started · updated
Latvian Ministry of Transport finds cybersecurity failures at CSDD
An investigation by a commission from the Latvian Ministry of Transport has identified multiple cybersecurity failures at the Road Safety Directorate (CSDD) that facilitated a recent data breach. The findings indicate that the incident was made possible by vulnerabilities in the “med. csdd. lv” web application, which allowed attackers initial access to information systems.
The commission cited several technical and organizational deficiencies, including incomplete security audits, insufficient network protection, a lack of multi-factor authentication, and flaws in software development. Minister Rihards Kozlovskis noted that these errors and instances of inaction prevented the full mitigation of cyberattack risks.
While the commission focused on technical vulnerabilities and recommendations for strengthening cybersecurity, the assessment of official responsibility has been referred to law enforcement agencies. Legal experts have emphasized that the incident raises broader questions regarding data protection regulations and the necessity of sanctions to ensure legal compliance and accountability.
Entities
Ministry of Transport · Rihards Kozlovskis · Road Safety Directorate