Expert: crisis resilience must be built by the state, businesses and every resident alike
Following August's storm and several cybersecurity incidents in Latvia, an industry expert argues that societal resilience in crises is a shared responsibility of the state, institutions and residents, taking different forms depending on the type of crisis. She notes that physical and digital crises demand different kinds of preparedness.

This year's August storm, the strongest since 2005, along with several cybersecurity incidents — including at Latvia's State Forests, the Road Traffic Safety Directorate, and Lithuania's State Register Centre, where around 600,000 records of real estate and legal entities were compromised — have raised questions about society's readiness for crises, writes Citadele representative Rūta Ežerskiene in an opinion piece for Delfi.
She stresses that resilience is a shared responsibility, resting on the ability of the state, businesses and residents to function as a connected system, though how responsibility is divided depends on the type of crisis. During the storm, the financial sector demonstrated strong resilience — customers were able to make payments without interruption, as bank data centres and payment systems were unaffected, while Latvia's network of critical ATMs, which receive priority support during crises, continued operating.
Physical versus digital threats
Unlike a storm, for which people generally know how to prepare, cyber incidents leave individuals largely powerless once they become public, since key decisions have already been made beforehand. As a result, a greater share of responsibility falls on institutions, which must continuously test their systems, strengthen security and cooperate with partners and government bodies.
Three levels of resilience
The author highlights that resilience should be assessed at the state, institutional and household levels. Latvia was among the first EU states to transpose the NIS2 directive's requirements into national law, yet recent incidents showed that regulation alone does not guarantee security — enforcing existing requirements matters more. At the institutional level, resilience is described as an ongoing process; this year, for example, Citadele worked with CIREN experts to test its business continuity plans under various stress scenarios.
At the household level, preparedness varies widely — readiness for a storm can often be achieved with simple practical steps, while cyber threats require constant vigilance, and households also differ significantly in the financial reserves they hold for unexpected events.
The author concludes that because critical infrastructure is interconnected, society's resilience is only as strong as its weakest link, and urges everyone to regularly assess their own readiness for the first 72 hours of a crisis.


