BlackTree Security · Infrastructure · Automation · AI

Chile’s Cybersecurity Framework Starts With a Three-Hour Alert

Chile’s Cybersecurity Framework Law creates a national regulator, defines essential services and requires an early incident alert within three hours. That first message is designed for speed, not forensic certainty.

Chile published Law No. 21.663, the Cybersecurity Framework Law, on 8 April 2024. It establishes a national system for preventing, containing and responding to cybersecurity incidents and creates the National Cybersecurity Agency, known as ANCI.

The law is notable for its breadth and for the pace of its reporting sequence. Organisations providing essential services need an incident process that can move from technical detection to a regulatory alert in hours.

Essential services reach far beyond government

The framework applies to public bodies and private organisations providing services classified as essential. The statutory list includes electricity, fuel, water, sanitation, telecommunications, digital infrastructure, managed IT services, transport, banking, financial services, payment systems, social security, postal services, healthcare and pharmaceutical activity.

ANCI can also identify operators of vital importance. These organisations carry enhanced duties because their disruption could significantly affect public order, safety, health, economic activity or the normal functioning of society.

This classification should be treated as a dependency question, not merely an industry label. A technology supplier may enter the framework because its managed platform supports an essential service, even if the supplier does not present itself as critical infrastructure.

Reporting is a sequence

When a cyberattack or incident may have significant effects, the institution must send an early warning to the National CSIRT within a maximum of three hours after becoming aware of it.

The next stage is generally an update within 72 hours containing an initial assessment of severity and impact and, where available, indicators of compromise. If an operator of vital importance has its essential service affected, that update is due within 24 hours.

A final report follows within 15 calendar days. If the incident is still active, a situation report replaces it and the final report is submitted after the incident has been managed.

The architecture recognises that incident knowledge develops over time. The three-hour warning says that something consequential may be happening. Later reports add analysis. An organisation should not delay the first stage while waiting for a complete root-cause investigation.

Security management becomes an executive duty

The framework is not only a reporting law. Covered organisations must adopt measures to prevent, report and resolve incidents, manage risks and maintain continuity. Operators of vital importance face stronger requirements, including information-security management, continuity and recovery planning, exercises, training and the appointment of a cybersecurity delegate.

The delegate is an organisational interface with ANCI, not a substitute for accountable management. Operational owners still need to maintain controls, fund remediation and accept residual risk.

The supply chain must support the clock

A three-hour alert cannot work if security evidence is scattered across outsourced providers. Contracts and technical integrations should require rapid notification, preserve logs, identify the affected service and communicate mitigation status.

The incident team should have a pre-agreed answer to a difficult question: who is authorised to notify ANCI when senior leadership cannot yet agree on the final severity? The law’s staged model makes it possible to alert early and refine later, but only if governance allows it.

A practical readiness checklist

  • Determine whether the organisation supplies an essential service or supports one as a critical dependency.
  • Identify which entities and systems may be designated as operators of vital importance.
  • Add the three-hour, 24/72-hour and 15-day stages to the incident playbook.
  • Define the event that starts the knowledge clock and record its timestamp.
  • Create Spanish-language templates for each reporting stage.
  • Ensure suppliers can provide usable facts within the first hour.
  • Exercise the cybersecurity delegate, executives, legal team and service owners together.
  • Map the framework to privacy, sector and contractual notification duties.

Chile’s model treats early visibility as a national resilience control. The first report does not need to solve the incident. It needs to make the incident visible soon enough for coordination to matter.

Official sources

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *