Accessibility

Conclusions from the Workshop to Strengthen Regional Cyber Norms Guidance through Practice-Based Approaches and the Case of Ransomware

EU CyberNet and LAC4 co-hosted on 8th July a workshop in New York in the premises of Estonian Mission to the UN to strengthen regional cyber norms guidance through practice-based approaches and the case of ransomware as a side-event of the UN Open-ended Working Group on ICTs together with RUSI, Estonia, Chile and the Dominican Republic.

The workshop aimed to enhance a practice-based and regionally sensitive norms guidance by addressing ransomware incidents in Latin America and the Caribbean. Participants shared experiences to collectively map how this cross-cutting regional concern can inform regional norms guidance.

Representatives of Chile and the Dominican Republic shared lessons from ransomware incidents. Chile detailed its Ministry of Foreign Affairs’ efforts to implement norms of responsible state behavior, focusing on international cooperation and information exchange. The Dominican Republic described their cybersecurity governance model, which enables quick interagency cooperation and collaboration with private sector actors, which crucial in handling major ransomware incidents.

Further insights were provided by representatives from Colombia, Uruguay, and Brazil. Colombia reported their swift and efficient response to ransomware attacks through cooperation with public institutions and private sector actors, emphasizing the importance of establishing incident response protocols and learning from past incidents. Uruguay discussed applying norms of responsible state behavior to ransomware cases, highlighting their participation in the Counter Ransomware Initiative and efforts to strengthen national cybercrime capabilities. Brazil outlined the role of government coordination, describing their Federal Incident Management Networks and special cybercrime directorate that coordinate responses at the state level, and mentioning their National Cybersecurity Council, which includes civil society organizations.

Participants discussed ransomware as an emerging threat to international peace and security, as recognized in the Annual Progress Report of the OEWG. The need for further steps towards a practice-oriented dialogue on how norms connect with such emerging threats was emphasized. It was acknowledged that countries in Latin America and the Caribbean have been dealing with an increasing number of ransomware incidents in recent years, disproportionately impacting governments and critical national infrastructure.

In response, LAC4 highlighted their work in enhancing regional capabilities to combat ransomware through awareness and technical trainings, crisis response, and collaboration at various levels. This ongoing effort by LAC4 serves as a mean to assist countries, underscoring the importance of collective regional efforts to address and mitigate the growing threat of ransomware.

The side-event workshop was organized by EU CyberNet, LAC4, Permanent Mission of Estonia to the United Nation, Ministry of Foreign Affairs of Chile, Ministry of Foreign Affairs of the Dominican Republic and Royal United Services Intitute (RUSI).


Keep reading similar articles
Memorandum of Understanding Between the Andean Community and LAC4

LAC4 and General Secretariat of the Andean Community signed a memorandum of understanding on 13 May 2026 in Lima, Peru that provides a framework for collaboration related to cybersecurity and digital transformation between LAC4 and the Andean Community and its members.

Supporting Cyber Resilience of Electoral Processes in Colombia

LAC4 supported information security and cyber resilience for electoral processes in Colombia with a three-day training for electoral authorities and relevant stakeholders to strengthen the capacity to protect electoral infrastructure, manage cyber risks and respond to incidents during elections ahead of Colombia’s presidential elections at the end of May 2026.

Sharing Best Cybersecurity Practices in Peru

LAC4 organised a training on cybersecurity and cyber hygiene for the staff of the General Secretariat of the Andean Community to improve understanding of modern cybersecurity risks, promoting secure digital practices and enhancing awareness of how cyber incidents can impact organisational operations, reputation and continuity.

Andean Region SME Training Concluded with Self-Reflection for Improving Cyber Resilience

The three-day training for small- and medium enterprises in Andean region concluded with participants’ presentation on how to improve their business resilience.

Day 2 of Andean Region SME Training: Understanding Data Protection and Supply Chain Security

Second day of cybersecurity training for Andean region small- and medium enterprises focused on data protection, Zero Trust principles and supply chain security.

Day 1 of Andean Region SME Training: Building Foundations for Cyber Resilience

First day of the cybersecurity training for Andean region small- and medium enterprises focused on building foundations and understanding of cyber resilience, understanding cyber risks and discussing cyber risk management.