REIZAN · ACADEMIC RESEARCH · CANONICAL

Canonical repository · research-driven · cite-able.

Reizan publishes quantitative research on coverage gaps in regulated critical-infrastructure cybersecurity. This page is the single institutional source of truth.

Under open-science principles (CC-BY-4.0) and permanent academic traceability (Zenodo DOI · ORCID). Every paper is reviewable, citable and reusable by regulators, CISOs and academic peers. Complementary open-source tooling under Apache 2.0.

  • Open Science
  • Zenodo DOI
  • CC-BY-4.0
  • ISO/IEC 29147
  • Reproducible
§ B · Publications

Research program.

PUBLISHED · OPEN ACCESSZENODO · DOICC-BY-4.0JUN 2026

The Coverage Gap

Chile vs USA · EU · UK · A Quantitative Benchmarking Analysis

METHODOLOGY

A quantitative comparison of coordinated-disclosure frameworks: Chile Law 21.663 · USA CISA · EU NIS2 · UK CyAP. Measurement over the formal OIV universe (915 · ANCI Exempt Resolution 87) from public sources, aligned with ISO/IEC 29147.

DOI

10.5281/zenodo.20501960
Zenodo · permanent link · open access.

PLATFORMS

Zenodo · permanent DOI · CC-BY-4.0 license · arXiv:2606.05594 [cs.CR] preprint

Read the paperView on Zenodo ↗Read the summary →
CONTINUED RESEARCH

Research in progress · publications follow on completion.

Reizan maintains active research in critical-infrastructure cybersecurity. Publications are announced at the moment of publication, not in advance.

Partners or prospective collaborators can receive roadmap detail under NDA · contact [email protected].

§ C · Proprietary methodologies

Coverage Gap Method™ · canonical source.

METHOD · COVERAGE GAP METHOD™

Reizan Coverage Gap Method™

The Coverage Gap Method™ is a framework for quantitatively measuring the observable distance between the public exposure of critical-infrastructure operators and their declared capacity to coordinate vulnerability disclosure. Operationally it is instantiated against the formal universe of state-regulated operators (in Chile: 915 OIVs designated by ANCI under Law 21.663, per Exempt Resolution No. 87 of the Diario Oficial, 16 December 2025).

The methodology relies on public sources, with no authorized system access, aligned with ISO/IEC 29147:2018 (vulnerability disclosure) and ISO/IEC 30111:2019 (vulnerability handling). Measurement is reproducible via open-source tooling published under Apache 2.0 (anci-oiv-resolver · latam-oiv-resolver).

The Method is complemented by the Coverage Gap Closure Method™ · an operational closure framework for organizations that have identified gaps through Reizan measurement. Both are original academic contributions from Reizan, published under CC-BY-4.0.

  • CC-BY-4.0
  • Reproducible
  • Public sources
  • Open science
FRAMEWORK · MATURITY · 10 LAYERS

Reizan Maturity Framework™ · 10 layers

A proprietary ten-layer framework to assess the cybersecurity maturity of regulated critical-infrastructure operators. Each layer is independently measurable and reproducible. Published as an open academic contribution; its integration into assessment engagements is progressive.

  1. L0
    ClassificationRegulatory designation + sector classification
  2. L1
    Coverage GapContact + verifiable disclosure channel
  3. L2
    DetectionSIEM + log coverage + operational alerting
  4. L3
    ResponseIR playbook + RACI roles + exercises
  5. L4
    RecoveryBackup + forensic readiness + RPO/RTO
  6. L5
    Supply ChainVendor mapping + critical dependencies
  7. L6
    IdentityIAM + MFA + least privilege
  8. L7
    Data SovereigntyLaw 19.628 · Law 21.719 · data residency
  9. L8
    TelemetryObservability coverage + event retention
  10. L9
    Human LayerAwareness + simulated phishing + culture

Trademark notice · Reizan Coverage Gap Method™, Reizan Coverage Gap Closure Method™ and Reizan Maturity Framework™ are unregistered trademarks introduced by Reizan (operated by AlmaAI SpA). The academic text of the framework is under CC-BY-4.0; use of the names requires attribution under the license.

§ D · Research principles

The principles behind the published research.

  • M.01On public sources. Research relies on publicly accessible information and official registries. No use of credentials · no unauthorized system access.
  • M.02Aligned with ISO/IEC 29147:2018 + 30111:2019. The coordinated-disclosure process is framed within the principles of ISO/IEC 29147 (vulnerability disclosure) and 30111 (vulnerability handling). A 60–90 day coordination window pre-publish for sensitive findings.
  • M.03Reproducible and traceable. The paper’s measurements rest on official public catalogs, traceable to regulatory publications (Diario Oficial · exempt resolutions · national registries). Open-source tooling enables independent reproduction.
  • M.04Open science by default. The method is documented in each paper and published under an open license, so it is reviewable and citable by regulators, CISOs and academic peers.
  • M.05Jurisdictional safe harbor. All research in Chile is framed within the protection of Law 21.459 (computer crimes · safe harbor for legitimate research). Disclosures coordinated with the National CSIRT / ANCI where applicable.
§ E · Open Science · commitments

Open Science by default.

PAPERS · LICENSE
CC-BY-4.0 universal

All Reizan papers published under Creative Commons Attribution 4.0 International. Free reuse with attribution. No commercial restrictions. No ShareAlike clauses.

CC-BY-4.0 ↗
TOOLING · LICENSE
Apache License 2.0

Complementary tooling (anci-oiv-resolver · latam-oiv-resolver) published under Apache 2.0. Allows commercial use · modification · distribution · sublicensing.

Apache 2.0 ↗
REPRODUCIBILITY
Open data and code

Traceable public data sources (Diario Oficial · ANCI · BCN · CSIRT). Methodology documented in each paper. Open-source measurement code. Independent third-party reproduction explicitly supported.

COORDINATION
60–90 day window

Sensitive findings enter a 60–90 day coordination window before publication, aligned with ISO/IEC 29147, giving the affected operator time to remediate.

CDP Protocol →
DOI · OPEN ACCESS
Permanent Zenodo DOI

Each paper receives a permanent Zenodo DOI, open-access with no paywall, with incremental versioning (Zenodo assigns DOIs per version). The Coverage Gap study is also available as a preprint on arXiv:2606.05594 [cs.CR].

§ F · Citation and attribution

How to cite Reizan research.

Canonical recommendation: always cite via the permanent Zenodo DOI. The reizan.io/papers page is the single institutional source of truth for citation metadata.

BIBTEX · PUBLISHED
Citation · Coverage Gap

Published on Zenodo · open access · permanent DOI 10.5281/zenodo.20501960. Copy the entry to cite.

@techreport{mellafe2026coveragegap,
  author      = {Mellafe Zuvic, David},
  title       = {{The Coverage Gap: Chile's
                 Cyber Disclosure Framework
                 vs USA / EU / UK}},
  institution = {Reizan · Independent
                 Security Research},
  year        = {2026},
  month       = jun,
  doi         = {10.5281/zenodo.20501960},
  url         = {https://doi.org/10.5281/
                 zenodo.20501960},
  note        = {CC-BY-4.0}
}
HOW-TO-CITE · GUIDANCE
How to cite tooling and methods
  • Papers · always cite via the permanent Zenodo DOI (stable canonical link)
  • Tooling · cite the npm package + specific version (e.g. anci-oiv-resolver v0.5.1)
  • Methods · when referring to the Coverage Gap Method™ or Maturity Framework™ include the TM symbol and attribute to “Reizan (Mellafe Zuvic, 2026)”
  • Plain · Mellafe Zuvic, D. (2026). Title. Reizan Independent Security Research. https://doi.org/...
§ G · Researcher identity

Identity and verification.

AUTHORSHIP · AFFILIATION
Lead author
  • Name · David Mellafe Zuvic
  • Role · Independent Security Researcher · Founder
  • Affiliation · Reizan · Independent Cybersecurity Research Advisory
  • Legal entity · AlmaAI SpA
  • Jurisdiction · Chile

Personal portfolio · individual contributions: dmzs.dev/research ↗

ORCID · ACADEMIC IDENTITY
Permanent identifiers

Identifiers appear as resolvable hyperlinks after activation. Live status at /.well-known/security.txt.

PGP · CRYPTOGRAPHIC INTEGRITY
Public key + encrypted channel
  • Encrypt inbound · live · public key published today at /pgp.asc to encrypt disclosures via security.txt (RFC 9116)
  • Sign outbound · forthcoming · cryptographic signature + SHA-256 hashes of papers and OSS tarballs from the first signed paper
  • Fingerprint · public signing record from the first signed paper

Public key available today via /.well-known/security.txt per RFC 9116. Full verification on the integrity portal.

§ H · Acknowledgments and collaborators

Collaborating organizations.

COMING SOON
Credited collaborators

If your organization, regulator, advisor or CSIRT team collaborates with Reizan on research, it will be acknowledged here post-publish with explicit consent and attribution under CC-BY-4.0.

Mentions are added as the corresponding advisories and papers are published. For collaborations, contact [email protected].

§ I · Resources and access

Open research · citable · accessible.

METHODOLOGY · CDP
Coordinated Disclosure Protocol

Reizan’s full coordinated-disclosure process. Aligned with ISO/IEC 29147 · Law 21.459 safe harbor (Chile).

View protocol →
COLLABORATE
Collaborate on research

Regulators, CISOs, academic researchers or CSIRT teams who want to take part in validation phases. Explicit acknowledgment in the papers.

[email protected]
OPEN SOURCE · npm
Reizan OSS tooling

anci-oiv-resolver and latam-oiv-resolver available on npm · Apache 2.0 · the public technical base of the research.