Mexico City, Mexico, July 29, 2026 — Mexico may be short more than 77,000 cybersecurity specialists as ransomware and AI-assisted attacks place greater pressure on businesses, government agencies, and public infrastructure.
The estimate came from Nicole Filippetti, an academic and industry liaison at the University of Advanced Technologies. She said that the country has about 6,000 qualified cybersecurity professionals, despite demand for about 85,000 positions.
UNIAT also estimates that ransomware attacks against Mexican companies increased by 38 percent over the past year, while the use of artificial intelligence in cyberattacks rose by nearly 90 percent.
The reports do not link to the workforce study, company sample, or methodology behind those percentages. The numbers should therefore be treated as industry estimates rather than an official labor-market count. UNIAT also has a commercial interest in the issue as it prepares new cybersecurity degree programs at its Tijuana campus.
The broader problem is clear even without relying on every estimate. Mexican businesses and public agencies are moving more customer records, payment systems, internal communications and essential services online, creating more systems that must be protected with a limited supply of trained personnel.
Attacks are becoming easier to scale
Ransomware can encrypt records and interrupt payments, manufacturing, reservations, medical services or government procedures. Some criminal groups also steal copies of the information before locking a system, allowing them to threaten to publish it even when the victim can restore its files.
Artificial intelligence can help criminals produce convincing messages in Spanish or English, imitate normal business correspondence and automate parts of an attack. A fraudulent email can impersonate a real supplier, invoice, or employee and pressure the recipient to open a file, disclose a password, or redirect a payment.
Human error remains one of the main openings. Filippetti estimated that 67 percent of successful attacks involve mistakes such as opening malicious email, reusing weak passwords or downloading unverified files.
The shortage of specialists makes those mistakes harder to prevent and more expensive to correct. Smaller companies may be unable to employ a dedicated security team, while larger organizations compete over a relatively small pool of engineers, analysts and digital investigators.
The public sector faces the same constraint. Cyberattacks have disrupted Mexican government systems and essential services, including an April 2025 ransomware attack against Guadalajara’s SIAPA water agency. The incident disabled payment and administrative systems for more than a week. Jalisco Governor Pablo Lemus later said the attackers demanded a ransom that the state did not pay.
Filippetti said the Jalisco Cyber Police alone had about 35 positions that were difficult to fill because candidates needed both law-enforcement training and technical experience in digital investigations, security audits and software.
The talent gap will take years to close
Mexico’s cybersecurity shortage cannot be resolved quickly through traditional university programs. A specialist may need several years of education, followed by certifications and practical experience, as cyber threats and business systems continue to evolve.
Companies have increasingly retrained programmers and systems engineers through shorter courses, professional certifications and graduate programs. Outside security providers have also become an alternative when maintaining an internal department is not practical.
The shortage extends beyond technical knowledge. UNIAT said employers also struggle to find candidates with the English-language skills needed to work with international companies, handle security documentation, and support cross-border operations.
Those hiring pressures can leave organizations dependent on a single employee or outside contractor who controls critical systems without a documented backup plan. A departure, illness, or dispute can then become an operational risk even without a cyberattack.
Businesses retain legal responsibility
Outsourcing technology does not eliminate a company’s responsibility over customer and employee information.
Mexico’s current Federal Law on the Protection of Personal Data Held by Private Parties requires private organizations to maintain administrative, technical and physical safeguards against unauthorized access, loss, alteration or destruction of personal data.
When a breach significantly affects someone’s financial or moral rights, Article 19 requires the responsible organization to inform that person immediately so protective measures can be taken.
The federal government’s cybersecurity manual aimed at small and medium businesses recommends controlled access, current software, employee training, tested backups and a documented incident-response process.
A company does not need 77,000 specialists to begin reducing its exposure. It does need to know what information it holds, who can access it, whether former employees still have working accounts, and whether its backups can actually restore operations.
Mexico’s talent shortage makes specialist help more difficult to obtain. It also makes basic preparation inside every organization more important.





