A cyber incident can quickly become an operational, contractual, regulatory and reputational crisis. The corporate response must contain the damage without destroying evidence, identify which obligations are triggered and communicate only verified information. In Mexico there is no single deadline applicable to every event: the compromised data, the sector, the contracts and the insurance policy all matter. This protocol summarizes essential decisions for a coordinated response. It is informational material and does not constitute legal advice.
The first hours
The initial priority is to activate a clear command that brings together technology, management, legal, privacy, continuity and communication. The team must open a log with the time, the source of the finding, affected systems, decisions and owners. Containment may involve isolating equipment, revoking credentials or blocking connections, but it is advisable to preserve images, logs and other evidence before altering the environment when feasible. The criticality must also be classified, backups confirmed and it must be defined which operations can safely continue. A brief internal message avoids rumors and improvised changes. Negotiating with attackers, contacting authorities or any payment require a separate assessment of legality, sanctions, coverage, traceability and the risk of recurrence.
Assess notices and communications
The legal analysis must distinguish between unavailability, unauthorized access, loss, alteration and extraction of information. If personal data are involved, the categories, data subjects, volume, protection applied and possible impact must be determined. The personal-data law requires informing people immediately when the breach significantly affects their property or moral rights. There may also be sectoral, contractual, insurance or corporate notices with different recipients and timelines. CERT-MX offers channels to report and coordinate incidents, but that channel does not turn every event into a general obligation to report. Each communication must be consistent, useful and based on facts; speculating or promising an unsupported recovery can worsen the exposure.
Recover and learn
Before restoring, the team must identify the root cause, close the entry vector and verify the integrity of the backups. Then it is advisable to rotate secrets, watch for persistence, prioritize critical services and record the criteria for return. Closure does not occur when the system comes back: it is necessary to reconcile evidence, notifications, costs, insurance decisions and commitments to clients. A subsequent review must translate the incident into concrete controls, such as reinforced authentication, segmentation, patching, better logs or contractual adjustments. The final report must separate confirmed facts, inferences and pending matters, and define owners and dates. Regular drills make it possible to verify that phones, authorities and providers remain available when they are really needed.
Key points
- Containing the incident and preserving evidence must happen in a coordinated way.
- Not all events trigger the same recipients or the same notice deadlines.
- Communications must be based on confirmed facts and a documented assessment.
- Recovery includes the root cause, subsequent monitoring and improvement of controls.
What to review
- Define a response team, backups and authorities before a crisis occurs.
- Prepare a matrix of legal, contractual, sectoral and insurance notices.
- Run a drill and turn its findings into tasks with an owner and a date.