
Marcelo Felman, director of cybersecurity for Microsoft Latin America.
In recent years, I have witnessed how organizations in Latin America are steadily moving towards digitization, and how this same transformation is opening up an ever-increasing range of cyber risks. Cybersecurity is no longer a technical issue: it’s a necessary business conversation. With this in mind, Microsoft commissioned the survey “Cybersecurity: Challenges and Strategies in the Age of Artificial Intelligence for Large Enterprises” to get a clear picture of how Latin American companies face this scenario and what solutions will be highlighted in the near future. The report was developed based on interviews with information technology professionals and security experts in Argentina, Chile, Colombia, Costa Rica, Mexico and Puerto Rico.
From this exercise, it is clear that risk perception is high in Latin America, where six out of ten organizations consider the level of threat to be high or very high; This concern is heightened in Mexico, which registers 65%, followed by Argentina at 62% and Costa Rica at 61%. Even more relevant, 74% of professionals in the region say these threats have increased in recent years, while nearly eight in ten believe cybersecurity will continue to grow as a priority. This is no accident: with the help of traditional mechanisms, attacks are faster, more automated and more difficult to detect.
Despite this, the analysis shows that although 55% of companies in Latin America today report the involvement of their boards of directors in cybersecurity, investment is still concentrated mainly at a moderate level. Which shows the gap between the significance of the risk and the executive sponsorship that is still required to consistently manage it, as cyber risk directly affects business continuity and reputation.
The natural reaction of companies was to search for new tools. And this is where artificial intelligence (AI) has become indispensable, because the level of complexity of today’s environment can no longer be managed solely by human teams. Working and responding to this scenario is possible only with the support of artificial intelligence capable of analyzing volumes of information and reacting with the speed that today’s threats demand. In practice, this reality is already reflected in the decisions organizations make, with 48% of professionals surveyed saying they have incorporated artificial intelligence into their processes to deal with digital threats at a high or moderate level, while only a minority say they do not use it. In countries such as Chile, this usage is as high as 63%, indicating steady and pragmatic adoption.
This evolution not only responds to the strengthening of defenses, but also to the fact that attackers are incorporating artificial intelligence into their tactics, increasing the speed and complexity of attacks. In fact, 94% of professionals believe that artificial intelligence will have a significant impact on their security practices in the next two to three years, indicating that automation will move from being an add-on to a core strategy.
But artificial intelligence does not solve by itself. A corresponding gap persists in the preparedness of organizations: while 37% of respondents feel very prepared to address cybersecurity challenges, most are at an average level. The region is considered strong in privacy and data protection, with 92% of professionals believing their organizations are well prepared in this area, but less prepared for incident response, where only 39% feel very prepared, and for implementing AI policies or developing internal capabilities. This lag is particularly evident in markets such as Puerto Rico, where 27% of companies admit to having limited cybersecurity training. Training teams remains a major unsolved problem, not because of a lack of tools, but because many organizations have yet to develop practical capabilities for incident response, working with clear criteria for using artificial intelligence, and acting quickly when risk materializes.
In turn, a conclusion that I consider particularly relevant is the adoption of artificial intelligence agents. Half of the companies in the region already have a formal policy for its use, and its application is beginning to be concentrated in critical areas such as cyber security, IT and customer service. These agents don’t just automate tasks; They help prioritize alerts, reduce investigation time, and close gaps in work that would otherwise lead to vulnerabilities. Its inclusion marks a before and after in our understanding of digital security.
Faced with such a scenario, I see six strategic decisions that could affect the region’s resilience:
- Rethink how risk decisions are made: Include cybersecurity in discussions about growth, investment and competitiveness.
- Move to operating models where intelligent automation is part of the DNA, not a separate project.
- Create a strong digital culture that empowers people to understand their role in security, especially in the face of transformative technologies such as artificial intelligence.
- Enhancing operational resilience, identifying vulnerabilities, scenario planning and preparing organizations to respond and rapidly recover from incidents.
- Invest in people, not just technology, closing the skills gap that limits the ability to operate and manage AI-driven environments today.
- Promote the safe use of technology through governance mechanisms that make the solution easiest for people and the safest.
Latin America faces a crucial opportunity: take advantage of artificial intelligence not only to protect itself, but also to work more efficiently, more nimbly and more securely. In an environment where complexity will continue to grow, sustainability ceases to be a desire and becomes a condition to compete and sustain a business. And at Microsoft, we accompany this journey with the belief that sustainability is not a destination, but a continuous process of evolution.

