Mexico has introduced a new National Cybersecurity Plan designed to address the nation's most pressing cyber threats over the next six years. The plan, published in December 2025, aims to bolster Mexico's digital defenses against organized crime, geopolitical adversaries, and emerging artificial intelligence threats, a move prompted by a series of significant cyber incidents affecting federal, state, and local institutions. These attacks have underscored the urgent need for a more unified national strategy to combat data theft, ransomware, service disruptions, and damage to institutional reputations.
Analysis of cyber trends from 2020 to 2026 indicates that Mexico has historically been a primary target for ransomware, financial malware and fraud, and hacktivism. Data breaches, organized crime-related cyber activities, and state-sponsored cyber threats also represent substantial risks. The government, healthcare, and financial sectors have been particularly vulnerable, with ransomware consistently identified as the leading threat. Mexico's deep integration into U.S. supply chains, its role in nearshoring manufacturing, and its developing cyber governance frameworks make it an attractive target for state-sponsored cyber operations. Furthermore, Mexico ranks among the top five countries globally for documented victims of infostealer malware and stolen payment card data.
The National Cybersecurity Plan, officially the 2025–2030 National Cybersecurity Plan, was released by the Mexican Digital Transformation and Telecommunications Agency (ATDT). Its objective is to modernize Mexico's federal cyber policy to align with current threat landscapes and foster a more secure and resilient digital security ecosystem. While the plan itself does not introduce new laws or policies, it establishes benchmarks and indicators to guide progress. The ATDT aims for Mexico to become a regional leader in cybersecurity through this initiative.
Mexico's commitment to cybersecurity was reflected in its "Tier 2" ranking in the International Telecommunication Union's (ITU) 2024 Global Cybersecurity Index, placing it among leading Latin American nations. However, the ITU has identified international cooperation as an area for improvement, and cybersecurity experts generally view Mexico as lagging in institutional capacity-building compared to international standards. The ATDT asserts that the plan will elevate Mexico's standing in regional cybersecurity, contributing to the protection of its digital assets and population, and strengthening overall security across Latin America and the Caribbean.
The plan's rollout follows a period of significant cyber incidents, including a 2022 hacktivist leak of sensitive files from the Secretariat of National Defense (SEDENA), a ransomware attack on the Secretariat of Infrastructure, Communications, and Transportation (SICT) in the same year, a BlackByte ransomware attack against the National Water Commission (CONAGUA) in 2023, and a RansomHub attack affecting the Legal Counsel’s Office of the Presidency in 2024. Incidents at the state and local levels, such as the exposure of Mexico City government emails in 2024 and an intrusion involving Yucatán’s Va y Ven transit system in 2025, highlight the widespread vulnerability of public institutions to data theft, service disruptions, ransomware, and reputational harm due to a fragmented response capability.
The National Cybersecurity Plan outlines a phased approach to enhancing Mexico's cyber capabilities. The initial "Foundation Phase," which began with the plan's publication in December 2025, involved establishing a general cybersecurity framework covering responsibilities, governance, risk management, incident reporting, vulnerability management, training, and coordination. During this phase, Mexico also joined the Latin America and Caribbean Cyber Competence Centre (LAC4) and signed a cybersecurity Memorandum of Understanding with Brazil.
The "Expansion Phase," currently underway in 2026, includes the development of a new National Cybersecurity Strategy by the third quarter, the passage of a new General Cybersecurity Law, and the creation of a National Center for Cybersecurity Operations for continuous threat monitoring and early detection of cyberattacks. This phase also aims to integrate a broader network of public, private, academic, and international incident response teams, identify critical infrastructure, establish a federal vulnerability assessment program, launch a Federal Virtual Academy, create a National Cybersecurity Contact Network (RNCC-MX), sign additional bilateral agreements, develop a federal CERT/CSIRT Network, and establish a critical alert system for the federal government.
Future phases include the "Consolidation Phase" in 2027, focused on establishing a National Cyber Range for realistic training exercises involving various cyber threats. The "Maturation" phase in 2028 will integrate artificial intelligence for cyber defense and develop a regional Latin America response center. The "Leadership" phase in 2029 aims to position Mexico as a leading regional cybersecurity provider by exporting services.
Organizations operating in Mexico are advised to enhance their threat detection capabilities, prioritize threat visibility, and strengthen incident response planning. This includes leveraging cyber threat intelligence solutions, adopting international cyber standards, conducting scenario-planning exercises for various threats, and educating staff and the public on cyber safety and incident response. The upcoming 2026 FIFA World Cup, co-hosted by Mexico, is expected to be an initial test of the country's resilience and ability to maintain digital services amidst increased international attention and tourism.






