It's three in the morning, the IT team just confirmed there's active ransomware on the network, and in the middle of the technical chaos someone asks: "who do we actually have to tell?" It's one of the most anxiety-inducing questions during an incident, and the honest answer is: it depends. Colombia doesn't have a single law saying "every cyberattack must be reported here within 72 hours," the way some other countries do. What exists instead is a set of obligations triggered by what type of information was compromised and what sector your business operates in.
This guide maps that landscape out, so that if it happens to you, you know exactly which legal steps come right after technical containment.
Anatomy of the attack described in the article.
The General Obligation Under Law 1581
If the incident compromised personal data — names, emails, ID numbers, customer or employee information — Colombia's Habeas Data Law requires reporting to the Superintendency of Industry and Commerce (SIC) when incidents involve a breach of security codes or put the administration of data subjects' information at risk. The general law's text doesn't set one universal deadline, but the expected practice — and what the SIC demands in its requirements — is to notify as soon as reasonably possible once the incident is confirmed, not days after it's already been contained.
Sector-Specific Obligations Are Stricter
If your business operates in a regulated sector, the rules get more specific and, generally, more demanding on timing.
Entities supervised by the Superintendencia Financiera, under the Circular 007 framework, must report significant cybersecurity incidents within deadlines set by the SFC, which tend to be considerably shorter than the general Law 1581 standard — precisely because an incident in the financial system can have systemic effects beyond a single company.
Healthcare operators, under Superintendencia de Salud oversight and the Resolution 2654 framework, have specific reporting obligations when an incident compromises electronic medical records or other health information, given that this is sensitive data with a higher protection standard.
When Reporting Also Becomes a Criminal Matter
If the incident constitutes one of the crimes defined under Law 1273 — unauthorized access, computer damage, theft by computer means — there's an additional, separate path: a criminal complaint with the National Police or the Attorney General's Office. This complaint doesn't replace the regulatory report to the SIC or the sector regulator; they're parallel processes with different purposes. One seeks to prosecute whoever is responsible for the crime; the other evaluates whether your business met its obligations as the data controller.
What Happens If You Don't Report
Failing to report when there was an obligation to do so can itself become an additional infraction — separate from the original incident. The SIC has been explicit that it views a lack of timely notification negatively when assessing the severity of a case, and in regulated sectors, hiding an incident from the relevant regulator tends to aggravate any subsequent sanction far more than the incident itself.
The Practical Order We Recommend
Having a 24/7 incident response team helps exactly at this point: part of a well-executed response is knowing, from minute one, what information needs to be documented to meet these obligations without delaying technical containment.
Frequently asked questions
Does every cybersecurity incident need to be reported?
No. The obligation is triggered when the incident compromises personal data or puts its security at risk, not for every minor technical event with no impact on third-party information.
Who do I report to if the incident doesn't involve a regulated sector?
The Superintendency of Industry and Commerce (SIC), under the general Law 1581 framework, if the incident compromised personal data.
Can I wait until the incident is fully resolved before reporting?
Not advisable. The regulatory expectation is to notify as soon as the incident and its nature are confirmed, not to wait until remediation is complete.
Does reporting to a regulator make the incident public information?
Not necessarily right away, but if the case results in a sanction, that decision typically does end up in the relevant regulatory entity's public record.
Controls and monitoring that stop the attack.
Let's talk
Knowing what to report and when is just as important as containing the attack technically — mishandling this part can turn a controlled incident into a much bigger legal problem. If your business is dealing with an active incident right now, our [24/7 incident response](https://tirescue.com/en/respuesta-ante-incidentes-247/) team helps you manage both fronts in parallel. Need immediate help? [Contact us now](https://tirescue.com/en/contacto-ti-rescue/).
Contact usYou may also like
Comments (0)
Be the first to comment.