Cybersecurity

Information and communication technologies (ICT) have gradually permeated every sphere of society, government and economy. Their malicious use, damaging, blocking or even destruction may threaten national security and public safety, undermine public order and economic systems, and even stunt the growth of national economy. Cyberspace may easily be used to target individuals, social groups or even whole states. Safe and secure cyberspace requires users to know and respect basic cybersecurity principles. Mitigation and reduction of cyber threats and risks in Latvia depends on shared understanding and well-coordinated cybersecurity policy supported by all relevant stakeholders representing industry, government and non-governmental actors.

Comprehensive National Defence is a framework that provides clear directions to government institutions, non-governmental actors, private sector companies and general population on how to act in case of crisis. As an element of Comprehensive National Defence framework, cybersecurity has recently become especially instrumental, requiring stakeholders to improve cybersecurity governance models, deepen international cooperation and increase focus on public awareness raising efforts.

Ministry of Defence is formally responsible for formulating and delivering national cybersecurity policy. However, national cybersecurity governance model is a collaborative framework where each government institution is delegated specific responsibilities, including cybersecurity tasks, which it fulfils in conjunction with other government bodies, private sector companies or common cooperation platforms of National Information Technology Security Council. Ministry of Defence supports the work of National Information Technology Security Council and Supervisory Committee of Digital Security.

National Cyber Security Centre

The National Cyber Security Centre acts as a single point of contact for cyber security matters, oversees the implementation of national cyber security requirements, and develops national cyber security policy initiatives. The centre’s functions are carried out by the Ministry of Defence in cooperation with CERT.LV, a unit of the Institute of Mathematics and Computer Science at the University of Latvia. The supervisory authority for critical information and communication technology infrastructure is the Constitutional Protection Bureau. The supervisory authorities are authorised to carry out inspections of entities’ documents and information and communications technology infrastructure and, where necessary, to require corrective measures to be taken to remedy any identified shortcomings, to issue a warning, suspend the operation of services until non-compliance is rectified, or impose sanctions.

The National Cyber Security Centre’s website, cyber.gov.lv, provides information regarding the services of the centre, the NCC-LV (Latvian Cyber Security Coordination Centre), the NIS2 Directive and minimum cyber security requirements, guidelines and recommendations for preparing cyber security management documentation, as well as other useful resources.

National Cyber Security Law

On 20 June 2024, the Parliament adopted the National Cyber Security Law. Its aim is to strengthen cybersecurity in Latvia and to implement the requirements of the revised Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive), which aims to achieve a uniformly high level of cybersecurity across the European Union.

The law applies to providers of essential and important services, as well as critical infrastructure of information and communication technology. Article 20 and 21 of the law sets out criteria for defining whether a public or private sector organisation belongs to one of these groups.  

Public and private sector organisations to which the law applies, must:

  • identify their status and register by 1 April 2025;

  • appoint a cybersecurity manager by 1 October 2025;

  • submit the first self-assessment report by 1 October 2025.

Providers of essential and important services in the public and private sectors will also be required to provide regular cybersecurity self-assessments, mandatory reporting of detected cyber threats, risk management and business continuity plans and adhere to other cybersecurity requirements.

The law entered into force on 1 September 2024. The Ministry of Defence organized information seminars for organisations representing the sectors to which the requirements of the law apply.