Las empresas argumentan que sus operaciones no afectan la infraestructura crítica nacional y que el proceso de calificación fue opaco, sin fundamentación individualizada ni ponderación de proporcionalidad. La inclusión como operador de importancia vital les impone nuevas responsabilidades de ciberseguridad y los expone a multas de hasta 40 mil UTM (US$3,1 millones) por incumplimiento.
Luksic y Angelini recurren a tribunales contra inclusión en listado de ciberseguridad
Forzados a participar en un procedimiento materialmente a ciegas
Why would a mining company or fuel distributor fight so hard to stay off a cybersecurity list? It sounds like a technical classification, not something worth taking to court.
Because the classification carries real teeth. Once you're on it, you have to build security systems, hire compliance staff, conduct training, and appoint a cybersecurity officer. If you slip up, you face fines up to $3.1 million. For a company that thinks it's not actually critical infrastructure, that's a lot of cost for no benefit.
But aren't these companies actually important? If Copec stops delivering fuel, doesn't that affect the whole country?
That's the agency's argument. But Copec says its plants operate independently—one can fail without affecting the others. They proved it during the February blackout, when everything kept running on manual systems. They're saying the agency treated them as a category rather than looking at what they actually do.
So the real complaint is that the process was sloppy?
Partly. But it's also about power. The agency published a list of 239 entities with almost no explanation of why each one was included. Companies submitted objections, and the agency ignored them. UC Christus said they were forced to participate "blind." That's not just annoying—it's the difference between a legitimate regulatory decision and an arbitrary one.
What does the agency say in its defense?
They say this is normal. Companies always challenge these things, especially in sectors that haven't dealt with cybersecurity regulation before. They see it as part of the process, not a sign that something went wrong.
Do you think the courts will side with the companies?
That depends on whether the judges believe the agency had to justify each company individually, or whether a broad sectoral approach is enough. The companies have a point about transparency and proportionality. But the agency also has a point about national security. It's genuinely unclear.
O Pulso
- Doce entidades presentaron recursos contra la resolución de la Anci del 24 de julio
- Multas de hasta 40 mil UTM (US$3,1 millones) por incumplimiento
- 239 entidades incluidas en el listado de operadores de importancia vital
- Copec continuó suministrando combustible durante el apagón del 25 de febrero de 2025
Las empresas argumentan que sus operaciones no afectan la infraestructura crítica nacional y que el proceso de calificación fue opaco, sin fundamentación individualizada ni ponderación de proporcionalidad. La inclusión como operador de importancia vital les impone nuevas responsabilidades de ciberseguridad y los expone a multas de hasta 40 mil UTM (US$3,1 millones) por incumplimiento.
Doce entidades, incluyendo mineras del grupo Luksic y Copec del grupo Angelini, recurren a tribunales para impugnar su inclusión en el listado de operadores de importancia vital de la Agencia Nacional de Ciberseguridad, argumentando que la decisión no consideró sus observaciones y les impone costos injustificados.
A dozen companies filed legal challenges this month against Chile's National Cybersecurity Agency, arguing they should not be classified as vital infrastructure operators—a designation that imposes new compliance costs and exposes them to fines of up to 40,000 UTA, roughly $3.1 million.
The disputes center on a roster published July 24 by the Agencia Nacional de Ciberseguridad (Anci), which identified 239 entities across fuel, water, transport, electricity, telecommunications, and other sectors as operators of vital importance. Three mining operations from Antofagasta Minerals—Zaldívar, Antucoya, and Centinela, all controlled by the Luksic group—filed complaints with the Santiago Court of Appeals, as did Copec, the fuel distributor owned by the Angelini group, and UC Christus, which operates hospitals and clinics affiliated with the Pontifical Catholic University of Chile.
The companies contend the agency ignored their written objections during the consultation period and failed to provide individualized justification for their inclusion. Zaldívar argued that its internal electrical lines serve only its mining operations, not the general public, and that any cybersecurity incident would affect only its own production processes, not the national electrical grid. The other Luksic mines made similar arguments. Copec went further, noting that during the nationwide blackout on February 25, 2025, all of its storage plants, trucks, and stations continued supplying fuel manually and without incident, demonstrating that its operations do not depend on interconnected digital systems whose failure could cascade across the broader infrastructure.
The legal framework underlying these designations is the Cybersecurity Framework Law, approved two years ago. The Anci began operations on January 1, 2025, tasked with coordinating national cybersecurity policy and identifying entities whose failure could threaten national security. Once classified as a vital operator, a company must establish continuous information security management systems, develop operational continuity and cybersecurity plans, conduct training programs, and designate a cybersecurity delegate to serve as the agency's point of contact. Failure to comply with these obligations can result in the maximum fine.
UC Christus raised a broader complaint about the process itself. The agency, the health system argued, never explicitly stated the criteria or evidence justifying any company's inclusion, leaving the public consultation "materially blind." More fundamentally, UC Christus objected that the designation doubles the company's exposure to penalties and multiplies the grounds for violation, yet the agency applied a generic, standardized approach rather than conducting strict, individualized analysis with real consideration of necessity and proportionality. The company also noted an inequity: while private operators now face potential fines, public health facilities—which make up much of the network serving the population—were excluded from the penalty regime altogether.
Copec received a 374-page file on July 31 detailing its classification, but found it contained no analysis, memo, report, matrix, minutes, or working document from the Anci itself showing how the agency applied its methodology to the company, weighed its objections, or explained why it remained on the final list. The companies had 15 business days from July 24 to file their legal challenges.
When asked about the lawsuits, the Anci responded that the court challenges are a normal part of the legal process created by the Cybersecurity Framework Law, allowing institutions to contest their designation. The agency noted that the second stage of the roster included sectors with less mature cybersecurity practices, which may explain why companies feel they do not belong on the list. Whether the courts agree remains to be seen.
Citações Notáveis
El expediente no contiene pieza alguna elaborada por la propia agencia. No existe en él ficha, minuta, informe, matriz, acta ni documento de trabajo de la Anci que aplique la metodología de calificación a la compañía— Copec, en su reclamo contra la Anci
Los recursos interpuestos en la Corte de Apelaciones es parte del proceso creado por la Ley Marco de Ciberseguridad para la calificación de operadores de importancia vital. Es un flujo absolutamente normal— Agencia Nacional de Ciberseguridad