Cybersecurity for companies means preventing, detecting and responding to incidents that put an organization’s information, systems and operations at risk. Castro Defense provides this service to companies, law firms and institutions across Mexico from Santiago de Querétaro, including foreign companies with operations in the country, combining technical response with evidence preservation and legal defense. Our work follows Mexican law.
Request an assessment in 2 minutes →
What does the cybersecurity service include?
- Incident response. Containment, investigation and recovery from ransomware, compromised email accounts, impersonation fraud or data leaks, without losing the evidence.
- Security assessment. A review of configurations, access, backups and internet exposure, with a report of findings ranked by risk.
- Forensic readiness. Logs, backups and procedures in place so that, if an incident happens, you can tell what occurred and the evidence can stand up before a Mexican authority.
- Awareness training. Sessions for staff on phishing, passwords, two-step verification and information handling.
- Compliance support. Security measures for the personal data your organization handles and a plan for dealing with breaches.
Confirmed scope and deliverables: scope, deliverables and delivery mode (remote or on site) for each service. Team certifications: the team’s cybersecurity certifications, if any.
Who is it for?
Organizations of any size that rely on email, the cloud or their own systems and handle data about customers, employees or suppliers: companies, law firms, retailers, and schools or healthcare providers.
What does Mexican law require?
- Security measures. The Federal Law on the Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, LFPDPPP), published in Mexico’s Official Gazette (DOF) on March 20, 2025, requires every data controller to maintain administrative, technical and physical security measures that protect personal data against damage, loss, alteration, destruction or unauthorized access (art. 18).
- Breaches. Security breaches that significantly affect people’s property or moral rights must be reported to them immediately (art. 19).
- Computer crime. The Federal Criminal Code (Código Penal Federal) punishes unlawful access to computer systems and equipment (arts. 211 bis 1 to 211 bis 7).
- Evidence. If the case leads to a criminal complaint, chain of custody records who handled each item of evidence and under what conditions (National Code of Criminal Procedure, art. 227).
How does it work?
- Initial assessment. You answer a few questions and a specialist contacts you to understand the situation and its urgency.
- Scope in writing. Before anyone accesses a system, goals, limits and confidentiality are agreed.
- The work. Containment and investigation, technical review or training, depending on the case.
- Report. Findings, evidence and recommendations in language management can use to make decisions.
Cybersecurity, forensics and legal defense
When an incident ends in a criminal complaint, a labor dispute or a claim, digital forensics documents the evidence with chain of custody and legal defense sets out what needs to be proven.
This content is for information only and is not legal advice for a specific case. The outcome of any proceeding depends on the facts, the evidence and the authority’s decision; Castro Defense does not guarantee results.
Official sources
- Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), arts. 18 and 19. Chamber of Deputies, current text (DOF March 20, 2025; last amended November 14, 2025) (Spanish).
- Federal Criminal Code (Código Penal Federal), arts. 211 bis 1 to 211 bis 7. Chamber of Deputies, current text as amended March 13, 2026 (Spanish).
- National Code of Criminal Procedure (Código Nacional de Procedimientos Penales), art. 227. Chamber of Deputies, current text (Spanish).
Frequently asked questions
What should we do if our company is being attacked right now?
Disconnect affected machines from the network without powering them off, change critical passwords from a device that is not compromised, and do not delete logs or the attacker's messages. Then write down what you saw and when, and get specialist help to contain the incident and preserve the evidence.
Is my company legally required to have security measures in Mexico?
If it handles personal data of customers, employees or suppliers, yes. Mexico's Federal Law on the Protection of Personal Data Held by Private Parties requires every data controller to set up and maintain administrative, technical and physical security measures to protect that data (art. 18).
Do we have to notify people affected by a data breach?
Yes, when the breach significantly affects their property or moral rights. The law requires the controller to inform them immediately so they can take steps to protect their rights (Federal Law on the Protection of Personal Data Held by Private Parties, art. 19).
Is unauthorized access to a computer system a crime in Mexico?
Yes. The Federal Criminal Code punishes anyone who, without authorization, alters, destroys, accesses or copies information held in computer systems or equipment protected by a security mechanism (arts. 211 bis 1 to 211 bis 7). That is why evidence should be preserved from the start.