Skip to content

SecurityNot yet confirmed elsewhere1 publisher3 min readPublished

Mexico's cyber plan puts the phone number in 2026 and the scoreboard in 2030

The National Cybersecurity Plan 2025-2030 loads its operational machinery into a single legislative year. Firms operating in Mexico should budget for weak state incident response until it lands.

The Watch · Security desk

How we use AISend a correction

Photograph accompanying Mexico's cyber plan puts the phone number in 2026 and the scoreboard in 2030
Photo: eleconomista.com.mx

What happened

  • Mexico's National Cybersecurity Plan, introduced in December 2025, sets a six-phase roadmap running through 2030.
  • Mexico sits at Tier 2 in the ITU's 2024 Global Cybersecurity Index, with Canada, Ecuador and Uruguay, behind Tier 1 United States and Brazil.
  • State-linked activity includes SparrowDoor malware at Universidad Nacional Autonoma in early 2025 and TGR-STA-1030 against at least 70 government and infrastructure bodies.

Why it matters

  • constraint Until the General Cybersecurity Law passes and the operations centre is staffed, a company breached in Mexico has no consolidated federal counterpart to escalate to, so containment stays in-house.
  • exposure The incident-to-victim ratio means remediation budgets should assume the same site gets hit twice rather than treating the first event as the one-off.
  • decision Security spending for 2026 to 2028 now comes down to a choice between paying for local retained response or betting on a state capability whose first deliverable is a bill in Congress.
  • precedent Scheduling an export ambition in 2029 ahead of the domestic incident observatory in 2030 sets the order other regional plans can copy: selling capability before instrumenting it.

Insikt Group's count is the number to budget against. 223 documented ransomware incidents in Mexico from January 2020 through April 2026 works out at about three a month across 76 months [14][19]. The more instructive figure is the ratio inside it: 223 incidents against slightly more than 100 victims, roughly two hits per named organisation [14][20]. Ransomware is the dominant category in the assessment, with government, manufacturing, IT and food and beverage absorbing most of it [18][15]. A first incident in Mexico has not bought immunity from the second.

The Plan's sequencing explains why that repeat rate is unlikely to move soon. Everything a breached company could actually call sits in one year: the 2026 Expansion Phase has to deliver a General Cybersecurity Law, stand up a National Cybersecurity Operations Center, and integrate the federal CSIRTs [4]. What follows is deepening rather than response capacity. A national cyber range for red and blue team exercises in 2027 [5]. AI in cyber defence and a regional response centre in 2028 [6]. An export posture for Latin America and the Caribbean in 2029 [7]. A permanent Cybersecurity Observatory in 2030 [8]. The instrument meant to track incidents arrives four years after the year that has to produce the responders [21].

Recorded Future does not oversell this. Its own assessment is that it remains uncertain whether the government can build the institutions the risks demand [1], and that earlier attempts at national cyber policy failed to gain traction [11]. The change it points to is political rather than technical: President Sheinbaum's administration has committed to full implementation across her term, with her party holding a majority in Congress [12].

That leaves the index problem. Mexico is Tier 2 in the ITU's 2024 Global Cybersecurity Index, in company with Canada, Ecuador and Uruguay, behind Tier 1 United States and Brazil [9]. The same source records that cyber experts nonetheless read Mexico as lagging international standards on institutional capacity-building, with international cooperation flagged as needing growth [10]. The 2025 Foundation Phase moved on that second point through LAC4 membership and a memorandum of understanding with Brazil [3]. Neither produces an on-call responder.

This lands on foreign operators rather than on Mexican agencies alone because the attributes drawing state-sponsored attention are the attributes that put the subsidiary there. Insikt Group's read is that deep integration into US supply chains, a nearshoring-linked manufacturing base and underdeveloped cyber governance make the country attractive to foreign operations [16]. The cited activity includes Chinese state-sponsored TAG-141 deploying SparrowDoor at Universidad Nacional Autonoma in early 2025, TGR-STA-1030 observed against at least 70 government and critical infrastructure organisations, and North Korean remote IT-worker schemes reaching Mexican entities [17].

Recorded Future frames the post-tournament period as the opening for real implementation, the 2026 World Cup having served as a high-profile stress test [13]. The defensible planning assumption for 2026 through 2028 is the one the Plan's own calendar implies: state response capacity is a legislative outcome, not an existing service [4].

What to watch

  • Whether the General Cybersecurity Law is enacted during 2026, and what mandatory reporting duties it places on private operators.
  • Whether the National Cybersecurity Operations Center receives staff, a budget line and a published intake channel, or appears only on the org chart.
  • Whether Insikt Group's Mexico ransomware count keeps running near three incidents a month once the 2026 phase closes.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence54
Adoption31
Hype gap+28
Incentives68
Confidence46
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Mexico's National Cybersecurity Plan, introduced in December 2025, recognises many of the country's cyber risks, but it remains uncertain whether the government can build the institutions needed to address them proactively.

    ReportedSupportedView cited source
  2. [2]

    The Plan lays out a six-phase roadmap designed to gradually build Mexico's cybersecurity capabilities through 2030, with later phases intended to deepen and institutionalise them.

    ReportedSupportedView cited source
  3. [3]

    The 2025 Foundation Phase established a general framework for governance, risk management, incident reporting and coordination, plus initial international cooperation steps including formal Mexican membership in the Latin America and Caribbean Cyber Competence Centre (LAC4) and a cybersecurity memorandum of understanding with Brazil.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. recordedfuture.com

    1 article · August 24, 2026

    Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories