Latvia proposes legal framework for 'white hat' hackers in critical infrastructure
Latvia's Defence Ministry has opened for public consultation draft amendments to the National Cybersecurity Law that would give ethical hackers a legal basis for finding and reporting vulnerabilities in critical infrastructure. Feedback is accepted until 28 August.
The Defence Ministry has prepared amendments to the National Cybersecurity Law introducing a legal framework for good-faith security researchers, known as 'white hat hackers', to participate in coordinated vulnerability disclosure in critical infrastructure. The draft has been submitted for public consultation, and anyone – particularly security researchers, cyber enthusiasts and entities covered by the law – can comment until 28 August on the official draft legislation portal.
Latvia has had a vulnerability reporting platform run by CERT.LV since 2023, but only 20 organisations have published testing programmes on it. According to the ministry's impact assessment, this shows that the coordinated disclosure process is still immature and trust in ethical hackers is low. Without clear legal rules, reports about vulnerabilities are often treated as attacks or offences, discouraging researchers from coming forward.
The draft law would generally allow access to an organisation's information systems and electronic communications networks for the purpose of finding vulnerabilities, but only to the extent necessary. Researchers would have to follow basic principles: avoid placing a disproportionate burden on systems, refrain from denial-of-service, social engineering and password-guessing attacks, and not compromise data confidentiality, integrity, availability or business continuity. Once enough information has been gathered to report the vulnerability, the researcher must stop.
The annotation stresses that if these principles are followed, the access would not be considered unauthorised and the person would not face criminal liability under Article 241 of the Criminal Law. The amendments also clarify that organisations may receive vulnerability reports directly from researchers, but in that case they must notify the competent cyber incident response institution and take steps to address the issue. Under current rules, a vulnerability must be reported no later than five working days after it is discovered.


