Trends Seen General Trends In 2012, governments generally noted an increase in the frequency of cyber incidents compared with 2011, even where definitive quantitative data was incomplete or unavailable. The minimum assessed increase in cyber incidents over the period 2011 to 2012 reported by a government was 8–12%, while on the high end, two others reported an increase of 40%. Most governments cited increases somewhere within this range, although, interestingly, several reported that overall, fewer incidents were detected. In addition to highlighting the varied definitions of cybersecurity terms, interpreting and analyzing the data collected raised other important considerations. Several governments clarified that the numbers they provided did not necessarily reflect real changes in attack frequency, but rather improvements in network monitoring and better trained personnel, which allowed organizations to detect more system breaches and other illicit cyber activities. Interestingly, those countries with recently established national CSIRTs reported some of the most significant increases in managed incidents. These reinforced the notion that attacks had been occurring all along but had simply gone undiscovered or undocumented. Also noteworthy is the fact that most states did not differentiate between the types or severity of the cyber incidents they reported. This presents a shortcoming in data analysis, given the range in potential consequences of different kinds of incidents or attacks—a large-scale and sophisticated attack on national critical infrastructure will likely have a greater impact than the defacement of a government website. Data that did specify attack types was usually aggregated, although in some places, we have been able to display frequencies of the types or severity of attack received. One nascent national CISRT, for example, indicated that it managed 45 incidents in 2012, and deemed only one a “priority” case. Obviously, the cyber incidents about which OAS Member State governments reported represent only a fraction of the total number of incidents and other forms of cybercrime carried out in the region. But collecting data to enable a truly comprehensive and detailed picture of the extent of all such incidents and activities in the Americas and the Caribbean, or anywhere else, remains at this point simply impossible. As stated before, information sharing within governments—even those with the most advanced cybersecurity capabilities—continues to come up short, largely due to the practical realities of multiple organizations having to simultaneously respond to an ever-evolving range of threats and targets. And many private companies and other nongovernmental entities continue to be hesitant to report attacks or breaches. Accounting for the number of incidents affecting individual citizens poses an even greater challenge, given the still higher percentage of these that go undetected and unreported. Finally, a general and persistent lack of collaboration among stakeholders at all levels further complicates the collection of reliable and actionable information on data breaches. The net consequence of all of these factors is a less than adequate awareness of the problem, and the continued vulnerability of critical networks and information systems (IS). PAGE 3 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3