🇨🇴⚖️ La Rama Judicial valida a Ariel en prueba de concepto de IA. Conoce los resultados aquí

OEA - CP - Resolución CP CSH 2381

OEA - Organización de Estados Americanos

Icono de documento PDF

Descargar PDF

Disponible

Detalles

Título
OEA - CP - Resolución CP CSH 2381
Autor
OEA - Organización de Estados Americanos
Categoría
Infralegal
Área del derecho
Internacional_Publico
Año

PERMANENT COUNCIL OF THE OEA/Ser.G

ORGANIZATION OF AMERICAN STATES CP/CSH-2381/26 20 February 2026

COMMITTEE ON HEMISPHERIC SECURITY Original: Spanish

CONCEPT NOTE ON THE INTER-AMERICAN DEFENSE BOARD'S

CYBER DEFENSE PROGRAM

(Presented by the Inter-American Defense Board in preparation for the meeting of the Committee scheduled for February 26, 2026) This document is presented in compliance with the Structure for the consideration of substantive issues during regular meetings (2025-2026), document CP/CSH/INF.602/25.

Contents CYBERDEFENSE: HEMISPHERIC OVERVIEW...............................................................................2

HETEROGENEITY IN MATURITY LEVELS.....................................................................................2

INCREASING DIGITALIZATION AND INCREASED RISK............................................................2

PROTECTION OF CRITICAL INFRASTRUCTURE AND SYSTEMS.............................................3

PERSONNEL SPECIALIZING IN CYBERNETICS: RECRUITMENT, TRAINING, AND RETENTION..........................................................................................................................................3

HEMISPHERIC COOPERATION AS A STRATEGIC FACTOR........................................................4

QUESTIONS FOR MEMBER STATE DELEGATIONS:.....................................................................4

QUESTIONS FOR PERMANENT OBSERVER DELEGATIONS:.....................................................42CYBERDEFENSE: HEMISPHERIC OVERVIEW Over the past two decades, the Western Hemisphere has undergone an unprecedented digital transformation. The expansion of connectivity, the massive use of mobile devices, the migration of services to the cloud, and the incorporation of emerging technologies have redefined the way in which States interact with citizens and perform their essential functions. In this context, cybersecurity has ceased to be a purely technical issue and has become a strategic axis of national defense, democratic stability, and economic development. The member states of the Organization of American States today face a digital environment

characterized by sophisticated threats, state and non-state actors with growing capabilities, and technological interdependence that amplifies risks. At the same time, the region has made significant progress in building institutional capacities, regulatory frameworks, and cooperation mechanisms. However, these advances are not homogeneous, which generates a complex and diverse set of circumstances that requires analysis and coordinated action. HETEROGENEITY IN MATURITY LEVELS Particularly notable is the diversity in levels of cyber defense maturity in the Hemisphere. There are countries that have consolidated comprehensive national strategies, with updated legal frameworks, specialized agencies, fully operational incident response centers, and data protection policies aligned with international standards. In these cases, cybersecurity is approached from a crosscutting perspective involving the defense, public safety, digital economy, telecommunications, and judicial sectors. These States often have national risk management plans, public-private cooperation schemes, and periodic simulation exercises to strengthen preparedness for large-scale incidents. They have also made progress in adopting governance frameworks that include inter-agency coordination mechanisms and clear protocols for dealing with cyber crises. In contrast, other countries in the region are still at the initial or intermediate stages of development. While they have recognized the strategic importance of cyber defense, they face structural limitations that make it difficult to implement robust policies. Among these limitations are the scarcity of budgetary resources, the lack of specialized personnel, the absence of comprehensive regulatory frameworks, and limited coordination between government entities. This heterogeneity creates gaps that can be exploited by malicious actors, who tend to identify and exploit the weakest links in the regional ecosystem. In an interconnected environment, the vulnerability of one country can have wider repercussions, reinforcing the need to strengthen hemispheric cooperation as a mechanism for reducing shared risks. INCREASING DIGITALIZATION AND INCREASED RISK Expedited digitalization has been a driver of growth and modernization in the Americas. Governments have implemented digital service platforms to improve administrative efficiency and expand citizen access to procedures and services. The financial sector has adopted advanced technological solutions that facilitate online transactions and electronic payment systems. Education and health have incorporated remote modalities that expand coverage and inclusion.- 3However, this technological expansion has significantly increased the attack surface. Every

Governments have implemented digital service platforms to improve administrative efficiency and expand citizen access to procedures and services. The financial sector has adopted advanced technological solutions that facilitate online transactions and electronic payment systems. Education and health have incorporated remote modalities that expand coverage and inclusion.- 3However, this technological expansion has significantly increased the attack surface. Every new connected system, every digital platform, and every online database represents a potential point of vulnerability. Ransomware attacks, theft of sensitive information, phishing campaigns, and intrusions into government networks have become recurrent threats in several countries in the region. In addition, the incorporation of emerging technologies such as artificial intelligence, the Internet of Things, and industrial automation poses new risk management challenges. In many cases, the implementation of these technologies exceeds institutional capacity to establish adequate security controls from the moment of their design, which generates structural vulnerabilities. The increasing sophistication of threats also reflects the fact that malicious actors are becoming increasingly professional. There are organized groups operating with highly structured illicit business models, as well as politically or strategically motivated actors seeking to undermine institutional stability or influence democratic processes. This reality calls for a comprehensive response that combines technical capabilities, strategic intelligence, international cooperation, and more effective regulations. PROTECTION OF CRITICAL INFRASTRUCTURE AND SYSTEMS One of the most sensitive challenges in the region is the protection of critical infrastructure and systems. Sectors such as energy, transportation, telecommunications, water, healthcare, and financial services are increasingly dependent on interconnected digital systems. The interruption of these systems can trigger severe economic impacts, impair the provision of essential services, and compromise the safety of the population. Interdependence between critical sectors increases the complexity of the risk. An incident in the energy sector may affect telecommunications; a failure in financial systems may affect economic stability; an interruption in hospital systems may endanger human lives. In this context, critical infrastructure cybersecurity cannot be addressed in isolation, but as part of a systemic approach to

national resilience. Many countries have begun to develop specific regulatory frameworks for critical infrastructure protection, including the identification of strategic assets, the definition of minimum security standards, and the obligation to report incidents. However, effective implementation of these frameworks requires sustained investment, specialized technical supervision, and close collaboration with the private sector, which in many cases is the owner or operator of these systems. Regional cooperation is also essential in this area. Harmonizing standards, sharing hazard information, and conducting joint exercises can help strengthen collective resilience and reduce the likelihood of cross-border impacts. PERSONNEL SPECIALIZING IN CYBERNETICS: RECRUITMENT, TRAINING, AND RETENTION The human dimension is one of the most critical factors in the development of cybersecurity capabilities. In the region as a whole, the demand for specialized professionals far exceeds the available supply. This talent gap affects both the public and private sectors, but has particularly sensitive implications for state institutions responsible for defense and security.- 4In terms of recruitment, many countries face difficulties in attracting highly qualified personnel. Universities and training centers have begun to expand their curricula and courses in areas related to IT security and cyber defense, but the speed with which training is provided does not always keep pace with the growth in demand. In addition, global competition for specialized talent increases pressure on national labor markets. Ongoing training poses another key challenge. Cybersecurity is a dynamic field where threats evolve rapidly. Therefore, training cannot be limited to initial training, but requires constant updating, specialized certifications, participation in practical exercises, and access to advanced simulation environments. For some countries, the costs associated with these activities constitute a significant barrier. Talent retention is equally complex. Experienced professionals tend to receive more competitive offers in the private sector or in international markets, which leads to frequent turnover in public institutions. Salary limitations, administrative rigidity, and the lack of structured career plans make it difficult to consolidate stable and highly specialized teams within the State.

Faced with this scenario, several countries have begun to explore innovative strategies, such as scholarship programs with public service commitments, non-salary incentives, partnerships with universities, and various forms of collaboration with the private sector. However, the challenge remains and calls for a long-term strategic vision. HEMISPHERIC COOPERATION AS A STRATEGIC FACTOR Given the transnational nature of cyber threats, no country can meet this challenge in isolation. Cooperation within the framework of the Organization of American States plays a central role in the promotion of common standards, capacity building, and the exchange of best practices. Technical assistance mechanisms, regional training programs, and policy dialogue forums help reduce gaps and build mutual trust. Cooperation also contributes to improving the capacity to respond to incidents that may have impacts in multiple countries. Building a shared cybersecurity culture, based on principles of accountability, transparency, and collaboration, is an essential component of moving towards a more secure and resilient digital environment in the Hemisphere. QUESTIONS FOR MEMBER STATE DELEGATIONS: - Does your country engage in any international collaboration in the area of cyber defense? - Has your country identified any specific needs for capacity building, technical assistance, and international cooperation to counter cyber defense threats? - How can the IADB support your country on the issue of cyber defense? QUESTIONS FOR PERMANENT OBSERVER DELEGATIONS: - Has your country developed any international cooperation initiatives or programs in the area of cyber defense?

Consultar sobre este documento ...