Thursday, 1 October 2026
Rīga TV

World and Latvian news in one place

EconomyPublished: 1 October 2026 at 09:21

Who really owns cybersecurity in an organization? Experts say responsibility must be shared

Experts note that under Latvia's National Cybersecurity Law, an organization's top executive bears ultimate responsibility for cybersecurity governance, though effective protection only works when accountability is spread across every level.

Foto: Dienas Bizness

Cyberspace is increasingly becoming an arena for geopolitical rivalry and hybrid warfare, with tensions such as Russia's war in Ukraine directly shaping the intensity and methods of cyberattacks, including those affecting Latvia. Cybersecurity is no longer a theoretical risk limited to large international corporations — it is a daily reality for both public and private sector organizations.

Executive responsibility cannot be delegated

Article 25 of Latvia's National Cybersecurity Law states that an organization's leader is responsible for ensuring cybersecurity governance, though the leader may appoint a cybersecurity manager to carry out specific measures. However, the underlying responsibility for governance itself cannot be handed off — much as financial risk cannot be treated as solely the accountant's concern.

Resources and leadership engagement are essential

A cybersecurity manager's legally defined duties include organizing IT infrastructure security measures, conducting security audits, addressing identified shortcomings, and ensuring regular staff training on cyber risks. Carrying out these duties requires resources and prioritization, which depend on leadership decisions. If management repeatedly delays investment despite warnings about critical vulnerabilities, that becomes a business risk created by leadership itself. The EU's NIS2 directive reinforces this by requiring organizational leadership to approve and oversee cybersecurity risk management measures, placing the issue alongside financial and legal matters on the leadership agenda.

Shared responsibility across all levels

At the same time, responsibility cannot rest solely with leadership — in practice, security works only when accountability is distributed across the whole organization. Leadership sets priorities and allocates resources, IT and security specialists implement technical solutions, and every employee is responsible for their own behavior in the digital environment. Even a technically well-protected organization can be compromised by a single convincing phishing email or a weak password.

This makes regular, meaningful employee training essential, along with a culture where staff feel safe reporting mistakes without fear. Since absolute security is unattainable, an organization's maturity should be measured not by how many security technologies it has purchased, but by its ability to detect incidents quickly and restore operations without delay.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category