SecurityNot yet confirmed elsewhere1 publisher3 min readPublished
Mexico's cyber plan puts the phone number in 2026 and the scoreboard in 2030
The National Cybersecurity Plan 2025-2030 loads its operational machinery into a single legislative year. Firms operating in Mexico should budget for weak state incident response until it lands.
The Watch · Security desk

What happened
- Mexico's National Cybersecurity Plan, introduced in December 2025, sets a six-phase roadmap running through 2030.
- Mexico sits at Tier 2 in the ITU's 2024 Global Cybersecurity Index, with Canada, Ecuador and Uruguay, behind Tier 1 United States and Brazil.
- State-linked activity includes SparrowDoor malware at Universidad Nacional Autonoma in early 2025 and TGR-STA-1030 against at least 70 government and infrastructure bodies.
Why it matters
- constraint Until the General Cybersecurity Law passes and the operations centre is staffed, a company breached in Mexico has no consolidated federal counterpart to escalate to, so containment stays in-house.
- exposure The incident-to-victim ratio means remediation budgets should assume the same site gets hit twice rather than treating the first event as the one-off.
- decision Security spending for 2026 to 2028 now comes down to a choice between paying for local retained response or betting on a state capability whose first deliverable is a bill in Congress.
- precedent Scheduling an export ambition in 2029 ahead of the domestic incident observatory in 2030 sets the order other regional plans can copy: selling capability before instrumenting it.
Insikt Group's count is the number to budget against. 223 documented ransomware incidents in Mexico from January 2020 through April 2026 works out at about three a month across 76 months [14][19]. The more instructive figure is the ratio inside it: 223 incidents against slightly more than 100 victims, roughly two hits per named organisation [14][20]. Ransomware is the dominant category in the assessment, with government, manufacturing, IT and food and beverage absorbing most of it [18][15]. A first incident in Mexico has not bought immunity from the second.
The Plan's sequencing explains why that repeat rate is unlikely to move soon. Everything a breached company could actually call sits in one year: the 2026 Expansion Phase has to deliver a General Cybersecurity Law, stand up a National Cybersecurity Operations Center, and integrate the federal CSIRTs [4]. What follows is deepening rather than response capacity. A national cyber range for red and blue team exercises in 2027 [5]. AI in cyber defence and a regional response centre in 2028 [6]. An export posture for Latin America and the Caribbean in 2029 [7]. A permanent Cybersecurity Observatory in 2030 [8]. The instrument meant to track incidents arrives four years after the year that has to produce the responders [21].
Recorded Future does not oversell this. Its own assessment is that it remains uncertain whether the government can build the institutions the risks demand [1], and that earlier attempts at national cyber policy failed to gain traction [11]. The change it points to is political rather than technical: President Sheinbaum's administration has committed to full implementation across her term, with her party holding a majority in Congress [12].
That leaves the index problem. Mexico is Tier 2 in the ITU's 2024 Global Cybersecurity Index, in company with Canada, Ecuador and Uruguay, behind Tier 1 United States and Brazil [9]. The same source records that cyber experts nonetheless read Mexico as lagging international standards on institutional capacity-building, with international cooperation flagged as needing growth [10]. The 2025 Foundation Phase moved on that second point through LAC4 membership and a memorandum of understanding with Brazil [3]. Neither produces an on-call responder.
This lands on foreign operators rather than on Mexican agencies alone because the attributes drawing state-sponsored attention are the attributes that put the subsidiary there. Insikt Group's read is that deep integration into US supply chains, a nearshoring-linked manufacturing base and underdeveloped cyber governance make the country attractive to foreign operations [16]. The cited activity includes Chinese state-sponsored TAG-141 deploying SparrowDoor at Universidad Nacional Autonoma in early 2025, TGR-STA-1030 observed against at least 70 government and critical infrastructure organisations, and North Korean remote IT-worker schemes reaching Mexican entities [17].
Recorded Future frames the post-tournament period as the opening for real implementation, the 2026 World Cup having served as a high-profile stress test [13]. The defensible planning assumption for 2026 through 2028 is the one the Plan's own calendar implies: state response capacity is a legislative outcome, not an existing service [4].
What to watch
- Whether the General Cybersecurity Law is enacted during 2026, and what mandatory reporting duties it places on private operators.
- Whether the National Cybersecurity Operations Center receives staff, a budget line and a published intake channel, or appears only on the org chart.
- Whether Insikt Group's Mexico ransomware count keeps running near three incidents a month once the 2026 phase closes.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence54
- Adoption31
- Hype gap+28
- Incentives68
- Confidence46
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Mexico's National Cybersecurity Plan, introduced in December 2025, recognises many of the country's cyber risks, but it remains uncertain whether the government can build the institutions needed to address them proactively.
- [2]
The Plan lays out a six-phase roadmap designed to gradually build Mexico's cybersecurity capabilities through 2030, with later phases intended to deepen and institutionalise them.
- [3]
The 2025 Foundation Phase established a general framework for governance, risk management, incident reporting and coordination, plus initial international cooperation steps including formal Mexican membership in the Latin America and Caribbean Cyber Competence Centre (LAC4) and a cybersecurity memorandum of understanding with Brazil.
- [4]
The 2026 Expansion Phase, now underway, focuses on passage of a new General Cybersecurity Law, creation of a National Cybersecurity Operations Center, and integration of federal computer security incident response teams (CSIRTs).
- [5]
The 2027 Consolidation Phase would establish a National Cyber Range for red team and blue team exercises.
- [6]
The 2028 Maturation Phase would incorporate AI into cyber defence and develop a regional response centre.
- [7]
The 2029 Leadership Phase aims to position Mexico as a cybersecurity services exporter across Latin America and the Caribbean.
- [8]
The 2030 Transformation Phase culminates in establishment of a permanent Cybersecurity Observatory to track incidents, threats and emerging technologies.
- [9]
Mexico is ranked Tier 2 in the ITU's 2024 Global Cybersecurity Index, alongside Canada, Ecuador and Uruguay, trailing the United States and Brazil, which reached Tier 1 in the Americas.
- [10]
Mexico is generally perceived by cyber experts as lagging behind international standards in institutional capacity-building, with international cooperation identified as an area requiring growth.
- [11]
Previous attempts to advance national cybersecurity policy in Mexico failed to gain traction.
- [12]
President Claudia Sheinbaum's administration has committed to full implementation of the Plan over the course of her term, aided by her party's majority control of Congress.
- [13]
The FIFA World Cup 2026 provided a high-profile stress test for Mexico's digital defences; with the tournament over, implementation of the 2025-2030 plan is beginning in earnest.
- [14]
From January 2020 through April 2026, Insikt Group documented 223 ransomware incidents involving 64 groups and over 100 victims in Mexico.
- [15]
The top ransomware groups affecting Mexico were LockBit, Qilin, CL0P, Kazu and ALPHV (BlackCat), with government, manufacturing, information technology, and food and beverage the sectors most heavily impacted.
- [16]
Insikt Group assesses that Mexico is an attractive target for foreign cyber operations because of its deep integration into US supply chains, a nearshoring-linked manufacturing base, and underdeveloped cyber governance.
- [17]
Chinese state-sponsored group TAG-141 (FamousSparrow) deployed SparrowDoor malware against Mexico's Universidad Nacional Autonoma in early 2025; Asia-linked TGR-STA-1030 was observed targeting at least 70 government and critical infrastructure organisations; North Korea-sponsored remote IT-worker schemes have also affected Mexican entities.
- [18]
Ransomware is identified as the dominant threat in Insikt Group's assessment of Mexico's threat landscape across six persistent categories.
- [19]
223 ransomware incidents across the 76 months from January 2020 through April 2026 averages about 2.9 incidents per month.
- [20]
223 incidents spread across slightly more than 100 victims implies an average of roughly two incidents per named victim organisation, meaning repeat victimisation.
- [21]
The Cybersecurity Observatory that would track incidents arrives in 2030, four years after the 2026 phase that must produce the law, operations centre and integrated CSIRTs.
Sources
1 independent publisher whose own reporting we read for this story.
- recordedfuture.comMexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
1 article · August 24, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
Entities
- MexicoFollow
- National Cybersecurity Plan 2025-2030Follow
- General Cybersecurity Law (Mexico)Follow
- National Cybersecurity Operations Center (Mexico)Follow
- Recorded FutureFollow
- Insikt GroupFollow
- Claudia SheinbaumFollow
- ITU Global Cybersecurity IndexFollow
- Latin America and Caribbean Cyber Competence CentreFollow
- LockBitFollow
- ALPHV (BlackCat)Follow
- QilinFollow
- Cl0pFollow
- TAG-141 (FamousSparrow)Follow
- TGR-STA-1030Follow
- SparrowDoorFollow
- 2026 FIFA World CupFollow