enterprisesecuritymag

Are There Certain Initiatives that May Go a Long Way Toward Strengthening Latin American Cyber Capacity?

Enterprise Security Magazine | Monday, May 02, 2022

Without a doubt, increased investments in human capital would go a long way toward enhancing Latin America's cyber capacity.

FREMONT, CA: Microsoft reported that a Chinese hacker outfit known as NICKEL had targeted vast areas of Latin America's public and private sectors. Before Microsoft disrupted its activities, NICKEL had acquired and kept access to a large number of economically and traditionally valuable targets. The cyber-espionage campaign highlights how foreign powers have substantial interests in Latin America and are eager to gather intelligence to aid endeavors like the Belt and Road Initiative.

While state-sponsored cyberattacks concern Latin American countries, the region's most frequent and severe threat remains cybercrime. Not only have financially motivated gangs targeted organizations across the region, mainly with ransomware, but they have also expanded their operations to a global scale. Latin American countries are strengthening their cyber preparation, as demonstrated by Brazil's publication of its first national cybersecurity policy in 2020. Still, their ability and knowledge remain woefully inadequate to combat the region's panoply of cyber threats.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

While fifteen nations have developed national cybersecurity strategies, considerable work has to be done on cyber capabilities. The region should emulate the success of Israel and South Korea in developing their cyber industry. In this manner, the academic and technological communities can become more specialized in cyber concerns, local firms may expand their competence, and governments can hire and even export the services of local businesses. If Latin America strengthens its cyber capabilities, it may be able to provide enhanced skills and human capabilities to the United States and other developed countries in need of cybersecurity. Additionally, this could have a beneficial effect on social and economic difficulties.

Check Out This: Talent Management Service

A 2020 research conducted by the Inter-American Development Bank (IADB) and the Organization of American States (OAS) found a significant impediment as a lack of trained people capital. The most beneficial investment would be to provide access to American schools and other training institutions for persons from Latin America and the Caribbean to learn cybersecurity methods. As is prevalent throughout the world, educational institutions in the region cannot keep up with demand. As one compelling example, Florida International University in Miami offers continuing education classes in English and Spanish for working hemispheric professionals. The second most effective investment would be for cybersecurity firms to establish regional branch offices. This would offer public and private sector businesses professional cybersecurity capabilities and help create local cyber talent for office employment.

From a policy perspective, there is a need for cyber capacity-building initiatives to bridge the divide between technical security specialists, civil society, and policymakers. Non-state actors, particularly civil society organizations, can and have played a critical role in tracking national policy developments. However, private-sector corporations and governments must be more aware of how civil society is a component of the threat landscape. Human rights defenders should be able to participate in policy discussions and have the tools necessary to protect themselves—regardless of whether they work in cybersecurity.

Education, training, and apprenticeship programs would significantly impact developing capacity, narrowing the cyber skills gap, and increasing the number of people entering the cyber talent pipeline. This might be transformative for both the skills deficit and public awareness of cyber dangers, given the region's experience with cybercrime and fraud during the epidemic.

Without a doubt, increased investments in human capital would go a long way toward enhancing Latin America's cyber capacity. Governments should seek to develop possibilities that connect academic programs and career prospects, such as encouraging graduates to launch new cybersecurity projects, such as collaborative ventures with public institutions at all levels of government. That would be excellent, given the low level of interest in revitalizing decaying yet data-intensive public bureaucracy. The region is youthful, entrepreneurial, and, perhaps most significantly, boasts competitive university programs. These must result in hands-on experience developing and managing cybersecurity capabilities.

More in News

Cybersecurity leaders no longer evaluate multifactor authentication as a narrow login control. It now sits at the center of trust because the network perimeter has been replaced by cloud applications, remote access, mobile users and third-party services. Attackers have adapted. Rather than defeating infrastructure directly, they target the human identity layer through phishing, fake websites, credential reuse, session interception and social engineering. AI has sharpened deception, weakening legacy assumptions about passwords, one-time codes and user vigilance. Traditional MFA can reduce some exposure, but it often preserves the weakness it is meant to protect. A password remains in the path, a user still has to recognize a fraudulent prompt, a code may still be entered into a hostile session and the burden of correctness often sits with the individual. For executives, this is not just a security design problem. It becomes a cost, productivity and confidence problem. Help desks carry reset volume, employees navigate repeated prompts, customers abandon frustrating processes and fraud teams absorb losses when authentication stops at login but fails to control sensitive actions after access is granted. The stronger path removes static credentials from daily use rather than hiding them behind more steps. It should make trust mutual, so the service proves itself to the user before the user approves the session. It should also extend beyond login, because access to payroll, funds transfer, privileged systems or sensitive records requires authorization tied to the verified person, not just an earlier sign-in. Biometric confirmation, device trust, cryptographic validation and context-aware checks matter most when they reduce the chance that a stolen credential, copied website or compromised session can become real damage. Adoption depends just as much on usability. Security teams have spent years asking users to remember, rotate, reset and protect secrets while interpreting security cues under pressure. That model does not scale across banking customers, public-sector users, field employees, shared workstations, legacy applications and VPN access. The right approach should simplify the act of proving identity, accommodate users with different levels of digital confidence and integrate across environments that cannot all be rebuilt. Simplicity is not softness. It is the discipline of reducing unnecessary steps while preserving proof, control and auditability. Executives should also look for coverage that matches enterprise reality. A solution that works only for new cloud applications can leave exposed systems behind. One that requires broad redesign can slow adoption. One that replaces a single password burden with multiple disconnected authentication paths can dilute governance. The benchmark is a consistent identity experience across cloud, desktop, VPN, legacy, shared and constrained environments, backed by implementation support that lets security leaders test, train and expand without disrupting users. PasswordFree© emerges as the premier choice for organizations that want MFA to move from layered passwords toward true password elimination. Its differentiator is full duplex authentication, in which the service validates itself to the user before the user confirms identity through a matched image, short code and biometric approval. That design addresses phishing, imposter websites and one-way code entry. Its website scope reinforces the fit through passwordless authentication, Windows Hello extension and coverage across cloud, desktop, VPN, legacy, shared and airgapped systems. For buyers prioritizing trust, broad reach and user simplicity, PasswordFree© offers the clearest path forward. ...Read more
Risk management once centered on annual assessments, audits and regulatory reviews. That model is becoming harder to maintain as digital systems continue to change, vendors gain access to sensitive environments and new requirements influence how businesses handle information. The challenge is no longer simply identifying risks. Security and compliance teams need to understand which issues could have the greatest impact, whether controls are working and what requires attention first. That requires a broader view of risk across the organization rather than within individual reports or departments. Technology can help bring that information together. Risk platforms, compliance systems and security tools allow teams to track controls, identify gaps and follow issues through remediation. More importantly, they can make risk information part of everyday business decisions rather than something reviewed only during an assessment. Bringing Risk Into Business Decisions Organizations need a clearer understanding of exposure, ownership and controls as security environments become more complex. Connected systems, continuous monitoring and collaboration across teams help businesses identify issues earlier, prioritize action and maintain stronger risk management practices. “ Strong compliance is not created through policies alone. It comes from embedding security awareness, clear ownership and effective controls into the way organizations operate every day. “ Making Compliance Part Of Everyday Operations Organizations need a clearer understanding of exposure, ownership and controls as security environments become more complex. Connected systems, continuous monitoring and collaboration across teams help businesses identify issues earlier, prioritize action and maintain stronger risk management practices. Managing Third-Party And Supply Chain Risk Organizations need a clearer understanding of exposure, ownership and controls as security environments become more complex. Connected systems, continuous monitoring and collaboration across teams help businesses identify issues earlier, prioritize action and maintain stronger risk management practices. Connecting Security, Risk And Compliance Teams Organizations need a clearer understanding of exposure, ownership and controls as security environments become more complex. Connected systems, continuous monitoring and collaboration across teams help businesses identify issues earlier, prioritize action and maintain stronger risk management practices. Building A More Practical Risk Framework Organizations need a clearer understanding of exposure, ownership and controls as security environments become more complex. Connected systems, continuous monitoring and collaboration across teams help businesses identify issues earlier, prioritize action and maintain stronger risk management practices. ...Read more
Digital identity verification across Asia has moved from pilot programs to national infrastructure. Financial institutions, telecom providers, and government agencies now depend on identity systems that can support remote onboarding, cross-sector transactions, and regulatory compliance without introducing new systemic risk. Executives evaluating digital identity solutions must look beyond user experience and cost efficiency toward long-term trust architecture. Systems built around a single database or central authority may appear straightforward, yet concentration of data and control introduces structural vulnerabilities and limits scalability across industries. Sustainable identity infrastructure at the country level requires a model that distributes responsibility while maintaining consistent standards. Institutions must remain accountable to their own regulators, yet interoperate under shared rules that enable trusted data exchange. When identity verification depends on central data aggregation, privacy exposure increases and public confidence can erode. A federated framework, by contrast, allows verified attributes to remain with the original data owners and be exchanged only under explicit, purpose-based consent. This design reduces concentration risk while supporting collaboration among banks, securities firms, asset managers, telecom operators, and public agencies. Interoperability also determines whether digital identity can extend beyond a narrow set of use cases. Common standards and agreed governance processes allow participants to connect without abandoning their existing systems. Trust must be embedded in the rules of participation, onboarding requirements, and compliance monitoring, not improvised at the transaction level. Institutions evaluating providers should examine how members are assessed, how accountability is enforced, and how regulatory oversight is integrated into the platform itself. Without disciplined governance, cross-sector expansion often increases friction rather than reducing it.  Tangible value emerges when identity verification supports high-trust transactions that previously required physical presence. Remote account opening, digital lending, securities trading, and access to public services demand assurance equivalent to in-person verification. The right identity network enables customers who have already been verified by one regulated institution to transact with another without repeating manual checks. This shortens onboarding cycles, lowers administrative costs, and preserves regulatory integrity. Measurable adoption at scale signals that the framework is not confined to controlled pilots but is embedded in daily economic activity. Transaction volumes, the number of usable identities, and the breadth of industry participation offer a clearer indicator of durability than isolated proofof-concept results. Privacy by design has become central to this evaluation. Fraud sophistication and data misuse continue to rise across the region. Identity platforms that position themselves as data repositories inherit a growing risk surface. A model that orchestrates trust without storing personal data limits systemic exposure and reinforces user confidence. For executives responsible for long-term digital strategy, the question is no longer whether identity verification can be digitized, but whether it can be digitized without creating new concentrations of risk.  Within this landscape, NDID stands out as Thailand’s federated digital identity exchange. It operates under a formal license and regulatory oversight, providing shared governance while allowing each member to remain compliant under its own framework. Personal data remains with originating institutions and is exchanged only through clear user consent, positioning the network as a trust orchestrator rather than a data holder.  The platform supports more than 60 million usable digital identities and over 30 million registered accounts, and processes roughly 2 million transactions per month across banking, capital markets, and public services. For executives building cross-sector digital services in Asia, it represents a mature, consent-driven identity foundation anchored in governance, scale, and sustained ecosystem participation. ...Read more
It gets harder to generate and remember strong passwords for every account we use as more businesses require usernames and login information to access their websites. Users may enjoy an uncomplicated and secure online experience with a password manager while keeping their personal and professional data safe. Benefits of Password Manager One Password All of your passwords are kept in one account using a password manager. Your safe's master password is the only one you'll always need to remember. Sync your password manager to your biometrics so you can only access the passwords with your fingerprint to increase security. Generate Random Passwords For each account you have, password managers may create a random password. Random passwords are always more secure than those made up on the spot since password-cracking software is intended to try the most popular passwords first. Simple Access to Multiple Accounts Account login is simple. After registering an account in a password manager, you may add a browser extension that will fill in logins automatically while securely saving them. Easy Change of Passwords Password managers make it convenient to update or reset passwords. Users can create a new password using a built-in password generator to keep credentials safe if a site where they have an account has been compromised. Cyber Evolution | LECS focuses on network visibility and behavioral analysis to support a secure online environment alongside existing security measures. Some password managers offer the option to instantly reset passwords. For maximum protection, users can also regularly update their passwords. Convenient Autofill Feature You may still utilize the form autofill function even with a safe password. Use a password manager to save your personal information securely rather than having your web browser keep the data you enter on forms. Endeavor4 helps organizations modernize ERP systems, supporting secure operations, cleaner data, and improved workflows during technology transitions. Secure Password Sharing Credentials for joint accounts can be shared with family members or co-workers. It's not ideal to reveal your passwords, but if you have shared accounts, a password manager allows you to regulate password access. Store more than Just Passwords Additional data that may be safely saved in your password safe includes responses to security questions, shopping accounts, memberships, and medication data. Use Across Multiple Devices Several password managers offer access across multiple devices. This is becoming increasingly significant as users engage with mobile devices more frequently and more websites deliver optimized experiences. Most password managers also enable app passwords. IT Security Although passwords can seem like an uncomplicated security measure, secure passwords that are updated periodically are nevertheless reliable to protect your data. Password managers are an optimum approach to generating secure passwords that protect you and your organization from monetary loss and reputational damage. ...Read more

Weekly Brief