Skip to content

Offensive security focused on what keeps the business running

Since 2003, Berghem has operated in critical environments, combining adversarial expertise, business logic and new artificial intelligence capabilities.

REG · 003  ·  Berghem by the numbers

Two decades of offensive security, audited and reproducible.

Updated · Q2 2026
01 · LEGACY
20+
Years of Expertise

Continuous operation in offensive security since 2003.

02 · DELIVERY
10K+
Projects Delivered

Documented engagements with reproducible evidence.

03 · SECTORS
5
Industries served

Financial services, healthcare, government, technology and retail.

04 · CATALOG
8
Specialized Pillars

Pentest, red team, AI, compliance, DevSecOps and IR.

05 · REACH
2
Continents

Operations in Latin America and Europe via Berilo.

Source · Audited internal recordsISO 27001 · LGPD · GDPRSão Paulo · Lisbon

Our Story

2003Founded at LSI-TEC, USP
2008First core-banking pentest
2014Trusted by Tier-1 banks
2019Berilo launches in Europe
2023AI Security practice
TodayAgentic EHT in operation

Berghem was built on a single conviction: the best defense starts with a deep understanding of offense. From day one, our focus has been on offensive security — finding vulnerabilities before attackers do. Our roots are in the financial sector, where over 80% of our historical work has been dedicated to securing payment systems, core banking platforms, and fintech infrastructure for major institutions across the globe. Today, Berghem is at the forefront of AI security, developing AI pentesting methodologies, mission-oriented security agents, and AI-powered risk management frameworks. Our European subsidiary, Berilo, brings this expertise to the European market with GDPR-first methodology.

What Sets Us Apart

Hidden flaws

Business Logic Analysis

We go beyond automated scanners to find vulnerabilities in your application's business logic — the flaws that matter most.

20+ years

Financial Expertise

20+ years securing payment systems, core banking, and fintech for major financial institutions worldwide.

AI native

AI-First Approach

Pioneering AI security services and autonomous security agents powered by multi-model architecture technology.

Supplier risk

AI-VRM Framework

Our AI-powered Vendor Risk Management framework automates third-party security assessments.

TEAM

Leadership

The names that sign every report.

Four profiles, one operation. Decades in pentesting, AI research, delivery and culture — signing every engagement end to end.

  1. 01
    FILE/lead/01nava.m

    Matteo Nava

    Founder & CEO
    25 yearsFounder, 2003Banking & Payments

    Founder of Berghem with over 25 years of experience in information security and technology management. Matteo established Berghem as a reference in ethical hacking and offensive security, building the company from the ground up into a trusted partner for major banks and financial institutions across the globe.

    With deep experience in red team, pentesting and adversarial simulation, he leads a team dedicated to raising the defensive maturity of organizations in regulated, high-criticality environments — combining technical rigor, business reading and a commitment to measurable results.

    CertCISSP·CISM
    LinkedIn
  2. 02
    FILE/lead/02bueno.g

    Gislaine Bueno Oliveira

    VP of Human Resources & Compliance
    TalentCultureCompliance

    Gislaine leads Berghem’s talent management strategy, organizational development, and the strengthening of a culture of continuous learning, in a market highly competitive for professionals specialized in offensive security.

    Beyond her work in people management, she is also responsible for overseeing projects for large enterprises, connecting business needs to human development and delivery excellence.

    FocusSenior recruiting · Culture · L&D · Compliance
    LinkedIn
  3. 03
    FILE/lead/03schneider.r

    Raphael Schneider

    VP of Cybersecurity
    OperationsRed TeamEnterprise Delivery

    Seasoned cybersecurity professional leading Berghem's security operations and service delivery. Raphael oversees the execution of penetration testing engagements, red team exercises, and security assessments for enterprise clients. With extensive experience in offensive security and project management, he ensures the highest quality and consistency across all client engagements.

    Responsible for ensuring methodological consistency, on-time delivery and quality across all projects, he leads coordination between offensive teams and client interlocution, sustaining the level of technical excellence that defines Berghem's reputation in critical, regulated environments.

  4. 04
    FILE/lead/04nava.l

    Lorenzo Nava

    Lead Security and ML Researcher
    AI / LLM ResearchBerghem AgentsBerilo · EU

    Cybersecurity researcher leading Berghem's AI security practice and the development of Berghem Agents. Specializes in offensive security, AI/LLM vulnerability research, and multi-model architecture development. Has authored thousands of penetration testing reports for major financial institutions worldwide, and leads the European operations through Berilo S.r.l.

    Author of thousands of pentest reports for financial institutions, he has consolidated a high-density technical track record in critical and regulated environments. He also leads the group's European operations at Berilo S.r.l., extending Berghem's standard to the international market.

HOW WE WORK

Principles that guide the work

Clear principles and verifiable evidence guide every mission, every claim and every decision.

Business before tooling

The investigation starts from what sustains the organization.

Evidence before hype

Claims, results and demonstrations must be reproducible.

Experts in command

AI amplifies capacity; judgement and accountability remain human.

Proportional control

Autonomy, data and access are defined according to risk.

AI UNDER CONTROL

Applied research and multi-model architecture

Berghem develops specialized models from open-weight models and combines different execution options according to task, confidentiality and environment.

Development

CPT, adaptations, evaluations and versioning on controlled infrastructure or contracted compute capacity.

Deployment

Berghem models, private models, authorized third parties, or served inside the client's own tenant.

Let's Talk Security

Ready to strengthen your security posture? Let's discuss how Berghem can protect your organization.

Get in Touch