Nearshoring Makes Cybersecurity a Strategic Pillar
By Diego Valverde | Journalist & Industry Analyst -
Fri, 05/08/2026 - 09:10
Mexico is establishing cybersecurity as a strategic pillar for nearshoring. As supply chain attacks affect 43% of organizations, investing in digital infrastructure and Zero-Trust architectures is becoming essential to ensure operational resilience, attract global capital, and protect interconnected logistics ecosystems from professionalized cyber threats.
Mexico is redefining its logistics landscape by integrating cybersecurity as a critical factor for competitiveness and foreign direct investment, shifting from a focus on physical infrastructure to the protection of digital ecosystems.
The transition toward a model where digital security is a prerequisite for logistics operations responds to an evolution in the selection criteria of global corporations. Santos Campa, Vice President for Latin America, Futurex, says that this change is already a reality in the market. "I believe it is already happening," says Campa.
Historically, logistics competitiveness in Mexico was evaluated through indicators of physical connectivity such as port capacity, the extent of the highway network, and the availability of industrial parks. However, contemporary operations strictly depend on data flows for traceability, customs compliance, and inventory management. The pandemic functioned as a turning point that accelerated the adoption of digital environments, forcing organizations to prioritize the resilience of their systems.
In this scenario, digital infrastructure has become as relevant as physical infrastructure. Global technology companies have begun a migration of cloud services to national territory, increasing investment in data centers located in strategic hubs such as Queretaro, Monterrey, and Mexico City.
This movement seeks to reduce latency and ensure compliance with local regulations regarding data residency, consolidating Mexico as a regional digital hub. According to Campa, investment in cybersecurity ceased to be a technical item to become a strategic priority that guarantees business continuity.
Escalating Threat Landscapes and Professionalized Cybercrime
Mexico’s threat landscape presents significant structural challenges. According to Kaspersky, 43% of organizations in the country reported cybersecurity incidents in their supply chain during the last 12 months, a figure that exceeds the global average. This vulnerability intensifies due to the expansion of digital ecosystems where every external connection represents a potential attack vector.
Claudio Martinelli, General Manager for the Americas, Kaspersky, says that modern protection requires an approach that covers not only individual systems, but the entire network of commercial relationships that sustains the operation.
The evolution of cybercrime in Mexico shows accelerated professionalization. Data from IQSEC indicates that the country ascended from 16th place in 2024 to 11th place globally in ransomware attempts by the end of 2025, positioning it as the second most targeted market in Latin America, after Brazil. This increase is linked to the adoption of Ransomware as a Service (RaaS) models, powered by artificial intelligence and automation tools that allow for large-scale attacks.
Technical complexity worsens the issue. The Global Cybersecurity Outlook 2026, published by the World Economic Forum (WEF), reveals that 65% of large companies identify vulnerabilities in suppliers as the primary obstacle to resilience. On average, a large organization manages technical relationships with 100 suppliers, and in many cases, more than 130 third parties have direct access to internal systems.
A critical point in the execution of these attacks is identity management. According to research conducted by Permiso Security, 76% of security professionals reported incidents related to identity in the last 12 months. Non-human identities, such as AI agents, cloud services, and automation tools, represent 44% of all identity types in organizations. Technical data indicates that 98% of these AI agents have access to sensitive data, yet only 52% of companies have the capacity to detect modifications in their permissions.
Response latency is another risk factor. In Mexico, only 18% of security teams can confirm an identity-based threat in less than one hour. About 61% of organizations require between one and 24 hours to determine the blast radius of a breach, a delay attributed to the fragmentation of defense tools.
Security teams use, on average, between three and 10 separate tools to obtain identity visibility, which requires between 10 and 40 hours per week for the manual correlation of data from different sources.
Strategic Risk Mitigation and Tactical Recommendations
To mitigate these risks, the integration of advanced technologies such as the Internet of Things (IoT) and AI in risk management is fundamental. Luis Villatoro, Director of Supply Chain Security and Intelligence for Latin America, Overhaul, says that device-agnostic systems allow for the centralization of data from various tracking technologies, such as GPS and General Packet Radio Service (GPRS), into a single platform.
This real-time visibility facilitates regulatory compliance and the identification of operational vulnerabilities by carrier, location, or incident type. In sectors such as food and beverages, which accounts for nearly one-third of all cargo theft incidents, this data granularity is vital for proactive prevention.
The future of cybersecurity in Mexico will depend on the effective execution of the National Cybersecurity Plan 2025–2030. Although the state has created bodies such as the Digital Transformation and Telecommunications Agency (ATDT), specialists warn that the volume of intrusions exceeds the installed capacity of entities like the Mexico Cyber Incident Response Center (CERT-MX).



