---
title: "CNO 1960 Agreement: Compliance for the Colombian Electricity Sector"
description: Practical guide to comply with the CNO 1960 Agreement, strengthening cybersecurity in the Colombian electricity sector in the face of growing digital threats.
image: https://blog.internexa.com/hubfs/001-Portada%20blog.webp
---

![CNO 1960 Agreement: Practical Compliance Guide for the Colombian Electricity Sector](https://blog.internexa.com/hs-fs/hubfs/001-Portada%20blog.webp?width=1296&height=460&name=001-Portada%20blog.webp)

# CNO 1960 Agreement: Practical Compliance Guide for the Colombian Electricity Sector

October 31,2025  | [Mines & Energy](https://blog.internexa.com/en/tag/mines-energy)

Jhon Jairo Mira Duque

*How to prepare for new critical infrastructure cybersecurity requirements*

On September 2, 2024, Air-e, the main energy marketer in the Colombian Caribbean, faced a ransomware-type cyberattack that compromised its critical systems. Thousands of users were left unable to pay their bills online. Most worrying: the attack managed to breach Kaspersky's advanced protection tools using a previously unidentified ransomware. [10]

This incident is not isolated. Colombia faced 36 billion attempted cyberattacks in 2024, ranking as the fourth most attacked country in Latin America. The energy sector represents 10% of these attacks, evidencing a critical vulnerability in the country's infrastructure.

In response to this growing threat, the National Operation Council (CNO) issued **Agreement 1960** on April 3, 2025, which updates the cybersecurity requirements for all companies in the National Interconnected System (SIN). This article provides a practical and objective guide to understand what the new regulations require and how to prepare for compliance.

## 1. The Threat Landscape that Motivated the 1960 Agreement

### 1.1 Statistics on Cyberattacks in Colombia

The numbers are overwhelming:

- **36 billion attempted cyber-attacks** in 2024 (Fortinet, IBM X-Force).
- **77,866 reports of cybercrime** to the National Police (+23% vs. 2023)
- **22,086 vulnerabilities** identified in critical systems (ColCert)
- **10% of attacks** specifically target the energy sector

Colombia is currently the fourth most attacked country in Latin America, demonstrating the urgency of strengthening digital defenses, especially in critical infrastructures such as the electricity sector.

### 1.2 The Air-e Case: Anatomy of a Critical Infrastructure Attack

The Air-e attack illustrates the sophistication of today's threats:

- **Date:** September 2, 2024
- **Victim:** Air-e (main energy distributor in the Colombian Caribbean)
- **Attack Type:** Previously unidentified ransomware
- **Impact:** Disruption of critical services, inability to make online payments.
- **Sophistication:** Managed to evade advanced Kaspersky tools.

This incident demonstrates that even with enterprise-grade cybersecurity solutions, threats evolve faster than traditional defenses.

### 1.3 International Precedents Justifying the Agreement

The 1960 Agreement responds to a global trend. Recital 7 of the CRO is explicit: "The likelihood of high-impact cyber-attacks has increased. Cases such as the blackouts recorded in Ukraine in 2015, 2016, 2022 and 2024 produced by cyber-attacks, as well as attacks on electricity infrastructures in the United Kingdom, Ireland, the United States, Israel, India, among others have shown that cyber-attacks on these infrastructures are an active part of the current and future risk landscape."

### Flagship cases:

- Ukraine (2015-2024): The first blackout caused by [cyberattack ](https://www.welivesecurity.com/la-es/2016/03/02/ciberataque-causo-cortes-de-luz-ucrania/)affected 225,000 people in December 2015. A year later, the [Industroyer ](https://www.elespanol.com/omicrono/software/20171119/verdadera-historia-detras-informatico-provoco-apagon-ucrania/263224383_0.html)malware knocked out power to one-fifth of Kiev. Attacks continued in 2022 and 2024, demonstrating that these threats are persistent and evolving.
- Stuxnet (2010): The first[ cyber-weapon designed for critical infrastructure](https://books.spartan-cybersec.com/malware/los-malwares-mas-impactantes-de-la-historia/stuxnet-el-malware-que-destruyo-una-planta-nuclear) destroyed approximately 1,000 nuclear centrifuges in Iran, proving that malware can cause actual physical destruction.
- Colonial Pipeline, USA (2021): The largest attack on [U.S. oil infrastructure](https://www.nytimes.com/es/2021/05/11/espanol/colonial-pipeline-ransomware.html) disrupted the supply of 45% of the East Coast's fuel for six days, causing shortages and panic among the population.
- **Lesson for Colombia:** These cases share a disturbing pattern: infrastructure considered secure was compromised, traditional defenses proved insufficient, and the impacts transcended the digital to cause real blackouts and economic losses. The 1960 Agreement translates these international lessons into concrete requirements for the National Interconnected System.

## What is the CNO 1960 Agreement?

The 1960 Agreement is the most recent update of the Cybersecurity Guide for the Colombian electricity sector, issued by the National Operation Council on April 3, 2025.

### 2.1 Scope and Applicability

The agreement applies to all agents of the National Interconnected System (SIN):

- System Operator (XM)
- Power generators
- Transmitters
- Distributors

This includes both major and minor plants, with requirements differentiated according to the criticality of the assets.

### 2.2 Change of Focus: From Regulatory Compliance to Risk Management

One of the most significant innovations of the 1960 Agreement is the paradigm shift:

**Previously (1502 Agreement):** Regulatory compliance approach with standardized controls for all.

**Now (1960 Agreement):** Risk-based approach that allows each agent to tailor their controls according to their specific risk profile.

This change allows optimizing investments in cybersecurity, prioritizing resources towards the protection of those assets with the greatest potential impact on the operation of the SIN.

## 3. Structure and Controls of the 1960 Agreement

The 1960 Agreement establishes **58 mandatory controls** organized into **10 main categories**. Each control has specific deadlines for implementation and periodic review.

### 3.1 The 10 Categories of Controls

| **#** | **CATEGORY** | **FOCUS AND SCOPE** |
| --- | --- | --- |
| 1 | Identification of Critical Assets | Inventory and classification of cyber assets |
| 2 | Governance and Personnel Management | Personnel policies, responsibilities, risk assessment |
| 3 | Perimeter | Logical security, access lists, monitoring |
| 4 | Cyber Asset Security Management | Change control, anti-malware, vulnerability assessment |
| 5 | Recovery planning | Operational resilience and business continuity |
| 6 | Incident Response | Detection, containment and response procedures |
| 7 | Physical Security | Physical protection of critical cyber assets |
| 8 | Supply Chain Management | Evaluation of suppliers and third parties |
| 9 | Risk Management | Comprehensive risk analysis and penetration testing |
| 10 | Compliance | Periodic audits and reporting |

### 3.2 Critical Implementation Timelines

The Agreement establishes different deadlines according to the criticality of each control:

**Urgent Controls (6 months or less):**

- Verification of authorization records
- Access lists to critical cyber assets.

**Medium Term Controls (12 months):**

- Identification and updating of critical assets
- Personnel risk assessment
- Access management procedures
- Recovery and resiliency plan

**Long Term Controls (24 months):**

- Internal cybersecurity audits
- Change control procedures
- Validation of configuration changes

## 4. How to Prepare for Compliance

Compliance with the 1960 Agreement requires a structured and planned approach. The following is a practical implementation roadmap.

### 4.1 Phase 1: Initial Diagnosis (Months 1-2)

**Objective:** Assess the current state of cybersecurity and identify gaps.

**Key Actions:**

- **Conduct comprehensive inventory** of critical assets and cyber assets.
- **Evaluate existing controls** against the 58 requirements of the 1960 Agreement
- **Identify critical gaps** requiring immediate attention
- **Estimate resources needed** (budget, personnel, technology)

### 4.2 Phase 2: Strengthening Governance (Months 3-4)

**Objective:** Establish organizational structure and base policies.

**Key actions:**

- **Designate and notify the CNO of** the cybersecurity officer (deadline: 6 months).
- **Update** cybersecurity**policies** aligned with the 1960 Agreement.
- **Implement awareness program** for all personnel
- **Establish** access management and revocation**procedures**

### 4.3 Phase 3: Implementation of Technical Controls (Months 5-12)

**Objective:** Deploy priority technical controls.

**Key Actions:**

- **Implement 24/7 monitoring** of critical systems.
- **Deploy** threat detection**tools** (SIEM, EDR)
- **Establish vulnerability management** and continuous patching
- **Set up backup and recovery** of critical information
- **Perform penetration testing** on critical assets

### 4.4 Phase 4: Risk Analysis and Optimization (Months 13-18)

**Objective:** Perform comprehensive risk analysis and adjust controls.

**Key actions:**

- **Execute** internal and supplier**risk analysis** (deadline: April 2026).
- **Evaluate** technological**supply chain**
- **Adjust controls** according to specific risk profile
- **Document evidence** of compliance for audits

## 5. Strategic Decisions: Build or Contract?

One of the most critical decisions INS operators will face is how to implement the monitoring, detection and response capabilities required by the 1960 Agreement.

### 5.1 Option 1: In-house Security Operations Center (SOC)

**Advantages:**

- Full control over infrastructure and processes
- In-depth knowledge of in-house OT/SCADA systems
- No dependence on third parties for operation

**Disadvantages:**

- **High initial investment:** SIEM, EDR, SOAR platforms can cost between USD 200.000 - 500.000
- **Talent shortage:** difficult to recruit and retain specialized OT analysts
- **Implementation time:** 12-18 months for effective operation
- **Limited coverage:** difficult to maintain 24/7/365 operation with internal resources

### 5.2 Option 2: SOC-as-a-Service (SOC-as-a-Service)

**Advantages:**

- **Rapid implementation:** operational in 30-60 days
- **Predictable cost:** monthly subscription model
- **Access to expertise:** specialized and up-to-date threat analysts
- **Complete coverage:** 24/7/365 monitoring guaranteed
- **Up-to-date technology:** access to latest tools without additional investment

**Disadvantages:**

- Vendor dependency for critical operation
- Need to select vendor with OT/SCADA expertise
- Long-term recurring cost

### 5.3 Option 3: Hybrid Model

Many organizations are opting for a **hybrid model** that combines:

- **Small internal team** for business knowledge and coordination
- **External SOC** for 24/7 monitoring, threat analysis and initial response
- **Specialized consultants** for risk analysis, audits and penetration testing

This model allows for efficient compliance with the 1960 Agreement while progressively building internal capabilities.

## 6. Recommendations for Successful Implementation

Based on international best practices and the Colombian context, the following actions are recommended:

### 6.1 Start with a Rigorous Diagnosis.

Do not assume the current level of cybersecurity. Conduct a professional diagnostic that evaluates:

- Current compliance status vs. the 58 controls in the 1960 Agreement.
- Existing cybersecurity process maturity
- Available technical and staffing capabilities
- Investment gap required

### 6.2 Prioritize by Actual Risk

The risk-based approach of the 1960 Agreement allows for prioritization. Focus first on:

- **Highest criticality assets:** systems that, if they fail, impact INS operation.
- **Closest time-bound controls:** meet 6-12 month requirements first
- **Highest risk gaps:** critical vulnerabilities identified in diagnosis

### 6.3 Invest in Staff Training

Human error remains the leading cause of security breaches. It is critical:

- Implement continuous awareness program for all staff.
- Train technical teams in OT/SCADA security
- Train leaders in security incident management
- Certify the cybersecurity manager in relevant standards (CISSP, CISM, IEC 62443).

### 6.4 Establish Clear Governance

Cybersecurity is not just a technical issue. It requires:

- **Executive sponsorship:** senior management must prioritize and approve resources.
- **Clear accountabilities:** define who does what and with what authority
- **Documented policies:** formalize procedures and formally approve them
- **Periodic reporting:** inform the board of directors on cybersecurity status

### 6.5 Document Everything

The 1960 Agreement requires documentary evidence of compliance. From inception:

- Keep records of all cybersecurity activities.
- Document risk analysis decisions and compensating controls.
- File evidence of audits, evaluations and tests.
- Prepare periodic reports for the CRO

### 6.6 Consider Strategic Alliances

Given the scope of the 1960 Agreement, evaluate alliances with:

- **Specialized SOC providers** that understand the operation of the electricity sector.
- **OT cybersecurity consultants** with expertise in NERC CIP and IEC 62443
- **Other NIS operators** to share best practices and lessons learned
- Sector**guilds and associations** to keep up to date

## 7. Conclusion: A Challenge Transformed into an Opportunity

The CNO 1960 Agreement represents a fundamental change in how the Colombian electricity sector approaches cybersecurity. Far from being a regulatory burden, it should be understood as an opportunity to:

- **Modernize the technological infrastructure** with international standards.
- **Reduce operational risk** in the face of increasingly sophisticated threats.
- **Strengthen the resilience of the SIN**, guaranteeing the national electricity supply.
- **Position itself competitively** with world-class cybersecurity capabilities.

The Air-e case demonstrated that no organization is immune to cyber-attacks, no matter what tools it has in place. What makes the difference is:

- A comprehensive approach that combines technology, processes and people.
- Rapid detection and response capabilities
- Dedicated continuous monitoring in OT/SCADA environments
- Proven resilience and recovery plans

The timeline for meeting the 1960 Agreement may seem challenging, but with structured planning and the right partnerships, it is entirely achievable. Organizations that proactively address this challenge will not only be compliant, but will build a sustainable competitive advantage in an increasingly digital environment.

***Cybersecurity is no longer optional for the Colombian electricity sector. It is the foundation on which the energy reliability of the future will be built.***

*InterNexa, part of the ISA Group, offers SOC services as a Service specialized in critical infrastructure, with more than 25 years of experience in the Colombian energy sector. For inquiries about cybersecurity solutions aligned to the 1960 Agreement, you can contact us through our website.*

[![Más información](https://no-cache.hubspot.com/cta/default/8220154/interactive-156531700072.png) ](https://blog.internexa.com/hs/cta/wi/redirect?encryptedPayload=AVxigLIbxAYQtvIXcIjQt0PssiwErVsNB%2Bk6e%2FCFFDSMjDsexGhjhSZENunZrATtMoVKtQJ9qGTf91UPKJ8jcjy%2FI3IPnAJHmV5nIZdMTsCZp12kPn%2BNxWUq7OwLAPiiQ19XRsR7Vmk%2Bp7EMGQD4zfFkQyRnkmXxceeckokC70uDrKcv%2Flnx%2FsIY93WkzXdd6%2F0MWkNw6sfAk7WI&webInteractiveContentId=156531700072&portalId=8220154&hsLang=en)

- SHARE
- <http://www.facebook.com/sharer.php?u=https://blog.internexa.com/en/acuerdo-cno-1960-cumplimiento-para-el-sector-electrico>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://blog.internexa.com/en/acuerdo-cno-1960-cumplimiento-para-el-sector-electrico>
- <http://twitter.com/share?text=[TITLE]&url=https://blog.internexa.com/en/acuerdo-cno-1960-cumplimiento-para-el-sector-electrico>

Jhon Jairo Mira Duque

Passionate about how data is captured and the stories it tells that drive business outcomes. I work as Market Manager at InterNexa Colombia, where I leverage strong relationships with clients, manufacturers, and industry suppliers, combined with sharp negotiation skills to deliver on business objectives.

[mailto:jjmira@internexa.com](mailto:jjmira@internexa.com) <https://www.linkedin.com/in/jhon-jairo-mira-duque-931b3b95/>

## Discover more content

![Fast and stable connections in ISP networks](https://blog.internexa.com/hs-fs/hubfs/Conexiones%20r%C3%A1pidas%20(1).jpeg?width=352&height=180&name=Conexiones%20r%C3%A1pidas%20(1).jpeg)

Connectivity ISP (Internet Service Providers)

### [Fast, efficient and stable connections: a wish that can come true](https://blog.internexa.com/en/fast-and-stable-connections-in-isp-networks?hsLang=en)

We are in the era of connectivity, of immediacy... There is little patience, even. Slow connections,...

![Maximizing content delivery on OTT, CDN and Gaming](https://blog.internexa.com/hs-fs/hubfs/Contenidos%20(1).jpeg?width=352&height=180&name=Contenidos%20(1).jpeg)

Connectivity OTT

### [Maximizing content delivery on OTT, CDN and Gaming platforms with high-capacity networks in Latin America](https://blog.internexa.com/en/maximizing-content-delivery-on-ott-cdn-and-gaming?hsLang=en)

The growing consumption of digital services in Latin America, especially in emerging markets such as...

![infrastructure-neutral-automated-growth-telecommunications](https://blog.internexa.com/hs-fs/hubfs/Shutterstock_1958852539.png?width=352&height=180&name=Shutterstock_1958852539.png)

ISP (Internet Service Providers) 5G OTT

### [How infrastructure automation accelerates growth for ISPs, Carriers, and OTTs](https://blog.internexa.com/en/infrastructure-automation-accelerates-growth-telecommunications?hsLang=en)

In an increasingly competitive telecommunications market, ISPs, mobile operators and OTT providers face the...

![telecommunications](https://blog.internexa.com/hs-fs/hubfs/futuristic-smart-city-with-5g-global-network-technology.jpg?width=352&height=180&name=futuristic-smart-city-with-5g-global-network-technology.jpg)

Connectivity

### [State of the Network 2025: key TeleGeography report and global telecommunications trends](https://blog.internexa.com/en/trends-in-telecommunications-informe-state-of-the-network-2025?hsLang=en)

InterNexa has analyzed the report Stateofthe Network 2025 by TeleGeography, an essential guide to...

![Optical Fiber and 5G Networks: Allies in the Quest for Better Connectivity](https://blog.internexa.com/hs-fs/hubfs/Fibra%20%C3%B3ptica.webp?width=352&height=180&name=Fibra%20%C3%B3ptica.webp)

Connectivity ISP (Internet Service Providers) OTT

### [Optical Fiber and 5G Networks: Allies in the Quest for Better Connectivity](https://blog.internexa.com/en/benefits-of-optical-fiber-in-5g-networks?hsLang=en)

The arrival of 5G technology promises to transform our digital lives, but its success depends largely on...

![Internet Speed](https://blog.internexa.com/hs-fs/hubfs/Velocidad%20de%20internet%20(1).jpeg?width=352&height=180&name=Velocidad%20de%20internet%20(1).jpeg)

Connectivity ISP (Internet Service Providers)

### [How to Reduce Latency and Increase Internet Speed?](https://blog.internexa.com/en/reduce-latency-increase-isp-speed?hsLang=en)

Internet speed is a fundamental aspect of modern life, as it influences our ability to work, study, entertain...

![Innovation as a guarantee for your business continuity](https://blog.internexa.com/hs-fs/hubfs/Imported_Blog_Media/05-InterNexa_Articulo_Semana_2_Banner_2-2.png?width=352&height=180&name=05-InterNexa_Articulo_Semana_2_Banner_2-2.png)

Business transformation

### [Innovation as a guarantee for your business continuity](https://blog.internexa.com/en/innovation-as-a-guarantee-for-your-business-continuity?hsLang=en)

Progressively, and in a very controlled way, we are beginning to sail thedigital nowwaters immersed into...

![FTTX](https://blog.internexa.com/hs-fs/hubfs/_FTTX-1.jpeg?width=352&height=180&name=_FTTX-1.jpeg)

Connectivity

### [Optimize Your FTTX Implementation: Strategies for Ensuring Efficient Coverage](https://blog.internexa.com/en/why-optimize-your-fttx-implementation?hsLang=en)

## **Focusing on Efficiency**

In this article, we explore a series of fundamental strategies that allow companies to...

![Cybersecurity Glossary for Critical Sectors](https://blog.internexa.com/hs-fs/hubfs/001-Glosario%20Ciberseguridad.webp?width=352&height=180&name=001-Glosario%20Ciberseguridad.webp)

Mines & Energy

### [Cybersecurity Glossary for Critical Sectors](https://blog.internexa.com/en/cybersecurity-glossary-for-critical-sectors?hsLang=en)

**A practical guide for mining, energy and government professionals in Colombia and Peru.**

*A reference guide...*

![Latency](https://blog.internexa.com/hs-fs/hubfs/Latencia.webp?width=352&height=180&name=Latencia.webp)

### [Low latency in cloud gaming: keys to a seamless experience](https://blog.internexa.com/en/low-latency-in-cloud-gaming?hsLang=en)

Latency is a critical challenge for Internet Service Providers (ISPs), especially in the context of **cloud...**

![Benefits of Cloud Backup for Ensuring Business Continuity](https://blog.internexa.com/hs-fs/hubfs/001-Backup-1.webp?width=352&height=180&name=001-Backup-1.webp)

Cloud

### [Benefits of Cloud Backup for Ensuring Business Continuity](https://blog.internexa.com/en/cloud-backup-with-internexa?hsLang=en)

Where is your information stored? Is it secure where you have it? What if you want or need to access it from...

![IP Routing](https://blog.internexa.com/hs-fs/hubfs/Direccionamiento%20IP.png?width=352&height=180&name=Direccionamiento%20IP.png)

Connectivity ISP (Internet Service Providers)

### [Keys to successful IP routing](https://blog.internexa.com/en/keys-to-successful-ip-routing?hsLang=en)

The key to the efficient and secure flow of information through complex networks has a name: IP routing. But...

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jhon Jairo Mira Duque",
    "url" : "https://blog.internexa.com/en/author/jhon-jairo-mira-duque"
  },
  "dateModified" : "2026-05-14T16:07:29.852Z",
  "datePublished" : "2025-10-31T15:02:21.000Z",
  "headline" : "CNO 1960 Agreement: Compliance for the Colombian Electricity Sector",
  "image" : [ "https://blog.internexa.com/hubfs/001-Portada%20blog.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.internexa.com/en/acuerdo-cno-1960-cumplimiento-para-el-sector-electrico",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.internexa.com/hubfs/Logo%20fondos%20claros-3.png"
    },
    "name" : "INTERNEXA S.A"
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "El DWDM es una técnica de transmisión, que realiza la multiplexación por división en longitudes de onda, es decir, que utiliza varias longitudes de onda de luz, descompuesta en colores, para enviar datos desde dos o más colores de luz que pueden viajar sobre una sola fibra óptica."
    },
    "name" : "¿Qué es DWDM?"
  }
}
```