La Jornada: “Mexico has to invest in cybersecurity, human resources and training”

Faced with the rise of artificial intelligence agents capable of identifying and exploiting vulnerabilities that increase computer attacks, the main challenge for Mexico is to train more specialists, develop infrastructure and strengthen a culture of cybersecurity, warned Rocío Aldeco Pérez, specialist in cryptography, blockchain and distributed systems.

“Mexico has to invest in cybersecurity, generate more human resources and have companies trained in this area. The government, companies and universities have an important role,” he said in an interview with The Day.

Although different reports from cybersecurity companies place Mexico among the countries with the most cyber attacks in Latin America, the National Cyber ​​Security Index (NCSI) places the country below Chile, Uruguay, Brazil and Argentina, in terms of institutional preparation to face these risks.

Furthermore, the NCSI index, which evaluates countries’ capabilities to prevent and respond to these incidents, reveals that Mexico has a negative difference between its level of digital development and its cybersecurity capabilities, indicating that the latter have not advanced at the same pace.

Aldeco Pérez considers that one of the biggest gaps facing the country is the training of specialists: “Of all the public universities we have in the country, only seven offer a specialty or a set of specialized subjects for cybersecurity, which is insufficient to cover the demands.”

He explained that the shortage of specialists causes the majority of graduates to be hired by large companies, while small and medium-sized companies are left without these personnel. “As there are very few personnel with this specialty, salaries in that area are very high and few can pay it. Large companies can hire them, but SMEs are left unprotected.”

The specialist also emphasized the lack of cybersecurity culture that predominates in the productive sector. “Many companies think they don’t need this, but anyone who uses a server for their website should have a computer security expert.”

He added that in both the public and private sectors the idea persists that, after the development of a digital system, updates are no longer required; although potential threats evolve continuously.

Database theft

He explained that the phishing It usually relies on databases previously stolen from financial institutions, companies or public agencies, and it is this information that allows criminals to personalize deceptions and increase the likelihood that victims will reveal confidential data.

“How does he know my address or the state I live in? Probably because they stole that database from the bank, and now he gives you that information so that you can give him others that don’t have it,” he said.

Aldeco Pérez stressed that in recent years the theft of databases in Mexico has skyrocketed, “we are talking about banks, private companies but also cases in which the government itself has been violated by these attacks.”

He mentioned that this is even the main reason why many citizens refuse to let the authorities have their biometric information. “There is a refusal to participate in these registries because we know that these databases can be stolen.”

The specialist pointed out that the recent incident in which an OpenAI artificial intelligence agent interacted in an unexpected way with the Hugging Face platform, which occurred in mid-July, shows that this type of attacks could become increasingly frequent, faster and difficult to detect.

He explained that AI agents automate processes that previously required hours or days of work by specialized personnel, which accelerates the detection of vulnerabilities and their exploitation for malicious purposes. “When a generative AI agent does it, it happens much faster than when it is done by a group of people, because they have very large processing power and a huge infrastructure.”

The OpenAI incident, he added, generated alert among the computing community, given the possibility that this type of incident could be replicated in other environments, without the capabilities to confront them.

For Mexico, Aldeco Pérez insisted that the response should not be alarmism but rather foresight: “Rather than alarming us, it should increase its cybersecurity culture.”

By Editor