Latvijas kiberdrošības un CERT.LV tehnisko aktivitāšu 2025. gada pārskats

The report aims to provide Latvian cybersecurity managers and specialists with operationally applicable information, and analysts with a compilation of events from the past year in the cyber environment of Latvia and the Northern Europe region, as well as forecasts for the development of the cybersecurity situation in the near future. Achieving these goals involves implementing and ensuring a comprehensive set of CERT.LV services and support mechanisms, which are available to recipients free of charge. By deploying CERT.LV services for national cybersecurity entities, response times to complex cyber incidents have been reduced from 6 months to 1 day or even closer to real-time threat mitigation. Although the rules of the game are never entirely equal—attackers need only one vulnerability, while infrastructure defenders must identify and fix all possible weaknesses—it must be acknowledged that defenders also have access to the same information, tools, and opportunities to implement protective measures. Before deploying new technological solutions, automation, or artificial intelligence, a clear understanding of existing information resources, computer systems, users, access rights, data flows, and software within the organization is necessary. The results of the CERT.LV SOC service include a report on Security Operations Center (SOC) services, which centrally collect security telemetry from client infrastructure and correlate events with the threat indicators and knowledge base available to CERT.LV.

This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.

Read original source