The cyberattack on Latvia’s Road Traffic Safety Directorate (CSDD) and the leak of data belonging to 1.2 million residents show that Latvia is largely prepared for various crises only “on paper”. In fact, the situation is even worse – a security vulnerability in CSDD’s IT system could have been fixed several years ago, but instead CSDD took the person who discovered it to court. As a result, Latvia is where it is today, with its preparedness for crises and military threats rated at just four out of ten. BNN asked political scientist and co-owner of Mediju tilts Filips Rajevskis what needs to be done to prevent such situations in the future.
“Crisis preparedness begins with the way we approach very basic things, from shelters to procedures for what to do if a drone is approaching,” Rajevskis says. “Let’s be realistic – a drone is not the fastest thing that can come flying at us. Missiles can also arrive, including ballistic missiles, which travel much faster and can cause considerably greater damage. Crisis preparedness also depends heavily on how we approach other issues. And in the CSDD case, we can see quite clearly the attitude towards our data, which is vitally important. If an enemy uses this data, it can obtain an enormous amount of information about the people who live here, their daily routines and their lives.”
Rajevskis stresses that it is precisely this attitude towards matters of critical importance to national security that also affects assessments of Latvia’s preparedness for crises and military threats.
“We saw that, in the initial stage of the CSDD crisis, the management board, which later resigned, approached the situation with an attitude along the lines of: what’s the big deal? From publicly available information, we can see that they had previously dismissed warnings that the data was not sufficiently protected and that there were risks. If I am not mistaken, this may be the first time in Latvia’s history that the President has turned to the Prosecutor’s Office over the actions of the CSDD management board. I do not recall presidents filing such complaints with prosecutors in other cases. It shows the outrage of both the President and the Prime Minister following the closed Cabinet meeting, when it was said that they were being lied to their faces. This shows that we do not even need an external enemy – internal actors who negligently handle data that is, in reality, an extremely important resource and must be protected are enough.
This can affect Latvia’s defence capabilities and security.”
Responding to BNN’s observation that it is currently difficult to predict the consequences of the leak involving data on 1.2 million individuals and 200,000 legal entities, Rajevskis says: “If we exclude babies and children who have not yet reached the age at which they receive their first identity documents, then practically everyone else was in there. A very large number of people have a driving licence or some other connection with CSDD.”
Asked to what extent the case highlights questions about the usefulness of various supervisory and management boards, the political scientist says that before discussing their usefulness, it is important to focus on these people’s attitude towards their work and the responsibilities entrusted to them.
“In this case, the CSDD management board was responsible for the data placed in its care. That is directly their responsibility.”
Asked to comment on the case of inventor Raimonds Skuruls, who warned CSDD several years ago about a security vulnerability and, instead of being thanked, was taken to court on extortion charges, Rajevskis says the issue once again comes down to attitude.
“Perhaps it is also connected to the high salaries –
people become so detached from society and so arrogant that they ignore warning signs.
The question now is who will cover the losses. They are enormous. This is not simply a case of data going missing somewhere. The data leak will also result in financial losses. Who will pay for them – the taxpayers? And this brings us back to the responsibility of the management board. The high salaries paid to board members are justified on the grounds that board members are accountable for their actions. This is one of those moments when accountability should actually work, considering the large salaries these people have received for years.”
Asked whether such accountability will actually work, or whether instead there will be cries that “democracy is under threat” because officials are being asked to cover the losses, Rajevskis responds:
“Democracy really is under threat. A great many people use e-CSDD, and the data includes people’s addresses as well as their official electronic addresses. This information can be used to manipulate society and, consequently, democracy itself.”
Finally, asked whether the case will serve as a sufficiently powerful lesson for other state institutions to start paying greater attention to data security, Rajevskis says:
“Seeing the enormous arrogance displayed by the CSDD management board in the early stages, I am going to be pessimistic.”
Read also: Data of 1.2 million people leaked in CSDD cyberattack in Latvia – including personal ID numbers and addresses
Read also: BNN IN FOCUS | airBaltic’s dilemmas and the difficult decisions facing the state
