Cyberattack on a Company: What to Pay Attention to Before the "Bill" Arrives

The summer of 2026 changed the phrasing of the question for Latvian entrepreneurs. In June, a foreign, financially motivated ransomware group using the pseudonym "Bytetobreach" breached the systems of AS "Latvijas valsts meži", obtained corporate data, and gradually published part of it. While analyzing this incident, CERT.LV established that the same attacker had also compromised a server belonging to the pharmaceutical company AS "Olpha" in a separate incident. Both incidents were technically unrelated and occurred independently of each other.

In August, CSDD (Road Safety Directorate) was subjected to a targeted cyberattack which, according to CERT.LV's assessment, involved prior preparation. Upon analyzing the incident, it was determined that between August 8 and August 10, the attacker obtained payment receipt data dating back to 2008. CSDD indicated that data belonging to 1.2 million individuals and 200 thousand legal entities was affected.

This means the question is no longer whether a company will be attacked. The question is who will pay the bill for downtime, recovery, and lost customer trust.

Statistics also show that the cybersecurity threat level remains high. In the second quarter of 2026, CERT.LV registered 673 manually processed cyber incidents—20 percent fewer than in the previous quarter—and identified 396,444 compromised devices. CERT.LV assesses that the cybersecurity threat level in Latvia remains high and that cyber threat intensity is increasing in the long term.

It should be noted that publicly known incidents do not reflect the full picture. Companies have specific reporting obligations, but this does not mean that the public is informed about every incident. In practice, incidents involving state-owned enterprises and public institutions enter the public eye more frequently, whereas many private-sector incidents may never appear in the public domain. Therefore, the lack of comparable public cases does not, in itself, indicate low risk.

Below, Viesturs Briežkalns, Partner at BDO Latvia, outlines five key areas deserving special attention, as these are precisely where cyber risk transitions from an IT issue into a management and financial issue.

1. The Cost of Downtime – When an IT Issue Becomes a Business Loss

Until a company knows what a day, a week, or a month without critical systems would cost, cybersecurity risk remains difficult to compare with other items on the board's agenda. A technical vulnerability is hard to translate into business language, whereas downtime costs can be calculated in monetary terms.

Furthermore, downtime costs do not consist solely of lost or deferred revenue. They must include employee costs during periods when work cannot be fully performed, overtime after operations are restored, crisis-mode outsourcing expenses, urgent procurements and deliveries, as well as potential contractual penalties. The longer a company is unable to restore critical processes, the broader the scope of losses becomes.

System recovery, on the other hand, is not always a matter of a few days. The LVM GEO mobile app was one of the systems completely disconnected from LVM's IT infrastructure on the morning of June 22. Its functionality was partially restored on July 9, and fully restored on July 27. According to public media reports, nearly all of the company's systems were restored approximately two months after the incident. The total costs of the incident have not been publicly disclosed, but the duration of the recovery itself illustrates why a company must evaluate such a scenario before a crisis occurs, rather than during one.

Sophos's 2026 study also illustrates the potential scale of costs. The survey included 2,158 IT and cybersecurity leaders, C-level executives, and other decision-makers from 17 countries whose organizations had experienced a ransomware attack within the preceding 12 months. The average recovery cost reached 1.7 million USD. While this should not be considered a typical cost level for a Latvian enterprise, it demonstrates how substantial incident response and business recovery costs can become.

Cyber risk insurance can mitigate part of this financial risk, but it does not replace a company's own readiness. Policy coverage, liability limits, and exclusions vary, and not all incident-related costs will be insured. Therefore, what matters is not simply the fact that a company holds cyber risk insurance, but an understanding of what that specific policy does and does not cover.

2. Data Leaks – When Systems Are Back Up, but Problems Persist

Downtime accounts for only a portion of incident costs. The financial and reputational impact of a data breach can persist long after system functionality is restored.

In the case of CSDD, daily service provision was not disrupted, and customer usernames and passwords were not compromised. However, personal identification numbers or company registration numbers, full names or business names, payment amounts and dates, vehicle license plate numbers, and registered addresses on the day of service were acquired by the attackers.

Varis Teivāns, Deputy Director of CERT.LV, pointed out that one of the most significant risks associated with data leaks is the use of the stolen information in subsequent social engineering attacks. In practice, this means the company's customers may face plausible scam attempts using details about their identity or past transactions for a long time to come.

This is not uniquely a Latvian or public-sector issue. On August 27, Manchester Airports Group announced a cyber incident in which an unauthorized third party acquired customer data related to parking, lounge, and Fast Track bookings, as well as airport Wi-Fi registrations. The company notified approximately 8.7 million affected customers. The acquired data included email addresses, phone numbers, vehicle registration numbers, and postal codes. Banking and payment details were not compromised, and airport operations were not disrupted.

For a company, the costs of a data breach do not end once the incident itself is resolved. Afterward, it may be necessary to notify affected individuals, manage ongoing communication and customer support, cooperate with the Data State Inspectorate (DVI) or other regulatory authorities, and invest in restoring reputation. Meanwhile, the risk of leaked data being misused can remain long after IT systems have been fully restored.

3. IT Outsourcing and the Supply Chain – Liability Is Defined by Contract

A company's cybersecurity depends not only on its own measures, but also on its suppliers and service providers. In July, "Lidl" informed customers in Germany, Belgium, and the Netherlands of a data breach after attackers accessed a file containing Lidl online store customer data stored on an external service provider's system. The incident occurred at the service provider, but Lidl had to communicate the consequences to its customers.

This is precisely why trusting an IT service provider is not enough on its own. Contracts often cap liability at a few months' worth of service fees, while service level agreements (SLAs) define response times rather than the time frame within which critical systems must be restored. Responsibility for verifying backups and the ability to restore systems from them is also not always clearly defined.

These nuances become critical at the moment an incident strikes. If a company's actual losses significantly exceed the vendor's contractual liability limit, the company will have to cover the difference itself. Therefore, the question of who pays for what in a cyber incident should be answered when signing the contract, not after the breach.

4. Regulation – In an Incident, Timing Is Critical

A cyber incident can cause operational disruptions and financial losses for a company, as well as specific obligations toward regulatory authorities. Article 34 of the National Cybersecurity Law requires an early warning immediately, but no later than 24 hours after becoming aware of a significant cyber incident, and an initial notification immediately, but no later than 72 hours. For trust service providers, the deadline for the initial notification is 24 hours. A final report must be submitted within one month of the initial notification.

This means that during an incident, a technical response plan alone is insufficient. It must also be clear who evaluates reporting obligations, who makes the necessary decisions, and who ensures communication with the relevant authorities. If personal data has been leaked, parallel obligations under data protection regulations may also arise.

Even for companies that do not fall directly within the scope of the National Cybersecurity Law, cybersecurity requirements can become a practical business condition—for example, in customer procurement processes or supply chain requirements. Compliance is therefore not just a matter of statutory obligations, but also of what customers and business partners expect from the organization.

5. Governance and Board Responsibility – Cybersecurity Can Be Delegated; Accountability Cannot

Article 169 of the Commercial Law requires members of executive and supervisory boards to perform their duties with the care of an honest and prudent manager. In a cybersecurity context, this does not mean the board must master technical details. However, the board must ensure that key risks are identified, responsibility for their management is assigned, and received warnings are acted upon.

In the LVM incident, this governance aspect warrants particular attention. Latvian Television's investigative program "De facto" reported that the attacker had entered LVM's internal system as early as June 11, with the active attack phase starting on June 22. It was also publicly disclosed that CERT.LV had informed the company about the exploited vulnerability approximately two years prior; however, the information was misunderstood within the organization, and the vulnerability was not remediated.

The key question here is not who opened a specific email, but whether an organizational process existed to ensure that such warnings were evaluated, routed to the responsible individual, and subsequently verified to confirm that necessary actions were taken.

The CSDD incident brought this question into even sharper focus. On August 19, following the cyberattack, the CSDD supervisory board resigned, and later that day, the executive board also stepped down. Multiple authorities—including the Prosecutor General's Office and the Data State Inspectorate—began evaluating the circumstances of the breach and official conduct, while the Minister of Transport initiated an administrative inquiry evaluating contracts with the cybersecurity service provider. This demonstrates that following a cyber incident, management decisions and legal accountability may be scrutinized alongside technical failures.

Cybersecurity today is no longer just a technical issue. It is a matter of business continuity, financial risk, and leadership accountability. The costs of preventive measures can be predicted and budgeted, whereas losses resulting from a cyber incident are far more difficult to forecast.

Therefore, the answer to the question posed at the beginning is simple in most cases: the majority of costs resulting from a cyber incident are borne by the company itself. Insurance and vendor contracts can mitigate or redistribute part of the risk, but the company itself must be prepared to act when a cyber incident occurs.

Viesturs Briežkalns
Partner at BDO Latvia