Case Studies

Cybersecurity in Payment Institutions: How iugu Went Beyond Compliance with Gamification

How did iugu go beyond compliance with gamification?

Learn how the payment institution iugu — a technology company specializing in financial infrastructure — was able to implement a cybersecurity awareness culture that went beyond compliance and became part of the company’s DNA. 

Getting to Know iugu

Founded in 2012, iugu is a Brazilian technology company that offers a complete financial infrastructure ecosystem. 

iugu provides solutions that simplify and automate financial operations, helping businesses grow with efficiency, predictability, and control, while eliminating complexities and enhancing results. 

iugu was born 100% cloud-based. For this reason, cybersecurity has always been part of the institution’s reality from the very beginning of its journey, not as an add-on, but as an essential pillar of the business. 

In addition, as an institution approved by Brazil’s Central Bank and recognized for PCI DSS compliance, the company has always met the requirements of audits, controls, and regulatory compliance.

In Search of an Awareness Culture

Even though it operated in a highly regulated and technically mature environment, iugu faced a challenge common to many organizations: turning cybersecurity awareness into something that went beyond the formal fulfillment of requirements and truly became part of people’s routines. 

The company already had its own learning platform. However, the available training programs were mostly focused on compliance and followed a more static format — a perception shared by the employees themselves. 

“Talking about cybersecurity requires something more dynamic. Formal and regulatory training programs are denser and can feel distant from everyday situations,” says Ricardo Chagas, Infrastructure & Information Security Manager at iugu.

It was necessary to find a path that would make learning lighter, more continuous, and closer to people’s daily lives. 

 

When Cybersecurity Gains a Name Within iugu

The turning point came when iugu discovered Hacker Rangers. Looking for a new dynamic and a training experience that would engage people, the company conducted market research until it found a fully gamified solution. 

After a presentation by Vinícius Perallis, CEO of Hacker Rangers, it became clear that the proposal went beyond one-off content. 

“We realized that we were not just buying content, but something that would become part of employees’ daily lives,” says Ricardo.

This connection was also quickly perceived by the iugu team, which readily adopted the solution. 

A iugu has a more relaxed atmosphere, and Hacker Rangers reflects that essence very well: it is light, accessible, and, at the same time, maintains the necessary level of seriousness,” adds Alisson Almeida, security analyst and operational lead for the program at the company. 

Cyberattitudes: When Cybersecurity Becomes a Hallway Conversation

The transformation did not take long to appear. In a short time, cybersecurity stopped being just a compliance item or a topic restricted to the security area and began to share space with other relevant subjects in the company’s daily routine. 

What most caught the attention of the program managers was how naturally the topic began to be addressed: something that had once been almost taboo, surrounded by hesitation when talking about incidents and security, became part of everyday conversations. 

In the hallways, over coffee, and during quick breaks between one task and another, technical terms began to come up naturally. Colleagues started sharing day-to-day experiences, such as enabling a security setting, identifying scams, or taking actions to protect people close to them. 

Many employees even took on the role of “cyberdetectives,” paying attention to potential flaws or suspicious situations in the workplace. These observations began to be registered through Cyberattitudes, in a lighter, less formal format that was aligned with iugu’s style.

This movement made it clear that awareness had gone beyond the platform screen and turned into behavior. 

Today, cybersecurity awareness within iugu has a name: Hacker Rangers.” –  Ricardo Chagas.

Gamification as the Main Ally

Over five years of using Hacker Rangers, iugu began to notice a transformation that went beyond numbers, rankings, or the volume of interactions with Cyberattitudes. 

According to Alisson, the main impact was in the way knowledge was absorbed, practiced, and retained by people over time. 

With the gamified method, security content became part of the daily routine. This helped reinforce concepts frequently and sparked greater interest among employees, who felt motivated by the game dynamics, the challenges, and the sense of progress. 

In addition, the platform made it easier to monitor the learning journey, with real-time reports that allowed the team to identify metrics, knowledge gaps, and opportunities to strengthen the security culture. 

Ricardo emphasizes that one of the clearest changes is in the employees’ own everyday vocabulary: 

“The main thing is people’s vocabulary. Talking about cyberattitudes and talking about incidents are things that would not normally happen. You would not hear cybersecurity terms over coffee, in a casual conversation during a meeting… And today, that happens because of Hacker Rangers, which is really cool.”

Results That Speak for Themselves

This cultural transformation was also reflected in the numbers. In the last season, more than 130 employees accessed the platform and more than 270 Cyberattitudes were registered, demonstrating not only engagement, but also the practical application of what was learned in everyday routines.

+130 platform accesses
+270 Cyberattitudes submitted, with an average of 3.5 per user

Since gamification is also directly connected to recognition, iugu promoted a special initiative that quickly gained internal visibility. On the company’s TV screens, employees who stood out in the ranking began to be featured in an “expert tips” board. 

The impact was immediate: the initiative recognized those who were already engaged and sparked curiosity among the others. The ranking began to receive more attention and, at the end of the season, the top performers were awarded. 

According to Camila Tambacha,current Cybersecurity Awareness Specialist at Hacker Rangers, iugu has always been an example when it comes to information security: 

“I would especially like to highlight an initiative we carried out every two weeks in pursuit of the Red Certified certification. The results were so positive that the company not only achieved Red, but has now just reached Black Certified! And this shows how tangible the results are: a true change in employees’ habits.” 

Next Steps

With the achievement of the long-awaited Black Certified certification, iugu is now looking ahead to the next steps with a focus on continuous evolution. 

The goal is to maintain the high level already reached and advance even further in the maturity of its cybersecurity culture. Among the next objectives is even greater involvement from C-level executives, bringing them into the ranking and strengthening their presence in the day-to-day practice of information security. 

The proposal is simple and powerful: to bring everyone closer, regardless of their role, and reinforce that cybersecurity is, above all, a shared responsibility.