Reizan publishes quantitative research on coverage gaps in regulated critical-infrastructure cybersecurity. This page is the single institutional source of truth.
Under open-science principles (CC-BY-4.0) and permanent academic traceability (Zenodo DOI · ORCID). Every paper is reviewable, citable and reusable by regulators, CISOs and academic peers. Complementary open-source tooling under Apache 2.0.
Open Science
Zenodo DOI
CC-BY-4.0
ISO/IEC 29147
Reproducible
§ B · Publications
Research program.
PUBLISHED · OPEN ACCESSZENODO · DOICC-BY-4.0JUN 2026
The Coverage Gap
Chile vs USA · EU · UK · A Quantitative Benchmarking Analysis
METHODOLOGY
A quantitative comparison of coordinated-disclosure frameworks: Chile Law 21.663 · USA CISA · EU NIS2 · UK CyAP. Measurement over the formal OIV universe (915 · ANCI Exempt Resolution 87) from public sources, aligned with ISO/IEC 29147.
Research in progress · publications follow on completion.
Reizan maintains active research in critical-infrastructure cybersecurity. Publications are announced at the moment of publication, not in advance.
Partners or prospective collaborators can receive roadmap detail under NDA · contact [email protected].
§ C · Proprietary methodologies
Coverage Gap Method™ · canonical source.
METHOD · COVERAGE GAP METHOD™
Reizan Coverage Gap Method™
The Coverage Gap Method™ is a framework for quantitatively measuring the observable distance between the public exposure of critical-infrastructure operators and their declared capacity to coordinate vulnerability disclosure. Operationally it is instantiated against the formal universe of state-regulated operators (in Chile: 915 OIVs designated by ANCI under Law 21.663, per Exempt Resolution No. 87 of the Diario Oficial, 16 December 2025).
The methodology relies on public sources, with no authorized system access, aligned with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling). Measurement is reproducible via open-source tooling published under Apache 2.0 (anci-oiv-resolver · latam-oiv-resolver).
The Method is complemented by the Coverage Gap Closure Method™ · an operational closure framework for organizations that have identified gaps through Reizan measurement. Both are original academic contributions from Reizan, published under CC-BY-4.0.
CC-BY-4.0
Reproducible
Public sources
Open science
FRAMEWORK · MATURITY · 10 LAYERS
Reizan Maturity Framework™ · 10 layers
A proprietary ten-layer framework to assess the cybersecurity maturity of regulated critical-infrastructure operators. Each layer is independently measurable and reproducible. Published as an open academic contribution; its integration into assessment engagements is progressive.
Data SovereigntyLaw 19.628 · Law 21.719 · data residency
L8
TelemetryObservability coverage + event retention
L9
Human LayerAwareness + simulated phishing + culture
Trademark notice · Reizan Coverage Gap Method™, Reizan Coverage Gap Closure Method™ and Reizan Maturity Framework™ are unregistered trademarks introduced by Reizan (operated by AlmaAI SpA). The academic text of the framework is under CC-BY-4.0; use of the names requires attribution under the license.
§ D · Research principles
The principles behind the published research.
M.01On public sources. Research relies on publicly accessible information and official registries. No use of credentials · no unauthorized system access.
M.02Aligned with ISO/IEC 29147:2018 + 30111:2019. The coordinated-disclosure process is framed within the principles of ISO/IEC 29147 (vulnerability disclosure) and 30111 (vulnerability handling). A 60–90 day coordination window pre-publish for sensitive findings.
M.03Reproducible and traceable. The paper’s measurements rest on official public catalogs, traceable to regulatory publications (Diario Oficial · exempt resolutions · national registries). Open-source tooling enables independent reproduction.
M.04Open science by default. The method is documented in each paper and published under an open license, so it is reviewable and citable by regulators, CISOs and academic peers.
M.05Jurisdictional safe harbor. All research in Chile is framed within the protection of Law 21.459 (computer crimes · safe harbor for legitimate research). Disclosures coordinated with the National CSIRT / ANCI where applicable.
§ E · Open Science · commitments
Open Science by default.
PAPERS · LICENSE
CC-BY-4.0 universal
All Reizan papers published under Creative Commons Attribution 4.0 International. Free reuse with attribution. No commercial restrictions. No ShareAlike clauses.
Complementary tooling (anci-oiv-resolver · latam-oiv-resolver) published under Apache 2.0. Allows commercial use · modification · distribution · sublicensing.
Traceable public data sources (Diario Oficial · ANCI · BCN · CSIRT). Methodology documented in each paper. Open-source measurement code. Independent third-party reproduction explicitly supported.
COORDINATION
60–90 day window
Sensitive findings enter a 60–90 day coordination window before publication, aligned with ISO/IEC 29147, giving the affected operator time to remediate.
Each paper receives a permanent Zenodo DOI, open-access with no paywall, with incremental versioning (Zenodo assigns DOIs per version). The Coverage Gap study is also available as a preprint on arXiv:2606.05594 [cs.CR].
§ F · Citation and attribution
How to cite Reizan research.
Canonical recommendation: always cite via the permanent Zenodo DOI. The reizan.io/papers page is the single institutional source of truth for citation metadata.
BIBTEX · PUBLISHED
Citation · Coverage Gap
Published on Zenodo · open access · permanent DOI 10.5281/zenodo.20501960. Copy the entry to cite.
@techreport{mellafe2026coveragegap,
author = {Mellafe Zuvic, David},
title = {{The Coverage Gap: Chile's
Cyber Disclosure Framework
vs USA / EU / UK}},
institution = {Reizan · Independent
Security Research},
year = {2026},
month = jun,
doi = {10.5281/zenodo.20501960},
url = {https://doi.org/10.5281/
zenodo.20501960},
note = {CC-BY-4.0}
}
HOW-TO-CITE · GUIDANCE
How to cite tooling and methods
Papers · always cite via the permanent Zenodo DOI (stable canonical link)
Tooling · cite the npm package + specific version (e.g. anci-oiv-resolver v0.5.1)
Methods · when referring to the Coverage Gap Method™ or Maturity Framework™ include the TM symbol and attribute to “Reizan (Mellafe Zuvic, 2026)”
Identifiers appear as resolvable hyperlinks after activation. Live status at /.well-known/security.txt.
PGP · CRYPTOGRAPHIC INTEGRITY
Public key + encrypted channel
Encrypt inbound · live ·public key published today at /pgp.asc to encrypt disclosures via security.txt (RFC 9116)
Sign outbound · forthcoming ·cryptographic signature + SHA-256 hashes of papers and OSS tarballs from the first signed paper
Fingerprint ·public signing record from the first signed paper
Public key available today via /.well-known/security.txt per RFC 9116. Full verification on the integrity portal.
§ H · Acknowledgments and collaborators
Collaborating organizations.
COMING SOON
Credited collaborators
If your organization, regulator, advisor or CSIRT team collaborates with Reizan on research, it will be acknowledged here post-publish with explicit consent and attribution under CC-BY-4.0.
Mentions are added as the corresponding advisories and papers are published. For collaborations, contact [email protected].
§ I · Resources and access
Open research · citable · accessible.
METHODOLOGY · CDP
Coordinated Disclosure Protocol
Reizan’s full coordinated-disclosure process. Aligned with ISO/IEC 29147 · Law 21.459 safe harbor (Chile).