Accessibility

Critical Information Infrastructure Protection in Focus for Panama

On 8 July, an online seminar organized by LAC4 in collaboration with the Panama National Authority for Government Innovation was held to support members of the Panama Government in defining, identifying, and protecting Critical Information Infrastructures (CII). Led by Perit Kirkmann-Raave, a CIIP Lead Expert at the National Cyber Security Centre of Estonia (NCSC-EE), the session brought together 47 participants from key Panama institutions.

The workshop opened with remarks from Adolfo Campos, Political Officer at the Delegation of the European Union to Panama, Francisco Guinard, Deputy Administrator General of the Panama National Authority for Government Innovation (AIG) and César Moliné, Regional Director from LAC4.

Throughout the session, the importance of Critical Infrastructures (CI) and the relevance of correctly distinguishing them were analyzed, including Critical Information Infrastructures (CII) as a fundamental part of CI. Specifically, the session focused on effective measures and mechanisms to protect CII, drawing lessons from the European Union’s frameworks and Estonia’s leading practices in the field. The discussions emphasized the importance of a combination of updated regulations and security policies with practical exercises and testing, involving collaboration between public institutions and private sector stakeholders.

Most important take-aways for successful CIIP include:

  • Critical infrastructure is generally thought of as the key systems, services and functions whose disruption or destruction would have a debilitating impact on public health and safety, commerce, and national security or any combination of those matters.
  • It’s crucial to identify and prioritize truly essential services; trying to protect everything equally can dilute resources and jeopardize the most critical systems.
  • Modernised cybersecurity laws and regulations are fundamental for safeguarding national networks and infrastructures.
  • Understanding how critical infrastructures support key societal functions, like public health, the economy, and national security, helps prioritize efforts, especially for high-impact entities.
  • Providers must conduct risk assessments as a mandatory part of their responsibilities. The state may review these processes to ensure they are properly carried out in accordance with applicable laws.
  • Clear, well-defined response plans are essential to prevent disruptions from escalating into crises.
  • CII operators must remain accountable for the full infrastructure, including outsourced components.
  • Governments must not only create targeted policies but also foster the use of advanced, efficient technologies to secure CII.
  • Adopting an information security standard provides a reliable roadmap for meeting baseline cybersecurity requirements.
  • CII protection should be based on four core principles: operator accountability, risk-based defenses, impact mitigation, and strong collaboration across sectors.
  • CIIP is a shared duty between public institutions and the private sector.
  • A successful protection strategy requires adequate resources, qualified personnel, robust processes, and suitable technology.
  • Regular tabletop and real-time (live-fire) exercises are essential for testing and improving cyber response readiness.
  • Penetration testing plays a key role in uncovering critical vulnerabilities in CIIs.
  • In case of incidents, forensic capabilities, including malware detection and tailed reports, are needed for thorough analysis and recovery.
  • Assigning a designated point of contact in each essential service streamlines coordination during a cyberattack.
  • Ongoing information sharing, through reports or events, on evolving threats and cybersecurity practices is vital for keeping defenses current.

Keep reading similar articles
Her CyberTracks Concluded with Practical Workshop in the Dominican Republic

The 4th edition of Her CyberTracks initiative concluded in Santo Domingo, the Dominican Republic with a five day workshop taking place from 17 to 21 August 2026, bringing together 17 participants from 12 countries to improve their cybersecurity incident response skills and knowledge.

Her CyberTracks Continues This Week in the Dominican Republic

The 4th edition of Her CyberTracks initiative, co-organised by LAC4 and partners continues with Her CyberTracks: Women in CyberTech Camp@LAC4 this week in LAC4 Centre in Santo Domingo, the Dominican Republic. Taking place from 17 to 21 August 2026, it brings together 17 participants from 12 countries to improve their cybersecurity incident response skills and knowledge.

LAC4 Participated in the Launch of the Cyber Cluster Global Alliance and the EU-LAC Digital Alliance Technical Exchange Visit in Costa Rica

LAC4 in cooperation with EU CyberNet participated in the EU-LAC Digital Alliance technical exchange visit on cybersecurity and secure connectivity in Central America and the Cybersec Summit 2026, held in San José, Costa Rica on 11-12 August 2026.

Members-Only Seminar: Project Glasswing & the Frontier of AI — The New Approach to Security

The 12th members-only seminar, organised in partnership with Palo Alto Networks and titled “Project Glasswing & the Frontier of AI — The New Approach to Security” took place on Wednesday, 12th August, bringing together 147 stakeholders and decision-makers from LAC4 member countries.

Inspiring the Next Generation of Cyber Talent from Fiji and the Bahamas

EU CyberNet, in cooperation with LAC4, supported the participation of teams from Fiji and the Bahamas in the 4th edition of annual international CyberWizards Summer Camp 2026 in Estonia, an initiative dedicated to introducing girls aged 13-16 to cybersecurity and coding.

Minister of Justice and Digital Affairs Visited LAC4 Centre

LAC4 centre received Ms Liisa-Ly Pakosta, the Minister of Justice and Digital Affairs of Estonia during her official visit to the Dominican Republic.