CiberLATAMbywhalemate

BCRA, Banxico and CNBV tighten digital controls

Argentina set a one-hour alert for critical cyber incidents. In Mexico, Banxico boosted security spending and CNBV focused on preventive controls.

Whalemate Labs · AI-assisted researchPublished:2 min read

Argentina's central bank, through Communication A 8280/2025, ordered financial institutions, payment service providers registered with the BCRA and systemic payment infrastructures to report critical and important cyber incidents within one hour. In Mexico, Banxico said it spent more than 1 billion pesos on cybersecurity, while the CNBV focused on preventive controls for Sofipos.

The BCRA's Communication A 8280/2025 requires financial institutions, payment service providers registered with the central bank, and systemic payment infrastructures to file an initial notice within one hour after critical or important cyber incidents. The rule raises the reporting bar for key players in Argentina's payments system and adds to other operational risk management requirements.

Who does the BCRA requirement apply to?

The obligation applies to financial institutions, payment service providers registered with the BCRA, and systemic payment infrastructures. The reference includes operators of payment services and components considered systemic within that ecosystem, according to Communication A 8280/2025 cited by a specialized source.

What must be reported, and within what deadline?

The text cited by Siberson sets an initial one-hour notification window for critical and important cyber incidents. The key point is not just whether an event occurred, but how quickly it must be reported to the regulator, with little room for internal delays.

What is Mexico doing in parallel?

Banxico allocated more than 1 billion Mexican pesos to cybersecurity, according to El CEO. Between 2022 and 2024, it also set aside 15.6 million pesos to implement policies and regulatory guidelines for supervised entities, in an agenda that combines direct investment with rules for the financial system.

What did the CNBV ask of Sofipos?

The CNBV said its priorities for popular financial institutions are to strengthen preventive controls and preserve the integrity, traceability, and transparency of operations. The guidance comes as these institutions expand digitally, with the supervisor seeking to ensure that growth is matched by stronger operational and control resilience.

What do these measures show together?

Argentina and Mexico are moving in the same regulatory direction, with more pressure on early reporting, internal controls, and response capacity after incidents. In Argentina, the emphasis is on fast notification. In Mexico, the approach combines budget investment with control requirements for digital financial entities.

Sources

View all