State of Cybersecurity in the Americas Each country approaches cybersecurity differently, depending on its prevailing economic, political, and cultural landscape. Some countries primarily see cybersecurity as a national security and defense issue. Others see it as having a greater impact on economic development or international competitiveness. Still others view it as an enabler of education, social interaction, and citizen-centric governance, although many countries are wisely trying to incorporate all of these considerations into their cybersecurity regimes. Despite varied approaches, case studies are emerging that will help all countries more efficiently enhance their cybersecurity policies. Many governments are confronting rapid technological advances with bureaucracies that are slow to adapt, providing hackers and illicit organizations avenues to operate with little worry of prosecution or capture. One of the main impediments to curbing illicit cyber activity in 2012 was the lack of adequate legislation and robust cybersecurity policies. Paired with inexperienced cybercrime investigators and the shortage of prosecutors who specialize in technology-related offenses, many countries are facing difficulties deterring and prosecuting hackers and other cybercriminals. In surveys submitted to the OAS, countries consistently discussed a need for highly skilled professionals who can secure networks, diagnose intrusions, and effectively manage cyber incidents as they unfold. This problem is manifested in the region by low enrollment in technical-degree programs. Given the time it takes to acquire cybersecurity skills and expertise, this low enrollment may have a noticeable impact in the coming years. Compounding difficulties facing incident responders, investigators, prosecutors, and network administrators is the persistently low level of cybersecurity awareness among Internet users. Governments believed that public interest in cybersecurity remained fleeting and inconsistent, and most have yet to implement effective, large-scale awareness-raising campaigns. In any case, the increased frequency of attacks and the associated publicity they received gave rise to changing attitudes and concrete improvements in cybersecurity in the region. While Internet users continue to be largely disengaged from the risks cyberthreats pose, governments are being roused to action and achieving positive results for their efforts. Several countries have adopted comprehensive cybercrime frameworks, taking into account both substantive and procedural laws. Others have expressed interest in adopting such frameworks and have begun to marshal resources and political will to the same end. Even countries with robust legal frameworks, however, continue to face difficulties in implementing and institutionalizing new norms, underlining the crippling effect of low levels of expertise in information security. * Note that the information in this section came from the OAS country surveys. PAGE 18 | Latin American and Caribbean Cybersecurity Trends and Government Responses

Select target paragraph3