targeting your employees. Your training platform runs on a quarterly calendar. These two systems were built for different buyers, measured by different metrics, and were never designed to exchange data — and that gap is where incidents happen.
News
Zepo Intelligence: the first cybersecurity ecosystem to connect threat detection with human risk management
Zepo Intelligence is now the first cybersecurity ecosystem for human risk — a platform where real-time threat detection and security training share a single data model. Every blocked attack immediately informs training. Every behavioral signal refines how protection is applied.
Blog post
What every regulation now requires from your cybersecurity training program — and why completion rates fail all of them
Modern cybersecurity regulations have shifted from "completion" to "competence," leaving organizations legally vulnerable when they prioritize annual check-boxes over actual behavioral change. Discover the five documentation gaps that fail regulatory scrutiny and how to build a training program that is truly defensible after an incident.
Blog post
One call to a vendor. 15,661 records exposed. The Ericsson breach shows where security awareness ends.
A single vishing call to a third-party vendor gave attackers access to Ericsson customer data for five days — and Ericsson wasn't notified for seven months. The gap most security awareness programs don't cover is vendor employees. Here's how to start bridging it.
Blog post
Deepfakes don't exploit technology gaps. They exploit obedience.
99% of security leaders say they're confident in their deepfake defenses. The average detection score is 44%. This post argues the industry is solving the wrong problem — and that verification culture, not detection technology, is the defensible response to AI-powered social engineering.
Blog post
The leak of 47 political leaders: A case study in context-driven risk
A recent breach has exposed the personal data of 47 high-profile Spanish politicians, including regional presidents and high-ranking officials.
News
Zepo Intelligence Selected for the 2026 CrowdStrike, AWS & NVIDIA Cybersecurity Startup Accelerator
Zepo Intelligence, an agentic social intelligence platform for workspace security, has been selected to participate in the 2026 Cybersecurity Startup Accelerator with CrowdStrike, Amazon Web Services (AWS) and NVIDIA through its Inception program, to help fuel the next generation of AI-driven cloud security innovation.
FraudGPT: what security leaders need to know in 2026
AI tools like FraudGPT have made convincing phishing attacks accessible to anyone with a subscription. Here's how the threat has evolved since 2023 and why the defense is behavioral, not technical.
News
Zepo Intelligence Raises $15M Seed Round to Protect Workspaces from AI-Driven Social Engineering
Zepo Intelligence, the company redefining human-centric security, announced today the closing of a $15 million Seed investment round. The round includes three European VCs with strong focus in cybersecurity, Kibo Ventures, eCAPITAL and TIN Capital, and will allow Zepo to expand its team and scale its proprietary technology globally as AI-driven social engineering rapidly escalates into one of the most persistent and costly challenges for security leaders in modern organizations.
News
Tangos, technology, and trust: a recap of our week in Buenos Aires
From exclusive roundtables at Happening Costanera to the bustling floor of IT Forum Financiero, our team spent an incredible week connecting with the heartbeat of LATAM’s financial sector.
News
The Art of Connection
In the relentless pursuit of goals and deadlines, sometimes the most productive thing you can do is pause, reconnect, and look at the world through new eyes.

Cómo Zepo ayuda a las empresas

Cuando todo se conecta, los resultados llegan

Nadia Cappelletti

Gerente de Seguridad de la Información Digital

Recomendaría Zepo a colegas de otras empresas porque creo que ha satisfecho todas nuestras necesidades. Nos ha permitido ejecutar tres tipos de campañas que otras herramientas que hemos probado simplemente no pueden hacer. Y más allá del producto en sí, el apoyo de todo el equipo nos ha ayudado a sacarle mucho más partido.”

+9K

Empleados Protegidos

–10%

Tasa de clics en ataques

+18%

Tasa de finalización de la capacitación

Ramon Fernandez Blanco

Ciberseguridad y Gerente de Producto Digital

Desde la implementación de Zepo, la concienciación de los empleados ha aumentado significativamente. Los empleados ahora debaten activamente sobre ciberseguridad y campañas de phishing, y los correos electrónicos sospechosos se reportan rápidamente en lugar de ser ignorados.”

+600

Empleados Protegidos

–15%

Credenciales enviadas

+26%

Tasa de finalización de la capacitación

Jonathan Nelson

Director de Inteligencia de Riesgos

La visión de Zepo para una solución de ciberseguridad en tiempo real, hiperpersonalizada y multiplataforma es verdaderamente única y está muy por encima de la competencia”

+100

Empleados Protegidos

Anticípate antes de que ataquen.