After a series of cyber incidents affecting state and municipal institutions this summer, the issue of protecting state information systems has once again come to the forefront. According to CERT.LV specialist Gints Malkalnietis, the main problem lies not only in individual vulnerabilities but also in the large number of outdated IT systems. The expert noted that many weak points can be identified even before they are exploited by malicious actors. > "A large number of tests need to be conducted. This is neither quick nor very simple," emphasized Malkalnietis during the broadcast of the program "900 seconds" ([TV3](https://tv3.lv/zinas/latvija/cert-lv-eksperts-latvija-joprojam-ir-daudz-novecojusu-valsts-it-sistemu/)). ## Why systems remain vulnerable According to the specialist, a significant portion of state information systems was created as separate projects, but their maintenance has not received sufficient attention over time. > "For many years, maintenance was simply forgotten," he noted. Although the situation has gradually improved in recent years, the accumulated problems still pose additional risks to cybersecurity. ## What is known about the incident at PTAC Commenting on the recent incident at the Consumer Rights Protection Center (PTAC), Malkalnietis explained that the institution's management was aware of a specific vulnerability and decided not to stop the service's operation. > "By law, they had the option to decide to continue operations," said the expert. He emphasized that the correctness of this decision can only be assessed after a detailed analysis of what happened has been completed. At the same time, the specialist noted that institutions can consult with CERT.LV on cybersecurity issues, but the final decision is always made by the organization itself. ## Not a system hack, but a data leak According to Malkalnietis, in the case of PTAC, the attacker did not gain full control over the information system. > "He obtained data, but did not hack the system to the extent that he could fully operate within it," explained the expert. In other words, this is about information compromise, not complete system takeover. ## What protective measures are considered mandatory At CERT.LV, they believe that regular automated security checks should be the first line of defense. > "If a system can be hacked using an automated test, it should not be accessible on the public internet," emphasized Malkalnietis. He also reminded that for modern state services, basic requirements have already become two-factor authentication and other standard protection mechanisms. ## Interest in security has increased after a series of attacks According to the specialist, the recent high-profile incidents have prompted many state institutions to take cybersecurity more seriously. > "The recent incidents have made everyone step up their game," he admitted. More and more organizations are turning to CERT.LV for checks of their information systems and assessments of their resilience to potential attacks. However, quickly solving the accumulated problems over the years will not be possible. This requires time, funding, and specialists, of which, as acknowledged at CERT.LV, there are currently not enough in Latvia. > "We simply have a lot of work ahead to bring order to everything that has been created over many years," noted Malkalnietis. The expert emphasizes that cybersecurity cannot be viewed as a one-time modernization. It is a continuous process that requires regular investments, technology updates, and qualified support. The latest cyber incidents have shown that long-term maintenance of state IT systems is becoming just as important as their initial development.