Latvia PM Demands Answers on Refusal of Early Warning Cyber Sensors After CSDD Attack
Translated from Latvian, summarized and contextualized by DistantNews.
At a glance
- Latvian Prime Minister Andris Kulbergs will demand an explanation from "Cert.lv" on which institutions have refused to implement early warning sensor systems.
- The Road Traffic Safety Directorate (CSDD) is criticized for refusing the system, which could have prevented a recent cyberattack that compromised 1.2 million people's data.
- New cybersecurity measures are being implemented, including mandatory system audits and the strengthening of the National Cybersecurity Center.
Latvian Prime Minister Andris Kulbergs announced that the information technology security incident prevention institution "Cert.lv" must inform the Cabinet of Ministers this week about which institutions have "arrogantly" refused to implement its early warning sensor system. Kulbergs specifically cited the Road Traffic Safety Directorate (CSDD) as an example, stating that implementing such a system could have identified and possibly prevented the recent attack.
"We see where it led," Kulbergs told reporters after a meeting with the President. However, CSDD board chairman Aivars Aksenoks, who announced his resignation, denied that the directorate had refused the system. He claimed the management was never officially informed and only correspondence between two employees occurred. "I am very sorry that this contract was not offered to us in a normal administrative manner. We would never have refused it," Aksenoks stated, adding that the contract is now being sent to "Cert.lv" for signature.
In response to the cyberattack on CSDD, which compromised personal data of 1.2 million individuals and approximately 200,000 legal entities, "Cert.lv" and the State Security Department (SAB) are tasked with identifying critical infrastructure systems requiring the early warning sensor system. The Ministry of Defense will amend regulations to make cybersecurity solutions mandatory for critical systems. All ministries must also conduct IT system audits, including penetration tests, for their subordinate institutions and companies.
Further measures include ensuring the National Cybersecurity Center operates 24/7 and increasing budget places for cybersecurity studies. The Data State Inspectorate will report on the CSDD data breach assessment by August 31, 2026. Additionally, the National Cybersecurity Center and SAB must submit an evaluation of CSDD's cyber risk management and cybersecurity measures to the Prime Minister by the same date, along with proposals for improvements.
Originally published by Delfi Latvia in Latvian. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.