Reg. No. 40203410806 VAT LV40203410806

Theme

Book a consultation Book

01 / 02 Briefing Latvia Threat Landscape

Latvia’s 2026 Threat Picture: 6 Moves to Make This Quarter

CERT.LV recorded 757,286 compromised devices in Latvian cyberspace in Q1 2026, the highest figure reported to date. Most were classified as configuration weaknesses. This briefing turns the published trends into six practical priorities for the quarter.

  • 7 min read
  • Published June 2026
Latvia’s 2026 Threat Picture: 6 Moves to Make This Quarter — Download PDF
PDF 11 pages 7.2 MB

CERT.LV’s quarterly activity review provides a national view of current cyber incidents and compromised devices. The Q1 2026 data is serious, but it also points to practical improvements: many of the observed weaknesses concern exposure, configuration and security hygiene that organisations can address directly.

CERT.LV recorded 757,286 compromised devices in Latvian cyberspace — the highest figure ever recorded — and the majority are configuration weaknesses: systems left exposed, misconfigured or unpatched, driven largely by human factors and insufficient security standards. Since Russia’s full-scale invasion of Ukraine in 2022, registered incidents have risen sixfold and compromised devices eightfold.

Our assessments of Latvian and European organisations regularly encounter the same categories of exposure described in the national data. This briefing translates the published trends into six concrete actions organisations can prioritise this quarter.

The Q1 2026 picture at a glance

What CERT.LV’s latest national data tells us — and what it means for the organisations we test.

  • 757,286 compromised devices in Latvian cyberspace — a record high (CERT.LV, Q1 2026)
  • 846 incidents handled manually by CERT.LV in Q1 2026 — the second-highest quarter on record
  • 6× / 8× more incidents and more compromised devices than before 2022
  • The majority are configuration weaknesses — exposure and misconfiguration, not exotic zero-days
  • Supply-chain and external-provider exposure remains an important risk that organisations must identify and manage
  • AI is accelerating attacks — faster, more automated, increasingly social-engineering-led

The six moves

  1. 01 06

    Find the misconfigurations before attackers do

    The single biggest category in the national data isn’t sophisticated malware — it’s exposure: forgotten services, misconfigured systems, expired certificates, weak settings. You cannot fix what you cannot see. Map your real external attack surface — every domain, subdomain, exposed service and piece of shadow IT — and keep watching it, because it changes daily.

    • Inventory everything internet-facing, not just what you assume is in scope
    • Hunt for misconfigurations, exposed admin panels, leaked files and outdated components
    • Re-check continuously — exposure drifts every time a system changes
  2. 02 06

    Reduce the risk from weak and exposed credentials

    Stolen and reused credentials remain a practical route to account compromise. Assume credential exposure is possible: enforce multi-factor authentication, discourage password reuse, monitor for exposed accounts and respond promptly to verified leaks.

    • Enforce multi-factor authentication everywhere it matters — email, VPN, admin and finance first
    • Block weak and previously-breached passwords; favour long passphrases over forced complexity
    • Monitor the dark web for leaked credentials tied to your domains — and reset fast when they appear
  3. 03 06

    Treat your supply chain as part of your attack surface

    CERT.LV identifies supply-chain control as a continuing priority. Suppliers with access to systems, identities or data can materially affect your security, and NIS2-related national requirements and customer contracts may require that this risk is assessed and managed.

    • Map which suppliers touch your systems, your data and your identities
    • Put cybersecurity requirements in contracts — and verify them rather than assume them
    • Monitor your key suppliers’ exposure and breach status, not only your own
  4. 04 06

    Prepare your people for AI-grade social engineering

    CERT.LV reports that attacks are becoming more automated and increasingly reliant on social engineering, with AI accelerating fraud and intrusion activity. Technical controls remain necessary, but employees also need practical procedures for verifying unusual requests and reporting suspicious activity.

    • Run realistic phishing, vishing and — now — prompt-injection simulations, not slideshows
    • Teach staff to verify any unusual request through a second, independent channel
    • Make reporting a suspicious message easy, fast and blame-free
  5. 05 06

    Move from annual snapshots to continuous visibility

    The data also shows the pace and scale of current activity. An annual penetration test remains valuable, but it is only a point-in-time view. Continuous asset inventory, change detection and vulnerability monitoring help identify new exposure between formal assessments.

    • Monitor your attack surface and credentials continuously, not annually
    • Track new, relevant vulnerabilities against the technology you actually run
    • Re-test after every significant change — and verify that fixes genuinely worked
  6. 06 06

    Make sure you can report an incident within 24 hours

    When something does happen, the clock is short: NIS2 requires an early warning within 24 hours of becoming aware of a significant incident. The time to write — and rehearse — your incident-response plan is now, not in the middle of the breach.

    • Document who does what, who decides, and who communicates
    • Pre-build your NIS2 reporting workflow, templates and contacts
    • Test the plan — a plan that has never been exercised cannot be relied upon.

Conclusion

The Q1 2026 data is a record high, but the priority areas are recognisable: exposure, credentials, suppliers, people, speed and response readiness. Addressing them systematically reduces avoidable risk. OffSeq helps organisations identify those gaps through testing and monitoring and verify whether the resulting controls work.

  • Reduce avoidable exposure and make attacks harder
  • Address the six recurring risk areas systematically
  • Find and remediate public exposure before it is exploited