The Coverage Gap: Chile’s critical infrastructure against the USA, EU and UK
The infrastructure every Chilean depends on — energy, health, banking, telecommunications, water — is now governed by a new cybersecurity law, yet an independent full-universe census shows the framework exists almost only on paper: for the vast majority of the regulated perimeter there is not even a defined channel through which a researcher could report a vulnerability.
- Author David Mellafe Z.
- Affiliation Reizan — Independent Security Research · Chile
- ORCID 0009-0001-3950-2505
- Press contact [email protected]
Since 1 January 2025 Chile has had a cybersecurity regulatory framework: a framework law (Law 21.663), a regulatory agency (ANCI) and a designated perimeter of 915 Vital Importance Operators (OIVs) — declared by Exempt Resolution No. 87, published in the Diario Oficial on 16 December 2025 — with binding obligations falling due in mid-2026.
The study The Coverage Gap measures, for the first time and across the full universe of those 915 operators, the distance between what those organizations expose publicly and their declared capacity to coordinate vulnerability disclosure. The conclusion is that the gap is structural, not circumstantial: it is not the product of an isolated incident or a single lagging sector, but a systematic pattern running across the entire regulated perimeter, including the most sensitive sectors. A well-drafted regulatory framework that coexists with a 98% coverage gap is, in practice, optional.
For context: in the United States, after CISA’s Binding Operational Directive 18-01 (2017), more than 99% of the civilian federal perimeter complies with these controls. The United Kingdom and the Netherlands exceed 95%. Chile, with the legal framework already in place but without the regulatory intervention that would operationalize it, starts from a different baseline.
Among the OIVs operating infrastructure with real-world physical impact — energy, health, banking, telecommunications, fuels, water, transport and state administration — fewer than ten publish a verifiable disclosure channel. The four largest banks and both incumbent telecommunications carriers lack one entirely.
“The coverage gap does not measure how secure Chile’s critical infrastructure is. It measures something more precise: whether the next vulnerability someone discovers has anywhere to go. Today, for 98.3% of the regulated perimeter, it does not.”
David Mellafe Z. · Reizan · Independent Security Research
Email authentication (SPF / DKIM / DMARC) is, in practical terms, what prevents a criminal from sending emails that appear to come from the exact domain of a trusted institution. When it is misconfigured across the vast majority of the regulated perimeter, the door is left open to impersonation (phishing) campaigns that spoof banks and state services to defraud the public.
This is not a theoretical risk: the fraudulent emails impersonating Chilean banking and public institutions — a phenomenon the public faces daily and that cybersecurity authorities have repeatedly warned about — rely precisely on this structural weakness. The 84% misconfiguration rate is not an abstract technical figure: it is the condition that lets impersonation fraud keep operating.
The study compares Chile with five jurisdictions that have an established public cybersecurity authority and a binding or comply-or-explain mandate. In each, disclosure-channel coverage across the critical-infrastructure perimeter exceeds 90% — in every case, after a binding regulatory intervention. In Chile, with the framework in place but without that intervention, the equivalent figure is 1.7%.
| Jurisdiction | Coverage bar | Disclosure-channel coverage |
|---|---|---|
| USA (civilian federal) | >99% | |
| United Kingdom (gov.uk) | >99% | |
| Netherlands | >95% | |
| Denmark | >90% | |
| Chile (OIVs) | 1.7% |
The eight-year lag is not a sentence. The leading countries show that, with a binding mandate equivalent to CISA’s Directive 18-01, the gap closes in twelve to twenty-four months. Chile arrives late, but for exactly that reason it can compress nearly a decade of regulatory iteration into a single step, adopting international best practice directly. The study proposes a low-cost closure roadmap that ANCI could activate within its existing statutory authority, with no need for legislative action.
Comparability note: the universes compared are not strictly equivalent (they differ in size, definition and measurement method). The comparison should be read as a directional gap on the dimension of email-authentication mandates, not as an exact quantitative delta. Full detail is in the paper.
The study is independent academic research. It has no client, was not commissioned by the State or by any operator, and does not sell a product to the entities it measures. That independence is deliberate and verifiable:
The paper is published under a Creative Commons Attribution 4.0 license (CC-BY-4.0). Anyone can read, cite and redistribute it.
An archived deposit with a permanent identifier on Zenodo: 10.5281/zenodo.20501960. The record cannot be altered retroactively.
The author’s academic identity via ORCID 0009-0001-3950-2505, the international standard for researcher identification.
An open-source tool (Apache 2.0) is released that lets any independent researcher reproduce, extend or contradict the operator mapping underpinning the census.
The analysis was carried out exclusively through observation of public information, with no interaction with operators’ systems beyond what an ordinary website visitor would do. It is framed in line with the principles of ISO/IEC 29147:2018 on responsible disclosure and within the bounds of Law 21.459 (Chile’s computer-crimes statute). Consistent with that responsible-disclosure practice, the study reports only aggregate figures across the full OIV set: it names no individual operator, so the document informs public policy without functioning as a target list.
The 915 OIVs are not abstract entities: they are the hospitals, banks, power transmission companies, telecommunications carriers, water utilities and state agencies on which the daily life of every Chilean depends. The study documents that the financial and telecommunications sectors — far from leading — concentrate the most severe findings, and that the health sector shows the highest density of findings relative to its size, consistent with its well-recognized underfunding.
The gap matters because it determines the fate of the next vulnerability discovered in any of those organizations. When no defined reporting channel exists, a legitimate finding from a good-faith researcher simply falls on the floor — or, in the worst case, ends up on the gray market. The study frames the present moment as a window of opportunity: the conditions to implement and adopt a disclosure mandate are most favorable right now, while the regulated perimeter is not yet the target of mass attack campaigns.
- Title: The Coverage Gap: Chile’s Cyber Disclosure Framework versus the USA, EU and UK
- Author: David Mellafe Z. · Reizan — Independent Security Research
- Year: 2026 · License: CC-BY-4.0
- DOI:
10.5281/zenodo.20501960 - Author ORCID: 0009-0001-3950-2505
- Preprint: arXiv:2606.05594 [cs.CR]
- Access: https://doi.org/10.5281/zenodo.20501960
The full paper (in English) is the canonical academic artifact and the source of truth for all figures and methodology. This summary is distributed under the same attribution terms (CC-BY-4.0).
Questions & answers
Short, citable answers to the most common questions about the study The Coverage Gap and Chile’s critical-infrastructure cybersecurity framework.
What is the cybersecurity coverage gap in Chile?
The coverage gap is the distance between Chile’s already-in-force cybersecurity framework (Law 21.663) and the real capacity of its regulated operators to coordinate vulnerability disclosure. Reizan’s independent study The Coverage Gap measures that only 1.7% of the 915 Vital Importance Operators publish a verifiable disclosure channel — a structural gap of 98.3%.
What is a Vital Importance Operator (OIV) under Chile’s Law 21.663?
A Vital Importance Operator (OIV) is an organization designated by Law 21.663 whose disruption would affect essential services — energy, health, banking, telecommunications, water, transport and state administration. Chile’s National Cybersecurity Agency (ANCI) designated 915 OIVs through Exempt Resolution No. 87, published in the Diario Oficial on 16 December 2025.
How many Vital Importance Operators are there in Chile?
There are 915 Vital Importance Operators designated by ANCI under Law 21.663, per Exempt Resolution No. 87 (Diario Oficial, 16 December 2025). That is the full universe measured by Reizan’s study The Coverage Gap.
What share of OIVs publish a vulnerability-disclosure channel?
Only 1.7% — 16 of 915 entities — publish a verifiable vulnerability-disclosure channel, per the study The Coverage Gap. Against more than 99% in the USA, the UK and most of the European critical-infrastructure perimeter, the 98.3% coverage gap is structural.
Why does misconfigured email authentication (SPF, DKIM, DMARC) matter?
Email authentication (SPF, DKIM, DMARC) prevents an attacker from sending emails that appear to come from the exact domain of a trusted institution. The study The Coverage Gap found 84% of OIVs — 766 of 915 — misconfigure it, the condition that enables impersonation (phishing) campaigns against banks and state services.
Who is David Mellafe Z. and what is Reizan?
David Mellafe Z. is an Independent Security Researcher (ORCID 0009-0001-3950-2505) and author of the study The Coverage Gap. Reizan is an AI-native cyber advisory practice for regulated critical infrastructure across LATAM, operated by AlmaAI SpA. The study is published under a CC-BY-4.0 license with permanent DOI 10.5281/zenodo.20501960.