The National Cybersecurity Plan, presented by the Agency for Digital Transformation and Telecommunications (ATDT) in December 2025, outlines a strategic roadmap for the 2025–2030 period. It recognizes the urgency of strengthening the Mexican State’s digital posture in a context marked by the advancement of artificial intelligence and quantum computing, as well as the massive expansion of connected devices. The strategy seeks to establish a national roadmap for protecting critical infrastructure, essential services, and public data, positioning Mexico as a regional cybersecurity benchmark.
The document acknowledges significant gaps, particularly the low per capita spending on cybersecurity compared to developed countries and the growing sophistication of attacks, which has already placed the country among the most affected in Latin America. According to the Plan itself, Mexico recorded 16 confirmed critical incidents across government, financial, industrial, and educational sectors between 2022 and 2025, as well as 155 ransomware victims between 2019 and 2025, ranking second-most affected in the region. These figures reflect the growing pressure on the country’s institutional capabilities.
However, the plan has several weaknesses, one of the most significant being its limited treatment of protecting critical infrastructure and operational technologies (OT), including those based on SCADA systems. Although the document identifies critical infrastructure as part of a 2026 project, it lacks specific technical frameworks for protecting industrial control systems. This omission is concerning given the relocation of strategic industries to Mexico (i.e., nearshoring), driven by United States tariff policies, which increases risks for sectors such as energy, telecommunications, water, transportation, and advanced manufacturing. Models such as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) framework or the European Union’s Cybersecurity Directive (NIS2) could serve as references for establishing minimum protection requirements, mandatory certifications, and technical oversight schemes.
The document also inadequately addresses supply chain risk management, even though global vulnerabilities such as SolarWinds and Log4j demonstrated how failures in software or external providers can affect governments, companies, and essential services in Mexico. Even though the Plan identifies interdependencies as a global challenge, it does not outline concrete measures to assess third-party risks, implement software bills of materials (SBOMs), or require minimum controls from technology providers.
Although the Plan envisions the creation of the National Cybersecurity Operations Center (CSOC) and the National CSIRT for the Federal Public Administration (CSIRT-APF), the description of operational capabilities remains general. The document does not detail escalation procedures, incident taxonomies, coordination protocols, or metrics for measuring response times—elements indispensable to ensuring effectiveness during cyber emergencies.
The intersection between cybersecurity and privacy is another weak point. Although Mexico has data protection laws, the Plan does not incorporate privacy-by-design principles, mandatory breach notification, or operational coordination between data protection and cybersecurity authorities. In regions such as the European Union, the General Data Protection Regulation (GDPR) requires adopting incident management models centered on the rights of data subjects, a requirement the Mexican Plan has yet to incorporate explicitly.
Likewise, the focus on small and medium-sized enterprises (SMEs) is limited, even though they represent the majority of the national economy and are an essential part of global supply chains. Countries such as Australia and Singapore have developed minimum control frameworks, assessment subsidies, and national awareness programs, especially aimed at SMEs. Mexico should adopt similar schemes to prevent international security requirements from becoming economic barriers that perpetuate inequalities.
A particularly serious gap is the absence of measures to protect electoral processes and civic infrastructure, or to mitigate disinformation campaigns and deepfakes. The incorporation of such measures is especially relevant in a global context in which digital interference has compromised democratic processes. The Plan mentions coordination for the 2026 World Cup but does not incorporate a comparable approach for the continuous protection of Mexican democracy.
To strengthen the strategy, government authorities should incorporate more systematic comparative analysis, establish quantitative risk metrics, and implement monitoring mechanisms and continuous feedback schemes. Public-private collaboration also needs to be deepened through formal information-sharing platforms, tax incentives for cybersecurity investment, and structured private-sector participation in national exercises.
The publication of the National Cybersecurity Plan represents a positive step by recognizing the urgency of protecting the country’s digital assets. However, its effectiveness will depend on addressing these critical gaps, strengthening its operational framework, and continuously adapting the strategy to an evolving threat environment in which Mexico faces daily attacks, ranging from fraud targeting individuals to sophisticated intrusions against private entities and government agencies.
Nevertheless, the simple fact that the document lacks a clear financial sustainability scheme that includes cost estimates, multi-year projections, and funding models that transcend political cycles is a very bad sign if the question focuses on the longevity, improvement, and sustainability of a national cybersecurity strategy.