Accessibility

A LAC4 Guide for SME-s is Now Available

LAC4 has published a “LAC4 Guide for Small and Medium Enterprises” to strengthen SME-s’ cyber resilience, written by EU CyberNet experts Mari Seeba and Milena Patiño-Villa.

“The guide offers and essential and hands-on roadmap to help SME-s across Latin America and the Caribbean to strengthen their digital defences and cyber resilience. With cyber threats increasingly targeting small and medium businesses, this guide translates complex global cybersecurity frameworks into actionable steps: from digital hygiene and phishing prevention to incident response and Zero Trust principles.” – Mari Seeba.

“Grounded in real-world examples, regional context and step-by-step activities, the guide seeks to empower SME-s to take ownership of their cybersecurity, regardless of size or budget. By following the action plan and fostering a culture of awareness in this guide, SME-s can not only reduce their vulnerabilities but also build trust with clients, partners and investors.” – Milena Patiño-Villa.

The guidebook is based on the LAC4 training for 18 small- and medium enterprises from Belize, Costa Rica, Guatemala, El Salvador, Honduras and Panama to build and strengthen their skills in protecting their systems, safeguarding valuable information and mitigate cyber threats, conducted in Antigua, Guatemala in March 2025. “This guidebook builds directly on the training materials that proved most useful during the training in Guatemala. As we observed carefully which methods worked best in practice and where adjustments were needed, we translated those lessons into this practical manual. We are grateful to the participants, who in addition to helping us test and refine the content also contributed with their own insights and experiences. We encourage SME-s to share this knowledge further in their networks to strengthen the region’s collective cyber resilience.” – Mari Seeba, Milena Patiño-Villa.

The guide, available in English and Spanish, offers several key take-aways and perspectives, for example:

  • Cybersecurity as a business imperative: cybersecurity is not a technical luxury, it is essential for business continuity, reputation and growth. SME-s in LAC4 are increasingly targeted due to limited resources and lack of awareness. Leadership must assign clear responsibility for cybersecurity, even without a formal CISO, and treat it as a shared business priority.
  • Practical risk management and prevention: common threats like phishing, ransomware, insider risks and emerging threats such as AI-powered attacks require proactive and practical measures. SMEs can start with a basic risk assessment, apply the “10 golden rules” of cyber hygiene and foster a security-aware culture through simple, continuous training and simulations.
  • Resilience through preparedness and partnerships: building cyber resilience means having a incident response plan, adopting Zero Trust principles and managing risks across the supply chain. SMEs should implement phased actions using globally recognized frameworks, perform regular assessments and demand baseline security practices from partners and vendors.

LAC4 and EU CyberNet express deepest gratitude to contributors and stakeholders whose expertise and insights have made this guide possible and impactful. LAC4 hopes that this work serves as a valuable resource for SME-s striving to protect their business and contribute positively to regional cybersecurity resilience.



Keep reading similar articles
EU CyberNet Launches Expert Podcast Series

EU CyberNet launches a podcast series to bridge the expertise from EU CyberNet’s Expert Pool and its partners to wider cybersecurity and cyber capacity building community on people, policies and practices shaping cybersecurity globally.

The 9th Blog Article of the EU CyberNet Expert Blog Series: When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer

EU CyberNet has published the ninth blog article in its Expert Blog Series. The ninth article, titled “When AI Makes Cybersecurity Decisions: Five Governance Questions Every Organisation Should Answer” is written by EU CyberNet Expert Anahiby Becerril.

The 8th Blog Article of the EU CyberNet Expert Blog Series: The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience

EU CyberNet has published the eight blog article in its Expert Blog Series. The eight article, titled “The Institutional AI Dependency Test: Can Public Services Continue When AI Cannot Be Trusted? An Evidence-Led Governance Exercise for Cyber Resilience” is written by EU CyberNet Expert Andra T. Alcalá.

Reflecting EU CyberNet Summer School 2026: Participants’ Testimonials

EU CyberNet asked four EU CyberNet Summer School 2026 participants – Gabrielle Botbol, Emmanuel Chagara, Olesya Danylchenko and Lisbeth Laurie – to share their experience in the Summer School.

Reflecting EU CyberNet Summer School 2026: Andrea Calderaro

EU CyberNet discussed with Summer School 2026 participants their experience and thoughts on the future of cyber diplomacy. Read an interview with our co-organiser Andrea Calderaro, Project Director of EU Cyber Direct.

EU CyberNet Participated in Regional Cybersecurity Exchange and the Launch of the Cyber Cluster Global Alliance in Costa Rica

EU CyberNet,together with LAC4, participated in the EU-LAC Digital Alliance technical exchange visit on cybersecurity and secure connectivity in Central America and the Cybersec Summit 2026 in San José, Costa Rica on 11-12 August 2026.