NoticiasNews

4 de cada 10 empresas en América Latina no saben si fueron hackeadas, revela el reporte de ESET 20264 in 10 Latin American Companies Don't Know If They Were Hacked, ESET's 2026 Report Reveals

2026-08-06

El ESET Security Report Latinoamérica 2026, publicado el 3 de agosto, encuestó a más de 1.500 profesionales de ciberseguridad en 962 organizaciones de 10 países de la región. El hallazgo más inquietante no es cuántas empresas fueron atacadas, sino cuántas no pueden saberlo: un 15,4% de las organizaciones no logra confirmar si fue víctima de un incidente, y entre las que no detectaron ataques, una de cada cuatro (25,1%) reconoce que podrían haber ocurrido sin ser detectados por falta de tecnología adecuada. En conjunto, esto sugiere que cuatro de cada diez organizaciones de la región carecen de la capacidad analítica para conocer su nivel real de exposición.

Los números clave del informe

  • El 52,7% de las organizaciones detectó intentos de ataque durante el último año.
  • El phishing sigue siendo el vector más frecuente, afectando al 73% de las empresas encuestadas, con picos en Educación (81,4%), Manufactura (81,1%) y Banca (79,6%).
  • Solo el 57% usa autenticación multifactor, el 36% cuenta con herramientas de prevención de fuga de datos (DLP) y apenas el 23% tiene alguna plataforma de Threat Intelligence.
  • El 56,3% de los profesionales cree que la IA facilitará ataques más sofisticados, pero el 39,2% de las organizaciones no tiene ninguna política interna que regule su uso.

La brecha real: visibilidad, no solo defensa

Mario Micucci, investigador de seguridad de ESET Latinoamérica, resume el problema con precisión: la falta de visibilidad sobre los propios entornos limita la capacidad de las organizaciones para prevenir, detectar y responder a tiempo. No es un problema de comprar más herramientas, sino de que la seguridad esté integrada en los procesos y no solo en el software.

Qué implica para empresas y entidades reguladas del Caribe

Para cualquier empresa que maneja datos de clientes —y en particular para instituciones financieras sujetas a supervisión AML— no poder confirmar si hubo una brecha no es solo un riesgo técnico: es un riesgo regulatorio. Si un regulador pregunta qué pasó con los datos de un cliente, “no lo sabemos” no es una respuesta aceptable.

En TEKFENIX construimos software empresarial a medida y productos como CumplimientoControl pensando exactamente en esta brecha: trazabilidad de cada acción, registros auditables y monitoreo continuo, para que ninguna empresa dependa de una corazonada para saber si algo salió mal. La ciberseguridad y el cumplimiento normativo dejaron de ser áreas separadas; hoy son la misma conversación.

The ESET Security Report Latin America 2026, published August 3, surveyed more than 1,500 cybersecurity professionals across 962 organizations in 10 countries in the region. The most unsettling finding isn't how many companies were attacked, but how many can't even tell: 15.4% of organizations cannot confirm whether they were victims of an incident, and among those that detected no attacks, one in four (25.1%) acknowledges that incidents could have occurred undetected due to insufficient technology. Combined, this suggests that four in ten organizations in the region lack the analytical capacity to know their real level of exposure.

Key Numbers From the Report

  • 52.7% of organizations detected attack attempts over the past year.
  • Phishing remains the most frequent attack vector, affecting 73% of surveyed companies, peaking in Education (81.4%), Manufacturing (81.1%) and Banking (79.6%).
  • Only 57% use multi-factor authentication, 36% have data loss prevention (DLP) tools, and just 23% have any Threat Intelligence platform.
  • 56.3% of professionals believe AI will enable more sophisticated attacks, yet 39.2% of organizations have no internal policy regulating its use.

The Real Gap: Visibility, Not Just Defense

Mario Micucci, security researcher at ESET Latin America, sums up the problem precisely: the lack of visibility into their own environments limits organizations' ability to prevent, detect and respond in time. It's not a matter of buying more tools — it's about security being built into processes, not just software.

What It Means for Companies and Regulated Entities in the Caribbean

For any company handling customer data — and particularly for financial institutions under AML supervision — being unable to confirm whether a breach occurred isn't just a technical risk, it's a regulatory one. If a regulator asks what happened to a customer's data, “we don't know” is not an acceptable answer.

At TEKFENIX we build custom enterprise software, and products like CumplimientoControl were designed exactly with this gap in mind: traceability of every action, auditable records and continuous monitoring, so no company has to rely on a hunch to know if something went wrong. Cybersecurity and regulatory compliance have stopped being separate conversations — today they're the same one.

← Volver al blog← Back to blog