The Latvian Ministry of Defence has drafted amendments that would provide a legal framework allowing “good-faith security researchers and cybersecurity enthusiasts” to access information and communication technology resources for the purpose of identifying vulnerabilities.
The draft legislation includes a general authorisation for individuals to access data contained in an entity’s information system or electronic communications network for the purpose of identifying vulnerabilities in that system or network. At the same time, it establishes proportionate restrictions and basic principles to ensure that vulnerability research does not place an excessive burden on organisations or threaten their interests or security.
For the purposes of the law, the term “entity” refers to providers of essential services, providers of important services, and owners and lawful operators of critical information and communication technology infrastructure.
Under the proposed amendments, a person would be permitted to access data in an entity’s information system or electronic communications network only to the extent necessary to identify a vulnerability. They would be allowed to carry out only those activities necessary to identify, verify and report vulnerabilities, provided that such activities do not impose a disproportionate burden on the entity’s information system or electronic communications network.
The activities must also not compromise the security of the information system or electronic communications network, the confidentiality, integrity or availability of data, or the continuity of the entity’s operations.
If an entity receives information from a person about a vulnerability identified in its information system or electronic communications network, it would be required to notify the competent cybersecurity incident prevention authority and take the necessary steps to address the vulnerability.
The Ministry of Defence notes that, due to the absence of a clear regulatory framework, reports of discovered vulnerabilities are often perceived as attacks or unlawful activity, leading to conflicts between security researchers and organisations.
According to the ministry, this practice weakens cybersecurity because it discourages good-faith researchers from participating in coordinated vulnerability disclosure.
A person acting in good faith who discovers a vulnerability may choose not to report it out of concern that the organisation could view the report negatively – as a threat or a violation of the law. At the same time, there is currently no regulation requiring organisations to accept and appropriately handle vulnerability reports received directly from individuals rather than centrally through CERT.LV. As a result, such reports may be ignored in practice, potentially creating security risks, the ministry said.
The proposed amendments to Latvia’s National Cyber Security Law are currently open for public consultation until the end of August.
As previously reported, in February the Vidzeme Regional Court found inventor Raimonds Skuruls guilty after he discovered a security vulnerability in the IT system of Latvia’s Road Traffic Safety Directorate (CSDD), reported it and requested €1,000 for his contribution to testing the system. His actions, however, were deemed to constitute extortion.
The court fined Skuruls €4,290.
Skuruls filed an appeal on points of law against the ruling, but the Supreme Court has not yet decided whether to initiate cassation proceedings.
























































































































































































































































































































































































