cybersecurity lawregulatory compliancesecurity awareness

    August 20, 2026 · 7 min read · By Fensivo Team

    The LATAM cybersecurity law and the human factor

    Leer en español

    Chile's Framework Cybersecurity Law (Law 21.663) is the first regulation in the region to turn cybersecurity risk management into an enforceable legal duty, backed by a state agency that oversees and sanctions it. For essential service providers and operators of vital importance, that duty includes something that used to be optional: training and raising the awareness of their staff on a continuous basis, because the law recognizes that how people behave is part of the system that must be protected.

    That shift sounds like paperwork and it is not. For years, staff training was the first thing to be cut when budgets tightened, precisely because no one required it. Chile has just moved that piece from the "nice to have" column to the "mandatory" one, and the rest of LATAM is watching closely. It is worth understanding what the law says, who it reaches and, above all, where the trap lies: complying on paper is not the same as reducing risk.

    What the Framework Cybersecurity Law is and who it binds

    Law 21.663 was enacted in April 2024, and its core articles (among them 5, 8 and 9, plus Title VII) took effect on March 1, 2025. The law creates the National Cybersecurity Agency (ANCI), which began operating in early 2025 and is the body that oversees compliance and applies penalties.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    The law does not reach every company in the same way. It binds state agencies, essential service providers and a reinforced category, operators of vital importance (OIV, keeping the Spanish acronym used by Chilean authorities and law firms): public or private entities whose interruption would have a significant effect on national security, public order, the health of the population or the economy. The law demands more from these operators, with one detail worth underlining: the responsibility of the head of the organization cannot be delegated. You cannot outsource the blame to whichever vendor is on hand.

    What it requires in staff awareness and training

    The heart of the obligation is the information security management system, which the law requires organizations to implement and maintain continuously, not as a project that gets closed out. That system includes ongoing risk management, the ability to respond to incidents and the duty to report them to the authority within defined timeframes.

    Within that system, staff training stops being an appendix and becomes part of the structure. The law treats the awareness and training of the team as a component that is planned, executed and documented: failing to keep a record of training actions and programs counts as noncompliance. Put differently, the law does not only ask that people be trained, it asks that you be able to prove it.

    Why the human factor went from optional to legal obligation

    That lawmakers put the focus on people is not a regulatory fashion, it is a reading of the data. Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor, and that proportion explains why no serious cybersecurity regulation can limit itself to firewalls and passwords.

    The channel through which that human factor is exploited is no mystery either. According to CISA, more than 90 percent of successful cyberattacks begin with a phishing email: a message designed to get a person to click, hand over a credential or authorize a payment. By requiring continuous awareness, the Chilean law is codifying what the evidence had been showing for a long time. An organization's largest risk surface is not in its servers, it is in its people's inbox.

    Checking the box on the plan is not the same as reducing risk

    Here comes the uncomfortable part. A legal obligation is met by showing evidence, and the easiest evidence to produce is a record of courses delivered and employees who attended. The risk is real: an organization can have the plan documented, the training logged and the audit in order, and still keep falling for the first well-crafted email.

    This is not our opinion. There is peer-reviewed evidence, from studies published at the IEEE Symposium on Security and Privacy (Ho et al., 2025; Lain et al., 2022), showing that completing training does not by itself predict a reduction in real failures. The conclusion is as simple as it is uncomfortable: having taken the course does not mean behavior changed. And if what the law aims to protect is how people behave under a real attack, measuring attendance to a course measures the wrong thing.

    What a program that validates behavior, not just documents it, looks like

    The way out is not more training, it is closing the loop. A program that actually reduces risk does three things a checkbox plan does not: it exposes the team to realistic simulations of the attack they will actually receive, delivers the training at the exact moment of the failure, and tests again weeks later with a different scenario to confirm that the person learned the lesson and did not just memorize one email. That final test, the retest, is the only one that answers the question that matters: did behavior change or not?

    It is worth noting that this happens in a category that is no longer marginal. According to Mordor Intelligence, the security awareness training market is valued at 6.74 billion dollars in 2026, and small and medium-sized businesses are the fastest-growing segment as cloud delivery lowers cost and deployment barriers.

    Awareness has stopped being an expense reserved for large corporations and become a tool within reach of the mid-sized company, which is precisely the one that now has to answer to the law. (On how to tell a program that changes behavior from one that only fills the report, we wrote in detail in the seven signs your security awareness is just a checkbox and in the human risk business case.)

    The regional picture: what comes after Chile

    Chile opened the door, but it will not be the only country to walk through it. The region already had data protection frameworks and cybersecurity strategies, and the trend points to human risk management, today voluntary across most of LATAM, following the same path it took in Chile: from recommendation to requirement. For a company with regional operations, the strategic reading is clear. Getting ahead of the obligation costs less than reacting to an inspection, and a program that already validates behavior reaches the new rule with the work done, rather than scrambling to document courses at the last minute.

    At Fensivo we build exactly that: a closed loop that monitors exposed credentials, sends personalized phishing simulations by email, trains at the moment of the failure and, weeks later, tests again with a different scenario to validate that behavior changed. We do not promise to make anyone "compliant" with the signing of a contract, because compliance is each organization's responsibility; what we offer is the behavioral evidence that a regulation like this ends up demanding. If your team has between 25 and 500 people, you can see how it applies in our use cases.

    Could your awareness program prove today, with behavioral data, that your people fall for attacks less than they did three months ago, or can it only prove that they took the course?

    Sources and references

    • Biblioteca del Congreso Nacional de Chile, "Ley 21.663 Marco de Ciberseguridad": https://www.bcn.cl/leychile/navegar?idNorma=1202434
    • Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025: https://blogs.cisco.com/security/the-90-5-5-concept-your-key-to-solving-human-risk-in-cybersecurity
    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe": https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe
    • Mordor Intelligence, "Security Awareness Training Market Size & Share Analysis (2026-2031)": https://www.mordorintelligence.com/industry-reports/security-awareness-training-market
    • Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/11023357
    • Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/9833766

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment