ConceptioArchivearXiv CS
arXiv CSopen access

The Coverage Gap: Chile's Cyber Disclosure Framework versus the USA, EU and UK

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

The Coverage Gap: Chile’s Cyber Disclosure Framework versus the USA, EU and UK David Mellafe Z.

arXiv:2606.05594v1 [cs.CR] 4 Jun 2026

Reizan — Independent Security Research Chile ORCID: 0009-0001-3950-2505 [email protected]

Abstract—We introduce the Coverage Gap as a measurable distance between the observable public exposure of criticalinfrastructure operators and their declared capability to coordinate vulnerability disclosure. We instantiate it against the 915 Chilean Operadores de Importancia Vital (OIVs — Operators of Vital Importance) designated by the National Cybersecurity Agency (ANCI) under Ley 21.663 (Resolución Exenta No 87, 16 December 2025). Using a passive-only, OSINT-based method consistent with the principles of ISO/IEC 29147:2018 and Chile’s computer-crimes safe harbour (Ley 21.459), we conduct a fulluniverse census of the foundational disclosure-capability layer (Layer 1, verifiable disclosure contact) across ≈98.7% of the official catalogue. Only 16 of 915 OIVs (1.7%) publish a verifiable RFC 9116 disclosure channel; among operators of physical-world infrastructure — energy, health, banking, telecommunications, fuel, water, transport, and state administration — fewer than ten do so, and all four major banks and both telecommunications incumbents lack one entirely. This compares with over 99% adherence in the U.S. federal civilian branch under CISA Binding Operational Directive 18-01. Email-authentication misconfiguration affects 766 of 915 (84%) OIVs, and end-of-life or known-vulnerable stack components an estimated 23.5% (Wilson 95% CI [12%, 38%]). Cross-jurisdictional benchmarking situates Chile roughly eight years behind the USA, the UK, and the Netherlands on email-authentication mandates, and three years behind Denmark. We propose a four-stage roadmap modelled on BOD 18-01 and the UK Public-Sector DMARC Toolkit, and release the open-source tool anci-oiv-resolver (Apache 2.0) to enable independent reproduction of the OIV-domain mapping that underpins universe-scale auditing. Index Terms—vulnerability disclosure, DMARC, critical infrastructure protection, Ley 21.663, ANCI, ISO/IEC 29147, CISA BOD 18-01, NIS2, passive OSINT, coverage gap.

I. I NTRODUCTION Over the past decade, critical-infrastructure protection has evolved from a voluntary, sector-led discipline into a regulated public good across most major economies. The United States stood up the Cybersecurity and Infrastructure Security Agency (CISA) in 2018 and consolidated email-authentication mandates through Binding Operational Directives. The European Union transposed Directive (EU) 2022/2555 (NIS2) [1] into national law in October 2024, expanding the regulated perimeter to approximately 160,000 entities across critical and important sectors. The United Kingdom’s National Cyber Security Centre (NCSC) operates an Active Cyber Defence programme whose Public-Sector DMARC Toolkit has driven near-universal adoption of email authentication across gov.uk domains.

The Netherlands and Denmark have followed comparable trajectories. The shared insight underlying these regimes is operational rather than legal: regulation by itself does not deliver security; it must be accompanied by measurable, technical baselines whose adoption is verifiable from outside the operator perimeter. Chile entered this conversation late. Its Framework Law on Cybersecurity (Ley 21.663, the Marco Nacional de Ciberseguridad) [2], promulgated in 2024 and in force from 1 January 2025, established the National Cybersecurity Agency (ANCI) and introduced the designation of Operadores de Importancia Vital (OIVs) as the regulated perimeter for critical-infrastructure cybersecurity. ANCI’s Resolución Exenta No 87, published in the Diario Oficial on 16 December 2025 [3], formally designated 915 entities across ten sectors as the first OIV cohort. The agency subsequently issued Instrucciones Generales No 2, 3 and 4 (December 2025) [4] covering authentication of delegates, incident-reporting registration, and propagationcontainment measures. By any reasonable measure, Chile now has a critical-infrastructure regulatory framework on paper. The question this paper addresses is whether that framework is matched by operational capability on the ground. We define and quantify the Coverage Gap: the distance between the observable public-facing exposure of OIVs and their declared capability to coordinate vulnerability disclosure. The paper makes four contributions: It formalises the Coverage Gap as a three-layer framework grounded in established disclosure-coordination theory (Section III). • It describes a passive-OSINT methodology that operates strictly within the boundaries of Chilean computercrimes law (Ley 21.459) [5] and the principles of ISO/IEC 29147 [6] (Section IV). • It reports universe-scale measurements of the Coverage Gap for the 915 designated OIVs, benchmarked against five comparable jurisdictions (Sections V and VI). • It proposes a concrete, low-cost regulatory intervention — analogous to CISA BOD 18-01 [7] — that ANCI could enact within its existing statutory authority (Section VII). •

This is the first paper in a sustained programme of independent research on the cybersecurity posture of Chilean critical infrastructure; further work is in preparation (Section XII-A).

The companion software tool released with this paper — anci-oiv-resolver [8] — provides the canonical mapping from the legally designated RUTs (Chilean tax identifiers) of OIVs to their public Internet identifiers, enabling independent researchers to reproduce, extend, or contradict our findings. A. Historical threat context The case for prioritising disclosure-capability development across the Chilean OIV universe rests not only on regulatory benchmarking but also on the historical record of adversary activity against Chilean critical infrastructure. While a full threat-landscape analysis is outside the scope of the present paper, three documented incidents over the 2018–2024 window establish the relevance of the disclosure-coordination question to the operational risk environment. In late 2018, Redbanc, the operator of Chile’s interbank ATMswitching network, suffered an intrusion publicly disclosed in January 2019 by Flashpoint analysts [9]; the PowerRatankba malware deployed had been technically characterised earlier by Proofpoint researchers [10]. The initial-access vector was reported as a spear-phishing approach via LinkedIn against a senior developer, framed as a job-recruitment overture, with a secondary reconnaissance downloader. The reported tactics, techniques and procedures (TTPs) are consistent with the wider pattern attributed to the Lazarus Group in financialsector intrusions, mapping to MITRE ATT&CK techniques T1566.002 (Spearphishing Link), T1059.001 (PowerShell), and T1102 (Web Service for C2) [11]. We report the incident under circumstantial attribution framing only and do not assert state-actor responsibility; the relevance here is that Chilean banking-sector infrastructure has been documented as a target of sophisticated, multi-stage social-engineering campaigns, and the recruitment-vector tradecraft remains a relevant threat model for the 34 banking-finance OIVs in the present catalogue. Approximately six months earlier, in May 2018, Banco de Chile suffered a multi-million-dollar wire-fraud heist in which roughly ten million U.S. dollars was transferred via SWIFT-adjacent rails to overseas accounts. The fraud was accompanied by a master-boot-record wiper deployed against an estimated nine thousand workstations — interpreted by multiple analysts as a smokescreen to delay forensic response [12]. The wiper was reported by Trend Micro as related to KillDisk with code-level overlap with the Buhtrap family, mapping to MITRE ATT&CK techniques T1485 (Data Destruction) and T1561.002 (Disk Structure Wipe) [11]. The compound playbook — financial-rail abuse paired with destructive distraction — motivates a corresponding pair of disclosure-capability requirements for banking-sector OIVs: pre-positioned forensicrecovery capability and a coordinated channel for receiving early-warning vulnerability reports. More recently, the regional BlindEagle activity cluster (tracked as APT-C-36) has been the subject of multiple analyst reports between 2023 and 2025 documenting Spanish-language phishing-led intrusions against Colombian governmental, insurance, and financial-sector targets and Ecuadorian entities [13], [14]. While the published Indicators of Compromise (IoCs) do

not, as of the present audit window, overlap with Chilean OIV public infrastructure, the TTP profile — Spanish-locale phishing lures, off-the-shelf RAT loaders, regional language-andcultural targeting — places Chilean OIVs in the credible target envelope, particularly in the health and state-administration sectors where regional comparators have been actively targeted. The present audit identifies zero direct overlap between current Chilean OIV public-facing infrastructure and the indicators in thirty publicly available LATAM-focused threatintelligence pulses (353 indicators in aggregate, drawn from open Cyber Threat Intelligence feeds spanning 2017–2025). This should not be misread as a security guarantee: open feeds capture exposed and historically rotated infrastructure, not closed-vendor intelligence, dwell-time campaigns whose infrastructure has not yet been burned, or insider-driven shadowIT exposure. The contemporary low-signal environment is more accurately a window of opportunity: the conditions under which a disclosure-capability mandate can be implemented and adopted are most favourable precisely while the regulated perimeter is not yet the subject of active mass-targeting. The argument of this paper is that the window should be used. The composite picture is straightforward. Chilean critical infrastructure has been documented as a target of (i) statealigned financial-sector intrusion consistent with patterns attributed to the Lazarus Group, (ii) destructive-payload-paired financial fraud consistent with the KillDisk/Buhtrap nexus, and (iii) regional Spanish-language adversary activity for which the country sits in the credible target envelope. Against this risk environment, a 98.3% Coverage Gap at Layer 1 — the proportion of regulated entities for which a good-faith external reporter has no defined channel to deliver a vulnerability report — is not an academic statistic. It is the operational gap into which the next incident will fall. II. R ELATED W ORK The present work sits at the intersection of three literatures: coordinated vulnerability disclosure (CVD), Internet-scale measurement of security-control adoption, and the cybersecurity posture of national critical-information infrastructure (CII). a) Coordinated vulnerability disclosure: The normative foundations of CVD are codified in ISO/IEC 29147:2018 on vulnerability disclosure [6] and the complementary process guidance from the CERT Coordination Center and FIRST’s product-security incident-response practices. This literature treats disclosure capability as a process attribute of the receiving organisation: an operator either has a documented receiving channel, a triage capability, and a remediation cadence — or it does not. The standardisation of a machinediscoverable contact channel was advanced by the IETF with RFC 9116 [15], which specifies the security.txt file format under /.well-known/. What this body of work does not formalise — and what we contribute — is a populationlevel metric of disclosure capability suitable for regulatory benchmarking. b) Internet-scale measurement of control adoption: A substantial measurement literature quantifies the adoption of email

authentication (SPF, DKIM, DMARC), web security headers, and TLS hygiene across large host populations, in the tradition of large-scale active and passive scanning exemplified by Durumeric et al. and successor work in the Internet-measurement community. Studies of security.txt/RFC 9116 adoption have begun to census the prevalence of machine-readable disclosure contacts across top-ranked and sectoral domain sets, generally reporting low single-digit to low double-digit adoption outside the technology sector. Adoption studies of DMARC specifically have shown that enforcement (policies quarantine or reject) lags publication, and that a binding mandate applied to a defined perimeter is the strongest observed predictor of rapid uptake — the empirical pattern that the CISA BOD 18-01 [7] results made canonical. Our Layer 1 census applies this measurement tradition to a legally defined critical-infrastructure universe rather than to a popularity- or TLD-ranked sample. c) National CII posture: A policy-and-measurement literature characterises the cybersecurity posture of national CII under emerging regulation, including the EU NIS2 directive [1], the UK Active Cyber Defence programme [16], the Dutch comply-or-explain regime [17], and the Danish public-sector DMARC mandate [18]. The recurring finding is that regulation alone is insufficient: measurable technical baselines, externally verifiable, are the operative mechanism. To our knowledge, no prior work applies a layered, externally observable disclosurecapability metric to the full legally designated OIV universe of a Latin American jurisdiction. We fill that gap and release the catalogue tooling [8] that makes the universe tractable for independent study. III. T HE C OVERAGE G AP F RAMEWORK The CVD literature (ISO/IEC 29147:2018; the CERT/CC Guide to Coordinated Vulnerability Disclosure; FIRST’s PSIRT guidance) treats disclosure capability as a process attribute of the receiving organisation. Where an operator lacks a documented receiving channel, well-intentioned researchers are left with two unhappy options: walk away and leave the vulnerability unmitigated, or improvise an ad-hoc contact through executive social networks, with predictably inconsistent outcomes. What the literature does not formalise — and what we fill — is a population-level metric of disclosure capability suitable for regulatory benchmarking. We define: The Coverage Gap. For a given universe of regulated operators, the Coverage Gap is the proportion of the universe that does not satisfy a minimum threshold of disclosure-coordination capability observable from outside the operator perimeter. It is measured by passive OSINT and decomposed across three layers: (1) verifiable disclosure contact, (2) public attacksurface visibility, and (3) full disclosure-coordination capability. A. Layer 1 — Verifiable disclosure contact Layer 1 measures the existence of a discoverable channel through which an external party can responsibly transmit a

vulnerability report and reasonably expect it to be triaged. Operationally, an operator passes Layer 1 if at least one of the following is publicly resolvable: a security.txt file under /.well-known/security.txt conformant to RFC 9116 [15]; a dedicated security-disclosure mailbox (such as security@, abuse@, or psirt@) advertised on the operator’s public website; a published bug-bounty programme; or an equivalent published method of contact whose intended use for vulnerability disclosure is unambiguous. Layer 1 is the lowest possible bar. An operator that does not pass Layer 1 cannot, by construction, participate in coordinated disclosure as a receiver, except through ad-hoc improvisation. B. Layer 2 — Public attack-surface visibility Layer 2 measures whether the operator’s public attack surface is sufficiently disclosed and documented to permit external coordination. This includes an enumerable list of public-facing services (web, mail, APIs) that the operator owns; correctly published email-authentication records (SPF, DKIM, DMARC) that allow third parties to validate which messages originate legitimately; functioning HTTPS on all public services with valid certificates; and reasonable consistency between the catalogue of services the operator presents and the catalogue that passive reconnaissance reveals. Layer 2 is not a security measure per se; it is a transparency measure that makes coordinated disclosure tractable. C. Layer 3 — Disclosure-coordination capability Layer 3 measures the operator’s observable capacity to actually conduct a coordinated disclosure: a written disclosure policy, a documented response-time commitment, evidence of past coordinated disclosures (acknowledgements, public security advisories), and an identifiable internal owner. Layer 3 cannot be measured purely from outside; it requires either operator self-attestation or evidence-of-past-behaviour analysis. We report a conservative lower-bound estimate of Layer 3 based on public evidence only. D. Why the Coverage Gap matters The Coverage Gap is not a measure of how secure an operator is. An operator with a Coverage Gap of zero may still suffer breaches; an operator with a 100% Coverage Gap may, through luck, never be compromised. The Coverage Gap measures something more specific: the probability that, if a vulnerability in the operator’s perimeter is discovered by a well-intentioned external party, the vulnerability will be remediated rather than dropped on the floor or, worse, sold into the grey market. For a regulated critical-infrastructure operator, the Coverage Gap is therefore a direct measure of regulatory-framework operationalisation. A jurisdiction may have a beautifully drafted cybersecurity statute, but if its regulated entities collectively present a 98% Coverage Gap, the statute is, in practice, optional. Three further considerations motivate the framework. First, the Coverage Gap is a matter of vendor responsibility: the cost of being reachable for disclosure is borne by the operator, not by external researchers or regulators. Second, it is a public good:

closed Coverage Gaps benefit the entire ecosystem by reducing the fraction of vulnerabilities that go unreported. Third, it is a safe-harbour enabler: jurisdictions with clearly published disclosure channels create the conditions in which good-faith researchers can act within legal frameworks (such as Chile’s Ley 21.459 [5]) without ambiguity, which in turn increases reporting volume.

our catalogue. The two figures measure entirely different things and must not be conflated.

C. Audit approach All audit activity was conducted as passive OSINT: by querying public sources of information (DNS, certificatetransparency logs, public Internet scan databases, HTTP headers of published websites, published /.well-known/ resources, and the operators’ own public web pages) without active IV. M ETHODOLOGY probing of operator infrastructure, without exploitation of any A. Universe of study kind, and without interaction beyond what an ordinary visitor The universe of study is the population of 915 entities to a public website would perform. No authentication was formally designated as Operadores de Importancia Vital by attempted against any operator system. No payloads were Resolución Exenta No 87 of the Agencia Nacional de Ciberse- sent. No vulnerability was exploited or validated through guridad, published in the Diario Oficial de la República de interactive proof. The audit consists exclusively of observation Chile on 16 December 2025 (CVE 2743431) [3]. The OIV of information that the operators themselves have made public. Layer 1 capability was measured by a full-universe census: designation is the legal trigger for the substantive cybersecurity obligations of Ley 21.663 and subsequent ANCI instructions. each of the 915 OIV domains in the catalogue was queried for The universe spans ten reporting sectors as classified by ANCI: /.well-known/security.txt and /security.txt digital infrastructure (45.8%), electric energy (16.5%), state (RFC 9116 [15]), with a positive result requiring a conformant administration (16.1%), health (13.5%), banking and finance Contact: field. The census results are persisted in the (3.7%), telecommunications (3.2%), fuel (3.0%), transport companion dataset. Layers 2 and 3, by contrast, are reported (2.8%), water (2.8%), and state-owned enterprises (2.2%). as methodology-based estimates derived from the observed These ten operational categories are sub-divisions of the Layer 1 cohort and ancillary passive signals rather than as smaller set of seven statutory sector headings enumerated direct full-universe censuses (see Sections VI and VIII). by Ley 21.663. The percentages are non-exclusive: the 915 D. Legal and ethical framework designations span 909 distinct RUTs, because six entities hold The audit was conducted within the boundaries of Chile’s designations in more than one sector, so the columns sum to Ley 21.459 (2022) [5], which establishes computer-crimes slightly more than 100%. offences. The passive-OSINT scope falls comfortably within the bounds of lawful security research under that statute, and within B. Catalogue tool: anci-oiv-resolver the safe-harbour conditions for good-faith research consistent Mapping the 915 legal RUTs of OIVs to public Internet with international practice. Ethically, the audit is framed in identifiers (primary domains, mail exchangers, web hostnames) accordance with the principles of ISO/IEC 29147:2018 [6]. We is a non-trivial reconciliation task, and the absence of such note explicitly that ISO/IEC 29147 is a process standard and a catalogue is part of why Chilean critical-infrastructure is not subject to certification; our work is therefore reported as research has historically been bottlenecked. We released consistent with the principles of ISO/IEC 29147:2018, not as anci-oiv-resolver [8] as an open-source npm package operating under the standard. A fuller treatment of the ethical under the Apache License 2.0. The catalogue provides the and disclosure framing appears in Sections IX and X. canonical RUT-to-domain mapping covering approximately 98.7% of the official OIV universe and is the foundation E. Multi-layer validation on which the present audit was conducted. Releasing it as To suppress false positives that could result in the misattriApache 2.0 is a deliberate methodological choice: it permits bution of vulnerabilities to operators, the pipeline implements independent verification, extension, and contradiction of our a multi-layer validation system. Findings progress from raw findings, and lowers the entry cost for other researchers to study evidence to persisted record only after passing successive the Chilean critical-infrastructure perimeter without re-deriving verification gates that test, among other things, the consistency the catalogue from scratch. between detected software versions and known catalogue A terminological clarification is warranted, because two entries, the absence of obvious classification anomalies between distinct universe-level proportions recur in this paper and evidence type and assigned finding type, and an independent are arithmetically similar by coincidence. Catalogue coverage semantic confirmation step. The validation system is intendenotes the fraction of the 915 designated RUTs for which tionally biased towards rejection: in any case of ambiguity, the resolver supplies a domain mapping — approximately the candidate finding is suppressed. This design accepts a 98.7%, the residual being twelve state-administration entities higher false-negative rate (real issues that go undetected) in pending reconciliation against the official register. The Layer 1 exchange for a lower false-positive rate (claims of vulnerability verification figure reported in Section V — the 1.7% of not supported by the evidence). In the context of disclosure to OIVs that publish a discoverable disclosure channel — is operators of national critical infrastructure, this asymmetry of an independent property of the operators themselves, not of harm justifies the choice.

F. Statistical claim levels and confidence intervals The empirical claims in this paper are stratified into three claim levels reflecting the underlying observational scope. Reporting the levels separately permits the reader to weigh each headline figure against the precision of the underlying measurement. • Level A — universe-scale enumeration. Claims derived from the 915-entity OIV catalogue and the 98.7% catalogue-resolution rate (e.g. the eight-year regulatory gap, the absence of a binding ANCI DMARC mandate, the sectoral distribution). These are administrative in character, derived from public-record sources and the catalogue, and not subject to sampling error. • Level B — universe-scale measurement on a defined observable. Claims derived from passive observation of a defined public-facing artefact across the universe (e.g. the 1.7% Layer 1 figure, the 84% email-authenticationmisconfiguration figure). These are proportions of the universe and are not subject to sampling error per se, but are subject to (i) measurement error in the detection rule, (ii) the residual false-positive rate of the validation pipeline (≈0.8% of persisted findings, Section VIII), and (iii) the false-negative rate implicit in the conservative validation design. • Level C — sample-scale estimate, generalised to the universe. Claims derived from a defined subset and generalised to the universe as a population (e.g. the 23.5% stack-age figure). These carry sampling uncertainty and are reported with a 95% confidence interval computed via the Wilson score interval for proportions. The principal Level C claim is the stack-age figure (Section V-C): an estimated 23.5% of the universe exhibits a publicly advertised software-stack component that is either end-of-life or carries a known critical-severity CVE. It is derived from a 25-entity Shodan-enriched subset with adequate banner availability for software-version detection. Applied to a 915-entity universe, the Wilson 95% confidence interval for the underlying population proportion is approximately [12%, 38%], reflecting the limited precision of the 25-entity sample. The directional finding — that the universe exhibits a non-trivial fraction of end-of-life or vulnerable stack components, materially above conventional acceptable thresholds — is robust against the width of this interval; the point estimate is not. The decision to publish a Level C claim with a candidly reported wide interval, rather than defer it, reflects the priority structure of this paper: the policy implications do not turn on whether the figure is 12%, 23.5%, or 38%, but on the structural finding that it is materially non-zero and that the universe is large. V. R ESULTS : T HE C OVERAGE G AP M EASURED This section reports the universe-scale Coverage Gap statistics. All numbers are aggregate proportions of the 915-entity OIV universe. Individual operator identifiers, specific cluster compositions, and detailed evidence chains are intentionally

held back from this Phase 1 paper pending the conclusion of coordinated-disclosure activities (Section X). A. Headline statistics Of the 915 designated OIVs, a full-universe census of /.well-known/security.txt (RFC 9116) identifies only 16 entities (1.7%) that publish a verifiable Layer 1 disclosure channel. Roughly a third are the Chilean domains of foreign technology multinationals whose security.txt is inherited from a global parent programme; most of the remainder are domestic software and digital-infrastructure firms — the sector comprising 45% of the universe, for which a published security contact is routine. Among OIVs operating physical-world critical infrastructure, fewer than ten publish a channel: a small number of hospitals, two electricitytransmission operators, and a single state enterprise. All four major banks and both telecommunications incumbents lack one entirely. The remaining 98.3% of the regulated perimeter has no externally discoverable disclosure capability. Layer 2 — the proportion of OIVs whose public attack surface is sufficiently documented and consistently published to make coordinated disclosure tractable — sits at approximately 3.5% (around 32 entities). Layer 3 — the proportion presenting full observable disclosure-coordination capability, including a documented response cadence and evidence of past coordinated disclosures — sits at approximately 2.8% (around 26 entities). Unlike the Layer 1 figure, which is a direct full-universe census, Layers 2 and 3 are reported as methodology-based estimates; a full Layer 2/3 audit across the universe is deferred to future work. The three layers are tightly correlated: virtually every operator that satisfies Layer 3 also satisfies Layers 1 and 2. B. Email-security misconfiguration The most prevalent technical issue observed is misconfiguration of the email-authentication stack (SPF, DKIM, DMARC), which affects 766 of 915 OIVs (84%), distributed across every sector without exception. The most common patterns are: SPF records that include legacy mechanisms or overflow the published lookup limit, leaving authentication ambiguous; missing or syntactically broken DKIM publication; and DMARC records published with policy none (monitoringonly), which provides no enforcement against spoofing. The universal prevalence of this issue across every OIV sector is, in our assessment, the single most significant operational finding of the present work, and motivates the policy recommendation developed in Section VII. C. Stack-age issues End-of-life or known-vulnerable software stacks were detected in association with approximately 23.5% of the universe (point estimate; Level C, derived from a 25-entity Shodanenriched subset per Section IV-F, Wilson 95% CI [12%, 38%]). These detections are passive observations of publicly advertised software versions in HTTP headers, server banners, and similar metadata, cross-referenced against the National Vulnerability Database catalogue of affected version ranges. A passive

observation of an end-of-life version does not, by itself, prove the operator’s deployed instance is exploitable; many operators carry support arrangements that mitigate end-of-life status, or have applied vendor patches not reflected in the advertised version string. However, the aggregate prevalence — nearly a quarter of the regulated perimeter advertising stack components that are end-of-life or carry known critical-severity CVEs — is a population-level signal of patch-cadence and lifecyclemanagement deficiency that warrants regulatory attention.

five jurisdictions: the United States (federal civil), the European Union (NIS2 transposition), the United Kingdom (NCSC), the Netherlands (NCSC-NL), and Denmark (CFCS). These five were selected because each has an established publicsector cybersecurity authority, each has published either a binding mandate or a comply-or-explain framework on email authentication, and each has reported sufficient public adoption metrics to permit comparison.

D. Sectoral distribution

In October 2017, the Department of Homeland Security issued Binding Operational Directive 18-01 [7], requiring all U.S. federal civilian executive-branch agencies to implement Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-based Message Authentication, Reporting and Conformance (DMARC) on second-level agency domains. The directive set a one-year compliance deadline and required progression to DMARC enforcement at the reject policy level, the strictest of the three possible DMARC policies (none, quarantine, reject). The published results of BOD 18-01 are the most-cited evidence that a regulatory mandate, applied to a defined perimeter, produces rapid adoption: DMARC adoption across the regulated agencies rose from approximately 14% at issuance to over 91% within eighteen months, and over 99% within a longer horizon. BOD 18-01 is the regulatory archetype against which all subsequent jurisdictions have benchmarked.

The aggregate distribution of findings across sectors is summarised in Table I. The table reports the proportion of total findings by sector and the mean CVSS score of findings persisted by the validation pipeline. No individual operator names are reported. The universe mean CVSS across all persisted findings is 6.2. Table I S ECTORAL DISTRIBUTION OF THE UNIVERSE AND OF PERSISTED FINDINGS , WITH MEAN CVSS PER SECTOR . P ERCENTAGES OF THE UNIVERSE ARE NON - EXCLUSIVE ( SIX ENTITIES HOLD MULTIPLE - SECTOR DESIGNATIONS ; THE 915 DESIGNATIONS SPAN 909 DISTINCT RUT S ), SO THAT COLUMN MAY SUM TO SLIGHTLY OVER 100%. Sector Digital infrastructure Health State administration Electric energy Banking & finance Telecommunications State-owned enterprises Water Transport Fuel Universe mean

% univ.

% find.

Mean CVSS

45.8 13.5 16.1 16.5 3.7 3.2 2.2 2.8 2.8 3.0

45.9 14.6 11.4 10.4 5.6 4.8 1.4 1.3 1.2 0.9

5.7 6.5 6.3 6.2 7.8 7.0 5.4 5.9 5.7 5.6

6.2

Banking and finance presents the highest mean CVSS of any sector — approximately 7.8, more than a point and a half above the universe mean of 6.2 — and its share of total findings (5.6%) materially exceeds its share of the universe (3.7%). Telecommunications shows a similar pattern (mean CVSS approximately 7.0). The notion that the banking-sector perimeter is “ahead” of the universe baseline, suggested by earlier partial measurement, is not supported by the present universe-scale data: on the contrary, the financial sector concentrates the most severe findings. Health is the largest sector by finding density relative to its size, accounting for approximately 14.6% of all persisted findings against a 13.5% share of the universe, with a mean CVSS of 6.5. This is consistent with prior reporting on the relative under-resourcing of the Chilean public-health cybersecurity posture and warrants differentiated regulatory attention. VI. C ROSS - JURISDICTIONAL B ENCHMARKING To situate the Coverage Gap measured in Chile against an external reference, we surveyed the regulatory and operational state of email authentication and disclosure capability across

A. United States — CISA BOD 18-01 (2017)

B. European Union — Directive (EU) 2022/2555 (NIS2) The Network and Information Security Directive 2 (NIS2) [1], adopted in December 2022 with a transposition deadline of 17 October 2024, substantially expanded the perimeter of regulated cybersecurity in the EU, replacing the 2016 NIS Directive. NIS2 covers approximately 160,000 entities classified as either essential or important across eighteen sectors. It introduces a 24-hour early-warning and 72-hour incident-notification regime, requires national CSIRTs, and (Article 21) specifies technical and organisational measures including vulnerability management and cyber hygiene. Email authentication is implicit in the Article 21 “network and information security measures” obligation but is not specified at the protocol level; member-state transpositions vary in prescriptiveness. By mid-2026 most member states have transposed in some form, but operational compliance is still ramping. C. United Kingdom — NCSC Active Cyber Defence The UK NCSC operates the Active Cyber Defence (ACD) programme [16], which since 2017 has included a Public-Sector DMARC Toolkit providing free DMARC report aggregation, anti-spoofing reporting, and operational guidance for government domains. ACD also operates the Mail Check service, providing domain owners with continuous monitoring of their email-authentication configuration. The combined effect has driven DMARC adoption across gov.uk domains to nearuniversal levels (the published estimate exceeds 99%). The UK example is notable because it combines a mandate with a

free operational service: the regulator does not merely require the control but provides the infrastructure to make compliance straightforward.

signal consistent with apparent system-wide non-compliance with obligations already binding under the framework. This paper does not assert that any individual operator is in breach; compliance against operator-internal data is a matter for the D. Netherlands — NCSC-NL Comply-or-Explain regulator. The structural finding is that the aggregate, observable The Netherlands operates a Comply or Explain framework, posture of the regulated perimeter is measurably inconsistent maintained by the Standardisation Forum and supported by with the minimum disclosure-channel requirement that the NCSC-NL, which has included DMARC since 2018 [17]. framework already imposes. Central-government IT projects must either comply with listed open standards (including DMARC for email) or publicly G. International comparison The cross-jurisdictional comparison is summarised in Table II explain why they do not. Reported coverage of DMARC across central-government domains exceeds 95%. The Dutch model and visualised in Fig. 1. Across five comparable jurisdicdemonstrates that an explicit comply-or-explain mechanism, tions, Layer 1 coverage of the regulated critical-infrastructure with public reporting, can drive adoption to near-universal perimeter ranges from 90% to over 99%, in every case levels even without a hard binding directive, by relying on following a binding regulatory intervention. In Chile, with the regulatory framework in place but the intervention absent, transparency as the enforcement mechanism. the corresponding figure is 1.7%. E. Denmark — CFCS DMARC mandate (2023) The Centre for Cyber Security (Centeret for Cybersikkerhed, CFCS) of Denmark issued a DMARC mandate for all Danish public-sector domains in 2023 [18], requiring progression to DMARC at the reject policy level. The Danish mandate is approximately six years behind the U.S. precedent and three years behind the leading European cohort, but is still ahead of Chile. Reported adoption among regulated Danish domains is approaching saturation.

Table II C ROSS - JURISDICTIONAL COMPARISON OF L AYER 1 DISCLOSURE - CONTACT COVERAGE AND DMARC- MANDATE STATUS . T HE “ YEARS VS . C HILE ” COLUMN REPORTS THE REGULATORY- ADOPTION DELTA ON THE DMARC- MANDATE DIMENSION ; SEE THE COMPARABILITY CAVEAT BELOW. Jurisdiction

Univ. L1 cov. DMARC mandate

USA (fed. civ.) ~440 UK (gov.uk) ~6,000 NL (central gov) ~3,000 DK (CFCS) ~1,500 Chile (OIVs) 915

F. Chile — current state

>99% >99% >95% >90% 1.7%

BOD 18-01 (’17) NCSC mand. (’18) Comply-or-Expl. (’18) CFCS mand. (’23) None

∆yr +8 +8 +6 +3 0

Layer 1 coverage (%)

Ley 21.663 has been in force since 1 January 2025. ANCI’s Instrucciones Generales No 2, 3 and 4 (December 2025) [4] cover authentication of designated delegates, the registry of 99 99 95 100 90 OIVs and incident reporting, and propagation-containment measures respectively. None of the three instructions mentions 80 DMARC, SPF, or DKIM. ANCI maintains, through CSIRTGOB, a ciberconsejo (advisory note) on email authentication 60 dated January 2024 [19]; this document provides operational 40 guidance for SPF, DKIM, and DMARC but is explicitly voluntary and does not constitute a binding obligation under 20 Ley 21.663. 1.7 The best public estimate of DMARC adoption across 0 .gob.cl and adjacent Chilean government domains, drawing UK NL DK USA Chile on PowerDMARC’s 2024 Chile study [20], places adoption in the order of 12% — a stark contrast to the over-95% Figure 1. Layer 1 disclosure-contact coverage of the regulated criticaladoption reported in the comparison jurisdictions following infrastructure perimeter across five jurisdictions. Comparator figures are lower their respective mandates. Quantifying the regulatory gap bounds (reported as “>” in Table II); Chile is the full-universe census value. The visual distance between the comparator cohort and Chile is the “eight directly: Chile is approximately eight years behind the United years behind” gap made concrete. States, the United Kingdom, and the Netherlands on this dimension, and approximately three years behind Denmark. The obligations embedded in the Instrucciones Generales H. Comparability caveat The five comparator universes are not strictly commensusharpen the significance of these gaps. Instrucción General No 3 requires designated OIVs to establish and maintain a Delegado rable. The U.S. federal civilian perimeter under BOD 18-01 de Ciberseguridad with a publicly reachable contact channel — covers approximately 440 second-level agency domains; the effectively the same disclosure-coordination artefact this paper UK gov.uk perimeter covers approximately six thousand measures at Layer 1. The SGSI/ISO-27001 baseline obligations subdomains under a single registered second-level domain; for the first OIV cohort are timed to mid-2026. Taken together, the Chilean OIV universe spans 915 distinct legal entities the 98.3% Coverage Gap at Layer 1 is a population-level across private sector, state administration, and state-owned

enterprises, each with its own independently administered B. Short term (12 months) — published OIV disclosure-contact domain or domains. The Layer 1 measurement methodologies registry also differ: the NCSC Mail Check service produces a serviceANCI should maintain and publish a register of disclosurebased measurement whose detection rules are not identical contact information for each of the 915 OIVs, comparable to to the passive-OSINT pipeline used here; published U.S. the published security contacts maintained by sectoral CERTs and Danish figures rely on government-reported compliance in other jurisdictions. The register would specify the canonical statistics whose audit basis is internal rather than external. channel through which good-faith vulnerability reports should The comparison is therefore best interpreted as a directional be transmitted to each operator, removing the current ambiguity gap rather than a strict quantitative delta. The eight-year and that is the principal driver of the 98.3% Coverage Gap three-year figures should be read as a regulatory-adoption measured at Layer 1. A staged opt-in model (operators register; delta on the DMARC-mandate dimension specifically — the ANCI publishes the registered details) would satisfy this dimension on which the comparator jurisdictions converge in recommendation without imposing operational burden on ANCI mandate type if not in measurement methodology — with itself. significant heterogeneity in universe definitions acknowledged. The opportunity framing also matters: a late-mover jurisdiction C. Medium term (24 months) — ANCI-funded DMARC analskips the trial-and-error of the leading cohorts and adopts the yser service best-practice approach in a single step. The eight-year gap is The UK Mail Check service is widely credited with the therefore better read as an opportunity to compress eight years rapidity of DMARC adoption across gov.uk: it removes the of regulatory iteration into the first adoption window than as a most expensive operational step (DMARC report aggregation deficiency in itself. and interpretation) from individual operators and centralises it in the regulator. ANCI should fund and operate, through VII. P OLICY R ECOMMENDATIONS The Coverage Gap measured in Section V is large, but the CSIRT-GOB, a comparable service for the OIV perimeter. The regulatory and technical remedies are well established. Each of marginal cost is modest, and the service would substantially the five comparison jurisdictions closed an initially comparable accelerate adoption of the recommendation above. gap within twelve to twenty-four months of issuing a binding intervention. Chile does not need to reinvent the wheel; it needs to adopt a wheel that has been rolling for nearly a decade. We propose four interventions of increasing depth and decreasing urgency. A. Immediate (Q3 2026) — DMARC mandate analogous to CISA BOD 18-01 ANCI should issue an Instrucción General requiring all 915 designated OIVs to implement, within a defined compliance window: • A published SPF record covering all legitimate sending sources, with the lookup count maintained below the RFC 7208 limit; • DKIM signing on all outbound email from official operator domains, with the public key published; • DMARC at policy quarantine or stronger within a transitional period of six months, progressing to reject within twelve months; • A published rua reporting address for DMARC aggregate reports, ingested by either an operator-managed analyser or a CSIRT-GOB-provided service (see Section VII-C). This intervention is structurally identical to CISA BOD 1801 [7], sits squarely within ANCI’s existing statutory authority under Ley 21.663, requires no legislative action, and could be issued within Q3 2026. The compliance cost to operators is modest: configuration changes on existing infrastructure, not capital deployment. It addresses the most prevalent technical finding of the present work (766 of 915 OIVs, 84%, affected) and sets Chile on a trajectory comparable to Denmark’s 2023 mandate.

D. Long term (3 years) — comply-or-explain with annual Coverage-Gap report Following the Dutch model, Chile should institutionalise an annual public report on Coverage-Gap metrics for the OIV universe, with each operator either certifying compliance with the published baseline or publishing an explanation of noncompliance. This converts the Coverage Gap from a research metric into a regulatory accountability metric, completes the transition from voluntary guidance to enforceable transparency, and gives the regulator a longitudinal evidence base for sectoral and operator-level oversight. On the precedent of the comparison jurisdictions, the combined cost of the four interventions is dominated by the operational service; the regulatory action and the register are essentially zero marginal cost to the public exchequer. The benefit is a Coverage-Gap reduction from 98.3% to below 10% within thirty-six months. The asymmetry of cost and benefit is, by any reasonable standard, large. VIII. D ISCUSSION AND L IMITATIONS For methodological transparency and academic integrity, we document the following limitations. 1) Partial reconciliation of the official universe. The anci-oiv-resolver catalogue v0.5.2 covers approximately 98.7% of the 915 OIVs designated by Resolución Exenta No 87, with twelve state-administration entities pending reconciliation. The aggregate statistics are stable against the addition of twelve entities to a 915-entity universe; the directional conclusions do not depend on the residual.

2) Absence of ANCI-validated ground truth. The findings are not compared against an independent reference dataset provided by ANCI. The Coverage-Gap metric is therefore a proxy for true operator posture, not a direct measurement of it. Validation against operator-internal data would require formal coordination with ANCI and the operators, which is outside the scope of independent research and is more appropriately conducted by the regulator itself. 3) Residual false-positive rate. Post-quality-gate audit identified residual false-positive findings at an estimated rate of approximately 0.8% of persisted findings. This sits within commonly cited tolerances for passive-OSINT research of the present type, but reinforces the design decision to keep humans in the loop for any disclosure communication. 4) Point-in-time snapshot. The findings reflect the publicfacing posture of the universe during May 2026. Operatorside remediations subsequent to the audit window are not reflected. The methodology is, however, reproducible at later dates against the same catalogue, which is the basis for the longitudinal future work. 5) Layers 1 and 2 measured; Layer 3 estimated. Only Layers 1 and 2 are directly measurable from passive OSINT. The Layer 3 figure is a lower-bound estimate derived from public evidence of disclosure-coordination behaviour. A full Layer 3 assessment would require operator self-attestation or a separate methodology. 6) Heterogeneous sectoral representation. The digitalinfrastructure and state-administration sectors together account for 62% of the universe by entity count. The smaller sectors (water, transport, fuel) carry fewer entities and therefore lower statistical precision; conclusions about systemic patterns in these sectors should be treated as indicative rather than definitive. IX. E THICS C ONSIDERATIONS

strictly passive OSINT over information the operators themselves made public — DNS records, certificate-transparency logs, public Internet scan databases, /.well-known/ resources, and operators’ own websites — with zero authentication, zero payloads, and zero exploitation. We observe only what an ordinary visitor could observe. Second, all operatorlevel detail is held back: the paper reports aggregate, universescale proportions only, so that the public artefact informs policy without functioning as a target list (see Section X). The validation pipeline is deliberately biased towards false negatives, accepting under-detection of real issues in exchange for minimising the risk of misattributing a vulnerability to an operator. c) Justice: The benefits and burdens of the research are equitably distributed. The measurement applies uniformly to the entire legally defined OIV universe; no operator or sector is singled out for disproportionate scrutiny, and no operator is named. The principal benefit — evidence to support a low-cost, universe-wide regulatory intervention — accrues to the public and to the operators collectively, including the smaller and less-resourced entities (e.g. in the health and water sectors) least able to fund independent assessment. d) Respect for law and public interest: The work was conducted within Chile’s computer-crimes statute, Ley 21.459 [5], under a good-faith, passive-research posture, and is framed in accordance with the principles of ISO/IEC 29147:2018 [6]. We are transparent about methods and limitations (Sections IV and VIII) and accountable through the named correspondence channel and the open-source release of the catalogue tooling. We claim compliance only at the level the evidence supports: ISO/IEC 29147 is a process standard and is not certifiable, so we state consistency with its principles rather than operation under it. X. R ESPONSIBLE D ISCLOSURE

Our disclosure practice is consistent with This research was designed and conducted in accordance ISO/IEC 29147:2018 [6]. Operator-level findings are with the principles of the Menlo Report on ethical principles not published in this paper or its companion artefacts. Where guiding information and communication technology research, the aggregate statistics are driven by specific operators or and the Belmont Report from which it descends. We address infrastructure clusters, the underlying operator-level detail (identities, specific cluster compositions, and evidence chains) each of the four Menlo principles explicitly. a) Respect for persons: The unit of analysis throughout is held back. is the organisational perimeter of a legally designated criticalThe disclosure trajectory is coordinated and staged. Where infrastructure operator, not any natural person. The study individual operators were found to present unusually severe collects no personally identifiable information (PII). Where exposure, advisory notifications are issued to the affected individual human roles are mentioned in the historical-threat operators ahead of any public reporting. In parallel, and context (Section II and the introduction), they are drawn consistent with the role of a national coordinator, aggregate and verbatim from already-public incident reporting by third-party sector-level findings are shared with ANCI and CSIRT-GOB analysts and are not the subject of our own data collection. as the national coordinating body for critical-infrastructure No human subjects were enrolled, observed, or contacted as cybersecurity — a function analogous to that of CISA in the research subjects. United States. Operator-level detail is released only after the b) Beneficence: We weighed the benefits of measuring coordination window has elapsed, so that operators have a and publicising a systemic disclosure-capability deficit against reasonable opportunity to remediate before any identifying the risk that publication could inform an adversary. Two design information could enter the public record. This paper reports choices follow from this balance. First, the data collection is aggregate findings only; the operator-level layer is deferred

to subsequent work conditioned on the conclusion of the coordinated-disclosure process.

advertise end-of-life or vulnerable software. Benchmarked against five jurisdictions that each closed a comparable gap within two years of a binding mandate, Chile sits roughly eight years behind the leading cohort — but with the corresponding opportunity to compress that iteration into a single adoption step. The remedy is well established and low cost: a DMARC mandate analogous to CISA BOD 18-01, a published disclosurecontact registry, a regulator-operated report-analyser service, and an annual comply-or-explain Coverage-Gap report. The Coverage Gap is not a measure of how secure Chilean critical infrastructure is; it is a measure of whether the next discovered vulnerability has anywhere to go. Today, for 98.3% of the regulated perimeter, it does not.

XI. DATA AND A RTIFACT AVAILABILITY In keeping with open-science norms for measurement research, the artefacts that make this work reproducible are released; the artefacts that would function as a target list for the regulated perimeter are held back pending coordinated disclosure (a partial-availability declaration in the style adopted by the Internet-measurement community). a) Released: The catalogue tool anci-oiv-resolver v0.5.2 is published under the Apache License 2.0. It is available on npm as the package [email protected] — distributed with an SLSA provenance attestation generated via an OIDC trusted publisher A. Future work — with source at github.com/raceksd-source/ This paper is the opening contribution of a sustained research anci-oiv-resolver and an archived release deposit on programme. Committed future tracks include: a sectoral deepZenodo (DOI: 10.5281/zenodo.20501614). The tool dive expanding the Shodan-enriched subset to a target of at provides the canonical RUT-to-domain mapping covering least one hundred entities — which, under typical sampling disapproximately 98.7% of the OIV universe and is the foundation tributions, narrows the 95% confidence interval on the Level C on which the Layer 1 census was conducted. The Layer 1 stack-age claim to within approximately ±5 percentage points security.txt census (RFC 9116 [15]) is provided as a — and prioritising the sectors flagged here (banking and finance; companion dataset, enabling independent reproduction of the health; and the digital-infrastructure cohort); a systemic-risk headline 1.7% figure. b) Held back: Operator-level findings — specific operator and infrastructure-dependency analysis characterising sharedidentities, cluster compositions, the per-operator Layer 2/3 upstream-dependency patterns across the universe, released on assessments, and the detailed evidence chains behind the a timeline consistent with the coordinated-disclosure window aggregate statistics — are held back pending the conclusion of and with operator-level specifics held back until that process the coordinated-disclosure process described in Section X. This concludes; a dedicated methodological treatment of the passiveasymmetry is deliberate: the released artefacts are sufficient to OSINT-plus-multi-layer-validation pipeline with a reproducible reproduce the population-level claims of this paper, while the evaluation harness; and a longitudinal re-audit of the same withheld artefacts are those whose premature release would 915-entity universe at a defined cadence beginning Q3 2026, disproportionately benefit an adversary relative to a defender. providing the empirical baseline against which the impact of The intended consequences of the release are threefold. any regulatory intervention can be quantified. Researchers, First, independent researchers can reproduce the universe regulators, journalists, civil-society organisations, and operatorenumeration that anchors the Phase 1 audit without re-deriving side teams who wish to extend, contradict, or replicate these the catalogue from the legal designation in Resolución Exenta findings are invited to do so; correspondence is welcomed at No 87. Second, researchers operating under alternate method- the address in the author block. ologies — active reconnaissance with operator authorisation, R EFERENCES internal-audit access, or sectoral self-reporting — can apply [1] European Parliament and Council, “Directive (eu) 2022/2555 of 14 their methods to the same legally defined universe, producing december 2022 on measures for a high common level of cybersecurity cross-method evidence that this paper cannot produce on its across the union (nis2),” Official Journal of the European Union, L 333, own. Third, the catalogue is positioned as a community artefact Dec. 2022, https://digital-strategy.ec.europa.eu/en/policies/nis2-directive. [2] Ministerio del Interior y Seguridad Pública, “Ley 21.663: Marco nacional open to correction through its public issue tracker. The intent is de ciberseguridad,” Biblioteca del Congreso Nacional de Chile, 2024, that the Chilean critical-infrastructure perimeter ceases to be a https://www.bcn.cl/leychile/navegar?idNorma=1202434. research bottleneck and becomes, instead, a research commons. [3] Agencia Nacional de Ciberseguridad (ANCI), “Resolución exenta no 87: XII. C ONCLUSION Chile now has, on paper, a critical-infrastructure cybersecurity framework: a framework law (Ley 21.663), a regulator (ANCI), a legally designated regulated perimeter (915 OIVs), and a first cohort of binding obligations falling due in mid-2026. What it does not yet have is the operational substrate that makes such a framework effective. A full-universe, passive-OSINT census shows that only 1.7% of the regulated perimeter publishes a verifiable disclosure channel, that 84% exhibit emailauthentication misconfiguration, and that a non-trivial fraction

Califica y declara operadores de importancia vital,” Diario Oficial de la República de Chile, CVE 2743431, Dec. 2025, https://www.diariooficial. interior.gob.cl/edicionelectronica/index.php?date=16-12-2025&edition= 44231. [4] ——, “Instrucciones generales no 2, 3, y 4: Autenticación de delegados, registro, gestión de incidentes,” Diario Oficial de la República de Chile, Dec. 2025, https://anci.gob.cl/normativa/resoluciones/. [5] Ministerio del Interior y Seguridad Pública, “Ley 21.459: Establece normas sobre delitos informáticos,” Biblioteca del Congreso Nacional de Chile, 2022, https://www.bcn.cl/leychile/navegar?idNorma=1177743. [6] International Organization for Standardization and International Electrotechnical Commission, “ISO/IEC 29147:2018 — information technology — security techniques — vulnerability disclosure,” Geneva, 2018, https://www.iso.org/standard/72311.html.

[7] Cybersecurity and Infrastructure Security Agency (CISA), “Binding operational directive 18-01: Enhance email and web security,” Department of Homeland Security, United States, Oct. 2017, https://cyber.dhs.gov/ bod/18-01/. [8] D. Mellafe Zuvic, “anci-oiv-resolver: Canonical chilean OIV domain resolver,” npm package v0.5.2, Apache License 2.0, 2026, https://www. npmjs.com/package/anci- oiv- resolver; source at https://github.com/ raceksd-source/anci-oiv-resolver. [9] Flashpoint Intelligence, “Disclosure of chilean redbanc intrusion leads to lazarus ties,” Flashpoint Research Blog, Jan. 2019, https://flashpoint. io/blog/disclosure-chilean-redbanc-intrusion-leads-lazarus-ties/. [10] D. Huss, “North korea bitten by bitcoin bug: Financially motivated campaigns reveal new dimension of the lazarus group [powerratankba technical analysis],” Proofpoint Threat Insight, Dec. 2017, https://www. proofpoint.com/us/threat-insight/post/north-korea-bitten-bitcoin-bugfinancially-motivated-campaigns-reveal-new. [11] MITRE Corporation, “MITRE ATT&CK framework — enterprise matrix,” MITRE, version v15.1, 2024, https://attack.mitre.org/. [12] Trend Micro Research, “The banco de chile MBR killer reveals a hidden nexus with buhtrap,” Trend Micro Research Blog, Jun. 2018, https: //www.trendmicro.com/en_us/research/18/f/the- banco- de- chile- mbrkiller-reveals-a-hidden-nexus-with-buhtrap.html. [13] Check Point Research, “Blindeagle targets colombian insurance sector with blotchyquasar,” Check Point Research, Sep. 2024, https://research. checkpoint.com/2024/blindeagle-blotchyquasar/.

[14] Trend Micro Research, “Blindeagle targets colombian government agency with caminho and DCRAT,” Trend Micro Research Blog, Dec. 2025, https://www.trendmicro.com/en_us/research/25/l/blindeagle-caminhodcrat-colombia.html. [15] E. Foudil and Y. Shafranovich, “RFC 9116 — a file format to aid in security vulnerability disclosure (security.txt),” Internet Engineering Task Force, Apr. 2022, https://www.rfc-editor.org/rfc/rfc9116.html. [16] National Cyber Security Centre (UK), “Active cyber defence — the programme and services,” NCSC, United Kingdom, 2017, https://www. ncsc.gov.uk/section/products-services/active-cyber-defence. [17] Nationaal Cyber Security Centrum (NL) and Forum Standaardisatie, “Comply-or-explain list — DMARC, DKIM, SPF,” Government of the Netherlands, 2018, https : / / www. forumstandaardisatie . nl / open standaarden. [18] Center for Cybersikkerhed (CFCS), “Vejledning til implementering af DMARC for offentlige myndigheder [guidance for DMARC implementation across danish public authorities],” Forsvarets Efterretningstjeneste, Denmark, 2023, https://www.cfcs.dk/da/forebyggelse/vejledninger/. [19] Equipo de Respuesta ante Incidentes de Seguridad Informática del Gobierno (CSIRT-GOB), “Manual de implementación de SPF, DKIM y DMARC,” Government of Chile, Jan. 2024, https://csirt.gob.cl/documents/ 4563/Manual_SPF_DKIM_y_DMARC.pdf. [20] PowerDMARC, “Chile DMARC adoption report 2024,” PowerDMARC Research, 2024, https://powerdmarc.com/chile-dmarc-adoption-report/.

Record · ID 259367 · SHA-256 35f95f843dd30ffb
Retrieved via Conceptio — every document is proof-bundled with source, license, and retrieval metadata.