Memo · Sector cyber defense · Argentine energy
Denmark caught the attack on 22 utilities because it was watching 300 companies at once
SektorCERT is a Danish non-profit association with 25 staff, owned by its members and funded entirely by dues. This memo takes that model apart piece by piece and prices an equivalent for Argentine energy: USD 270,000 a year to start, which four anchor companies cover. It closes with two drafts for discussion, a regulation and the skeleton of a bill.
The model
Twenty-five people watching the edge traffic of three hundred companies
SektorCERT started in April 2020 as EnergiCERT and changed its name when it widened its scope past energy. It is a non-profit association owned by three trade bodies, Green Power Denmark, Dansk Fjernvarme and DANVA, plus Energinet, the Danish transmission system operator. It now covers electricity, district heating, water and transport.
| Legal form | Non-profit association |
| Incorporated | April 29, 2020 |
| Staff | 25 |
| Members | more than 300 companies |
| Sensors | 270 as of May 2023 |
| Funding | 100% member dues, no public money |
| Watch | 24 × 7 since late 2025; best effort before that |
The sensor is engineered against the objection, not against the attack
The first question any security officer asks is who gets to see their traffic. Every technical choice in the SektorCERT sensor answers that question before it is asked. It is a passive tap, so it copies traffic and cannot touch the network. It watches the edge only, meaning traffic the company already sends to the open internet. And the data goes back over a separate out-of-band 4G link, encrypted in transit and at rest, so it never touches the member's own line.
Two things sit on top of that, neither of which a commercial provider offers. The first is analysis of industrial protocols such as Modbus and Profinet, which is what makes PLC and RTU traffic visible. The second is an optional honeypot inside the production environment, a physical device dressed up as a PLC that raises an alarm if anyone tries to reach it.
It buys scale outside and keeps the sector knowledge
A small sector CERT cannot staff 450 analysts, nor size an incident response bench for the peak. SektorCERT does not try. It contracts analysis to Red Canary, runs CrowdStrike as its endpoint agent, and holds a retainer with mnemonic, the largest incident response firm in the Nordics, covering every member: the contract is part of the dues, and the hours are paid by whoever uses them.
What it keeps is what nobody can sell it: the sensor network, the closed forum where members talk to each other, the knowledge of the sector and the relationship with the authorities. That split is what makes the model workable at Argentine scale.
Dues only, for two reasons that are written down
The membership brochure is blunt about it: SektorCERT is 100% funded by member dues and no public money is involved. It gives two reasons. The first is being able to act without depending on which agenda is in focus in Danish politics. The second is sharper, and it is the one that travels: as a private entity, it cannot be subject to freedom-of-information requests, so a shared incident stays confidential.
That argument translates to Argentina without loss. The public information access law binds government bodies and state-owned companies. An incident reported to a state agency can be requested by a third party. Reported to an industry association, it cannot.
Membership comes in four shapes, and one of them explains how the count reaches 300 without selling one company at a time: the trade body signs on behalf of its members. The other three are a subset enrolled by the trade body at a discount, individual membership, and critical-supplier membership, which requires two members to vouch for the applicant.
May 2023
The case everyone cites, and the part almost nobody cites
Twenty-two companies operating parts of Danish energy infrastructure were compromised within a few days. The attackers reached industrial control systems, and several companies had to fall back to island mode. SektorCERT's report documents it minute by minute.
The first wave exploited a Zyxel firewall flaw, CVE-2023-28771, disclosed with its patch on April 25. Eleven of the 22 companies had not installed the update, despite an earlier warning from SektorCERT itself, and that earned them public criticism. One member did not believe it owned a Zyxel device at all: a contractor had installed one while putting in cameras. Another lost the firewall that doubled as the router for its operational network, sent staff out to run remote sites by hand, and spent six days in island mode.
Here is the part that gets cited less. In January 2024 Forescout published an analysis arguing that the two waves were unrelated, and that the second was mass opportunistic exploitation of unpatched firewalls worldwide. The attribution to Sandworm, which the Danish report left open, does not hold for that second wave.
Worth saying, and worth saying first, because it does not weaken the argument: it strengthens it. If an entire country's critical infrastructure was compromised by an actor with no state resources, working off unpatched equipment, then the problem is within reach of the ordinary attacker. And the detection is not in dispute. The sensor network saw the pattern because it was looking across companies rather than inside one.
That is where SektorCERT's own two conclusions come from, and they are the whole argument in two lines. First: a systemic vulnerability is the same flaw sitting in many companies, and none of them sees it as its own problem. Second: looking at data from hundreds of companies surfaces what is invisible when each one is monitored alone.
Argentina
The coalition this would need has existed since 1992 and already co-runs dispatch
SektorCERT is owned by three trade bodies plus the system operator. That ownership structure exists in Argentina, with the same kinds of actors, and it is 33 years old.
CAMMESA is a corporation in which 80% is split evenly among the four associations of the power sector, covering generators, transmission, distribution and large users, with the remaining 20% held by the State, which appoints the chair (Decree 1192/92). The companies a sector CERT would have to convene are already shareholders together in the body that runs the national power dispatch.
There is a second precedent, and it comes from the gas side. Decree 180/2004 created the Electronic Gas Market and defined its function, but did not operate it: the Buenos Aires Stock Exchange incorporated MEGSA in October of that year, and the gas regulator approved its operating rules afterwards. Twice, twelve years apart, Argentina ran the same pattern: the State convenes by decree, and private parties incorporate and operate.
| SektorCERT | What it is | Argentine counterpart |
|---|---|---|
| Green Power Denmark | Power trade body | AGEERA, ATEERA, ADEERA |
| Energinet | System operator | CAMMESA |
| DANVA | Water trade body | Water utilities, at a later stage |
| Dansk Fjernvarme | District heating | Not applicable |
| No counterpart | Oil and gas | IAPG, MEGSA |
The contrast sits inside the same country. Argentine banks have shared critical infrastructure since 1980, and the central bank requires them to report a cyber incident within the first hour. Energy has no reporting rule, no channel and no register: fourteen incidents in six years, seven of them known only because the attacker published them.
The gap
Denmark has three pieces and Argentina has none of them
What gets cited as "the SektorCERT model" is really three separate institutions that need each other. Only one of the three is private, and it is the one that showed up last.
The law that compels
Act 258, in force since March 7, 2025, implements the EU NIS2 and CER directives for the energy sector and sorts companies into five tiers of obligation. Argentina has nothing equivalent: neither the regulator nor the energy secretariat imposes cybersecurity requirements or reporting duties on operators.
The state strategy unit
The decentralized cyber security unit for energy has sat inside the Danish Energy Agency since 2018, producing sector strategy, guidance and exercises. Argentina has none for energy: the national cybersecurity center is the competent authority, but its first technical rule reaches only the public sector.
The private CERT that operates
SektorCERT, since 2020. It writes no rules and audits nobody: it detects, warns and coordinates response. Argentina has none, and neither does any other country in Latin America, where the only consolidated private sector CSIRT is the Colombian banking one.
The Danish state supplied the mandate and the strategy, and stayed out of running detection. That split was a decision rather than an oversight, and it is the part of the design most worth copying.
Argentina's own measure of the gap sits in a government document. The Inter-American Development Bank program for critical information infrastructure starts from a baseline of 9% coverage of sectors with critical information infrastructure identified, measured in 2021, and aims for 50% by 2028.
Budget
Three scenarios, and four signatures pay for the smallest one
The only hard reference available is Norwegian. KraftCERT, the sector CERT for Norwegian energy, spent NOK 19,522,718 in 2025 with 12 employees, per the accounts it filed with the company register. That is USD 2,051,838 at the August 7, 2026 rate, or USD 171,000 per person per year at Norwegian cost.
| Scenario | What it does | People | USD per year |
|---|---|---|---|
| Minimum | Sharing, alerts and coordination. No sensors of its own | 3 | 270,000 |
| Middle | Adds detection, with sensors at 25 sites | 7 | 775,000 |
| Full | Operations center with a round-the-clock watch, 80 sites | 16 | 2,000,000 |
The full scenario lands in the same order of magnitude as KraftCERT, with more people and more sensors, which is what changing cost country should do. The minimum is the one that matters, because it is the one that decides whether this starts at all.
| Tier | Who | Annual dues |
|---|---|---|
| Founding anchor | Gas transporter, large producer | USD 80,000 |
| Large | Generator, power transmission, large distributor | USD 35,000 |
| Mid | Provincial distributor, gas marketer | USD 12,000 |
| Small | Electric cooperative, small distributor | USD 3,000 |
| Supplier | Critical vendor, vouched for by two members | USD 6,000 |
Four anchors bring in USD 320,000 against a cost of 270,000. That pays for year one, and it is the number to carry into the first meeting. Forty members spread across the five tiers yield USD 710,000, which covers most of the middle scenario. For scale: SektorCERT has more than 300 members.
Funding
The loan has USD 27.5 million undisbursed and the private-sector line at zero
The Cybersecurity for Critical Information Infrastructure Program, IDB loan 5735/OC-AR, was approved on January 11, 2023 and signed on June 7 of that year, for USD 30,000,000 with no local counterpart funding. The Chief of Cabinet's office executes it, and it closes in 2028.
The public monitoring report for January to December 2025, validated in May 2026, records USD 2,500,000 disbursed. That is 8.33% in three years.
Inside the results matrix, under the first component, there is an output with this name: "platforms for threat analysis and information sharing with the private sector implemented". Target, one platform by 2028. Budget, between USD 950,000 and 2,600,000 depending on whether you read the planned or the adjusted figure. Physical and financial progress as of the end of 2025, zero.
The rest of the component explains why. The outputs carrying real budget are the government security operations center, with SIEM and sensors to monitor ministries, and the operational capabilities of the national CERT. It is the SektorCERT architecture pointed at the State. The private sector shows up in a single line under a million dollars, and that is the line that never moved.
The open question is not where the money comes from. It is who signs on the other side.
Sequence
Four phases, and each one is worth having even if the next never happens
Order matters more than speed here. If the State convenes before any operator is committed, the table fills with officials and vendors, which is exactly what happened to the 2011 critical infrastructure program.
A map, not meetings
An attack surface map of the sector built from open sources alone, touching no system. This is what opens doors: nobody takes a meeting about founding a consortium, and almost everyone takes one to see an inventory of what their company looks like from the outside.
The table, on a light contract
A formal convening, a confidentiality agreement signed before anything is shared, and a cooperation consortium contract under articles 1470 to 1478 of the civil and commercial code, which creates no legal entity and cannot direct members' activity. Plus a sensor pilot at one or two sites.
The entity, with dues coming in
A civil association, three or four anchors as members, the minimum scenario running, and response capacity contracted rather than built. International accreditation and an agreement with a peer sector CERT, which is quick to get because all three European ones already sign with foreign partners.
Scale and legal framework
Extension to water and transport, an annual sector exercise, and the push for the bill. With two years of operation and its own data, the consortium stops petitioning for a law and becomes the technical source behind it.
Drafts
A regulation that costs nothing, and a bill for what the regulation cannot do
Both texts below are working drafts, written by someone who is not a lawyer, so that a conversation can start from a text instead of an idea. They need professional review before being tabled anywhere.
Draft regulation from the energy secretariat
It creates the Energy Sector Cybersecurity Table as a voluntary forum, with no power to direct or audit its participants. Members are the secretariat as chair, the regulator, the national cybersecurity center as standing guest, CAMMESA, the four power associations, the oil and gas institute, MEGSA, and any operator that opts in.
Its remit has two halves. The first is design: propose the legal vehicle and the funding for a permanent sharing mechanism run by the operators themselves. The second is rules: the information handling protocol, the criteria for identifying critical infrastructure in the sector, a voluntary notification scheme, and the legal changes needed. It also creates a voluntary, free register of cybersecurity points of contact, readable only by its registrants.
Three clauses do the heavy lifting. Information shared at the table is not used as grounds for enforcement, audit or tariff review. The table has 180 days to deliver its proposal with a budget. And running it carries no budget appropriation: a non-profit sector body serves as technical secretariat at no charge. A closing article invites the Chief of Cabinet's office to consider assigning the loan's private-sector sharing output to whatever the table proposes.
That design is deliberate. It costs nothing, imposes no duty on private parties, creates no structure or posts, and hands the signer an agenda in a field where Argentina trails Chile and Brazil. The precedent is the Norwegian regulator, which in 2014 urged the industry to build its own security team, and KraftCERT is what came out of it.
What only a law can do
A regulation binds the conduct of the body that issues it. It cannot carve out an exception to the public information access regime, and it cannot waive liability toward third parties. Those protections are the reason the second draft exists, and there are five of them.
No enforcement use
What is shared in good faith with a recognized sector center cannot ground enforcement, audit or tariff review proceedings against the party that shared it. This is the problem the 2015 US sharing act was written to fix, and without it sharing goes cold.
Civil liability exemption
Sharing threat or vulnerability information under the applicable protocol creates no liability toward third parties. Without this clause, every operator's legal department has reason to recommend silence.
Freedom-of-information carve-out
Incident and vulnerability information about critical infrastructure held by government bodies falls under the exceptions of the access law. It is the public-side mirror of why SektorCERT chose to be private.
Antitrust safe harbor
Threat information sharing among competitors, confined to that purpose, does not by itself constitute a restrictive practice under competition law.
Use limitation
Shared information may be used for cybersecurity purposes only, and is not passed to intelligence agencies without a court order. This clause answers the 2024 precedent, when cybersecurity was moved under the intelligence agency.
The rest of the bill wraps around those five: tiered obligations, staged notification at 3 hours, 72 hours and 15 days as in the Chilean law in force since 2025, and the figure of the recognized sector center, with one clause that changes the entire incentive: notifying through the center discharges the duty to notify the authority.
The drafting references are Chile's Law 21.663, the Cybersecurity Information Sharing Act of 2015, and two Argentine bills, 4878-D-2021 and 0146-D-2023, which proposed a national plan for energy critical infrastructure and were never taken up.
Limits
What this memo cannot claim
It cannot claim that a consortium would have prevented any of the fourteen incidents in the Argentine register, or that it would prevent the next one. SektorCERT did not prevent the 2023 attack either: eleven of the 22 companies had not patched despite the warning. A sector center makes an attack visible and cuts it short. It does not fix its members' hygiene.
The three cost scenarios are own estimates, not a validated budget. The USD 60,000 per person assumption does not come from a salary survey: it comes from bracketing between what dollarized remote work pays and the verified Norwegian cost. Change that assumption and everything else moves with it.
About the IDB loan, only what its monitoring report says can be claimed: that the private-sector sharing output is budgeted and unexecuted as of the end of 2025. Not that those funds are available, nor that a private entity could receive them, nor that a program running at 8.33% after three years would speed up because a counterpart appeared.
Nor can it be claimed that no informal channels exist today among security officers at Argentine energy companies. What is verified is that no public or institutional trace of one exists, and absence of trace is not proof of absence.
Who is behind this
Matías Podeley. An ITBA engineer, eighteen years in energy: four in operations in Neuquén, simulation of giant fields like Camisea and technical backing of asset purchases above US$ 300 million. Buenos Aires.
The empirical work underneath this memo: the register of cyber incidents in Argentine energy and critical infrastructure, sourced row by row.
If this is your problem
Operators, trade bodies and agencies
This memo was written to circulate. If something here is wrong, a note with the source is enough to get it corrected. If there is interest in discussing the design, the budget or the drafts, the conversation is open.
matias@podeley.ar · Buenos Aires