Accessibility

Day 2 of Andean Region SME Training: Understanding Data Protection and Supply Chain Security

Second day of cybersecurity training for Andean region small- and medium enterprises focused on data protection, Zero Trust principles and supply chain security.

Participants discussed protecting data and were introduced to the CIA triad (confidentiality, integrity and availability) as one of the fundamental concepts of information security. Through discussions on protection needs and loss scenarios, participants examined how cybersecurity risks translate into broader business risks, including regulatory violations, operational disruption, reputational damage, financial losses and risks to human health and safety.  A practical exercise challenged participants to assess protection needs within their own organisational contexts by identifying key requirements, analysing possible loss scenarios and determining which assets require the highest level of protection. A key takeaway from the session was the importance of understanding what needs to be protected and why, helping establish a common language between business and technical teams for more effective cybersecurity risk management.  

Participants were introduced to Zero Trust security principles where no used, device or system should be automatically trusted. Unlike traditional perimeter-based security models, Zero Trust continuously verifies every access request through measures such as multi-factor authentication, least privilege access and network segmentation. Session highlighted why this approach is increasingly important for businesses facing modern threats such as phishing, ransomware and supply chain attacks. Participants explored how Zero Trust can help organisations limit the spread of attacks inside networks. For example, preventing a compromised employee account from gaining unrestricted access to sensitive systems or company-wide data while also improving visibility, breach containment and overall organizational resilience.  

A session explained supply chain security and the growing risks organisations face through external supplies, software providers and service partners. Participants discussed how cybercriminals increasingly target supply chains because compromising a single vulnerable supplier can provide access to an entire business ecosystem. Through case studies and practical discussions, the session highlighted the challenges SMEs face, including limited resources, dependence on third-party providers and reduced visibility across supplier networks. Moreover, participants discussed practical steps for improving supply chain security, such as establishing supplier security requirements, conducting risk assessments, implementing multi-factor authentication and limiting supplier access through Zero Trust principles. The importance of continuous monitoring, incident reporting and employee awareness was also emphasised, with participants examining how proactive supplier security policies and automation can help SMEs reduce risks and improve overall resilience against supply chain attacks.  

Additionally, participants reviewed ten rules of cyber hygiene which help to establish regular practices and precautions to maintain digital security. Participants discussed the importance of strong passwords, multi-factor authentication, updating software, caution with external links, data backups and user access.  

The day also included preparations for participants’ final presentations, where groups began outlining business goals, primary loss scenarios and initial security implementation plans, including proposed standards, priorities and first practical steps for improving cybersecurity resilience. 

Training, conducted by EU CyberNet experts Mari Seeba and Milena Patiño Villa, is organised cooperation with the General Secretariat of the Andean Community and the Delegations of the European Union to Bolivia, Colombia, Ecuador and Peru. Training takes place from 11 to 13 May in Lima, Peru.    

Photos: https://www.flickr.com/photos/eucybernet/albums/72177720333581545    


Keep reading similar articles
Cyber Policy Bootcamp Concludes in Santo Domingo, Advancing Regional Dialogue on Cyber Governance and Legislation

The Cyber Policy Bootcamp, held from 9 to 12 June 2026 in Santo Domingo, Dominican Republic, successfully concluded after four days of high-level discussions, technical exchanges and practical sessions dedicated to strengthening cybersecurity governance, policy development and legislative frameworks across Latin America and the Caribbean.

Cyber Policy Bootcamp to Take Place This Week

A four-day Cyber Policy Bootcamp focused on strengthening cybersecurity governance, policy development and legislative frameworks will take place from 9 to 12 June 2026 in Santo Domingo, Dominican Republic.

Supporting Cyber Resilience in Suriname

LAC4, in cooperation with the Ministry of Foreign Affairs, International Trade & Cooperation of the Republic of Suriname organised a specialized 3-day training “Open-Source Security for Implementing Enterprise-Grade Defense for Government Networks” from 3 to 5 June 2026 in Paramaribo, Suriname.

Guyana Joins LAC4

The Cooperative Republic of Guyana on behalf of the Office of the Prime Minister, Hon. Mark Phillips, has become the 19th member of LAC4. Accession ceremony took place on 4 June 2026 in Georgetown, Guyana in the presence of the Prime Minister of the Cooperative Republic of Guyana, the National Data Management Authority, the LAC4 team and the Delegation of the European Union to Guyana.

SME-s Cybersecurity Training Webinars’ Series Concluded

LAC4 and the Chamber of Commerce of Bogota co-organised a webinar series to bolster digital transformation and cyber resilience of small and medium-sized enterprises in Colombia. Over 110 participants took part of the five webinars focused on topics such as cybercrime, artificial intelligence, risk management, social engineering and supply chain.

LAC4 Analysis “A Comparative Legal Analysis of Cybersecurity in LAC Region” Now Available in English

A recently published LAC4 and EU CyberNet comparative legal analysis of cybersecurity in Latin America and the Caribbean, titled “Cybersecurity in Latin America and the Caribbean: Towards a Legal Architecture and a Common Framework” is now available in English. Analysis has been written by Jersain Zadamig Llamas Covarrubias and César Moliné Rodríguez, and reviewed by Juan Pablo González Gutiérrez.