CiberLATAMbywhalemate

Argentina boosts critical infrastructure defense

Argentina’s government is rolling out a national cyber plan and a SOC for public agencies and critical services. CERT.ar has topped 700 incidents.

Whalemate Labs · AI-assisted researchPublished:3 min read

Argentina’s government has unveiled a plan to strengthen critical infrastructure and essential services, with a focus on energy, health and telecoms. The package includes a national SOC, cyber ranges, early warnings and new obligations for public agencies, as CERT.ar has already surpassed 700 incidents in 2026.

Argentina’s government has moved ahead with a national cybersecurity plan aimed at strengthening protection for the public sector and critical infrastructure against data theft, fraud, ransomware and service disruptions. The strategy includes a national SOC, cyber ranges to simulate attacks, and new coordination requirements for public agencies and strategic operators.

What does the new official framework include?

The plan, led by the National Cybersecurity Center (CNC), calls for centralizing alerts from public agencies in a national Security Operations Center and sharing information on detected threats. According to La Voz, it is expected to begin operating in early 2027. The coverage also says the CNC ordered public agencies in February to appoint cybersecurity leads, inventory their systems and measure outage times.

It also adds liaison officers in agencies and critical infrastructure, creating an operational coordination layer for sectors such as energy and health. La Voz adds that the project includes a cyber range to simulate attacks in real-world energy and health environments and measure response capacity before actual incidents.

What changed in the state cybersecurity structure?

The CNC was created as an independent agency after cybersecurity and cyberintelligence functions were split at the end of last year, and since May 2026 it has overseen CERT.ar as the main technical body for incident management, according to YNA. The same agency said the CNC issued a system renewal mandate that requires all public institutions and national critical infrastructure to update their technology under a new security framework.

That scope extends regulation beyond the administrative public sector and reaches strategic operators. YNA also reported that Argentina’s cybersecurity chief expects cooperation with South Korea on complex, distributed threats, with a search for technical collaboration agreements to improve protection and response.

What do the incident reports show?

CERT.ar records show incidents rising from between 200 and 400 per year in recent periods to more than 700 in 2026, according to Infobae and La Voz. CNC officials told La Voz that the increase is tied to greater detection capacity and persistent underreporting, so the real volume of incidents would be higher than the official figures.

Infobae added that the state still does not have a complete picture of incidents because reporting requirements are only partially being met. The coverage also noted that the strategy seeks to reduce the risk of outages, ransomware and failures in critical systems that could affect energy, health and telecoms.

How is this approach being replicated in Mendoza?

Mendoza already has Law 9726 in force, which requires state agencies, technology providers and critical services to adopt security standards, report incidents and strengthen data protection, according to Mendoza Post. The law also creates a monitoring center and a Provincial Cybersecurity Incident Registry.

The province has also defined its own category of essential critical infrastructure, covering health, security, education, justice, finance, digital identity and public services. That provincial framework runs in parallel with the national strategy and adds a local oversight layer for agencies and services considered sensitive.

Sources

View all