- What: Mexico's new cyber plan faces its first real test
- Impact: National cybersecurity strategy is being tested in practice
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Сloud Security Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours by Alexander Culafi Jul 8, 2026 4 Min Read Application Security Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft by Alexander Culafi Jul 7, 2026 3 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyber Risk Cybersecurity Operations Threat Intelligence ICS/OT Security News Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific Mexico's New Cyber Plan Faces Its First Real Test The Latin American nation's cybersecurity plan — still in the expansion phase — has to survive its own knockout round during the FIFA World Cup. Robert Lemos , Contributing Writer July 8, 2026 4 Min Read Source: Santiago Castillo Chomel via Shutterstock Mexico adopted its Plan Nacional de Ciberseguridad 2025-2030 — its National Cybersecurity Plan — seven months ago, and while the strategy is still in its "expansion phase," the FIFA World Cup 2026 tournament has become an early test for the government's ability to implement the document, experts say. Drafted by the Agencia de Transformación Digital y Telecomunicaciones (ATDT), or Mexico's Digital Transformation and Telecommunications Agency, the plan aims to guide efforts to update federal legislation and establish cybersecurity capabilities throughout the government. For the current year, the cybersecurity plan calls for the creation of a National Cybersecurity Strategy by the end of the third quarter, the creation of a National Cybersecurity Center to track threats, and greater cooperation between cybersecurity professionals in government, private industry, and academia, according to an analysis published June 25 by threat intelligence firm Recorded Future. Related: UK Social Media Ban for Minors Has Privacy Experts Worried The ongoing FIFA World Cup 2026 tournament, which includes three stadiums in Mexico among its venues, casts a spotlight on the country's cybersecurity efforts and is an early test of Mexico's capabilities, the report stated. "Cyber risk around the tournament is likely to be elevated, as the event creates a target-rich environment for ransomware groups, hacktivists, fraud actors, credential thieves, and disinformation networks seeking financial gain or disruption," Recorded Future stated in the report . "If a cyber incident occurs, it will likely shape public debate over cybersecurity in Mexico and attract greater international attention to any perceived gaps." Cybercriminals, hacktivists, and nation-state threat actors are all cybersecurity risks for Mexico's government. While Recorded Future rated the digital-security risk for Mexican organizations as "medium" prior to the World Cup , the country has seen an increase in cyberattacks just prior to and during the tournament , according to various cybersecurity firms . In addition, some major attacks have targeted Mexico this year, including a purported massive data leak, which may have included a lot of recycled data. And an AI-fueled attack on at least nine Mexican government agencies harvested data but failed to affect operational-technology (OT) systems . Mexico (and Latin America) Under Attack To secure the three host cities during the World Cup 2026, the Mexican government created an overall plan called the "Kukulkán Plan," which includes international cooperation mechanisms, information exchange with the US, Canada, and FIFA, and specialized training for officials. The government also conducted risk-management exercises and reinforced security measures around stadiums and other important visitor destinations. Related: As Global Powers Explore Humanoid Robots, Cyber-Risk Looms Last year, Mexico embarked on a process to improve its national cybersecurity readiness and address the lack of a specific cybersecurity law. The National Cybersecurity Plan is a long-term document that will lead to a more comprehensive strategy for improving digital security and creating the culture and infrastructure necessary to improve its detection and response capabilities. "The plan comes at a crucial time for cybersecurity in Mexico, after several high-profile cyber incidents that have highlighted the need for greater resilience and coordination," Recorded Future stated in its analysis, adding, "These incidents show that Mexico's cyber risks are not limited to a single agency or sector, and that a fragmented, uncoordinated national response capacity can leave public institutions vulnerable to data theft, service disruptions, ransomware, and reputational damage." While the plan is a good start, the country currently lacks an adequate strategy for tackling the cybersecurity of operational technology and supply chains, José Felipe Otero, an adjunct professor at New York University and an expert on Latin American telecom infrastructure, said in an analysis of the plan . Related: Dutch Raid Fails to Dent Russian Bulletproof Host "Even though the plan identifies interdependencies as a global challenge, it does not outline concrete measures to assess third-party risks, implement software bills of materials (SBOMs), or require minimum controls from technology providers," he says. "The focus on small and medium-sized enterprises (SMEs) is limited, even though they represent the majority of the national economy and are an essential part of global supply chains." The Region Sees More Cyberattacks In addition, current Mexican federal regulations are a hodgepodge of laws, jurisdictions, and regulatory regimes, according to an analysis of current cybersecurity regulations by Mexican financial consultancy Nader Hayaux & Goebel. "Several cybersecurity law proposals have been submitted to Congress for discussion. However, none have been enacted into law, remaining as proposals that could serve as a foundation for future legislative discussions," the firm's analysis stated. "Given the increasing frequency and sophistication of cyber threats, there is a growing need for a comprehensive cybersecurity law that establishes clear regulations and penalties for cyber-related offenses." Overall, Mexico is just seeing a small part of the overall cyberthreat landscape of Latin America, which has experienced a significant surge in weekly attacks per organization, up 13% year over year, to nearly 3,150 per week in May. "Facing this dynamic, organizations in Mexico should enhance their ability to detect cyber threats, prioritize threat visibility, and strengthen incident response planning," Recorded Future stated in its report. "They should also train staff and the public on basic cyber safety, with an emphasis on building a practical understanding of how to respond quickly and effectively when incidents occur." Read more about: DR Global Latin America About the Author Robert Lemos Contributing Writer Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity. A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports. Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major). See more from Robert Lemos Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impact™ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program Threat Hunting That Gets Big Results Despite Small Budgets More Webinars Editor's Choice Cybersecurity O