Puerto Rico Turned Government Cybersecurity Into a Legal Operating Model
Puerto Rico enacted Law 40-2024 on 18 January 2024. The law does more than tell public bodies to improve security. It assigns leadership, creates an incident function and turns a set of technical safeguards into legal operating requirements for government.
Cybersecurity laws often begin with broad duties and leave the operating model for later. Puerto Rico took a more direct route. Law 40-2024, the Puerto Rico Cybersecurity Law, places a Chief Information Security Officer within the Puerto Rico Innovation and Technology Service and creates a Cyber Incident Assessment Office.
The result is a framework that connects governance, prevention, incident response and supplier oversight. Its immediate audience is the public sector, but contractors that handle government systems or information are also part of the risk chain.
The law gives cybersecurity an owner
The government CISO is responsible for developing and coordinating public cybersecurity policy, standards and programmes. The Cyber Incident Assessment Office supports the analysis and management of incidents across agencies and municipalities.
This structure matters because fragmented accountability is one of the most persistent public-sector weaknesses. An agency can purchase security tools without establishing who accepts risk, who coordinates an incident or who can require another body to act. Law 40-2024 makes those questions part of governance rather than leaving them to informal arrangements.
Risk assessment becomes a recurring duty
Covered public bodies must maintain cybersecurity programmes and conduct risk assessments at least annually. They must also provide awareness and training, test for vulnerabilities and maintain privacy notices that explain the treatment of personal information.
The annual cycle should not be treated as a compliance snapshot. A useful assessment connects assets, services, suppliers, known vulnerabilities and recovery dependencies to named owners and deadlines. It should also be updated when a major system, threat or service provider changes.
Technical controls now have legal weight
The law addresses controls including multifactor authentication, data classification, encryption and backups. These are familiar security measures, but putting them in legislation changes the evidence expected after an incident. An organisation must be able to show where the control applies, who monitors it and how exceptions are approved.
Backups, for example, are not useful merely because they exist. They must be protected from the same event affecting production systems and tested for restoration. Data classification must guide access, retention and encryption rather than remaining a label in a policy document.
Suppliers are inside the incident clock
Contracted service providers must notify the relevant government body of a cyber incident within 48 hours. That requirement makes procurement language operationally important. Contracts need a clear trigger, a notification route available at all hours and an obligation to preserve and share enough evidence for government response.
A supplier agreement that promises notice but does not define who calls whom, what information is required or how updates will be delivered is unlikely to work under pressure.
What public bodies and suppliers should do
- Assign accountable owners for the security programme, incident coordination and risk acceptance.
- Map Law 40-2024 requirements to implemented controls and retain evidence that they operate.
- Run the annual assessment as a prioritised remediation process, not a checklist.
- Review government contracts for the 48-hour supplier notice and practical evidence-sharing terms.
- Exercise escalation, restoration and cross-agency coordination before an actual incident.
The operating model is the real reform
Law 40-2024 is important because it treats cybersecurity as a continuing public function. Leadership, risk assessment, technical safeguards, supplier duties and incident response sit inside one framework.
The test will not be whether agencies can point to a policy. It will be whether that operating model produces faster decisions, better evidence and more resilient public services.
Official sources
- Government of Puerto Rico: Law 40-2024
- Office of Legislative Services: approved-law record
- PRITS: implementation and cybersecurity responsibilities
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


