Security1 distinct publisher3 min readPublished
The National Cybersecurity Plan 2025-2030 loads its operational machinery into a single legislative year. Firms operating in Mexico should budget for weak state incident response until it lands.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Insikt Group's count is the number to budget against. 223 documented ransomware incidents in Mexico from January 2020 through April 2026 works out at about three a month across 76 months [14][19]. The more instructive figure is the ratio inside it: 223 incidents against slightly more than 100 victims, roughly two hits per named organisation [14][20]. Ransomware is the dominant category in the assessment, with government, manufacturing, IT and food and beverage absorbing most of it [18][15]. A first incident in Mexico has not bought immunity from the second.
The Plan's sequencing explains why that repeat rate is unlikely to move soon. Everything a breached company could actually call sits in one year: the 2026 Expansion Phase has to deliver a General Cybersecurity Law, stand up a National Cybersecurity Operations Center, and integrate the federal CSIRTs [4]. What follows is deepening rather than response capacity. A national cyber range for red and blue team exercises in 2027 [5]. AI in cyber defence and a regional response centre in 2028 [6]. An export posture for Latin America and the Caribbean in 2029 [7]. A permanent Cybersecurity Observatory in 2030 [8]. The instrument meant to track incidents arrives four years after the year that has to produce the responders [21].
Recorded Future does not oversell this. Its own assessment is that it remains uncertain whether the government can build the institutions the risks demand [1], and that earlier attempts at national cyber policy failed to gain traction [11]. The change it points to is political rather than technical: President Sheinbaum's administration has committed to full implementation across her term, with her party holding a majority in Congress [12].
That leaves the index problem. Mexico is Tier 2 in the ITU's 2024 Global Cybersecurity Index, in company with Canada, Ecuador and Uruguay, behind Tier 1 United States and Brazil [9]. The same source records that cyber experts nonetheless read Mexico as lagging international standards on institutional capacity-building, with international cooperation flagged as needing growth [10]. The 2025 Foundation Phase moved on that second point through LAC4 membership and a memorandum of understanding with Brazil [3]. Neither produces an on-call responder.
This lands on foreign operators rather than on Mexican agencies alone because the attributes drawing state-sponsored attention are the attributes that put the subsidiary there. Insikt Group's read is that deep integration into US supply chains, a nearshoring-linked manufacturing base and underdeveloped cyber governance make the country attractive to foreign operations [16]. The cited activity includes Chinese state-sponsored TAG-141 deploying SparrowDoor at Universidad Nacional Autonoma in early 2025, TGR-STA-1030 observed against at least 70 government and critical infrastructure organisations, and North Korean remote IT-worker schemes reaching Mexican entities [17].
Recorded Future frames the post-tournament period as the opening for real implementation, the 2026 World Cup having served as a high-profile stress test [13]. The defensible planning assumption for 2026 through 2028 is the one the Plan's own calendar implies: state response capacity is a legislative outcome, not an existing service [4].
Ranked by verification strength, evidence, and original report placement.
Mexico's National Cybersecurity Plan, introduced in December 2025, recognises many of the country's cyber risks, but it remains uncertain whether the government can build the institutions needed to address them proactively.
The Plan lays out a six-phase roadmap designed to gradually build Mexico's cybersecurity capabilities through 2030, with later phases intended to deepen and institutionalise them.
The 2025 Foundation Phase established a general framework for governance, risk management, incident reporting and coordination, plus initial international cooperation steps including formal Mexican membership in the Latin America and Caribbean Cyber Competence Centre (LAC4) and a cybersecurity memorandum of understanding with Brazil.
The 2026 Expansion Phase, now underway, focuses on passage of a new General Cybersecurity Law, creation of a National Cybersecurity Operations Center, and integration of federal computer security incident response teams (CSIRTs).
The 2027 Consolidation Phase would establish a National Cyber Range for red team and blue team exercises.
The 2028 Maturation Phase would incorporate AI into cyber defence and develop a regional response centre.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific vendor telemetry, single uncorroborated publisher
The threat-landscape half of the story is unusually concrete: dated incident counts, named ransomware groups, named state-sponsored clusters and a third-party benchmark placement. The institutional half rests entirely on one vendor's description of the plan, with no government document, legislative text, budget figure or independent reporting in the cluster, and the expert-perception claim is asserted without named sources. One publisher, no corroboration, so the ceiling is moderate.
Foundation steps done, 2026 machinery unbuilt
Adoption evidence is real but shallow. Reported completions are framework-level and diplomatic: the 2025 governance framework, LAC4 membership and the Brazil MOU. The operationally consequential items - the General Cybersecurity Law, the National Cybersecurity Operations Center and integrated federal CSIRTs - are described as in progress in 2026 with no passage, launch or staffing evidence, and everything from 2027 onward is roadmap only. Threat-side activity is heavily adopted by attackers, not by defenders.
Plan ambition runs ahead of delivered institutions
The overstatement sits in the policy artefact rather than in the article. A country whose national operations centre, cyber law and CSIRT integration are all still pending in 2026 is scheduled to incorporate AI into cyber defence by 2028 and export cybersecurity services regionally by 2029, with the incident-tracking Observatory arriving only in 2030 - after the years it would have been needed to judge progress. The reporting publisher partially discounts its own subject by flagging institutional uncertainty and prior policy failures, which keeps the gap moderate rather than severe.
Threat-intel vendor documenting the gap it sells into
The sole source is a commercial threat-intelligence provider publishing its own research arm's findings. Its business benefits from a narrative of heavy ransomware and state-sponsored pressure combined with weak state incident response, which is exactly the conclusion the piece reaches, and the item carries no disclosure of that relationship. This does not make the counts wrong - they are specific and falsifiable - but the framing and severity choices are commercially aligned, and no counterweight publisher is present.
Checkable numbers, single voice, forward-dated promises
Confidence is limited by structure, not by internal inconsistency: one publisher, an incentive-aligned author, and a story whose most consequential elements are 2026-2030 commitments that cannot yet be verified. The historical and benchmark data points are precise enough to act on with moderate confidence; the institutional timeline should be treated as unconfirmed until legislative or operational evidence appears.
security
Influence Operations Now Target Construction Schedules, Not Just Elections1 distinct publisher
security
North Korea's hiring funnel: 60 applications a day, 22 personas, ten jobs landed1 distinct publisher
invest
The $2 trillion rulebook is now two rulebooks, and Mexico wants Canada's1 distinct publisher
security
FamousSparrow's fake certificate prompt: one MSI, two backdoors, and a very short hunt rule1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026