Cybersecurity and regulatory compliance consulting.
We support you in the joint implementation of Law 21.663 (Cybersecurity Framework) and Law 21.719 (Data Protection), integrating legal and technical advisory. Compliance as a competitive advantage.
Law 21.663
In force since 2025 · progressive OIV designationIt requires detecting and responding to incidents, notifying the authority within deadlines and training teams. Fines can reach up to 40,000 UTM and also fall personally on the Cybersecurity Delegate.
Law 21.719
Deadline · December 1, 2026It fully reorders how personal data is processed: record of activities, impact assessment, appointment of a DPO and breach protocol. Fines can reach up to 20,000 UTM or 4% of annual revenue and also fall personally on the Data Protection Officer.
We are a consultancy that approaches cybersecurity from the technical and legal sides, integrating both areas for a correct interpretation of the regulation.
A multidisciplinary team of specialists in cybersecurity, regulatory compliance and data protection.
Technical Analysis
- Maturity assessment and risk management
- Implementation of security controls
- Training and awareness for compliance
Legal Backing
- Specialized regulatory interpretation
- Valid evidence before regulators and audits
- Governance and documented processes
Compliance as an investment.
Reaching the 2026 deadlines in compliance protects three things at once: the finances, the operation and the commercial position.
Avoid sanctions
The fines the law contemplates reach the highest range of Chilean regulation and can fall personally on the designated delegates. Complying on time is how that exposure is reduced and kept under control.
Operational continuity
Detect, respond to and recover from an incident without stopping the business. The continuity and recovery plans the norm requires are, before a requirement, a defense of revenue.
Commercial advantage
Being able to prove compliance opens doors: tenders, contracts with large clients and the trust of counterparts that already demand the evidence. The reputation of being in compliance is an asset.
Our services.
Regulatory compliance, risk management and audit readiness under the Cybersecurity Framework Law (LMC), the Data Protection Law (LPD) and Information Security Management System (SGSI) recommendations.
For Vital Importance Operators and Essential Service Providers. Main deliverables: critical-asset inventory, continuity and recovery plans (BCP/DRP) with ANCI protocol, support in appointing the Cybersecurity Delegate, IT risk assessment and technology recommendations.
Deliverables subject to OIV/PSE evaluation and classification
For any organization that processes personal data. Main deliverables: Record of Processing Activities, impact assessment (DPIA), support in appointing the DPO, privacy annexes for suppliers and breach protocol before the authority (APDP).
All of the above, plus the full management system. Main deliverables: ISMS scope and policy, ISMS Manual and Statement of Applicability (SoA), legal-requirements matrix, internal-audit program and awareness plan.
SGSI: mandatory for OIV
Gap analysis against Law 21.663 and Law 21.719, with a compliance report per framework.
Analysis of processes, vulnerabilities and configurations, with an asset inventory and a remediation plan.
Cyber-hygiene workshops, phishing simulation and team training based on both laws.
Custodian provides cybersecurity and compliance consulting and audit services. Frameworks and management systems (including the ISMS) are implemented as services for the client. Custodian does not claim to hold certifications it has not obtained.
December 2026 is already on the calendar.
Start with an initial assessment: we tell you where you stand against Law 21.663 and Law 21.719, and what is missing to arrive on time.