Summary

  • Graciela Martínez Giordano’s public record at LACNIC connects three practical ideas that are often separated in accounts of cyber resilience. A regional coordinating institution must state what it can and cannot do; it must cultivate trusted relationships before an urgent event; and it must convert experience into procedures, communication and training that other organizations can use. At the 2014 launch of WARP, Martínez was identified as responsible for a service built to coordinate handling, broker information confidentially and issue warnings while expressly lacking authority to act inside members’ systems. That boundary did not make the service passive. It defined where coordination could add value without displacing the organizations that retained operational control. LACNIC’s launch account places that institutional choice at the start of the record.

  • The same philosophy can be followed through later evidence without turning a collective history into a hero story. WARP’s first-year figures belong to the institution; the 2019 regional symposium belongs to a LACNIC-FIRST partnership and its program committee; and the 2024 credential response is described in a joint account using collective LACNIC language. Martínez’s individual contribution is clearest where the record identifies her leadership, attributes reasoning to her, names her as an author, or independently reports her capacity-building work. Her 2023 incident-management plan brings the strands together: preparation, detection, containment, recovery, legal and communication duties, and learning after an event become a repeatable discipline rather than a set of improvised reactions. The plan supports a narrow conclusion: regional capacity grows when limits, trust and learning reinforce one another.

Coordination Without Command

Regional incident response has a structural difficulty that cannot be solved by technical competence alone. The organizations that need to exchange warnings, indicators and practical assistance do not surrender control of their networks when they join a regional community. They remain accountable for their own systems, policies and users. A coordinating institution therefore has to be useful without pretending to possess authority that belongs elsewhere. It has to shorten the path between a credible signal and the organization able to act, while protecting information whose careless disclosure could deepen the problem.

This is less dramatic than an image of a central team taking command, but it is closer to the actual work described in LACNIC’s publications.

Martínez’s record is valuable because it makes that tension visible. The public evidence does not present regional resilience as the product of one person intervening in every event. It presents a sequence of institutional choices: define a service boundary, make confidential exchange possible, avoid duplicated effort, connect regional teams with a wider professional community, and preserve lessons in guidance and training. FIRST later reported that Martínez spearheaded the creation of LACNIC CSIRT using its framework, but even that independent description is language about leadership within an institutional undertaking, not solitary authorship of every outcome. FIRST’s 2025 account is strongest when read alongside the operational record rather than as a substitute for it.

A Service Defined by Its Limits

When LACNIC announced WARP in November 2014, it identified Martínez as responsible for the new incident-response handling center. The announcement described a service intended to coordinate and facilitate incident handling in the region, serve as a broker for confidential information, and issue early warnings. Just as important, it stated what WARP would not do. It had no authority to act on the systems of LACNIC members, and it would not provide direct remote or on-site handling in their networks. The launch publication makes those limits part of the service description, not an afterthought.

At first glance, a list of exclusions can look like reduced capability. In a distributed regional setting, it can instead be the basis of legitimate coordination. An institution that overstates its authority risks delaying a response, confusing responsibility or discouraging disclosure. An institution that states its limits can give entities a clearer answer to several urgent questions: Who owns the decision? Who can safely receive the information? Who can connect the affected organization with relevant expertise? What warning can be shared without exposing sensitive details? The boundary channels the work toward those questions.

Confidential brokering is especially important in this design. An organization facing an incident may have information that is useful to peers but risky to circulate broadly. It may also need help locating the right counterpart without publicly identifying an affected system. WARP’s announced role allowed it to sit between isolation and command. It could facilitate a trusted handoff and coordinate exchange while the member organization retained control of its environment. The value was not possession of every technical lever. It was the ability to connect information, responsibility and action without collapsing them into one office.

This bounded role helps explain why trust appears repeatedly in Martínez’s later professional analysis. Trust is not a sentimental addition to technical response. It is what allows a limited coordinator to be useful. If the coordinator cannot compel participation and cannot enter another network, its effectiveness depends on organizations choosing to disclose, answer, verify and act. The 2014 design therefore linked institutional humility to practical capacity. Authority limits were not separate from response speed; they helped create the conditions under which information could move to the right owner without a contest over control.

The First Year as an Operating Test

By April 2016, LACNIC published a first-year account of WARP’s activity. It identified Martínez as head of the center and reported that WARP had handled more than 140 incidents involving Internet resources in the region. The same publication said that AMPARO workshops incorporated into WARP had trained close to 150 experts. Those figures belong to WARP and the wider program. They should not be turned into a personal case count or treated as proof that one leader performed every response task. LACNIC’s first-year account supports a more useful reading: the coordinating design had moved from announcement into sustained institutional practice.

The incident total shows demand for a place that could receive, connect and route information. It does not, by itself, measure the final effect of each intervention, and the publication does not justify claims about losses prevented. What it does establish is that the service boundary was compatible with real activity. WARP did not need authority over member systems to participate meaningfully in more than 140 matters. Its role could be exercised through notification, coordination, confidential exchange and referral while operational decisions remained with the responsible organizations.

The training figure belongs beside the incident figure because the two represent different time horizons. Handling an incoming matter addresses an immediate need. Training experts changes the capacity available for the next need. Folding AMPARO workshops into the WARP effort treated education as part of response infrastructure rather than as an unrelated outreach activity. The institution was not only moving information during incidents; it was also helping more professionals recognize, communicate and manage future events.

Martínez’s attributed reasoning in the first-year account sharpened the connection. She argued, in substance, that speed matters in incident response and that coordination and information sharing help organizations avoid duplicating work. This was not a claim that coordination guarantees a particular outcome. It was an operational diagnosis: when time is scarce, parallel parties should not repeatedly discover the same facts in isolation if trusted exchange can make their efforts complementary. The reported activity gave that reasoning a concrete setting.

Trust as Response Infrastructure

Trust becomes operational when it changes what people are prepared to share, how quickly they answer and whether they accept a warning as credible. A regional coordinator depends on all three. It needs enough confidence from entities to receive sensitive information, enough professional familiarity to find the right counterpart, and enough discipline to share only what is appropriate. These conditions cannot be manufactured after an urgent message arrives. They have to be built through repeated contact, useful exchange and respect for institutional boundaries.

Martínez’s later writing described trust, community and capacity building as keys to a more resilient Internet, and explicitly connected prior trust with faster coordination during incidents. That argument is consistent with the earlier WARP design but adds an important time dimension. Relationships built in ordinary periods become routes for action under pressure. Her 2026 professional analysis does not prove a universal numerical effect, yet it clearly states the philosophy: cooperation during an event is more effective when entities have already learned how to work together.

The first-year WARP account illustrates why. If two organizations investigate related activity without knowing each other or without a trusted intermediary, they may repeat the same work, withhold useful context or lose time locating a responsible contact. Coordination can reduce that friction, but only if the exchange is treated as credible and appropriately confidential. WARP’s brokering role and its lack of authority belong together here. Entities could engage a facilitator without transferring control, and the facilitator’s usefulness depended on handling the relationship responsibly.

Trust also disciplines the coordinator. It is not permission to collect or circulate everything. The service boundary requires judgment about what must remain confidential, what can be converted into a warning, and which organization has the standing to act. A trusted institution preserves those distinctions even when urgency creates pressure to blur them. In that sense, restraint is part of reliability. Organizations are more likely to share again when the previous exchange respected their authority and protected sensitive context.

From Partnership to Regional Practice

In 2019, FIRST documented the first regional symposium produced through its partnership with LACNIC. The three-day event combined technical training, incident-response and prevention content, material intended to be accessible to different entities, and structured networking. FIRST identified Martínez as a liaison member, head of WARP at LACNIC and a member of the program committee. It attributed to her the view that the symposium was an outcome of the partnership and a way to improve interaction between Latin American and Caribbean CSIRTs and the wider global security community. FIRST’s symposium account therefore supports both a person-level rationale and a collective result.

The attribution boundary is important. A partnership delivered the event, and a committee shaped its program. Martínez’s documented role and explanation should not be expanded into a claim that she alone created or delivered the symposium. Preserving the joint character actually makes the event more relevant to the regional-resilience thesis. Its purpose was to create working contact across institutional and geographic lines. The method embodied the same principle it promoted: capacity emerged through connected organizations, not through one central actor absorbing every role.

Independent evidence later placed Martínez’s work in a broader professional setting. An ITU agenda for a 2022 cyberdrill listed her as leader of LACNIC CSIRT, recorded her AMPARO capacity-building role and named a keynote topic focused on the team. The ITU speaker profile corroborates her public role, though it should not be used to invent outcomes for the event. Its significance is narrower: an independent intergovernmental organization recognized the same professional identity and area of responsibility described by LACNIC and FIRST.

FIRST’s 2025 announcement adds another independent marker. It reported that its membership elected Martínez Giordano to the Board of Directors, credited her with training more than 1,000 professionals and co-organizing nine regional FIRST symposia, and said she had spearheaded the creation of LACNIC CSIRT using the FIRST framework. Those are FIRST’s reported assessments and figures. They should remain attributed to FIRST, not presented as self-verifying personal totals. Read carefully, they show continuity in the type of work: institution building, training and bridges between regional and global response communities.

The progression from one symposium to independently reported repeated activity is not evidence that every regional gap was closed. It does show how a partnership can become practice. A one-time meeting offers contact; recurring collaboration can deepen shared expectations and professional familiarity. That is the connective tissue a limited coordinating institution needs. The institution still does not command member networks. It becomes more capable of helping because more entities know the channels, understand the norms and can translate a warning into action within their own authority.

The Credential Incident as a Decision Case

A July 2024 LACNIC publication, jointly authored by Martínez and Alfredo Verderosa, offers the clearest dated incident case in the record. The account reported that more than 574 credentials had been offered for sale, that 120 unauthorized logins to MiLACNIC had succeeded, and that 20 of those logins involved accounts used to manage resources. It also reported that roughly one in five members was not using two-factor authentication. These are aggregate figures from the joint publication. No account, credential, victim or technical artifact is needed to understand the decision problem. The joint account supplies the relevant scope while preserving a public, high-level boundary.

The constraints were layered. There was an immediate access problem that required containment and restoration. There was an investigative question about how access had occurred. There was a communication need because members had to understand the risk and the protective steps available to them. Finally, there was a longer-term adoption problem: a meaningful share of members had not enabled an available safeguard. Treating all four as one undifferentiated technical issue would have obscured who needed to decide and what kind of action each stage required.

According to the account, LACNIC created an incident working group, blocked compromised accounts, worked with affected organizations to restore access, investigated the pattern and warned members. The publication said the investigation found no evidence of brute force and no compromise of LACNIC systems; it attributed the unauthorized access to compromised credentials offered on black markets. Those findings should be repeated no more broadly than the account states. They do not establish that no harm of any kind occurred, and they do not support claims about culpability or third-party consequences.

The response sequence reflects bounded coordination. LACNIC could act on access under its control and work with affected organizations, while those organizations remained entities in restoration. The public wording is collective, and the byline is joint. It would therefore be inaccurate to say Martínez personally blocked every account, conducted every investigative step or restored every organization’s access. Her connection to the case is strong and specific—she coauthored the operational account—but the actions remain LACNIC’s documented response.

The account also described forward actions: a survey-led, phased plan to make two-factor authentication mandatory and a planned system for systematic alerts about compromised passwords. The survey element matters because the measure affected a community with varied circumstances. A phased approach recognizes that a security requirement can be necessary while still demanding communication, preparation and sequencing. It turns a discovered weakness into an institutional change process rather than treating the incident as finished when access is restored.

The evidence stops at the plan. It does not show that every phase was later completed, how every member responded or whether the change produced a measured reduction in incidents. A responsible account should not fill that gap with confidence. The value of the case lies in the decisions that were publicly documented: immediate containment, coordinated restoration, investigation, warning, assessment of adoption and a planned change. Each responds to a different part of the constraint.

The case also demonstrates why information exchange must be actionable. A warning that credentials may be exposed is only one step. Organizations need to know what action belongs to them, while LACNIC must act within its own responsibilities. Aggregate communication can raise awareness without exposing victims or publishing details that could enable targeting. The account keeps that boundary. It gives enough information to explain the issue and the institutional response without turning operational evidence into spectacle.

Finally, the incident links trust to governance. Members had to receive a warning from an institution they recognized, affected organizations had to cooperate in restoring access, and a broader community had to be prepared for a phased security change. None of those interactions depends on LACNIC commanding external systems. They depend on credible relationships and clear responsibility. The case therefore brings the earlier WARP principles into a later setting: bounded authority does not prevent decisive action; it shapes where action occurs and how parties coordinate it.

Containment Without Overclaiming

Incident narratives often become cleaner as they travel. Collective actions are assigned to a visible leader, a documented plan is described as a completed reform, and a limited investigative finding grows into a claim that all harm was prevented. The 2024 account requires the opposite discipline. It is detailed enough to show a response sequence, yet its language preserves uncertainty and shared responsibility. That combination makes it a useful case precisely because it resists a triumphant ending.

The immediate measures—forming a working group, blocking compromised accounts, restoring access with affected organizations, investigating and warning members—can be described as containment and response steps reported by LACNIC. They cannot be assigned one by one to Martínez. Her joint authorship means she helped present the institutional account; it does not erase the teams and organizations named by the collective wording. Likewise, the reported lack of brute-force evidence and lack of compromise to LACNIC systems are bounded findings, not proof that every possible consequence was absent.

This restraint is not merely editorial caution. It mirrors the authority principle at the center of the institution’s work. Accurate attribution tells readers where responsibility sat. It recognizes that affected organizations participated in restoring access and that a working group, rather than one individual, handled the response. In a field built on trusted exchange, overstating who did what can distort the very relationships that made the response possible.

The future-facing measures need the same care. The publication documented a phased mandatory two-factor plan and a planned alert system. Without a dated follow-up in the accepted record, later completion and effect remain open. Calling the plan an outcome would collapse intention, implementation and measurement into one claim. Keeping those stages separate lets the public account do something more valuable: show how an institution moved from evidence to a proposed change while leaving later verification to later evidence.

Turning Incidents into a Management Discipline

Martínez’s November 2023 publication, “Plan: Security Incident Management,” provides a structured view of what must surround technical action. The guidance covers preparation, reporting and triage, communications, detection, containment, recovery, post-incident lessons, legal notices and executive reporting. The authored plan should be read as management guidance, not evidence that every organization implemented every step. Its importance is that it makes response repeatable and gives different responsibilities a place in the same discipline.

Preparation comes first because an organization cannot make every decision during the pressure of an event. It needs defined roles, escalation paths and expectations about what information can be shared. Reporting and triage then turn a signal into an assessed matter rather than an unranked alarm. Detection and containment address what is happening; recovery addresses the return to an acceptable operating state. The order is not a promise that real incidents will unfold neatly. It is a way to prevent urgent action from crowding out necessary coordination.

Communication runs through the sequence rather than sitting at its edge. Technical teams need a common understanding of the event, leaders need information suitable for decisions, affected parties may need notices, and legal duties can shape timing and content. A repeatable practice makes those audiences visible before silence or over-disclosure creates a second problem. It also reinforces the authority boundary: not everyone should receive the same detail, and not every entity has the standing to make the same decision.

The post-incident stage closes the learning loop. An event can be contained without the institution becoming better prepared for the next one. Lessons have to be identified, assigned and incorporated into procedures, communication or training. This is where the management plan connects to the wider regional record. WARP combined handling with AMPARO workshops; the LACNIC-FIRST partnership connected practitioners through symposia; and the 2024 account carried an observed adoption gap into a phased action plan. Different publications describe different activities, but each treats experience as material for future capacity.

Legal notices and executive reporting also show why regional response cannot be reduced to a technical checklist. Decisions occur within organizational and legal responsibilities. Leaders may need to allocate resources or accept risk; legal obligations may determine what must be communicated; technical teams may need authority for containment. Bringing these strands into one practice does not centralize every decision. It clarifies the handoffs among people who already hold different responsibilities.

The plan’s contribution is therefore procedural memory. Individuals change, incidents differ and pressure disrupts recall. A written discipline helps an organization preserve the questions that should be asked: Are roles clear? Has the event been triaged? Who needs to know? What can be contained safely? What does recovery require? What must be learned and communicated afterward? Those questions help turn regional experience into something more durable than an anecdote.

Communication Is Part of the Response

Communication can accelerate action, but it can also expose sensitive information, create confusion or imply authority that the sender does not possess. The public record around Martínez treats communication as a managed response function. WARP was announced as a confidential broker and warning point; the 2023 plan includes communications, legal notices and executive reporting; and the 2024 account describes warnings to members alongside containment and investigation. These are different settings, yet each places information movement inside the response rather than after it.

The audiences are not interchangeable. An affected organization may need specific instructions about restoring access. The wider membership may need a protective warning. Executives may need a concise account of scope, decisions and residual uncertainty. Legal advisers may need facts connected to notification duties. Peers may need a sanitized lesson that improves their preparation. Good coordination distinguishes these needs and sends enough information for action without circulating details that create new risk.

The 2024 publication demonstrates that balance at a public level. It reports aggregate constraints and the collective response, while withholding account-level and victim-level detail. It communicates the absence of certain investigative evidence without transforming that finding into a universal assurance. And it presents planned changes as plans. Those choices preserve credibility. A message is more useful when readers can tell which facts are established, which actions occurred and which future steps still require completion.

For a regional institution, credibility compounds. A carefully bounded warning makes the next warning easier to trust; respectful handling of sensitive information makes future disclosure more likely; clear acknowledgment of uncertainty reduces the cost of later correction. Communication is therefore part of the relationship infrastructure on which rapid exchange depends. It is not decoration around the technical work. It is one of the ways a coordinator earns the continued cooperation it cannot command.