evidoria

← Back to browse

Good practice Imported

AIG's National Network Detection & Response Platform — Panama Blankets 500,000+ Government Devices in AI Threat Monitoring After a 2026 Cyberattack Wave

Panama · Panama City · See the Panama profile · See the Panama City profile

Top 83% 40/100 · Ask Evidence Copilot about this practice

After five major 2026 cyberattacks hit Panama's Social Security Fund, tax portal and ministries, AIG deployed an AI-driven Network Detection and Response platform covering 500,000+ government devices across 15 institutions, backed by a ~$6M investment.

AIG's National Network Detection & Response Platform — Panama Blankets 500,000+ Government Devices in AI Threat Monitoring After a 2026 Cyberattack Wave

Details

Promoter
Autoridad Nacional para la Innovación Gubernamental (AIG)
Period
2026–present
Keywords
cybersecurity, digital government infrastructure, public administration

Description

In 2026, Panama suffered at least five high-impact cyberattacks on public institutions, including the Social Security Fund (Caja de Seguro Social), the Panamá Emprende business portal, the Ministry of Health, the Ministry of Economy and Finance, and the Office of the Comptroller General.
In response, the Autoridad Nacional para la Innovación Gubernamental (AIG) deployed a Network Detection and Response (NDR) platform that uses artificial intelligence to identify anomalous network behaviour and potential intrusions across government systems, paired with a new Government Cybersecurity Operations Center (SOC) intended to shift the state from reactive to proactive monitoring. AIG director Adolfo Fábrega reported the platform now covers more than 500,000 government devices and digital environments across 15 critical institutions, including Tocumen International Airport, the national water authority (IDAAN) and the Ministry of Economy and Finance, with AIG investing approximately $6 million as part of over $5 million in recent cybersecurity spending.
These figures are self-reported by AIG; no independent audit of incidents prevented since deployment, nor the identity of the underlying technology vendor, was found in available public reporting, so the case should be read as evidence of rapid deployment scale rather than of demonstrated impact.

Read the full analysis: https://www.prensa.com/economia/monitorean-mas-de-500-mil-dispositivos-gubernamentales-en-panama-ante-amenazas-de-hackers/

Implementation

Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful