The Ministry of Defense of Latvia has prepared amendments to the National Cybersecurity Law, which aim to legalize the activities of so-called good-faith security researchers — specialists and enthusiasts who identify vulnerabilities in information systems. Currently, such activities are often perceived as attempts to hack or other offenses, even if the goal is to enhance security. The new amendments are intended to eliminate this legal uncertainty. The bill stipulates that a researcher will be able to access data from an information system or network only to the extent necessary to detect and verify a vulnerability. At the same time, they will be prohibited from taking actions that could disrupt the system's operation, lead to data leakage, or create a threat to its security. In fact, this is about creating a legal framework for the work of so-called 'white hackers' — specialists who help identify weaknesses before they can be exploited by malicious actors. At the same time, the document introduces obligations for organizations. If the owner of an information system receives a notification about a discovered vulnerability, they will be required to notify the competent authority for preventing cyber incidents and take measures to address the issue. The Ministry of Defense notes that the lack of clear rules currently hinders cooperation between researchers and organizations. Some specialists prefer not to report discovered flaws at all, fearing that their actions will be perceived as illegal. Furthermore, organizations are currently not obliged to consider reports of vulnerabilities if they come directly from the researcher, rather than through Cert.lv. As a result, important information may go unnoticed, creating additional risks for cybersecurity. The amendments are open for public discussion until the end of August. The proposed changes come a few months after the high-profile case of inventor Raimonds Skuruls. He discovered a vulnerability in the CSDD IT system, reported it, and requested a payment of 1,000 euros for the check he conducted. The court classified his actions as extortion and imposed a fine of 4,290 euros. Skuruls has appealed the verdict to the Supreme Court. A decision on whether to accept his cassation appeal for consideration has not yet been made.