Matías Podeley ES

Memo · Sector cyber defense · Argentine energy

Denmark caught the attack on 22 utilities because it was watching 300 companies at once

SektorCERT is a Danish non-profit association with 25 staff, owned by its members and funded entirely by dues. This memo takes that model apart piece by piece, sets it against the US oil and gas ISAC, whose tax filings show year one cost USD 149,881, and prices what Argentine energy would need: USD 270,000 a year, which four anchor companies cover. It closes with two drafts for discussion, a regulation and the skeleton of a bill.

Published August 8, 2026 The model ↓ What it costs ↓ The gap ↓ The drafts ↓

The model

Twenty-five people watching the edge traffic of three hundred companies

SektorCERT started in April 2020 as EnergiCERT and changed its name when it widened its scope past energy. It is a non-profit association owned by three trade bodies, Green Power Denmark, Dansk Fjernvarme and DANVA, plus Energinet, the Danish transmission system operator. It now covers electricity, district heating, water and transport.

Figures from the August 2025 membership brochure, the Danish company register and Green Power Denmark's January 2025 release.
Legal formNon-profit association
IncorporatedApril 29, 2020
Staff25
Membersmore than 300 companies
Sensors270 as of May 2023
Funding100% member dues, no public money
Watch24 × 7 since late 2025; best effort before that

The sensor is engineered against the objection, not against the attack

The first question any security officer asks is who gets to see their traffic. Every technical choice in the SektorCERT sensor answers that question before it is asked. It is a passive tap, so it copies traffic and cannot touch the network. It watches the edge only, meaning traffic the company already sends to the open internet. And the data goes back over a separate out-of-band 4G link, encrypted in transit and at rest, so it never touches the member's own line.

Two things sit on top of that, neither of which a commercial provider offers. The first is analysis of industrial protocols such as Modbus and Profinet, which is what makes PLC and RTU traffic visible. The second is an optional honeypot inside the production environment, a physical device dressed up as a PLC that raises an alarm if anyone tries to reach it.

It buys scale outside and keeps the sector knowledge

A small sector CERT cannot staff 450 analysts, nor size an incident response bench for the peak. SektorCERT does not try. It contracts analysis to Red Canary, runs CrowdStrike as its endpoint agent, and holds a retainer with mnemonic, the largest incident response firm in the Nordics, covering every member: the contract is part of the dues, and the hours are paid by whoever uses them.

What it keeps is what nobody can sell it: the sensor network, the closed forum where members talk to each other, the knowledge of the sector and the relationship with the authorities. That split is what makes the model workable at Argentine scale.

Dues only, for two reasons that are written down

The membership brochure is blunt about it: SektorCERT is 100% funded by member dues and no public money is involved. It gives two reasons. The first is being able to act without depending on which agenda is in focus in Danish politics. The second is sharper, and it is the one that travels: as a private entity, it cannot be subject to freedom-of-information requests, so a shared incident stays confidential.

That argument translates to Argentina without loss. The public information access law binds government bodies and state-owned companies. An incident reported to a state agency can be requested by a third party. Reported to an industry association, it cannot.

Membership comes in four shapes, and one of them explains how the count reaches 300 without selling one company at a time: the trade body signs on behalf of its members. The other three are a subset enrolled by the trade body at a discount, individual membership, and critical-supplier membership, which requires two members to vouch for the applicant.

May 2023

The case everyone cites, and the part almost nobody cites

Twenty-two companies operating parts of Danish energy infrastructure were compromised within a few days. The attackers reached industrial control systems, and several companies had to fall back to island mode. SektorCERT's report documents it minute by minute.

The first wave exploited a Zyxel firewall flaw, CVE-2023-28771, disclosed with its patch on April 25. Eleven of the 22 companies had not installed the update, despite an earlier warning from SektorCERT itself, and that earned them public criticism. One member did not believe it owned a Zyxel device at all: a contractor had installed one while putting in cameras. Another lost the firewall that doubled as the router for its operational network, sent staff out to run remote sites by hand, and spent six days in island mode.

Here is the part that gets cited less. In January 2024 Forescout published an analysis arguing that the two waves were unrelated, and that the second was mass opportunistic exploitation of unpatched firewalls worldwide. The attribution to Sandworm, which the Danish report left open, does not hold for that second wave.

Worth saying, and worth saying first, because it does not weaken the argument: it strengthens it. If an entire country's critical infrastructure was compromised by an actor with no state resources, working off unpatched equipment, then the problem is within reach of the ordinary attacker. And the detection is not in dispute. The sensor network saw the pattern because it was looking across companies rather than inside one.

That is where SektorCERT's own two conclusions come from, and they are the whole argument in two lines. First: a systemic vulnerability is the same flaw sitting in many companies, and none of them sees it as its own problem. Second: looking at data from hundreds of companies surfaces what is invisible when each one is monitored alone.

Argentina

The coalition this would need has existed since 1992 and already co-runs dispatch

SektorCERT is owned by three trade bodies plus the system operator. That ownership structure exists in Argentina, with the same kinds of actors, and it is 33 years old.

CAMMESA is a corporation in which 80% is split evenly among the four associations of the power sector, covering generators, transmission, distribution and large users, with the remaining 20% held by the State, which appoints the chair (Decree 1192/92). The companies a sector CERT would have to convene are already shareholders together in the body that runs the national power dispatch.

There is a second precedent, and it comes from the gas side. Decree 180/2004 created the Electronic Gas Market and defined its function, but did not operate it: the Buenos Aires Stock Exchange incorporated MEGSA in October of that year, and the gas regulator approved its operating rules afterwards. Twice, twelve years apart, Argentina ran the same pattern: the State convenes by decree, and private parties incorporate and operate.

SektorCERT's ownership structure and its Argentine counterpart, actor by actor.
SektorCERTWhat it isArgentine counterpart
Green Power DenmarkPower trade bodyAGEERA, ATEERA, ADEERA
EnerginetSystem operatorCAMMESA
DANVAWater trade bodyWater utilities, at a later stage
Dansk FjernvarmeDistrict heatingNot applicable
No counterpartOil and gasIAPG, MEGSA

The gap

Denmark has three pieces and Argentina has none of them

What gets cited as "the SektorCERT model" is really three separate institutions that need each other. Only one of the three is private, and it is the one that showed up last.

The law that compels

Act 258, in force since March 7, 2025, implements the EU NIS2 and CER directives for the energy sector and sorts companies into five tiers of obligation. Argentina has nothing equivalent: neither the regulator nor the energy secretariat imposes cybersecurity requirements or reporting duties on operators.

The state strategy unit

The decentralized cyber security unit for energy has sat inside the Danish Energy Agency since 2018, producing sector strategy, guidance and exercises. Argentina has none for energy: the national cybersecurity center is the competent authority, but its first technical rule reaches only the public sector.

The private CERT that operates

SektorCERT, since 2020. It writes no rules and audits nobody: it detects, warns and coordinates response. Argentina has none, and neither does any other country in Latin America, where the only consolidated private sector CSIRT is the Colombian banking one.

The Danish state supplied the mandate and the strategy, and stayed out of running detection. That split was a decision rather than an oversight, and it is the part of the design most worth copying.

Argentina's own measure of the gap sits in a government document. The Inter-American Development Bank program for critical information infrastructure starts from a baseline of 9% coverage of sectors with critical information infrastructure identified, measured in 2021, and aims for 50% by 2028.

Chile assembled all three pieces in two years, on a different design

The objection that this takes decades does not survive a look across the Andes. Law 21.663 created the National Cybersecurity Agency in 2024, and on July 24, 2026 the agency closed the first roster of Operators of Vital Importance, electric power included. The Chilean regulated perimeter now has names on it.

The third piece follows a different route from the Danish one, and it is the route Argentina would take by default if the sector does not organize first. Chile's electricity CSIRT will be run by the Coordinador Eléctrico Nacional, the counterpart of CAMMESA, and its build and operating costs will be requested inside that body's regulated budget once the cybersecurity technical standard is published. What accelerated all of it was the national blackout of February 25, 2025.

That design is faster and costs its sponsor nothing, but it carries a price worth facing. Housing the sharing function inside an entity with state ownership reopens the two things SektorCERT solved by staying private: exposure to freedom of information rules, and dependence on the State staying interested next year.

Budget

Three scenarios, and four signatures pay for the smallest one

There are two hard references, and the second one is worth reading first because it cuts against intuition. KraftCERT, the sector CERT for Norwegian energy, spent NOK 19,522,718 in 2025 with 12 employees, per the accounts it filed with the company register. That is USD 2,051,838 at the August 7, 2026 rate, or USD 171,000 per person per year at Norwegian cost. That is the number that scares people, and it describes cruising altitude.

An oil and gas ISAC started on USD 150,000 and no employees

The second reference is more useful because it covers the start, which is the part that decides whether anything exists at all. ONE-ISAC, the information sharing center for the US oil and natural gas sector, files an annual return with the IRS and those returns are public. It was founded in 2014 on top of a trade association, with no law requiring anyone to join.

ONE-ISAC Form 990 filings, via ProPublica's Nonprofit Explorer. The dues column is the program service revenue line.
YearRevenue USDOf which, duesExpenses USD
2014, founding567,100567,1000
2015, first operating year324,194324,194149,881
20171,004,4021,004,402716,203
20201,360,1531,299,4001,252,296
20231,755,5311,639,7451,352,446

Three things read off that table. Year one cost USD 149,881, in the most expensive country in the world to hire security people. In 2014 they collected and spent nothing, so the first operating year ran on cash banked before there was anything to operate, which is what KraftCERT's three founders did when they guaranteed the funding. And the third sits in what is absent: across all ten filings, the line for contributions and grants is zero. Ten years without a dollar of public money.

One figure changes the design rather than the budget. ONE-ISAC reports zero salaries in all ten years while spending as much as USD 1,352,446 annually. It has no employees. A third party runs the operation under contract. In-house staff is a choice the model does not require, and it is the most expensive choice to reverse.

Own estimate, built on an assumption of USD 60,000 in fully loaded annual cost per person in Argentina, within a range of 45,000 to 80,000. This is not a validated budget.
ScenarioWhat it doesPeopleUSD per year
MinimumSharing, alerts and coordination. No sensors of its own3270,000
MiddleAdds detection, with sensors at 25 sites7775,000
FullOperations center with a round-the-clock watch, 80 sites162,000,000

The full scenario lands in the same order of magnitude as KraftCERT, with more people and more sensors, which is what changing cost country should do. The minimum is the one that matters, because it is the one that decides whether this starts at all. Against the ONE-ISAC precedent, that USD 270,000 stops looking like a bet: it sits above the US start, in a country where a senior security hire costs a third as much. Buy the operation instead of building it and the floor drops toward the 150,000 to 200,000 range.

Dues tiered by size, on the WaterISAC model, with anchors guaranteeing the funding the way KraftCERT's three founders did in 2014.
TierWhoAnnual dues
Founding anchorGas transporter, large producerUSD 80,000
LargeGenerator, power transmission, large distributorUSD 35,000
MidProvincial distributor, gas marketerUSD 12,000
SmallElectric cooperative, small distributorUSD 3,000
SupplierCritical vendor, vouched for by two membersUSD 6,000

Four anchors bring in USD 320,000 against a cost of 270,000. That pays for year one, and it is the number to carry into the first meeting. Forty members spread across the five tiers yield USD 710,000, which covers most of the middle scenario. For scale: SektorCERT has more than 300 members.

Where dues funding breaks

The model has a documented breaking point, and it is better raised here than by a skeptic later. MS-ISAC, the sharing center for US state and local government, had 18,574 members on September 30, 2025, the day it lost the USD 27,000,000 a year the federal government had been providing. Moving to tiered dues starting at USD 1,495 a year for small jurisdictions, it shed roughly 70% of its membership.

The easy reading is that dues do not work. The accurate one is different: charging from birth is not the same as starting to charge. ONE-ISAC and WaterISAC have billed from day one and have grown for ten and twenty-four years respectively. MS-ISAC members were asked to pay for something they had been getting free, and 70% of them read that as what it was on their side of the ledger: a budget cut.

That yields a concrete design constraint. The value of a sector center rises with the number of firms reporting into it, so the entry rung has to be low enough that the long tail stays in. The USD 3,000 for an electric cooperative is the right order, and the US floor suggests going lower still: a small distributor that reports an incident is worth more than what it pays.

Funding

The State is about to know what is exposed, with nobody to tell

The Cybersecurity for Critical Information Infrastructure Program, IDB loan 5735/OC-AR, was approved on January 11, 2023 and signed on June 7 of that year, for USD 30,000,000 with no local counterpart funding. The Chief of Cabinet's office executes it, and it closes in 2028. Its documents are public, and read together they describe a design gap that can still be closed.

The monitoring report for January to December 2025, validated in May 2026, records USD 2,500,000 disbursed against 30 million. Measured against delivered outputs, the results matrix counts USD 713,215 executed in three years: 2.4%.

That does not mean the program is idle. The current procurement plan, dated July 2026, lists 42 processes worth USD 24,385,949, with contracts signed and tenders open. It means something else, and a word search through that plan shows it: "private", "sharing", "sector-specific" and "energy" do not appear once. The whole instrument points at the State.

The platform being bought scans the entire country

The program's most advanced tender, opened in May 2026 at USD 1,200,000, buys a cyberspace observation platform for the National Cybersecurity Center. Per its specification, it actively scans every IP address assigned to Argentina plus the .ar domain, on a cycle no longer than 12 hours, across a universe of more than 20 million nodes, and verifies vulnerabilities without exploiting them.

A large share of what that scan will surface belongs to private critical infrastructure operators: gas and power transmission and distribution companies, producers, refiners, generators. Firms outside the public sector, under no sector cybersecurity obligation, with no established channel to reach them.

The channel is written into the program itself. Under the first component sits an output called "platforms for threat analysis and information sharing with the private sector implemented", targeting one platform by 2028 with an adjusted budget of USD 2,600,000. The monitoring report confirms the operation's objectives were not reformulated, so the commitment stands. Its physical and financial progress at the close of 2025 is zero, and it had USD 650,000 programmed for that year that went unused.

That is the whole point of this memo. Within months the Argentine State will hold a detailed picture of what is exposed across the country's private energy infrastructure. Four things will be missing: a sector body to coordinate with, a protocol for handling that information, a confidentiality agreement, and any assurance that a shared finding will not turn into a penalty or a tariff review. Warning companies one at a time under those conditions is worse than not warning them, because it hardens the distrust that later blocks any sharing at all.

The open question is not where the money comes from. It is who signs on the other side.

Sequence

Four phases, and each one is worth having even if the next never happens

Order matters more than speed here. If the State convenes before any operator is committed, the table fills with officials and vendors, which is exactly what happened to the 2011 critical infrastructure program.

Before the order comes a decision about form, and this memo's two references point different ways. SektorCERT reached sensors after it already had a legal mandate and three hundred members recruited through trade associations. ONE-ISAC never deployed a sensor and has run for twelve years. Deploying sensors in year one forces the conversation to open on the hardest objection, which is who gets to watch the traffic, before any of the trust that makes it answerable has been built.

Hence the shape proposed here: SektorCERT as the five-year destination, ONE-ISAC as the starting form. Sharing, alerts and coordination first, housed in a trade association that already holds the roster; tiered dues from day one; operating capacity bought rather than built. Sensors arrive once the sharing works and somebody asks for them.

A map, not meetings

An attack surface map of the sector built from open sources alone, touching no system. This is what opens doors: nobody takes a meeting about founding a consortium, and almost everyone takes one to see an inventory of what their company looks like from the outside.

The table, on a light contract

A formal convening, a confidentiality agreement signed before anything is shared, and a cooperation consortium contract under articles 1470 to 1478 of the civil and commercial code, which creates no legal entity and cannot direct members' activity. No sensors, unless an operator asks for them.

The entity, with dues coming in

A civil association, three or four anchors as members, the minimum scenario running, and response capacity contracted rather than built. International accreditation and an agreement with a peer sector CERT, which is quick to get because all three European ones already sign with foreign partners.

Scale and legal framework

Extension to water and transport, an annual sector exercise, and the push for the bill. With two years of operation and its own data, the consortium stops petitioning for a law and becomes the technical source behind it.

Drafts

A regulation that costs nothing, and a bill for what the regulation cannot do

Both texts below are working drafts, written by someone who is not a lawyer, so that a conversation can start from a text instead of an idea. They need professional review before being tabled anywhere.

Draft regulation from the energy secretariat

It creates the Energy Sector Cybersecurity Table as a voluntary forum, with no power to direct or audit its participants. Members are the secretariat as chair, the regulator, the national cybersecurity center as standing guest, CAMMESA, the four power associations, the oil and gas institute, MEGSA, and any operator that opts in.

Its remit has two halves. The first is design: propose the legal vehicle and the funding for a permanent sharing mechanism run by the operators themselves. The second is rules: the information handling protocol, the criteria for identifying critical infrastructure in the sector, a voluntary notification scheme, and the legal changes needed. It also creates a voluntary, free register of cybersecurity points of contact, readable only by its registrants.

Three clauses do the heavy lifting. Information shared at the table is not used as grounds for enforcement, audit or tariff review. The table has 180 days to deliver its proposal with a budget. And running it carries no budget appropriation: a non-profit sector body serves as technical secretariat at no charge. A closing article invites the Chief of Cabinet's office to consider assigning the loan's private-sector sharing output to whatever the table proposes.

That design is deliberate. It costs nothing, imposes no duty on private parties, creates no structure or posts, and hands the signer an agenda in a field where Argentina trails Chile and Brazil. The precedent is the Norwegian regulator, which in 2014 urged the industry to build its own security team, and KraftCERT is what came out of it.

What only a law can do

A regulation binds the conduct of the body that issues it. It cannot carve out an exception to the public information access regime, and it cannot waive liability toward third parties. Those protections are the reason the second draft exists, and there are five of them.

No enforcement use

What is shared in good faith with a recognized sector center cannot ground enforcement, audit or tariff review proceedings against the party that shared it. This is the problem the 2015 US sharing act was written to fix, and without it sharing goes cold.

Civil liability exemption

Sharing threat or vulnerability information under the applicable protocol creates no liability toward third parties. Without this clause, every operator's legal department has reason to recommend silence.

Freedom-of-information carve-out

Incident and vulnerability information about critical infrastructure held by government bodies falls under the exceptions of the access law. It is the public-side mirror of why SektorCERT chose to be private.

Antitrust safe harbor

Threat information sharing among competitors, confined to that purpose, does not by itself constitute a restrictive practice under competition law.

Use limitation

Shared information may be used for cybersecurity purposes only, and is not passed to intelligence agencies without a court order. This clause answers the 2024 precedent, when cybersecurity was moved under the intelligence agency.

The rest of the bill wraps around those five: tiered obligations, staged notification at 3 hours, 72 hours and 15 days as in the Chilean law in force since 2025, and the figure of the recognized sector center, with one clause that changes the entire incentive: notifying through the center discharges the duty to notify the authority.

Limits

What this memo cannot claim

It cannot claim that a consortium would have prevented any of the fourteen incidents in the Argentine register, or that it would prevent the next one. SektorCERT did not prevent the 2023 attack either: eleven of the 22 companies had not patched despite the warning. A sector center makes an attack visible and cuts it short. It does not fix its members' hygiene.

The three cost scenarios are own estimates, not a validated budget. The USD 60,000 per person assumption does not come from a salary survey: it comes from bracketing between what dollarized remote work pays and the verified Norwegian cost. Change that assumption and everything else moves with it. The ONE-ISAC figures are tax filings, but they describe another country and another supplier market: they work as an order of magnitude, not as a transferable budget.

About the IDB loan, what its public documents say can be claimed: that the private-sector sharing output is still live and unexecuted, and that the procurement plan records no process aimed at the private sector. It cannot be claimed that those funds are available, nor that a private entity could receive them, since the borrower is the State and no other party holds any right to them. Nor that a program running at 2.4% execution after three years would speed up because a counterpart appeared.

That the cyberspace observation platform will surface vulnerabilities at private energy operators is a reasonable inference from its stated scope, not a verified fact. Nor is it verified that no mechanism for returning findings to those operators is already planned: what is verified is that none appears in the program's public documents.

Nor can it be claimed that no informal channels exist today among security officers at Argentine energy companies. What is verified is that no public or institutional trace of one exists, and absence of trace is not proof of absence.

Who is behind this

Matías Podeley. An ITBA engineer, eighteen years in energy: four in operations in Neuquén, simulation of giant fields like Camisea and technical backing of asset purchases above US$ 300 million. Buenos Aires.

If this is your problem

Operators, trade bodies and agencies

This memo was written to circulate. If something here is wrong, a note with the source is enough to get it corrected. If there is interest in discussing the design, the budget or the drafts, the conversation is open.

matias@podeley.ar · Buenos Aires