Accessibility

Critical Information Infrastructure Protection in Focus for Panama

On 8 July, an online seminar organized by LAC4 in collaboration with the Panama National Authority for Government Innovation was held to support members of the Panama Government in defining, identifying, and protecting Critical Information Infrastructures (CII). Led by Perit Kirkmann-Raave, a CIIP Lead Expert at the National Cyber Security Centre of Estonia (NCSC-EE), the session brought together 47 participants from key Panama institutions.

The workshop opened with remarks from Adolfo Campos, Political Officer at the Delegation of the European Union to Panama, Francisco Guinard, Deputy Administrator General of the Panama National Authority for Government Innovation (AIG) and César Moliné, Regional Director from LAC4.

Throughout the session, the importance of Critical Infrastructures (CI) and the relevance of correctly distinguishing them were analyzed, including Critical Information Infrastructures (CII) as a fundamental part of CI. Specifically, the session focused on effective measures and mechanisms to protect CII, drawing lessons from the European Union’s frameworks and Estonia’s leading practices in the field. The discussions emphasized the importance of a combination of updated regulations and security policies with practical exercises and testing, involving collaboration between public institutions and private sector stakeholders.

Most important take-aways for successful CIIP include:

  • Critical infrastructure is generally thought of as the key systems, services and functions whose disruption or destruction would have a debilitating impact on public health and safety, commerce, and national security or any combination of those matters.
  • It’s crucial to identify and prioritize truly essential services; trying to protect everything equally can dilute resources and jeopardize the most critical systems.
  • Modernised cybersecurity laws and regulations are fundamental for safeguarding national networks and infrastructures.
  • Understanding how critical infrastructures support key societal functions, like public health, the economy, and national security, helps prioritize efforts, especially for high-impact entities.
  • Providers must conduct risk assessments as a mandatory part of their responsibilities. The state may review these processes to ensure they are properly carried out in accordance with applicable laws.
  • Clear, well-defined response plans are essential to prevent disruptions from escalating into crises.
  • CII operators must remain accountable for the full infrastructure, including outsourced components.
  • Governments must not only create targeted policies but also foster the use of advanced, efficient technologies to secure CII.
  • Adopting an information security standard provides a reliable roadmap for meeting baseline cybersecurity requirements.
  • CII protection should be based on four core principles: operator accountability, risk-based defenses, impact mitigation, and strong collaboration across sectors.
  • CIIP is a shared duty between public institutions and the private sector.
  • A successful protection strategy requires adequate resources, qualified personnel, robust processes, and suitable technology.
  • Regular tabletop and real-time (live-fire) exercises are essential for testing and improving cyber response readiness.
  • Penetration testing plays a key role in uncovering critical vulnerabilities in CIIs.
  • In case of incidents, forensic capabilities, including malware detection and tailed reports, are needed for thorough analysis and recovery.
  • Assigning a designated point of contact in each essential service streamlines coordination during a cyberattack.
  • Ongoing information sharing, through reports or events, on evolving threats and cybersecurity practices is vital for keeping defenses current.

Keep reading similar articles
Cyber Policy Bootcamp Concludes in Santo Domingo, Advancing Regional Dialogue on Cyber Governance and Legislation

The Cyber Policy Bootcamp, held from 9 to 12 June 2026 in Santo Domingo, Dominican Republic, successfully concluded after four days of high-level discussions, technical exchanges and practical sessions dedicated to strengthening cybersecurity governance, policy development and legislative frameworks across Latin America and the Caribbean.

Cyber Policy Bootcamp to Take Place This Week

A four-day Cyber Policy Bootcamp focused on strengthening cybersecurity governance, policy development and legislative frameworks will take place from 9 to 12 June 2026 in Santo Domingo, Dominican Republic.

Supporting Cyber Resilience in Suriname

LAC4, in cooperation with the Ministry of Foreign Affairs, International Trade & Cooperation of the Republic of Suriname organised a specialized 3-day training “Open-Source Security for Implementing Enterprise-Grade Defense for Government Networks” from 3 to 5 June 2026 in Paramaribo, Suriname.

Guyana Joins LAC4

The Cooperative Republic of Guyana on behalf of the Office of the Prime Minister, Hon. Mark Phillips, has become the 19th member of LAC4. Accession ceremony took place on 4 June 2026 in Georgetown, Guyana in the presence of the Prime Minister of the Cooperative Republic of Guyana, the National Data Management Authority, the LAC4 team and the Delegation of the European Union to Guyana.

SME-s Cybersecurity Training Webinars’ Series Concluded

LAC4 and the Chamber of Commerce of Bogota co-organised a webinar series to bolster digital transformation and cyber resilience of small and medium-sized enterprises in Colombia. Over 110 participants took part of the five webinars focused on topics such as cybercrime, artificial intelligence, risk management, social engineering and supply chain.

LAC4 Analysis “A Comparative Legal Analysis of Cybersecurity in LAC Region” Now Available in English

A recently published LAC4 and EU CyberNet comparative legal analysis of cybersecurity in Latin America and the Caribbean, titled “Cybersecurity in Latin America and the Caribbean: Towards a Legal Architecture and a Common Framework” is now available in English. Analysis has been written by Jersain Zadamig Llamas Covarrubias and César Moliné Rodríguez, and reviewed by Juan Pablo González Gutiérrez.