MEXICO Law and Practice Contributed by: Alejandro Mendiola Diaz and Gunter A. Schwandt G, Nader Hayaux & Goebel
3.3 Key Operational Resilience Obligations As previously pointed out, Mexico does not currently have dedicated digital operation resilience regulation like the EU, but it has multiple regulatory frameworks that collectively govern operational resilience, cyber - security, and incident reporting for financial institu - tions and ICT providers. The main objectives of such regulation include: • ensuring business continuity and system availabil - ity; • bolstering cybersecurity and IT risk management; • mitigating risks related to third-party providers and cloud computing; • improving crisis management and incident response; • safeguarding personal data and financial informa - tion, while enhancing consumer protection and data security; and • following international standards. Additionally, financial institutions and other partici - pants, such as ICT service providers, payment pro - cessors, and cloud providers, in Mexico must com - ply with incident reporting obligations. Such reporting obligations include cybersecurity breaches, opera - tional disruptions, financial fraud and phishing attacks and third-party ICT failures. Financial institutions must also keep logs and forensic reports for potential regu - latory audits. 3.4 Operational Resilience Enforcement Enforcement of operation resilience obligations by regulators in relation to critical ICT services provid - ers in Mexico is done through supervisory audits, compliance inspections, penalty assessments and mandatory incident reporting. The primary authorities overseeing enforcement include the CNBV, Banxico and the MAGG. 3.5 International Data Transfers International data transfers must comply with the pro - visions of the DPR, financial sector rules and trade agreements. These rules apply to financial institu - tions, ICT providers and businesses in general that process or store personal or sensitive data outside of Mexico. Mexican businesses are obligated to imple - ment contractual safeguards, consent mechanisms
and cybersecurity measures to ensure compliance. Note that the United States-Mexico-Canada Agree - ment (USMCA) contains provisions on cross-border data flows and data localisation. 3.6 Threat-Led Penetration Testing Mexico does not have a formal TLPT regulation; how - ever, financial institutions and ICT providers must con - duct penetration tests, cyber resilience assessments and simulated cyber-attacks (red teaming) under Banxico and CNBV regulations, as part of regula - tory compliance. Specifically for financial institutions handling electronic payments, fintech platforms and banking infrastructure, CNBV and Banxico mandate penetration testing and cybersecurity assessments to assess resilience against cyber threats. Resilience obligations in Mexico are primarily related to financial services. Please refer to 3. Operational Resilience in the Financial Sector . 4.2 Key Obligations Under Legislation Resilience obligations in Mexico are primarily related to financial services. Please refer to 3. Operational Resilience in the Financial Sector . 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation In Mexico, there is no law requiring companies or indi - viduals to obtain a cybersecurity certification. While the country has established some data protection regulations, particularly through the DPR, these do not impose mandatory cybersecurity certification for organisations or professionals. Instead, the regulations generally require businesses to implement appropriate technical security measures to protect personal data from risks such as unauthorised access, alteration, or destruction. 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
252 CHAMBERS.COM
Powered by FlippingBook