Ecuadorian Cybersecurity: Bridging the Gap Between Infrastructure and Strategy
An Approach of Cyberattacks with the Use of Social Networks and Communication Media for Public Organizations of the Ecuador
The paper proposes a prototype Cybersecurity Management Model tailored for public organizations in Ecuador to combat the rising tide of cyberattacks leveraging social networks and communication media. It introduces a structured framework integrating risk assessment via a 3x3 matrix and strategic mitigation protocols aligned with international standards.
TL;DR
As cyberattacks against Ecuadorian public institutions escalate—reaching staggering figures of 40 million incidents in short periods—technical defenses are proven insufficient. This paper introduces a Cybersecurity Management Model that shifts the focus from purely technical fixes to a risk-driven management framework, utilizing a 3x3 matrix to quantify threats from social networks and decentralized media.
Background & Positioning
In the global landscape of cybersecurity, Ecuador stands at a crossroads. While the country has invested in technical infrastructure, the absence of a unified strategic plan has left critical sectors like the Civil Registry and CNE (National Electoral Council) exposed. This work serves as a tactical blueprint, positioning itself as a "bridge" between local policy (Mintal) and international excellence (ISO/IEC standards).
The Core Problem: The Social Media Vector
Traditional security models often fail to account for the human factor inherent in social media. Attackers increasingly use platforms like Twitter (X) and LinkedIn to deploy:
- Hammertoss Malware: Utilizing social media as a command-and-control channel.
- Application Layer DDoS: Exposing server-side vulnerabilities through high-frequency requests.
- Credential Sniffing: Exploiting the public disclosure of personal info to launch targeted spoofing.
The authors argue that the problem is not a lack of tools, but a lack of a deductive management method to prioritize these threats.
Methodology: The 4-Pillar Management Model
The heartbeat of the paper is a management architecture designed to be adopted by any public entity.
1. The Risk Matrix (The Quantitative Core)
The paper introduces a rigorous formula for determining risk priority: (Risk Value = Impact Level × Occurrence Probability)

2. Strategic Pillars
- Incident Response: Direct actions triggered by the Risk Value (Acceptable vs. Critical).
- Quality Management: Adhering to the ISO/IEC 27000 series, ensuring that the Information Security Management System (ISMS) is not just present, but audited and standardized.
- Legal Regulations: Integrating Ecuadorian data protection projects into the technical workflow.
Experiments & Observations: A Reality Check
The study highlights the vulnerability of the EXIM email environment and the high incidence of HTTP-based DDoS attacks. Unlike volume-based attacks, these application-layer strikes deplete server resources effectively, requiring the "Trust Management Helmet" mechanism to differentiate legitimate users from bots.
Table: The 3x3 Matrix classifying risk zones from "Acceptable" (1-2) to "Critical" (>6).
Critical Insight: Why This Matters
The most striking takeaway is the authors' insistence on Cybersecurity Awareness at the user level. They argue that technical mitigations for "Information Theft" are useless if users do not establish privacy settings or limit public data disclosure.
Limitations: The model is highly administrative. While it provides a "guide," the actual technical implementation of the "six-layer model based on cryptographic algorithms" mentioned in the discussion deserves more granular detail regarding computational overhead.
Conclusion
This paper shifts the narrative from "buying more firewalls" to "building better management." For Ecuador’s public sector, the viable path forward lies in adopting this 3x3 risk-standardized approach to turn chaotic reactive measures into a proactive, audited security culture.
