MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel
2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation As mentioned, there is no specific cybersecurity law that regulates critical infrastructure in Mexico. How - ever, the National Security Law ( Ley de Seguridad Nacional ) contains provisions emphasising the impor - tance of protecting critical infrastructure, though it does not define in detail what constitutes such infra - structure. Additionally, during the previous adminis - tration, a National Standardised Protocol for Man - aging Cybersecurity Incidents ( Protocolo Nacional Homologado de Gestión de Incidentes Cibernéticos ) was implemented. While this protocol is not a legal document, it serves as a reference for establishing the terms and procedures that strengthen cyberse - curity across government entities and the private sector. This initiative aims to ensure the continuous, coordinated management of cybersecurity incidents, improving overall resilience and response to emerg - ing threats. 2.2 Critical Infrastructure Cybersecurity Requirements In Mexico, there are no specific cybersecurity obliga - tions for protecting critical infrastructure. While various regulatory frameworks address cybersecurity issues, there is no comprehensive legislation that specifies the measures entities managing essential infrastruc - ture (such as energy, telecommunications, and trans - portation) must adopt. The absence of a clear legal framework for protecting critical infrastructure against cyber threats leaves institutions responsible for these key sectors with some flexibility but also creates a regulatory gap that could jeopardise the country’s resilience in the face of cyber incidents. 2.3 Incident Response and Notification Obligations There are no specific reporting obligations for cyber - security incidents related to critical infrastructure. However, the Protocol, as mentioned in 2.1 Scope of Critical Infrastructure Cybersecurity Regulation , includes a series of recommendations on how high- level, critical, and impactful cybersecurity incidents should be reported to the National Guard ( Guardia
Nacional ). For example, the protocol outlines mecha - nisms for incident notification, specifying how inci - dents should be classified and how government enti - ties should carry out the reporting process. Strengthening this protocol through new regulations that grant it mandatory status could significantly enhance the ability to respond to cybersecurity inci - dents, offering better protection for critical infrastruc - ture sectors in Mexico. 2.4 State Responsibilities and Obligations As mentioned above, the government has obligations regarding resilience and threat identification, which are set out in protocols or guidelines, such as the one mentioned earlier. However, these obligations are not specifically set out in any particular law. This frag - mented approach can make it difficult to implement effective security measures, as authorities and private entities may interpret the guidelines differently or may not be legally required to adopt them uniformly. To improve the situation, it would be advisable for Mexico to move toward enacting laws that establish obligations for cybersecurity resilience and threat identification in critical infrastructure. This would enable more coherent and coordinated management of cyber risks, ensuring that all parties involved follow a common set of rules that strengthen protection and response to cybersecurity incidents. The implemen - tation of more formal legislation could also improve cooperation between the public and private sectors, enhancing the ability to respond to cybersecurity chal - lenges. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Operational resilience in Mexico’s financial sector is primarily regulated by: • CNBV; • Banxico; and • the National Commission for the Protection and Defence of Financial Services Users (CONDUSEF).
250 CHAMBERS.COM
Powered by FlippingBook