Chile tightens cyber incident reporting deadlines
Chile now requires early incident alerts within three hours, plus updates, an action plan and a final report under new cyber rules.
Chile's Cybersecurity Framework Law and its implementing rules now set firm deadlines for incident reporting, including an early alert within three hours of discovery. The CMF has also raised security, continuity and risk-management requirements for exchanges, brokers and securities agents.
Chile's Cybersecurity Framework Law requires incident reporting and sets an early alert deadline of no more than three hours from the moment the event is identified, according to Revista Seguridad & Defensa. The same coverage said violations under this regime are classified as minor, serious and very serious, with fines ranging from 5,000 to 40,000 UTM depending on the category and severity.
Reporting in hours
Publimetro reported that Decree 295, which regulates incident reporting under Cybersecurity Framework Law 21,663, requires Critical Infrastructure Operators and Essential Service Providers to send an early alert to the ANCI within three hours of learning of an incident. The publication added that the decree sets follow-up updates at 24 or 72 hours, an action plan within seven days and a final report within 15 days.
That timeline leaves organizations with very little room to classify the incident, activate internal procedures and notify the authority. Publimetro also argued that cyber intelligence is a key element for meeting these requirements, especially for maintaining detection and response capabilities in the first hours.
Oversight and initial scope
DefOnline said the ANCI is already overseeing 915 critical infrastructure operators under the Cybersecurity Framework Law, a figure that gives a sense of the initial supervised universe. In parallel, BioBioChile reported that the agency activated a preventive protocol over a possible hack linked to LiteLLM and notified about 20 Chilean institutions, including public agencies, showing operational response capacity and early coordination in the face of a risk of broad exposure.
More demands in finance
Regulatory pressure also reached the financial sector. Garrigues said the CMF issued General Rule No. 571 on July 27, 2026, and that the measure requires stock exchanges, brokers and securities agents to demonstrate risk management, information security, cybersecurity and business continuity policies in order to operate. The firm's coverage added that the rule creates a comprehensive regulatory framework for stock and commodities exchanges, securities brokers and securities agents, with requirements for authorization to exist and begin operations, in addition to those policies.
The result is a framework with faster reporting obligations for essential and vital sectors, and higher standards for financial market players, as the ANCI continues to move with preventive alerts and coordination with public institutions.
Sources
- ANCI activa protocolo preventivo y notifica a veintena de instituciones chilenas por hackeo a LiteLLMbiobiochile.cl· BioBioChile
- Ciberinteligencia: la pieza clave para cumplir con la nueva ley de ciberseguridad en Chilepublimetro.cl· Publimetro
- Interés, temor y celeridad: ¿cómo avanzan las empresas en el cumplimiento de la Ley Marco de Ciberseguridad?revistaseguridad.cl· Revista Seguridad & Defensa
- Ley de ciberseguridad exige reportar ataques en 3 horas ...periodismo2.cl· Periodismo2
- Alerta en Chile sobre ciberataques de China, ¿qué se sabe?defonline.com.ar· DefOnline
- La CMF consolida la regulación de bolsas de valores e intermediarios y refuerza estándares de riesgosgarrigues.com· Garrigues



