Flagship report · Instituto Verlumia · Mexico
Verlumia Report
July 2026 Edition
The measured reading of the risk affecting citizens — computed from sealed official data, with the person at the center, not the company. Citizen Cyber-Risk Index (ICC).
In Mexico a citizen fraud case is reported every ~4 minutes — and July marks the highest reading of 2026.
First measured ICC figure for Mexico: computed from the official RNID/SESNSP series (139 months, 2015–2026) under the ICC/1.4 methodology, with auditable lineage and a hash per figure. Scope: one country. 2 of the ICC's 4 dimensions measured.
What this edition measures
The July 2026 findings for Mexico — measured first, context after, never at the same weight.
- Citizen fraud is at its highest reading of 2026. The measured index stands at 75.8/100 ("High") in July, over 10,995 investigation case files reported (RNID/SESNSP), in the "High" band continuously since March. Grade A · measured truth.
- Cyberbullying is persistent, not rising. 21.0% of internet users in 2024 (MOCIBA/INEGI), stable around 21% since 2021 (CI90 [20.5–21.5]). Grade B · survey.
- We measure 2 of the ICC's 4 dimensions. Data exposure and Defense remain in incubation — declared, not estimated. The gaps are shown on purpose.
- The nowcast is not the headline. The predictive annex (54.9) uses a proxy with weak predictive power; it is shown for transparency, never as the headline figure.
- Third-party context is clearly separated. The threat landscape is included as reference (grade C), never as a Verlumia measurement — and without teal.
The threat environment
Mexico does not measure in a vacuum: it operates in one of the most active threat environments in the region. This panorama is third-party context —not a Verlumia measurement— and is distinguished by design from our figures.
Threat landscape, from third-party sources. It helps situate the measured reading; it does not enter the index nor is it painted teal.
Ransomware remains the most disruptive form of attack; also concerning is the use of AI by attackers —kits like WormGPT or FraudGPT cheapen campaigns— and the abuse of legitimate tools already present in the target environment to go unnoticed. Cybersecurity spending is growing, but investment does not keep pace with digitalization: measuring risk in a neutral, comparable way is, in itself, a defense.
What we measure today
The fraud series over time
Measured series end to end, 139 months (2015–2026). The headline is the official datum; the nowcast is shown as an annex, never as the headline.
Teal only in grade A (fraud). Cyberbullying is a survey estimate (grade B) and is measured separately; it is not composed with fraud into a single figure.
What we don't measure yet
2 of the ICC's 4 dimensions are measured today. The gaps are shown on purpose: they are comparable country to country.
The impact on people
Cyber-risk does not end at the company: it affects people's finances and dignity. Our cyberbullying measurement anchors this layer; the bank-complaint figures are attributed official context, not a Verlumia measurement.
Cyberbullying reached 21.0% of internet users in 2024 —about 18.9 million people (MOCIBA)— and fraud victimization is, according to ENVIPE, the most frequent crime in the country.
The reading key
Official count of facts. The only grade painted teal.
Sample estimate with its stated confidence interval. No teal.
Third-party indices and context (the whole panorama and the bank complaints). No teal. A country's institutional capacity is not the same as measured citizen protection.
The framework took a leap
- General Cybersecurity Policy for the Federal Public Administration (Dec 2025). Published in the DOF and in force; it unifies mandatory criteria for the Federal Public Administration.
- National Cybersecurity Plan 2025–2030 (Dec 2025). The country's first specialized framework; it contemplates a National Strategy and a future General Law.
- Cybersecurity Law bill, in the Senate. It would create a National Agency and an incident-reporting regime; publication expected toward the second half of 2026.
Incident reporting will stop being voluntary and accountability will become enforceable. Demand accelerates for a credible measure of risk — a neutral yardstick that neither the regulator nor a vendor can offer without conflict.
The lineage of every figure
Every measured figure in this report is generated from sealed data —not typed— and carries its lineage, so it is reproducible. The full case record per figure lives in its sub-index:
| Pillar | Source | Version | Grade | Sealed edition · lineage |
|---|---|---|---|---|
| Fraud | RNID · SESNSP | ICC/1.4 | A | Jul 2026 · serie_retroactiva_fraude.csv 4651ab20… · methodology.yaml 27b0e9d3… · anchor 90ad6270… · commit ca52e1f · ACTA-023/024/022 · see full case record → |
| Cyberbullying | INEGI · MOCIBA | ICC/1.4 · mociba 0.2.0 | B · CI90 | 2021-2024 · serie_acoso_2021-2024.csv 8DF2B91A… · connector 57e8c11b… · ACTA-030/027/029 · see full case record → |
Check it yourself. Every figure in this report has its downloadable reproduction package: the sealed output, the exact methodology of that version, the official (open) input and the hashes to verify byte for byte. The 75.8 headline can be reproduced with a calculator from the SESNSP datum.
Measure to protect, not to surveil. This index doesn't only measure whether an organization is secure; it measures whether it protects the people who depend on it. That's why it never incorporates personal data.
What this reading is — and is not
The headline of each report is the strongest measured figure of that country —here, fraud—, not a fixed pillar; and it is never compared numerically with another country without its own record. Comparability rests on identical criteria, not on direct numerical comparisons across countries. A regional report would be a separate, later publication.
About this edition. July 2026 edition · Mexico · sealed and immutable. The ICC-fraud figure is real, computed under the public ICC/1.4 methodology with auditable lineage, and approved by Jorge A. Ramírez Vargas as signatory. Any third party with the same inputs and methodology reproduces the figure. No valuation, no ARR, no "leader." Scope: one country. Governed by the five guiding principles + an ethos of non-fabrication and auditability.
Sources
SESNSP · RNID (crime incidence, common-jurisdiction (fuero común) 2015–2026, fraud series — the ICC anchor) · INEGI · MOCIBA 2024 · ENVIPE 2025 · CONDUSEF (complaints; identity theft 2024). Third-party context (grade C): Kaspersky 2025 · CrowdStrike (LATAM Threat Landscape 2025). Framework: DOF (General Cybersecurity Policy for the FPA, Dec 2025) · National Cybersecurity Plan 2025–2030. Context figures are third-party and do not constitute a Verlumia measurement.