🇨🇴⚖️ La Rama Judicial valida a Ariel en prueba de concepto de IA. Conoce los resultados aquí

OEA - CP - Resolución CP CSH 2380

OEA - Organización de Estados Americanos

Icono de documento PDF

Descargar PDF

Disponible

Detalles

Título
OEA - CP - Resolución CP CSH 2380
Autor
OEA - Organización de Estados Americanos
Categoría
Infralegal
Área del derecho
Internacional_Publico
Año

PERMANENT COUNCIL OF THE OEA/Ser.G

ORGANIZATION OF AMERICAN STATES CP/CSH-2380/26 17 February 2026

COMMITTEE ON HEMISPHERIC SECURITY Original: Spanish/English

CONCEPT NOTE

"A FOCUS ON RISING CYBER THREATS TO

GOVERNMENT INSTITUTIONS IN THE HEMISPHERE"1 /

(Presented in preparation of the Committee meeting scheduled for February 26, 2026, at 10:00 AM) This document is submitted in accordance with the provisions established in the Structure for the consideration of substantive issues during regular meetings (2025-2026) , document CP/CSH/INF. 602/25, and pursuant to the request of the Presidency of the Committee on Hemispheric Security. Contents

I. Current status of the issue ..............................................................................................................2

II. Progress..........................................................................................................................................2

III. Challenges..................................................................................................................................3

IV . Suggested specialist ...................................................................................................................4 V . Expected results .............................................................................................................................4

VI. Guiding questions for delegations of Member States................................................................5

VII. Guiding questions for delegations of Permanent Observers......................................................5

1 . This document has been prepared by the Cybersecurity Section of the Secretariat of CICTE.- 2I. Current status of the issue The cyber threat environment facing governments in the Western Hemisphere is increasingly complex and professionalized. One of the most significant and least scrutinized developments is the rise of Initial Access Brokers (IABs)—cybercriminal actors who specialize in gaining unauthorized access to government networks, systems, and digital infrastructure and subsequently sell that access to third parties, including ransomware groups, cyberespionage actors, and transnational criminal organizations. Threats like these play a critical role in the cybercrime ecosystem. By monetizing access to compromised government systems, they reduce technical barriers to conducting cyberattacks, increase

the speed and scale of incidents, and exacerbate risks to public administration, national security, critical infrastructure, and citizen trust. These activities exploit weaknesses in identity and access management, unpatched systems, supply chains, and uneven cybersecurity governance in the region. Therefore, the following objectives are proposed for addressing this issue during the scheduled session: - To address the growing cyber threats to government institutions and hemispheric security. - To facilitate understanding of an example of an emerging cyber threat – how do Initial Access Brokers (IABs) operate and why do they pose elevated risks to the public sector? - To examine how existing OAS mechanisms, including confidence-building measures (CBMs) in cyberspace, can be leveraged to address this threat. - To promote dialogue and cooperation around preventive and capacity-building responses at the regional level.

II. Progress The OAS has long recognized cybersecurity as an integral part of hemispheric security. The Comprehensive Inter-American Strategy to Combat Threats to Cybersecurity (2004) established the basis for regional cooperation, emphasizing capacity building, information sharing, incident response, and the development of national legal and policy frameworks.

This framework has been reinforced institutionally through Executive Order No. 24-02, which formally established the Cybersecurity Section within the Secretariat for Multidimensional Security, under the Secretariat of the Inter-American Committee against Terrorism (CICTE). The establishment of the Cybersecurity Section reflects the increasing scale, sophistication and security implications of cyber threats affecting Member States. In accordance with Executive Order No. 24-02, the Cybersecurity Section plays a central role in supporting Member States to address threats -such as those posed by Initial Access Brokers - through the following functions: - Technical support for the formulation or implementation of policies, legal frameworks, and strategies3Supporting Member States in the design, development, implementation, and monitoring of

national laws, policies, and strategies to prevent and/or mitigate cybersecurity threats and incidents, protect digital critical infrastructure, and foster a secure and trustworthy digital environment. - Technical support for the implementation of confidence and security-building measures in cyberspace Providing technical and logistical support to the CICTE Working Group on Confidenceand Security-Building Measures in Cyberspace, and supporting Member States in the implementation of all recommended non-traditional (voluntary) measures that enhance trust, transparency, and cooperation. - Technical support for strengthening national cybersecurity capacities. Supporting Member States in strengthening their national cybersecurity capacities, including in the establishment, or strengthening of Computer Security Incident Response Teams (CSIRTs), cybersecurity workforce development, and cyber diplomacy. - Technical support in awareness-raising initiatives, research and multisectoral cooperation Designing and implementing cybersecurity awareness initiatives, conducting research, and facilitating cooperation, coordination, and information sharing among cybersecurity professionals from the public and private sectors, civil society, academia, and the relevant areas of the OAS General Secretariat.

III. Challenges - Increasing and sophisticating cyber threats against the public sector Malicious actors, including Initial Access Brokers (IABs), employ increasingly advanced techniques to compromise government networks, affecting institutional stability and hemispheric security. - Limited technical and strategic understanding of IABs Some countries still face gaps in understanding how IABs operate, how they monetize initial access, and how they facilitate subsequent attacks such as ransomware, espionage, or sabotage. - Challenges for early detection and information sharing Limitations persist in early warning mechanisms, timely intelligence sharing, and interagency coordination, making a rapid and effective response difficult. - Insufficient use of existing regional mechanisms4Confidence-Building Measures (CFMs) in cyberspace and other OAS instruments are not always fully utilized to collectively prevent, mitigate, and respond to emerging threats such

as IABs. - Gaps in technical capacities and resources among Member States There are significant inequalities in infrastructure, specialized talent, and regulatory frameworks, which complicates the implementation of cooperative, preventive, and sustainable responses at the regional level. Given the transnational nature of threats such as the IABs and their links to organized crime and other security threats, this issue constitutes a hemispheric security concern. IV . Suggested specialist The session will feature the participation of Mr. Andrés Velásquez, a renowned cybersecurity expert with extensive experience in the analysis of cybercrime ecosystems, methodologies of threat actors and risks for government institutions. The presentation during the session will include: - Practical insights into how government networks are often compromised. - Observations on the regional and global implications of access brokerage markets and an overview of other regional cybersecurity threats and trends. - Considerations for policy and operational responses by governments. V . Expected results Addressing cyber threats requires coordinated action, shared understanding, and sustained capacity building across the hemisphere. Through this meeting, the Committee on Hemispheric Security can make a significant contribution to strengthening regional cyber resilience and advancing the role of the OAS as a platform for cooperation in the face of emerging cybersecurity threats. The session is expected to result in: - Increased awareness of serious cyber threats to government institutions. - Better understanding of the links between ransomware, cybercrime, and broader hemispheric security challenges. - Identification of good practices and cooperative approaches to prevent unauthorized access and strengthen government cyber resilience. - Strengthening the relevance of confidenceand security-building measures in cyberspace as tools to promote transparency, trust, and information sharing.- 5 - - Guidance for the future work of the Committee on Hemispheric Security and the OAS Cybersecurity Section of CICTE, including possible areas of technical assistance, capacity building, and policy development.

VI. Guiding questions for delegations of Member States

  • Are we addressing cybercrime enablers, such as IABs, or just its consequences? - How can we improve the timely exchange of information on compromised access? - What national gaps are being exploited and how can we collectively close them? - How can confidence-building measures strengthen regional resilience?

VII. Guiding questions for delegations of Permanent Observers - How can Permanent Observers help strengthen Member States' cybersecurity capacities to address IAB-related threats? - How can Observers improve the exchange of information and best practices on emerging cyber threats? - What practical assistance (training, tools, partnerships) could Permanent Observers provide to improve regional cyber resilience? - How can Permanent Observers support the implementation of Confidence-Building Measures (CFMs) in cyberspace and promote coordinated responses to cyber threats?

Consultar sobre este documento ...