The Coverage Gap: Chile's Cyber Disclosure Framework versus the USA, EU and UK
This paper identifies a critical "Coverage Gap" in Chile's cybersecurity framework, revealing that only 1.7% of its 915 designated vital infrastructure operators publish verifiable vulnerability disclosure channels—a stark contrast to near-universal compliance in the US and EU—and proposes a four-stage roadmap alongside an open-source tool to bridge this multi-year regulatory lag.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Picture: The "Covered Gap"
Imagine Chile has just built a massive, high-tech fortress to protect its most important buildings (hospitals, banks, power plants, water systems). They have a new law (Ley 21.663) and a new security guard agency (ANCI) to watch over them.
However, this paper asks a simple question: If someone finds a hole in the wall of this fortress, do they know who to call to tell the owners about it?
The authors call this the "Coverage Gap." It's the distance between how visible these buildings are to the public and whether they have a working "Do Not Disturb" sign that says, "If you see a problem, text us here."
The Main Finding: A Silent Fortress
The researchers looked at 915 of these critical organizations (the "OIVs"). They used a method that is like walking down the street looking at the front doors and windows, without ever trying to break in or knock on the door.
Here is what they found:
- The Doorbell is Broken: Only 16 out of 915 (about 1.7%) organizations have a working, public "Do Not Disturb" sign (a specific digital file called
security.txt) that tells researchers how to report a bug. - The Big Players are Silent: None of Chile's four major banks and none of the two biggest phone companies have this sign.
- The Result: If a friendly researcher finds a security hole in 98.3% of these critical systems, they have nowhere to report it. They might just walk away, or worse, the information might get sold to criminals.
The "Email" Problem: The Unlocked Mailbox
The paper also checked if these organizations were protecting their email addresses. Imagine if a bank's email address was written on a piece of paper that anyone could easily fake.
- The Stat: 84% of these organizations have "misconfigured" their email security.
- The Analogy: It's like a bank sending out letters with a return address that anyone can copy-paste. This makes it very easy for scammers to pretend to be the bank and trick people.
- The Comparison: In the USA, UK, and Netherlands, almost 100% of government and critical systems have fixed this. Chile is roughly 8 years behind them on this specific fix.
The "Old Software" Problem: The Rusty Gate
The researchers also peeked at the software these organizations are using.
- The Stat: About 23% of them are using software that is "End of Life" (like a car model that the manufacturer stopped making parts for 10 years ago).
- The Risk: If a hacker finds a way to break that old software, the owners can't get a patch to fix it because the manufacturer stopped supporting it.
How Chile Compares to the World
The authors compared Chile to five other countries (USA, UK, EU, Netherlands, Denmark).
- The Gap: In those countries, the government issued a strict order (a "mandate") saying, "You must fix your email security and post a bug-reporting address." Within a year or two, almost everyone fixed it.
- Chile's Situation: Chile has the law on paper, but they haven't issued the specific order to fix these technical details yet. The authors say Chile is about 8 years behind the leaders in email security and 3 years behind in other areas.
The Proposed Solution: A Simple Roadmap
The paper doesn't suggest building a new, expensive super-system. Instead, it suggests four simple steps that Chile can take immediately, similar to what other countries have already done:
- The "Fix-It" Order: The security agency (ANCI) should issue a simple rule saying, "By next year, every critical organization must fix their email security and post a bug-reporting address." (This is like the US did in 2017).
- The Phone Book: Create a public list where anyone can look up the correct email address to report a bug for any of the 915 organizations.
- The Helper Service: The government should offer a free tool to help organizations check their email settings, so they don't have to hire expensive experts to do it.
- The Annual Report: Every year, publish a report showing who fixed their security and who didn't. If you don't fix it, you have to explain why in public.
The Conclusion
The paper concludes that Chile has the laws and the regulators, but it is missing the operational tools to make them work.
Right now, if a friendly hacker finds a vulnerability in a Chilean hospital or bank, they likely have no way to tell the owners. The "Coverage Gap" is huge. The good news is that the solution is cheap, easy, and already proven to work in other countries. The authors argue that Chile should stop waiting and start fixing these gaps immediately, because the next big cyber-attack will likely happen in that gap.
What the Paper Does Not Say
- It does not say that these organizations were hacked recently. It only says they are currently "unreachable" for reporting problems.
- It does not name specific banks or hospitals in the report to protect them from being targeted by bad actors.
- It does not claim that Chile is "unsafe" in general, but rather that the system for reporting problems is broken.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.