CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
Identification of Critical Digital Functions Through its December 2025 resolution, ANCI identi - fied 13 specific classes of services or “critical digital functions” that would fall within the scope of the Law. These include: • data hosting and cloud administration (IaaS, PaaS, SaaS); • security operation centres (SOC) and network operation centres (NOC); • cybersecurity incident management and remote monitoring of applications; • advanced electronic signature services and digital payment systems; and • fintechs, points of sale (POS) hardware/software, and commercialised own software. These sub-services are considered critical by ANCI because they often represent a single point of fail - ure for other essential sectors that outsource their technology management. The Agency’s analysis par - ticularly emphasised the “interdependency” criterion, noting that an incident in these digital providers can trigger cascading effects across the entire national infrastructure. Companies classified as OIVs have the option to appeal ANCI’s decision administratively or judicially. On the other hand, the second stage of this initial clas - sification process is expected to be completed during the first half of 2026. 2.2 Critical Infrastructure Cybersecurity Requirements General Obligations for Regulated Entities All institutions covered by the Cybersecurity Frame - work Law, including both essential service providers and OIV, share a core set of duties aimed at preserv - ing the integrity of the national digital ecosystem. These entities must permanently apply technical and organisational measures to prevent, report and resolve cybersecurity incidents. These measures must be consistent with the protocols and standards issued by the ANCI. Accountability begins with the mandatory registration in the ANCI electronic platform. All regulated institu -
tions must designate a specific person in charge of reporting incidents to the CSIRT Nacional . Governance and Accountability for OIVs OIVs must designate a Cybersecurity Delegate who serves as the official technical counterpart to ANCI. General Instruction No 3 specifies that this delegate must have specialised training or certification and a direct reporting line to the institution’s highest author - ity. To ensure objectivity, the delegate must possess func - tional independence from the operational IT depart - ments. The institution must provide the delegate with the necessary faculties and resources to fulfil their legal obligations. Asset Management and Risk Assessment Risk management is a continuous requirement for OIVs, which must implement a formal Information Security Management System (ISMS). This system is used to identify and evaluate the likelihood and potential impact of risks that could affect networks, computer systems and data. OIVs are also required to maintain a detailed record of all security actions that comprise their ISMS. OIVs are also mandated to perform continuous review operations, exercises and simulations to detect actions or programs that might compromise cyber - security. Business Continuity and Disaster Recovery OIVs have an explicit duty to develop and implement operational continuity and cybersecurity plans. These plans must undergo mandatory certification and be reviewed by the entity at least every two years. In the event of a significant incident, OIVs must imple - ment a specific Plan of Action within seven days of becoming aware of the event. This plan must include an information recovery programme, a clear definition of technical and administrative responsibilities, and an estimate of the time required to restore the interrupted services.
63 CHAMBERS.COM
Powered by FlippingBook