This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| CERT.LV | |
|---|---|
| Name | CERT.LV |
| Formation | 2006 |
| Type | Computer Emergency Response Team |
| Headquarters | Riga |
| Region served | Latvia |
| Parent organization | National Cyber Security Center (NCSC) |
CERT.LV
CERT.LV is the Latvian Computer Emergency Response Team established to coordinate cybersecurity incident handling, vulnerability disclosure, and resilience activities for information and communications infrastructure in Latvia. Operating from Riga, the team acts as a focal point for digital incident triage and stakeholder engagement, interacting with national institutions, private sector operators, and international partners. Its remit spans technical response, public advisories, capacity building, and contributions to national cyber policy debates, placing it at the intersection of operational cybersecurity and strategic digital resilience.
CERT.LV emerged amid a wave of national Computer Emergency Response Teams created after the widespread adoption of the internet in Europe, following models set by the Computer Emergency Response Team Coordination Center and the Réseaux IP Européens Network Coordination Centre. Its formal establishment in 2006 linked it with Latvia's efforts to modernize critical infrastructure protections during membership transitions with North Atlantic Treaty Organization and European Union accession processes. Early activities included cooperation with Estonian Defence Forces cyber units and knowledge exchange with the United States Computer Emergency Readiness Team and CERT-UK. After high-profile campaigns affecting Baltic states, including episodes associated with actor groups known from reports by NATO Cooperative Cyber Defence Centre of Excellence and analysis by European Union Agency for Cybersecurity, CERT.LV expanded operations, aligning with frameworks developed by Organisation for Economic Co-operation and Development and the Council of Europe.
CERT.LV's mission combines operational incident handling with advisory roles supporting critical information infrastructure owners such as telecommunications operators and financial institutions like Swedbank and SEB. Functions include vulnerability management influenced by standards from International Organization for Standardization and coordination practices referenced by the Forum of Incident Response and Security Teams. The team issues warnings and technical notes comparable to advisories from Microsoft Security Response Center, shares indicators of compromise consistent with VirusTotal reporting, and supports national preparedness aligned with policy instruments from European Commission cybersecurity strategies and directives like the NIS Directive.
The organizational structure situates CERT.LV within Latvia’s national cyber apparatus, interacting with the National Cyber Security Centre (Latvia), ministries such as the Ministry of Defence (Latvia) and the Ministry of Interior (Latvia), as well as supervisory bodies like the Financial and Capital Market Commission (Latvia). Operational teams cover incident response, threat intelligence, vulnerability handling, and public outreach, mirroring organizational models used by ANSSI and CERT-EU. Leadership liaises with parliamentary oversight through entities comparable to Saeima committees and cooperates with academic partners such as University of Latvia and technical research units affiliated with Tallinn University of Technology.
CERT.LV provides services including alert dissemination, malware analysis, coordination of mitigations for infrastructure providers, and cybersecurity awareness campaigns targeting sectors represented by Latvian Association of Information Technology and Telecommunications and industry groups akin to European Banking Federation. Activities include publishing advisories, running tabletop exercises similar to those organized by ENISA, and participating in capacity-building initiatives like trainings offered by Carnegie Mellon University and workshops modeled after SANS Institute curricula. CERT.LV also engages in public-private exercises with network operators such as Lattelecom and collaborates with research on vulnerabilities following methodologies from Common Vulnerabilities and Exposures.
In incident response, CERT.LV follows protocols for triage, containment, and recovery paralleling best practices advocated by FIRST and the Incident Response Consortium. Coordination often requires engaging with law enforcement partners including the State Police (Latvia) and prosecutorial authorities, and with international law enforcement such as Europol and the Federal Bureau of Investigation. For cross-border incidents, CERT.LV leverages information-sharing platforms used by OASIS and interoperability specifications promoted by IETF. Its role encompasses issuing indicators of compromise, coordinating patch rollouts with vendors like Cisco Systems and VMware, and assisting affected entities to restore operations while preserving forensic evidence for tribunals and investigative processes involving bodies like the European Public Prosecutor's Office.
CERT.LV maintains bilateral and multilateral cooperation with peer teams across the Baltic region and beyond, engaging with CERT-EE, CERT-LT, and pan-European structures including CERT-EU and ENISA. It participates in NATO exercises and networks such as those coordinated by the NATO Cooperative Cyber Defence Centre of Excellence and contributes to information exchange in forums like TF-CSIRT. Partnerships extend to industry groups including ISACA and academic alliances with institutions like Riga Technical University and international research centers such as Stanford University cybersecurity labs. These collaborations support joint incident handling, threat intelligence sharing, and harmonization of operational practices with frameworks from ISO/IEC standards committees.
CERT.LV operates under Latvian legislation governing information security and incident reporting, interfacing with regulatory instruments influenced by the NIS Directive and national statutes administered by ministries and agencies such as the State Chancellery of Latvia. Its policy inputs have informed amendments to national cybersecurity laws and contributed to policy debates at the European Commission and within the Council of the European Union. The team’s advisories and operational experiences feed into legislative discussions alongside stakeholders like the Latvian Information and Communications Technology Association and contribute to national preparedness aligned with international obligations under agreements with NATO and treaties negotiated within the European Union framework.
Category:Computer emergency response teams Category:Cybersecurity in Latvia