Mexico Unveils the National Cybersecurity Plan 2025–2030 - Mexico Business News
Mexico Business News
Archived Apr 05, 2026
✓ Full text saved
Mexico Unveils the National Cybersecurity Plan 2025–2030 Mexico Business News
Full text archived locally
All
Multimedia
Expert Contributor
Entrepreneurs
Tech
Talent
Energy
Oil & Gas
Mining
Health
Automotive
Aerospace
Finance & Fintech
Infrastructure
Sustainability
Professional Services
E-Commerce & Retail
Agribusiness & Food
Logistics
Mobility
Trade & Investment
Policy & Economy
Cybersecurity
AI, Cloud & Data
Chemicals
By Diego Valverde | Journalist & Industry Analyst - Mon, 12/08/2025 - 09:35
Mexico’s Digital Transformation and Telecommunications Agency (ATDT) has introduced the National Cybersecurity Plan 2025–2030, a strategic framework designed to establish the first transversal state policy for digital defense in the country. This initiative aims to standardize critical infrastructure protection and position the country as a regional leader in cyber resilience through a centralized, prevention-focused model.
The plan aims to address the urgent need to transition from fragmented defense mechanisms to a unified operational structure, driven by increasingly sophisticated digital threats and high-profile geopolitical events, such as the upcoming World Cup.
"We are not talking about if we are going to be attacked; we all know perfectly well that it is only a matter of when we are going to be attacked," says Heidy Rocha, Director General of Cybersecurity, ATDT. "The global context forces Mexico to stop thinking about cybersecurity as an isolated problem for technical teams and assume it as a structural axis of the state."
The urgency of this initiative stems from a severe technical diagnosis regarding the security posture of the region. According to data presented by the ATDT, cybersecurity incidents in Latin America increased by about 25% compared to the previous year. Mexico ranks as the second most attacked country in the region, surpassed only by Brazil.
Between 2019 and 2025, authorities documented 155 Mexican victims in specialized digital extortion forums. The LockBit ransomware family has been identified as the predominant threat and is responsible for one-quarter of the identified attacks. This attack vector has exerted significant pressure on strategic sectors, with the government and the financial system concentrating a significant proportion of malicious events.
Regarding human capital, the diagnosis acknowledges a global cybersecurity skills gap that limits response capabilities across both the public sector and the general industry. Furthermore, the historical absence of a homogeneous regulatory framework for the Federal Public Administration has led to isolated efforts. The new plan seeks to rectify this situation to face risks associated with geopolitical tensions and the massive adoption of AI.
Institutional Architecture and Implementation Phases
The National Cybersecurity Plan 2025–2030 proposes a complete reengineering of the digital ecosystem of the country. It articulates the 68 existing incident response teams — CSIRTs and CERTs — under a new centralized coordination architecture. Of those, 26 of these teams belong to the international FIRST network. The majority are concentrated in Mexico City and distributed among the academic, financial, energy, telecommunications, and government sectors, to name a few.
To eliminate operations in "islands," the ATDT will establish governing bodies that centralize intelligence and response. These include:
National Cybersecurity Operations Center (CNSOC): A federated entity responsible for continuous monitoring and operation.
National Incident Response Center (CSIRT/SESIR-APF): A specialized team for crisis management within the Federal Administration.
Critical Infrastructure Inventory: A detailed registry to prioritize the defense of strategic national assets.
Vulnerability Assessment Program: An active alert and notification system to identify and remedy security gaps in public institutions.
"What we seek is to perform a homologation and generally elevate all dependencies, so that we have a constant and growing level of maturity in cybersecurity," says Mario Cortés, Director of Strategy and Cybersecurity Government, ATDT.
Strategic Timeline and Maturity Phases
The deployment of the plan follows a structure divided into three stages defined by technical objectives. The first stage, named the Foundation Phase, centers on knowing the ecosystem, mapping actors and threats, and designing regulatory instruments. Deployed during 2025, it includes the imminent publication of the General Cybersecurity Policy for the Federal Public Administration in the Official Gazette. This phase will establish mandatory guidelines, required maturity levels, and standardized incident reporting mechanisms for all federal agencies. In parallel, the ATDT already operates a vulnerability alert and notification system to identify specific security gaps.
The second stage, the Strategy Phase, will take place in 2026. During which, the government plans to present a new National Cybersecurity Strategy, updating the last version created in 2017. Cortés indicates that the challenge is to renew this guiding document every two years to maintain technological currency.
Finally, the Consolidation and Leadership Phase, which will take place between 2027 and 2030, projects the creation of a national "cyber range" for advanced training and annual attack simulation exercises. It will integrate machine learning models and AI for automated preventive detection, with the goal of operating 24/7 cyber defense services and exporting technical capabilities to other countries in the region.
General Cybersecurity Law and International Collaboration
A critical component of the plan is the promulgation of the first General Cybersecurity Law. Unlike previous approaches centered on penal typology, this legislation will prioritize risk management, prevention, and coordinated response. The regulatory framework seeks to professionalize public servants, legally define the concept of critical infrastructure, establish a mandatory incident reporting system, and articulate sanctions that incentivize good practices without criminalizing human operational error.
The plan emphasizes that cybersecurity is a shared responsibility that requires the alignment of the government, academia, and private industry. To this end, the administration has constituted a National Cybersecurity Council.
The initiative relies on strategic alliances with international organizations. Ariel Nowersztern, Consultant, Inter-American Development Bank (IDB), and Jorge Mora, Consultant, Inter-American Development Bank (IDB), call this initiative a holistic plan suitable for existing challenges.
The project is backed by representatives from the Organization of American States (OAS), the Universidad Nacional Autónoma de México (UNAM), the Instituto Politécnico Nacional (IPN), and the National Council of the Maquiladora and Export Manufacturing Industry (Index).
"Cybersecurity is not about competing, about seeing who is more protected or who is less, but about collaborating," says Cortés. "Any plan, law, or strategy that does not go through collaboration is destined for failure."
Photo by: Government of Mexico
TAGS:
Mexico
Mexico City
ATDT
Cybersecurity
Technology
Digital Transformation
cyberattacks
Critical Infrastructure
Cloud Security
ai
Data Privacy
Industry 4.0
STEM Talent
Defensive AI
cyber defense
Incident response
Public Sector Security
Mario Cortés
Heidy Rocha
Ariel Nowersztern
Jorge Mora
IDB
OAS
UNAM
IPN
INDEX
YOU MAY LIKE
Mexico City Considers Remote Work During 2026 World Cup
TLW 2026: Why Talent is the New Supply Chain Priority
Low Adherence Drives Health Risks, Costs: Servier Mexico
UNODC, Scitum Join Forces to Fight Cybercrime in Mexico
Mexico: Key LatAm Market for Peruvian Companies
LLMs Changed the Marketing Playbook. Here's What Matters Now
NL Leads IMMEX Growth; Mexico Prepares for Compliance Forum 360
World Trade Center Industrial Park 3 Opens in San Luis Potosi
MOST POPULAR
Sustainability
Gulf Oil Spill Causes IDed, NL Approves Sustainable Tourism Law
Trade & Investment
IDB Opens Miami Office, Bets on Private Capital
Oil & Gas
Gulf of Mexico Oil Spill Exposes PEMEX Vulnerabilities
Trade & Investment
China Flags Retaliation Risk as Mexico Raises Trade Barriers
Finance & Fintech
USMCA 2026: Mexico Must Negotiate From Strength, Not Fear
Oil & Gas
Petrobras-PEMEX Partnership: The Week in Oil and Gas
Trade & Investment
PepsiCo Opens US$467 Million Sabritas Plant in Guanajuato
Av. Paseo de la Reforma 180, piso 20, Col. Juárez, Cuahutémoc, 06600, Ciudad de México.
Follow Us
Our Categories
Entrepreneurs
Tech
Talent
Energy
Oil & Gas
Mining
Health
Automotive
Aerospace
More
Finance & Fintech
Infrastructure
Sustainability
Professional Services
E-Commerce & Retail
Agribusiness & Food
Logistics
Mobility
Trade & Investment
Policy & Economy
Cybersecurity
AI, Cloud & Data
Chemicals
© 2025 Mexicobusiness.News. A Mexico Business Company. All Rights Reserved.
AddToAny
More…