Accessibility

Critical Information Infrastructure Protection in Focus for Panama

On 8 July, an online seminar organized by LAC4 in collaboration with the Panama National Authority for Government Innovation was held to support members of the Panama Government in defining, identifying, and protecting Critical Information Infrastructures (CII). Led by Perit Kirkmann-Raave, a CIIP Lead Expert at the National Cyber Security Centre of Estonia (NCSC-EE), the session brought together 47 participants from key Panama institutions.

The workshop opened with remarks from Adolfo Campos, Political Officer at the Delegation of the European Union to Panama, Francisco Guinard, Deputy Administrator General of the Panama National Authority for Government Innovation (AIG) and César Moliné, Regional Director from LAC4.

Throughout the session, the importance of Critical Infrastructures (CI) and the relevance of correctly distinguishing them were analyzed, including Critical Information Infrastructures (CII) as a fundamental part of CI. Specifically, the session focused on effective measures and mechanisms to protect CII, drawing lessons from the European Union’s frameworks and Estonia’s leading practices in the field. The discussions emphasized the importance of a combination of updated regulations and security policies with practical exercises and testing, involving collaboration between public institutions and private sector stakeholders.

Most important take-aways for successful CIIP include:

  • Critical infrastructure is generally thought of as the key systems, services and functions whose disruption or destruction would have a debilitating impact on public health and safety, commerce, and national security or any combination of those matters.
  • It’s crucial to identify and prioritize truly essential services; trying to protect everything equally can dilute resources and jeopardize the most critical systems.
  • Modernised cybersecurity laws and regulations are fundamental for safeguarding national networks and infrastructures.
  • Understanding how critical infrastructures support key societal functions, like public health, the economy, and national security, helps prioritize efforts, especially for high-impact entities.
  • Providers must conduct risk assessments as a mandatory part of their responsibilities. The state may review these processes to ensure they are properly carried out in accordance with applicable laws.
  • Clear, well-defined response plans are essential to prevent disruptions from escalating into crises.
  • CII operators must remain accountable for the full infrastructure, including outsourced components.
  • Governments must not only create targeted policies but also foster the use of advanced, efficient technologies to secure CII.
  • Adopting an information security standard provides a reliable roadmap for meeting baseline cybersecurity requirements.
  • CII protection should be based on four core principles: operator accountability, risk-based defenses, impact mitigation, and strong collaboration across sectors.
  • CIIP is a shared duty between public institutions and the private sector.
  • A successful protection strategy requires adequate resources, qualified personnel, robust processes, and suitable technology.
  • Regular tabletop and real-time (live-fire) exercises are essential for testing and improving cyber response readiness.
  • Penetration testing plays a key role in uncovering critical vulnerabilities in CIIs.
  • In case of incidents, forensic capabilities, including malware detection and tailed reports, are needed for thorough analysis and recovery.
  • Assigning a designated point of contact in each essential service streamlines coordination during a cyberattack.
  • Ongoing information sharing, through reports or events, on evolving threats and cybersecurity practices is vital for keeping defenses current.

Keep reading similar articles
Training “Is Your City Cyber Safe?” Concluded in Montevideo with Practical Exercise

The third and final day of the cybersecurity training for cities in Montevideo, Uruguay focused on understanding practical measures cities can take to strengthen cyber resilience. Practical exercise solidified theoretical knowledge from understanding the evolving cyber threat landscape to building long-term cybersecurity culture and improving urban cyber resilience.

Day 2 of the “Is Your City Cyber Safe?” Training: Turning Gaps into Opportunities for Resilience

The second day of the cybersecurity training for cities in Montevideo, Uruguay focused identifying gaps in urban cybersecurity and exploring how these gaps can be transformed into opportunities for improving cities’ cyber resilience.

Day 1 of the “Is Your City Cyber Safe?” Training: Approach to Urban Cyber Resilience

The first day of the cybersecurity training for cities in Montevideo, Uruguay focused on understanding key components of cyber resilient cities, discussing challenges Southern Cone cities face as well as exploring cybersecurity governance and crisis management practices across the region.

Focus on Cities’ Cybersecurity: Strengthening Cyber Resilience of Latin American Cities

LAC4 in cooperation with partners is organising a 3-day training “Is Your City Cyber Safe” for local authorities of Southern Cone countries Argentina, Brazil, Chile and Uruguay from 4 to 6 March in Montevideo, Uruguay.

Strengthening Cybersecurity Journalism in Latin America and the Caribbean

LAC4 in cooperation with Agency for Electronic Government and Information and Knowledge Society of Uruguay (AGESIC) and the Delegation of the European Union to Uruguay organised a training for journalists in Montevideo, Uruguay from 2 to 3 March 2026. The training, titled “Journalist on the Frontline: Reporting Safely and Accurately on Cyber Incidents” and led by EU CyberNet Experts Carlos Leonardo and Diogo Carapihna, focused on strengthening journalistic capacity among Uruguayan media representatives and journalists to improve understanding, covering and reporting on cybersecurity issues. 

LAC4 Enhances Jamaica’s Cyber Resilience with Advanced Cybersecurity Training

LAC4 organised an online advanced cybersecurity operations training for Jamaica’s public sector cybersecurity professionals from 23 to 26 February. Training focused on building rapid detection, analysis and response capabilities by leveraging open-source tools for threat detection and response.