How companies should respond when a cybersecurity incident occurs
An expert outlines what qualifies as a cybersecurity incident and the steps companies should take after detecting one, including reporting duties to authorities. Fast, planned action can significantly limit the damage.

Cyberattacks now affect companies of every size and sector, and advances in artificial intelligence combined with social engineering tactics are making these attacks more complex and harder to detect. Many organizations remain unaware for a long time that their systems have already been breached.
A cybersecurity incident is any event that threatens the availability, integrity or confidentiality of data or services. The most common types include ransomware attacks, where criminals encrypt data and demand payment for decryption; phishing attempts using fake emails to trick employees into revealing information; theft and publication of customer data; disruption of website operations; and supply-chain attacks, where a compromised IT service provider gives attackers access to its clients' systems.
First steps after detection
Speed is critical, since the first hours after discovery largely determine the scale of the consequences. Once an incident is identified, company management must be notified immediately, affected systems isolated to stop further spread, and the damage assessed with every action documented. Next, a crisis management plan should be prepared, relevant authorities notified where required by law, and outside support brought in, such as IT specialists, cybersecurity experts or lawyers.
To carry out these steps without delay, companies are advised to have an incident management plan in place beforehand, so staff already know where to turn. This reduces both financial losses and potential penalties.
Reporting deadlines
Companies covered by Latvia's National Cybersecurity Law must notify CERT.LV: an early warning within 24 hours, an initial report within 72 hours, and a final report within one month of discovery. If personal data is affected and there is risk to individuals' rights, the Data State Inspectorate must also be notified within 72 hours, and in high-risk cases the affected individuals themselves must be informed. Even when reporting is not mandatory, companies are advised to document all incidents to demonstrate compliance if needed.

