How Chile is betting on trust to secure its digital future
By Sol Gonzalez
Chile’s National Cybersecurity Agency’s Acting National Director and Deputy Director, Michelle Bordachar, explains why the agency treats incident reports as shared intelligence, rather than grounds for sanctions.
-1791269458507.jpg)
Chile’s National Cybersecurity Agency’s Acting National Director and Deputy Director, Michelle Bordachar, shares that Chile has moved from separate cybersecurity efforts to having a cybersecurity system, with a national authority and common rules that help to enhance intelligence and strengthen defence postures. Image: ANCI.
This story is part of GovInsider's Digital Trust & Cybersecurity Champions 2026 Special Report.
In 2025, Chile’s National Cybersecurity Agency (ANCI) traced a series of incidents to a single threat actor, and identified at least 21 institutions that could have been targeted as well.
Quick preventive measures followed, which helped to avert losses estimated at over one billion Chilean pesos (approximately S$1.3 million).
That is the point of the agency, says ANCI’s Michelle Bordachar.
"We do not want reports to simply accumulate statistics. Every incident contains information that can help prevent the next one.”
ANCI began operations in January 2025 as Chile's national cybersecurity authority. It coordinates public and private capabilities, generates threat intelligence, oversees compliance, and holds enforcement and sanctioning powers.
But success is not measured in fines, she says, highlighting that “the system is not necessarily any safer” once fines are imposed but nothing changes.
“Our objective is to prevent the incident from happening, and if it does happen, to minimise its impact, and that requires trust,” she adds.
Bordachar shares with GovInsider that cybersecurity goes beyond a technical team working in isolation, but needs to be embedded in hospitals, banks, local governments, and technology providers that ultimately provide services to the public every day.
Compliance alone isn’t security
“There’s an important difference between complying with a rule and being secure. An organisation can have perfectly organised documentation and still be extremely vulnerable,” Bordachar says.
The Agency recognises that organisations may have different levels of capacity for implementing regulations.
If a regulation is “impossible to implement,” it doesn’t serve its purpose improving cybersecurity.
As a result, ANCI’s approach is to require what improves security, support implementation, and reserve sanctions only for cases that truly warrant them, says Bordachar.
From scattered efforts to a system
Chile has moved from separate efforts to having a cybersecurity system, with a national authority, common rules, mandatory incident reporting, coordination mechanisms, and an institution capable of seeing what is happening across different sectors at the same time.
Instead of relying solely on sanctions, mandatory reporting is used for shared intelligence, on the principle that an institution that reports incidents may not have done something wrong.
According to the Cybersecurity Framework Law, a cybersecurity incident is “any event that harms or compromises the confidentiality or integrity of information, the availability or resilience of computer networks and systems, or the authentication of processes executed or implemented on computer networks and systems.”
“The information we receive allows us to identify patterns, investigate threats and warn other institutions.
“That is why we would rather have an organisation report while it is still trying to understand exactly what happened than wait until it has every answer,” explains Bordachar.
The result is that public agencies and companies no longer depend solely on their own level of maturity. They can turn to ANCI for support.
She adds that “trust” is an essential component of incident reporting, which ANCI seeks to leverage to provide alerts and guidance.
In the first half of 2026, ANCI registered 324 incident reports with significant impact, which enabled the agency to identify attack patterns, impacts, and preventive measures.
The agency also recently launched a new reporting portal for citizens to alert ANCI to digital incidents or vulnerabilities.
Scale, speed, and culture
ANCI’s leader understands that the agency is still small and building itself while operating. For that reason, she notes two main challenges: scale and speed.
“We did not have the luxury of setting up the agency first and starting the work later,” says Bordachar.
From day one, it had to analyse incidents, issue alerts, implement the law, and write regulation, while hiring staff and building processes.
This balancing act forces ANCI to “prioritise constantly” and multiply its capabilities through technology, international cooperation and public-private collaboration.
This includes working with different agencies, industries and institutions to obtain a holistic view of cyber risks.
According to Bordachar, “a cybersecurity agency that tries to do everything on its own is probably doing something wrong”.
Additionally, ANCI is developing mechanisms to reconcile equivalent requirements and reduce duplication.
“We want organisations to spend their resources managing risk and improving security, rather than reporting the same thing five times to five different authorities.”
The harder challenge is cultural: getting institutions to see reporting as a way for the whole system to learn.
That, Bordachar says, will take longer than passing any law.
The lawyer who built the system
Bordachar brings her law background into her leadership in cybersecurity.
Prior to leading the agency, she served as Executive Secretary of Chile’s Interministerial Committee on Cybersecurity and as a legal and legislative adviser to the National Cybersecurity Coordination Office.
Bordachar also participated in the evaluation of the 2017-2022 National Cybersecurity Policy, the development of the 2023-2028 Policy, and led the legislative process for the Cybersecurity Framework Law.
“Today, as Acting National Director and Deputy Director of ANCI, I’m implementing many of the institutions and rules I helped design,” she shares.
Her background is evidence that cybersecurity is not exclusively technical, she says.
“Of course, we need engineers and technical specialists in cybersecurity, but we also need lawyers, economists, public policy experts, communicators and many other disciplines.
“Broadening how we understand cybersecurity also broadens the range of people who can see themselves as part of it,” adds Bordachar.
Gender equity as talent strategy, not a side program
Since cybersecurity is a male-dominated field, gender parity has been a practical and fundamental ethos for ANCI.
Women represent around 16 per cent of the information technologies (IT) workforce in Chile, among the lowest female representation in IT jobs in Latin America.
“Women need to be at the tables where decisions are made,” says Bordachar. “There are realities women experience that are unlikely to be reflected in public policy if the people who live those realities are absent when that policy is designed.”
At ANCI, women account for 20 per cent of the technical staff and the entirety of the development team, by design.
“Chile needs around 28,000 new cybersecurity specialists. We cannot say we have a talent shortage while allowing ourselves to overlook half of our country’s potential talent,” she says.
As a rule, the Agency does not participate in all-male panels. It may seem like a small gesture, but it forces organisers to ask a very simple question: was there really no woman you could invite?
Its approach rests on integrating gender across public policy, designing evidence-based measures, treating equity as part of the talent response, and having the State lead by example.
“Perhaps the most powerful message for a girl or young woman deciding what to study today is seeing a woman writing code, leading a technical team, designing public policy, or heading a cybersecurity agency and thinking ‘I can be there too’,” says Bordachar.
What is at stake
“When a hospital cannot access its systems, an electricity company loses operational capacity or a public institution can no longer provide a service, the problem stops being digital very quickly,” Bordachar notes.
She’s firm in her position that cybersecurity is an institutional and shared responsibility between government, the private sector, and individuals, not just the task of technology professionals.
“That is the main shift we are trying to drive in Chile: moving away from thinking about cybersecurity simply as a reaction to attacks and understanding it as a necessary condition for a digital country to function, develop and trust,” she concludes.
