COMMENTARY | Challenges of the Framework Law and the Creation of the National Cybersecurity Agency

COMENTARIO |  Desafíos de la Ley Marco y la creación de la Agencia Nacional de Ciberseguridad

In December 2018, hackers affiliated with the Lazarus group launched a global attack on ATMs aimed at manipulating the software of the dispensers to make fraudulent withdrawals. In Chile, the RedBank group, a victim of the attack along with others in Argentina, Brazil, and Peru, alerted the Superintendency of Banks and Financial Institutions (SBIF) and the Association of Banks and Financial Institutions (ABIF) about the malware found in their systems. At that time, there were few points of information exchange regarding cyberattacks, and the State had limited tools to prevent, assess, and respond to these attacks. Just a year earlier, President Michelle Bachelet, along with her Interior and Defense ministers, initiated a national process to create public policy for the country’s cybersecurity and cyber defense. Patiently, this process overcame obstacles and allowed Congress to approve this month the Framework Law on Cybersecurity and Critical Information Infrastructure and the creation of the National Cybersecurity Agency (ANCI).

Currently, the levels of incident response, protection of critical infrastructure, and crisis management in cybersecurity have grown alongside greater multisectoral consensus among private companies and public entities. The trend in the region has been similar, but there is a long way to go to achieve consolidated maturity in cybersecurity, according to the standard measurement of the OAS cybersecurity observatory.[1] In Argentina, Brazil, Mexico, Colombia, and Chile, perhaps the greatest achievement has been the creation of national teams for responding to cybersecurity incidents (CSIRT) and military defense units in cybersecurity.

Now, with an annual budget of US$ 5 million[2], the ANCI will be tasked with “investing in preventive work; fostering a public culture regarding digital security; addressing contingencies in the public and private sectors, and safeguarding the security of individuals in cyberspace.”[3] The challenge is considerable, and whoever is chosen by the Public High Management to lead it will have a titanic but rewarding task.

The agency will follow a model similar to that of other regulatory entities of the State, for example, the Financial Analysis Unit (UAF), created in the early 2000s when combating money laundering became a global priority following the 9/11 terrorist attacks. The ANCI will have the authority to sanction entities mandated by law that are part of the Chilean cyber domain. The challenge is twofold, as these are the same entities with which a secure connectivity network will be attempted to be created, the so-called essential public services and vital private operators, which include everything from state agencies to service providers. Just as in the formative years of the UAF[4], the ANCI will need to raise awareness and educate a range of national and international entities operating in the country.

Regional Differences

Perhaps the largest comparative study on building cybersecurity capabilities estimated that a majority of countries globally are in the early stages of developing policies and institutions. The differences between regulatory frameworks and agencies are gradual and are associated with the wealth of countries and the level of internet penetration. Poorer nations with less connectivity tend to have worse preparedness and capabilities in cybersecurity.[5]

For Chile, which has 90% of its population connected, the problem arises as Latin America and the Caribbean have a connectivity rate of 73% and an average GDP 50 times lower than that of Chile. In the neighborhood, Chile is better prepared in its cybersecurity and cyber defense policy than Peru and Argentina, according to the OAS observatory.

In the short term, the need to create cybersecurity at the regional level will take on a central role, just as better management of state resources indicated by the framework law will. Our local advancements are not immune to a hemisphere constantly under threat from cybercriminals.

Leadership and Governance

Cybersecurity is an issue that transcends from the individual to the national level and requires constant measurement and evaluation by state agencies, at least in those countries with a liberal democratic framework where it is expected that the internet be free and uncensored (except for essential safeguards in sensitive areas). Most industrialized nations have agreed that at least five elements are needed to guide cybersecurity governance: a strategy, standardized processes, regulatory compliance, leadership, and resources.[6] In the Chilean case, inspired in part by current ties with agencies in the United States, the United Kingdom, continental Europe, and Oceania, an effort will be made to create a governance model based on risk management with a series of standards aimed at preventing, containing, and responding to incidents and cyberattacks. The model is broadly outlined by the law that promotes a public-private collaboration system. Cybersecurity obligations and sanctions will apply according to established risks and the size of essential public services and vital operators. A large entity that is a victim of a significant cyberattack will have to pay a higher fine if it is proven that it did not adhere to the standards expected by the State. The cost is high, as such an entity will bear the cost of the attack for its organization, plus the amount of the fine. It is foreseeable that many entities will need to fund new training in best practices in cybersecurity for their employees, in addition to seeking new insurance against cyberattacks following the announcement of the law and its sanctions. 

The point that calls for intersectoral collaboration is the law’s provision to seek cooperation with the intelligence system agencies of the State. The ANCI thus enters a complex network of actors in security and defense with extensive experience and data in cybersecurity matters. It will be important to define how “threats” and “cyberattacks” that represent “a risk to national security” will be identified, as stated in the law. The defense and public security sectors will need to unify practices, languages, and perspectives regarding the definitions understood by the law. In this regard, the relationship of the ANCI with the President of the Republic through the Ministry of the Interior and Public Security should consider the new horizontality of this emerging network, which will include the police and armed forces.

In times when civilians and military personnel work hand in hand in the cybersecurity of countries like Brazil (ComDCiber), the United States (CyberCommand and NSA), the United Kingdom (GCHQ), and Australia (ASD), among others[7], it will be necessary to amalgamate strategies, human and material resources, and comprehensive leadership that facilitates ministerial and agency integration.

Dr. Carlos Solar, Senior Research Fellow at the Royal United Services Institute (RUSI). Author of the book “Cybersecurity Governance in Latin America: States, Threats, and Alliances” (2023)

December 15, 2023

Photograph: France Presse

*The opinions expressed in this article are those of the author and do not necessarily reflect the views of AthenaLab.


[1] Organization of American States (2023). Cybersecurity Observatory

in Latin America and the Caribbean. Available at https://observatoriociberseguridad.org/#/home.

[2] Ministry of the Interior and Public Security (2023). Framework Law Project on

Cybersecurity and Critical Information Infrastructure (Bill 14847). April 25. Available at https://www.senado.cl/appsenado/templates/tramitacion/index.php?boletin_ini=14847-06

[3] Senate of Chile (2023). To the Law of the New Legal Framework on Cybersecurity and Critical Information Infrastructure. December 12. Available at https://www.senado.cl/a-ley-nuevo-marco-legal-sobre-ciberseguridad-e-infraestructura-critica

[4] Carlos Solar (2015). The Inter-Institutional Governance of Money Laundering: An In-Depth Look at Chile Following Re-Democratization, Global Crime, 16(4): 328-350, DOI: 10.1080/17440572.2015.1078241

[5] Sadie Creese, Will H. Dutton, Patricia Esteve-González, and Ruth Shillair (2021). Cybersecurity Capacity-Building: Cross-National Benefits and International Divides, Journal of Cyber Policy, 6(2): 214-235, DOI: 10.1080/23738871.2021.1979617.

[6] Salifu Yusif and Abdul Hafeez-Baig (2021). A Conceptual Model for Cybersecurity Governance, Journal of Applied Security Research, 16(4): 490-513, DOI: 10.1080/19361610.2021.1918995.

[7] Carlos Solar (2023). Cybersecurity Governance in Latin America: States, Threats, and Alliances (Albany: State University of New York Press)


Más publicaciones