CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5035

As cited

Copy frozen at (site build).

ransomware

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico introduced a National Cybersecurity Plan for 2025-2030 in December 2025 to address growing threats including ransomware, state-sponsored espionage, and cyber-enabled organized crime. The plan establishes a six-phase roadmap through 2030, with the 2026 Expansion Phase now underway, focusing on new legislation, a national operations center, and integrated incident response teams. Ransomware remains the dominant threat, with 223 documented incidents from January 2020 through April 2026 involving groups such as LockBit, Qilin, and CL0P targeting government, manufacturing, IT, and food and beverage sectors.

Why it matters: Mexican government agencies, universities, and critical infrastructure operators should monitor implementation of the new cybersecurity framework and prepare for potential regulatory requirements under the forthcoming General Cybersecurity Law, while organizations in targeted sectors should prioritize ransomware defenses and credential security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense

Mexico introduced a National Cybersecurity Plan for 2025-2030 in December 2025 to address growing threats including ransomware, state-sponsored espionage, and cyber-enabled organized crime. The plan establishes a six-phase roadmap through 2030, with the 2026 Expansion Phase now underway, focusing on new legislation, a national operations center, and integrated incident response teams. Ransomware remains the dominant threat, with 223 documented incidents from January 2020 through April 2026 involving groups such as LockBit, Qilin, and CL0P targeting government, manufacturing, IT, and food and beverage sectors.

Why it matters: Mexican government agencies, universities, and critical infrastructure operators should monitor implementation of the new cybersecurity framework and prepare for potential regulatory requirements under the forthcoming General Cybersecurity Law, while organizations in targeted sectors should prioritize ransomware defenses and credential security.

Actorslockbitalphvblackcatcl0pqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary