Latvia seeks to address long-standing cybersecurity issues

The government plans to review the distribution of European Union funds, centralise software procurement and pool limited human resources in centres of expertise to strengthen the security of Latvia’s information and communications technology infrastructure, LSM reports.

The Cabinet discussed on Thursday whether ministries and their institutions comply with the requirements of the Cybersecurity Law and considered further steps to improve the situation.

Long-standing cybersecurity issues remain unresolved

Krists Avots, parliamentary secretary to the prime minister, said after the meeting that he could not disclose which ministries were performing better or worse in implementing the requirements because the information is restricted.

He said, however, that all institutions shared the problem of many cybersecurity issues having remained unresolved for years.

“It is clear that ministries have very different-sized operations. It is no secret that some ministries have very large operations. Where operations are large, the challenges are greater; where they are smaller, it is easier to manage,” Avots said.

“We cannot afford to forget about cybersecurity as an issue until the day a crisis occurs. Today, a number of institutions openly pointed out where the risks are and where immediate action is needed so that a story like the one involving Latvijas Valsts meži is not repeated. It is therefore important that specific decisions are made through an open discussion on how to fix this and move forward,” he said.

EU funding and human resources to be reviewed

The Ministry of Smart Administration and Regional Development has been tasked with coordinating the joint procurement of software licences for all state institutions. EU funding is also expected to be redistributed to areas where shortcomings have been identified.

Avots said the financing model for the state federated cloud, which has historically been funded through European funds, would also need to be reviewed and made more sustainable so that its servers could always be new and updated.

He also said attention was being paid to human resources, noting that cybersecurity requires specialised skills.

Source 
(via LSM)