Ecuador turns to threat intelligence as cross-border cybercrime escalates

Ecuador turns to threat intelligence as cross-border cybercrime escalates

A new cooperation framework between Resecurity and Ecuador’s CiberPOL aims to strengthen the intelligence, technical expertise and investigative capabilities needed to tackle increasingly sophisticated cybercrime.

For Ecuador’s National Cybercrime Unit, CiberPOL, tackling increasingly complex attacks means investigators need access to timely intelligence, specialised technology and technical expertise.

That is the challenge behind a new Memorandum of Understanding (MoU) signed between CiberPOL and cybersecurity company Resecurity.

The agreement establishes a framework for technical cooperation focused on strengthening the prevention, detection, investigation, and prosecution of cybercrime.

The MoU was signed by Jorge Chungandro, Business Development Manager for Latin America at Resecurity and Lieutenant Colonel Héctor Gonzalo García Cataña, Head of the National Cybercrime Unit (CiberPOL).

Importantly, the agreement applies specifically to cooperation between Resecurity and CiberPOL and does not extend to the Ecuadorian National Police as a whole.

At its core, the partnership is about giving investigators more tools and knowledge to deal with a threat environment that is becoming harder to contain.

The cooperation is designed to strengthen the operational capabilities of CiberPOL through the exchange of cyber threat intelligence (CTI), specialised technical assistance, technological collaboration, and professional capacity building.

The framework is intended to support investigators as they respond to cyber-enabled criminal activity, develop technical expertise, and improve their ability to identify and investigate threats affecting individuals, organisations, and public institutions.

That includes early warning systems, AI-based analytical capabilities, specialised training programmes, technical workshops, seminars, practical exercises, and knowledge-sharing initiatives.

For investigators, the objective is not simply access to more technology. It is the ability to apply that technology effectively as criminal methods evolve.

These activities are intended to support CiberPOL personnel in applying current investigative techniques, understanding evolving cyber threats, and making effective use of relevant intelligence and analytical resources.

“Effective cybercrime investigations depend on timely intelligence, trusted cooperation, and continuously evolving technical expertise,” said Chungandro.

“Through this Memorandum of Understanding, Resecurity is contributing its cyber threat intelligence expertise, specialised technologies, and practical knowledge to help strengthen investigative capabilities and support Ecuador’s efforts to address increasingly sophisticated cybercrime.”

The need for that expertise reflects a wider change in the nature of cybercrime.

Cybercriminals can use digital infrastructure, online services, compromised accounts, and other technologies to conduct or facilitate criminal activity across multiple jurisdictions. Investigations can therefore depend on information and expertise that sit outside the immediate organisation or even outside the country where an offence is being investigated.

For CiberPOL, the cooperation provides a structured framework for engagement with Resecurity in areas relevant to cybercrime prevention and investigation.

The exchange of expertise and technical knowledge can support operational readiness while contributing to the continuing professional development of personnel responsible for cybercrime investigations.

For Resecurity, the MoU expands its engagement with law enforcement organisations seeking to strengthen their ability to understand and investigate cyber threats.

The company’s contribution will focus on cyber threat intelligence, technical expertise, specialised technologies, and knowledge-sharing activities within the scope established by the agreement.

The emphasis on intelligence is significant. Modern cyber investigations can require investigators to connect technical indicators with digital evidence, threat intelligence and contextual information while maintaining appropriate evidentiary and procedural standards.

That makes professional development as important as the technology itself.

Training sessions, workshops, seminars, and practical exercises can provide opportunities for investigators to examine emerging attack methods, analytical approaches, and investigative challenges in a controlled professional setting.

Early warning capabilities and intelligence-sharing mechanisms can further help participating personnel identify relevant indicators and develop a clearer understanding of threats that may affect their investigative work.

The MoU also places clear boundaries around the cooperation.

It establishes a framework for cooperation rather than creating a broader institutional agreement with the National Police of Ecuador. Any activities undertaken under the framework remain subject to applicable legal, regulatory, operational and institutional requirements.

The participating organisations will determine specific cooperation activities according to their respective mandates, capabilities, and priorities.

That distinction is important as public-private cybersecurity partnerships increasingly become part of the response to digital crime. Law enforcement agencies bring investigative mandates and operational experience, while cybersecurity companies can provide specialised intelligence, technologies and expertise.

In this case, the stated aim is to bring those capabilities together without replacing existing legal procedures or institutional processes.

Cybercrime continues to present challenges for governments, businesses, and citizens throughout Latin America. Online fraud, unauthorised access, malicious cyber activity, identity-related crimes, and other offences involving information technologies can affect victims across borders and require specialised investigative knowledge.

Strengthening the capabilities of cybercrime investigators is therefore an important component of broader efforts to prevent and respond to criminal activity in digital environments.

By combining CiberPOL’s investigative mandate with Resecurity’s expertise in cyber threat intelligence and cybersecurity, the MoU establishes a practical framework for public-private cooperation focused on capacity building, information exchange, technical collaboration, and investigative support.

The organisations will work within their respective responsibilities to identify opportunities for cooperation that can contribute to more effective cybercrime prevention and investigation.

The agreement also creates opportunities for continued dialogue between technical specialists and investigators.

As cyber threats evolve, regular knowledge exchange can help professionals remain familiar with emerging technologies, investigative methodologies, and relevant threat intelligence practices.

This continuing engagement can complement existing capabilities and support the development of specialised expertise within CiberPOL.

The partnership also recognises that effective cybercrime response requires more than individual tools or isolated investigations.

Investigators may need to correlate technical indicators, digital evidence, threat intelligence, and contextual information while maintaining appropriate evidentiary and procedural standards.

Capacity building can help personnel develop consistent approaches to these tasks and strengthen familiarity with technologies used in contemporary cyber investigations.

The cooperation may also support the identification of training priorities as CiberPOL personnel encounter new forms of cyber-enabled crime.

Workshops and practical exercises can be adapted to relevant operational needs, allowing participants to explore investigative scenarios and technical questions that arise in their work.

Knowledge-sharing activities can provide a forum for discussing lessons learned, emerging techniques, and changes in the cyber threat environment.

Resecurity and CiberPOL will maintain their respective roles and responsibilities under the framework. The MoU is intended to facilitate communication and cooperation without replacing existing legal procedures or institutional processes.

Any exchange of information or technical assistance will remain subject to applicable requirements governing confidentiality, data handling, evidence, privacy, and lawful investigative activity.

The initiative reflects a broader need for sustained investment in cybercrime expertise as digital technologies continue to influence economic activity, public services, communications, and everyday life.

Developing specialised capabilities within law enforcement can help investigators respond to offences involving increasingly diverse technologies and digital environments.

The MoU provides a foundation for continued cooperation and future activities that may be identified by the participating organisations.

Through structured engagement, technical collaboration, and professional development, the parties aim to support CiberPOL’s ongoing work in preventing and investigating cybercrime while encouraging responsible and effective use of cybersecurity expertise.

The framework can help connect operational experience with specialised cybersecurity knowledge and evolving investigative practices.

The initiative also supports continued dialogue, practical knowledge exchange, and professional development as investigators address changing cybercrime methods and technologies across the region.

Browse our latest issue

LATAM English

View Magazine Archive