Latvia’s Outdated IT Systems Elevate Cyberattack Risks

Following a wave of cyber incidents affecting state and municipal institutions this summer, Latvia’s state information systems face heightened security scrutiny due to widespread outdated technology, according to CERT.LV specialist Gints Malkalnietis. The cybersecurity challenges stem not only from isolated vulnerabilities but also from a large volume of aging IT infrastructure that has lacked adequate maintenance over the years.

Outdated Infrastructure and Forgotten Maintenance

A significant portion of state information systems in Latvia was originally built as separate projects, but long-term upkeep was frequently overlooked. According to Malkalnietis, “For many years, maintenance was simply forgotten,” leaving an accumulation of systemic issues that create ongoing cybersecurity risks. Although conditions have improved gradually in recent years, addressing these legacy problems requires extensive time, funding, and qualified specialists—resources that are currently in short supply across the country.

CERT.LV emphasizes that cybersecurity cannot be treated as a one-time modernization effort. Instead, it requires continuous investments, regular technology updates, and consistent support. Malkalnietis noted during a broadcast of the program “900 seconds” on TV3 that identifying weak spots before malicious actors exploit them demands a high volume of testing, which is neither quick nor simple.

Did You Know? CERT.LV specialist Gints Malkalnietis noted during a TV3 “900 seconds” broadcast that many state information system weak points can be identified through rigorous testing even before malicious actors manage to exploit them.

The Consumer Rights Protection Center Incident

Recent high-profile attacks have prompted state institutions to take digital security more seriously, leading to an increase in organizations requesting system checks and resilience assessments from CERT.LV. However, resolving accumulated technical debt will take considerable time. This reality was underscored by a recent security event at the Consumer Rights Protection Center (PTAC).

Commenting on the PTAC incident, Malkalnietis explained that the institution’s management was fully aware of a specific vulnerability and intentionally chose to keep the service operational. “By law, they had the option to decide to continue operations,” the expert stated, adding that the correctness of this decision can only be judged after a thorough, detailed analysis of the event concludes.

Malkalnietis clarified that while institutions can consult CERT.LV on cybersecurity matters, the final decision regarding operational status always rests with the organization itself. Furthermore, the PTAC event was classified as a data leak rather than a full system hack. The attacker obtained specific data but did not gain complete control or the ability to operate fully within the information system, resulting in information compromise rather than a total system takeover.

Mandatory Protections and Future Defenses

To prevent similar compromises, CERT.LV maintains that regular automated security checks must serve as the primary line of defense for public sector digital infrastructure. Malkalnietis emphasized that if any system can be successfully breached using an automated test, it should not remain accessible on the public internet.

Basic protective standards have also shifted for modern state services. Two-factor authentication and other standard protection mechanisms are now considered fundamental requirements across government networks. As state institutions continue to address years of neglected maintenance, long-term system upkeep is proving to be just as critical as initial software development.

Frequently Asked Questions

What is the main problem facing Latvia’s state information systems?
According to CERT.LV specialist Gints Malkalnietis, the primary issue is the large number of outdated IT systems whose maintenance was neglected for many years, compounded by a shortage of specialists and funding in Latvia.

Latvia's Outdated IT Systems Elevate Cyberattack Risks
Photo: en.bb.lv

Was the Consumer Rights Protection Center (PTAC) completely hacked?
No. Malkalnietis clarified that the attacker obtained data rather than gaining full control or the ability to operate within the information system, classifying the event as a data leak and information compromise rather than a total system takeover.

What mandatory protective measures does CERT.LV recommend?
CERT.LV advises that regular automated security checks should be the first line of defense, noting that systems vulnerable to automated tests should be taken off the public internet. Additionally, basic requirements now include two-factor authentication and standard protection mechanisms.

How will state institutions balance the demand for continuous public services with the urgent need to overhaul outdated IT infrastructure?

Leave a Comment