The Industrial Cybersecurity Center in Colombia

Team

Diego Andrés Zuluaga Urrea

Diego Andrés Zuluaga Urrea, Exc. MBA,CISM,CGEIT,CRISC, GICSP,CDPSE,CCICN ISO 27001 L.A. ISO 22301 I.A. Systems Engineer, Management Specialist and Executive MBA, Internationally certified in ICT risk and management, Privacy, information security and industrial control systems, With more than 20 years of experience in information security, cybersecurity and information systems security. industrial control and Integral Security. He […]

Claudio Caracciolo

He is Head of Platforms, Innovation and Talent. In addition to: General Coordinator for the Industrial Cybersecurity Center for LATAM (CCI-Es.org)· Chief Data Officer (CDO) of Auravant. Specialist Consultant of Information Security passionate about Social Engineering, Industrial Cybersecurity and CarHacking. Lecturer in the Cybersecurity Strategy and Management Diploma at UCEMA. Professor in the Postgraduate Program […]

Mr. Leonardo Huertas Calle, the Industrial Cibersecurity Center Coordinator in Colombia (CCI Coordinators Team), helps us to get in context of the state of the industrial cybersecurity in his country, and to do so, he shares with us his impressions.

He describes the level of sensitivity of industrial organizations in his country according to the following percentages:

He also affirms that the trend of recent years has exponentially grown.

Colombia counts with local and national public bodies promoting an adequate legal framework, in order to ensure the progressive incorporation of industrial cybersecurity measures in national presence companies (mainly critical infrastructure). The main organizations are:

  • Ciber Emergency Response Group of Colombia - colCERT
  • Cyber Joint Command - CCOC
  • Police Cyber Center - CCP
  • MINTICS
  • Ministry of National Defense

Among the main national laws and regulations affecting in this context in Colombia, Leonardo Huertas mentions:

  • CONPES 3701
  • Law 1273 2009
  • Law 1341 2009
  • Law 1621 of 2013 (Legal framework for intelligence functions performance and counterintelligence agencies & Databases Protection)
  • Decree 0032 of 2013 (creation of the Digital National Commission and State Information)

Analysing the most widely adopted industrial cybersecurity measures by Colombian organizations to protect industrial automation systems, Leonardo Huertas highlights the application of:

  • Industrial cybersecurity consulting / advisory
  • Ethical hacking
  • Implementation of safety management systems
  • Internal security audits
  • External security audits
  • Network design and architectures
  • Development of continuity and / or contingency plans
  • Industrial firewalls
  • SIEM (Security information and event management)
  • Industrial applications control

The CCI Coordinator in Colombia characterizes the industrial cybersecurity situation in his country with the following SWOT analysis:

Weaknesses

  • Lack of operational technologies certifications, processes and professionals

  • Lack of specific industry cybersecurity legislation

  • Lack of a solutions and services catalogue of industrial cybersecurity

  • Lack of specific CERTs

Strengths

  • Public organizations driven force (industry, national issues and defence).

  • Awareness, especially regarding industrial critical infrastructures

  • Frequent events and forums on industrial cybersecurity

Threats

  • Slow legislation

  • Shortage of local industrial cybersecurity professionals working for manufacturers

  • Shortage of specific industrial cybersecurity risk management tools

Opportunities

  • Increased of cibersecurity demand for Industry 4.0 and the Internet of things.

Activities

2nd Ibero-American Industrial Cybersecurity Congress: May 27th, 28th, Hotel Dann Carlton, Bogota (Colombia)

After the success of the first Ibero-American Industrial Cybersecurity Congress held in Madrid (Spain) on october 2nd and 3rd, 2013, with almost 200 attendees from different sectors of the industry, which  became the most relevant international reference in industrial cybersecurity during the last year, the Industrial Cybersecurity Center (CCI) organizes the second edition of the […]

CCI collaborates with the Latin America and Caribbean Oil & Gas Security Forum 2015

As a continuation of the collaboration between CCI and IRN, organizer of the event, the Industrial Cybersecurity Center is one of the partners of the next edition of this consolidated forum.

CCI held in Bogotá its first practical course addressed to the Responsible for Cybersecurity in Critical Industrial Infrastructures

CCI has held from November 30 to December 1, in Bogota, its first edition of the workshop to implement an Industrial Cybersecurity Management system based on both a risk analysis and a diagnosis of cybersecurity.

CCI held on November 29 in Colombia the meeting of “La Voz de Industria” with more and more prepared and more mature attendees

The Industrial Cybersecurity Center shared with the attendees a previous study on the recent situation of industrial cybersecurity in Colombia, in its fifth meeting this year in Latin America, which has allowed to know the advances in the Colombian industry in 2017, and its comparison with countries such as Argentina, Chile, Peru and Spain.

Excellent first meeting of The Voice of Industry held in Colombia last November 23

On November 23 we held our first meeting of The Voice of Industry in Latin America, specifically in Bogota (Colombia) as referring industrial site development. At this meeting the results of the Study of Industrial Cybersecurity occurred in Colombia, making an interesting comparison between the results obtained in Spain and Colombia. The full results of […]

How to face risks in the IT-OT Convergence (Ecosystem of Colombia)

In this webinar Diego Zuluaga, CCI coordinator for Colombia, Ignacio Álvarez and Belén Pérez, CCI experts who have participated in the Cybersecurity guide in the Life Cycle of an Industrial Digitization Project, will answer the following questions: – What are the main threats and vulnerabilities in IT-OT convergence? – How to reduce the risks of […]

The II Ibero-American Congress of Industrial Cybersecurity has been listed as “Super” for their organization and expert level

The II Ibero-American Congress of Industrial Cybersecurity has been listed as “Super” for their organization and expert level The conclusion of the Second Latin American Congress of Industrial Cybersecurity has been a success both attendance and content . For the first time in Ibero-American have come together in a common forum , representatives from all […]

XII International Congress of Industrial Cybersecurity in Latin America, celebrated on June 5 and 6, 2019

As a fundamental part of its activity, the Industrial Cybersecurity Center (CCI) celebrated its XII International Congress of Industrial Cybersecurity, in Latin America, one of the reference events for the European market, and a meeting point.

XIV International Congress of Industrial Cybersecurity in Latin America, held from October 27 to 29, in Virtual Format

As a fundamental part of its activity, the Center for Industrial Cybersecurity (CCI) has held its XIV International Congress on Industrial Cybersecurity in Latin America. Reference event for the Latin American market, and a meeting point and exchange of knowledge, experiences and relationships of all the actors involved in this field.

CERT's and CSIRT's from this Country

Argentina

CSIRT NQN

Sitio webWebsite View feed

Argentina

CSIRT Córdoba

Argentina

CERTUNLP

  • Academic
  • Ámbito de aplicaciónScope: IT

Academic Security Incident Response Centre (CSIRT) of the National University of La Plata

Argentina

BA-CSIRT

CSIRT for end users, Cybersecurity Centre of the Government of the Autonomous City of Buenos Aires

Argentina

Cert.ar

Austria

CERT.at

Bahamas

CIRT BS

Sitio webWebsite View feed

Belgium

CERT.BE

Sitio webWebsite View feed

Brazil

CTIR Gov

Centre for Prevention, Treatment and Response to Government Cyber Incidents

Brazil

CERTbr

Sitio webWebsite View feed

Canada

Cyber Centre

Chile

CSIRT Nacional

Article 24 of Law No. 21,663 creates within the National Cybersecurity Agency the National Computer Security Incident Response Team.

Sitio webWebsite View feed

Chile

CSIRT REUNA

  • Academic
  • Ámbito de aplicaciónScope: IT

Chile

CLCERT

  • Academic
  • Ámbito de aplicaciónScope: IT

Colombia

Min Defensa – Policia

  • Government
  • Ámbito de aplicaciónScope: Militar Military

Colombia

CSIRT‑CCIT

Colombia

colCERT

Croatia

CERT.hr

Sitio webWebsite View feed

Cuba

CSIRT-BCF

  • Private
  • Ámbito de aplicaciónScope: IT

Cuba

OSRI

Denmark

Airbus Protect CSIRT

  • OT, Private
  • Ámbito de aplicaciónScope: OT

Denmark

DKCERT

Sitio webWebsite View feed

Ecuador

CSIRT UTPL

  • Academic
  • Ámbito de aplicaciónScope: IT

Ecuador

CSIRT CEDIA

  • Academic
  • Ámbito de aplicaciónScope: IT

Ecuador

EcuCERT

Estonia

EDF CIRC

Sitio webWebsite View feed

Estonia

CERT‑EE

Sitio webWebsite View feed

European Union

ENISA CSIRT Network

The European Union CSIRTs network is a network composed of EU Member States’ appointed CSIRTs and CERT-EU (“CSIRTs network members”). The European Commission participates in the network as an observer.

European Union

EGI CSIRT

European Union

ESA CERT

European Union

EATM‑CERT

European Union

CERT‑EU

Finland

NCSC‑FI

France

PSIRT Scheneider Electric

  • OT, Private
  • Ámbito de aplicaciónScope: OT

France

ENGIE CERT

  • Private
  • Ámbito de aplicaciónScope: IT

France

CERT‑FR

Sitio webWebsite View feed

Germany

PSIRT Siemens

  • OT, Private
  • Ámbito de aplicaciónScope: OT

Guatemala

GT Cert

CERT coordinator of the Republic of Guatemala, covered by the regulatory framework of the Law Against Cybercrime and recognised by FIRST

Honduras

CSIRT_HONDURAS

Italy

Enel CERT

  • Private
  • Ámbito de aplicaciónScope: IT

Jamaica

JaCIRT

Sitio webWebsite View feed

Latvia

CERT.LV

Mexico

UNAM‑CERT

  • Academic
  • Ámbito de aplicaciónScope: IT

Mexico

CERT-MX

Sitio webWebsite View feed

Netherlands

NCSC‑NL

Sitio webWebsite View feed

Norway

NSM‑NCSC

Sitio webWebsite View feed

Panama

CertPA

Sitio webWebsite View feed

Paraguay

CERT-PY

Peru

PeCERT

Poland

CERT.PL

Sitio webWebsite View feed

Portugal

Euronext CSIRT

  • Private
  • Ámbito de aplicaciónScope: IT

Portugal

CNCS Portugal

Republica Dominicana

CSIRT-RD

CSIRT belonging to the National Cybersecurity Centre

Romania

CERT.RO

Sitio webWebsite View feed

Slovakia

ENERGOTEL.SK-CSIRT

  • Private
  • Ámbito de aplicaciónScope: IT

Slovakia

SK‑CERT

Sitio webWebsite View feed

Slovenia

SI‑CERT

Sitio webWebsite View feed

Spain

CSIRT-MIR-PJ

Spain

CSIRT-CV

Spain

INCIBE-CERT

Spain

CSIRT.gal

Spain

CCN‑CERT

Sitio webWebsite View feed

Surinam

SUR-CSIRT

Sitio webWebsite View feed

Sweden

CERT‑SE

Sitio webWebsite View feed

Swiss

PSIRT ABB

  • OT, Private
  • Ámbito de aplicaciónScope: OT
Sitio webWebsite View feed

Swiss

Swiss GovCERT

Sitio webWebsite View feed

Trinidad and Tobago

TT-CSIRT

Sitio webWebsite View feed

Ukraine

CERT‑UA

Sitio webWebsite View feed

United Kingdom

UK NCSC

United States

US-CERT OT Cybersecurity

United States

US-CERT Cybersecurity

Uruguay

CSIRT ANTEL

  • Private
  • Ámbito de aplicaciónScope: IT

Uruguay

Cert.uy

Venezuela

VenCERT

Patrocinadores del Centro en el País

Bronze