In collaboration with Trend Micro Incorporated, the Organization of American States (OAS) and its Secretariat for Multidimensional Security (SMS) would like to share this report to illustrate the cybersecurity and cybercrime trends in Latin America and the Caribbean. Information presented has been gathered through both quantitative and qualitative methods, drawing data from a survey of OAS member-state governments, as well as an in-depth analysis of global threat intelligence from honeypots and client-provided data collected by Trend Micro. Unless otherwise noted, graphs and tables use data that was collected by Trend Micro. The analysis and conclusions of this report only cover countries that responded to the OAS survey. OAS Country Survey Results The 32 OAS Member States from Latin America and the Caribbean were invited to voluntarily provide information on the types and extent of cybersecurity incidents their countries faced in 2012, as well as their responses to those incidents. Thirteen of the 18 Latin American Member States and seven of the 14 Caribbean Member States subsequently made contributions to this report. Qualitative data was provided by a mix of institutions, most prominently National Computer Security Incident Response Teams (CSIRTs), and to a lesser extent national police cybercrime units. Much of the information gathered is presented here in aggregate form to maintain the confidentiality of certain sensitive findings. And as with any largescale survey of cyber incidents and illicit cyber activity, this effort to collect and analyze such data for the Americas and Caribbean has inherent limitations. For one, no network administrator or national incident response team knows how many incidents succeed and go undetected. Network intrusions are routinely discovered months or even years after the original breach was perpetrated. Furthermore, discussions with participating Member States revealed that a lack of effective communication and information sharing within governments in reporting cyber incidents remains a key challenge. Whether due to interagency competition, concerns about projecting an image of ineffectiveness, or a simple lack of channels or mechanisms necessary for information sharing, failure to exchange information regarding cyber incidents or network security breaches remains a widespread reality that must be taken into account when analyzing data on cyber activity in the region. This study is also limited by a lack of defined and harmonized terminology. Upon analyzing data, it became clear that the term “cyber incident” was not uniformly understood or applied across the region, and it was beyond the scope of this study to urge states to integrate their respective definitions. Some governments interpret a cyber incident as any report or complaint sent to a national response team, while others are more exacting in their classification. Some survey results included incidents levied against the public and private sector as well as end users and academia. Others only included information pertaining to government networks while others still only described cyber incidents involving one or two key ministries. Despite the shortcomings presented by nuances in taxonomy or classification, this report offers an opportunity for governments to present their experiences, both positive and negative, in the hope that they allow relevant stakeholders to gain a better understanding of what is happening in the region, and what remains to be done. PAGE 2 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3