Although the number of cyberattacks is growing steadily and 18% of companies have encountered them, more than a third of companies are not concerned about them, according to the latest survey by the electronic communications and ICT service provider “Bite Latvija” and the research centre SKDS. This worrying contradiction shows that companies still do not treat cyber threats as a real business risk. As a result, some companies may not be sufficiently prepared for situations that threaten their operations, cause financial losses and put customer data at risk.
This year “Bite Latvija” and the research centre SKDS carried out their annual survey of companies for the fourth year, examining the use of ICT solutions in companies and their exposure to cyber risks. It involved the heads of 750 active companies across Latvia.
Cyber threats keep growing, yet one company in three is not concerned about cyber risks
The results of the survey “The use of ICT solutions in companies and exposure to cyber risks” show that, when thinking about the steadily growing number of cyberattacks, 34% of companies in Latvia are not concerned about them. At the same time, asked about their exposure to cyberattacks, 18% of the companies surveyed had experienced one, and this year 4 percentage points more company heads acknowledged this than in 2025.
“The events of recent months in Latvia show very clearly that cyber threats are not a theoretical risk, and that they can also affect organisations responsible for critically important services and for large volumes of citizens’ data. That is precisely why it is so worrying that a considerable proportion of companies still do not see growing cyber threats as a significant risk. The case of the Road Traffic Safety Directorate shows, too, that the consequences of a single cyberattack can reach far beyond the particular organisation, affecting hundreds of thousands of people. Companies therefore need to think about how ready they will be at the moment a cyberattack happens, rather than about whether it will happen,” stresses Vilnis Kibermanis, head of the technical solutions expert team at “Bite Latvija”.
The greatest concerns are financial losses caused by cyber risks and the theft of customer data
CERT.LV data also confirms that companies and organisations are having to deal with ever more varied cyber threats. According to CERT.LV’s current review of the situation in Latvia’s cyberspace, the dominant threats include phishing, malware that steals information, fake software updates and malicious browser extensions, as well as the theft of authentication data and unauthorised access. In the second quarter of this year, meanwhile, ransomware attacks and data leaks continued to have the greatest impact.
At the same time, experts point out that attackers most often exploit not sophisticated hacking methods but elementary security shortcomings, so a considerable proportion of incidents could be prevented by following basic cybersecurity principles and maintaining good cyber hygiene.
Meanwhile, in the “Bite Latvija” and SKDS survey, in 30% of cases business owners said their greatest concern was possible disruption to business operations and financial losses. In 21% of cases the greatest worry was the risk of customer data being stolen, in 15% of cases business owners pointed to employees’ insufficient knowledge of how to act in the event of a cyberattack, while in 10% of cases they said their greatest concern was inadequate ICT solutions for protecting the company against cyberattacks.
“Practice shows that the impact of a cyber incident is rarely limited to restoring IT systems. It can mean halted business processes, customers left unserved, additional costs, risks to customers from leaked data and, in the long run, a loss of trust as well. Cybersecurity therefore has to be seen as a single system in which technology, employees’ skills and clear procedures for action complement one another,” explains V. Kibermanis.
Alongside technical cybersecurity solutions, employees must also be trained and 24/7 support provided
Alongside technical security solutions, regular risk assessment, employee training, a clear action plan in the event of a cyberattack and access to technical support on a 24/7 basis are all important. Preventive measures put in place in good time make it possible both to reduce potential losses and to ensure business continuity, data security and customer trust.
The “Bite Latvija” and SKDS survey also reveals that companies have made improvements in certain areas, most of all in installing software updates regularly, backing up data, using cloud services and introducing two-factor authentication. Investment has been made less often in employee training, independent assessment of IT infrastructure, the use of specific antivirus software and moving servers to data centres.
“Today cybersecurity is part of a company’s responsibility towards its customers and partners, as well as a precondition for business continuity. If a company does not have sufficient resources or expertise to ensure the necessary level of cybersecurity on its own, the responsible choice is to work with a trusted ICT partner, because preparing before an incident always costs less than dealing with its consequences,” says V. Kibermanis.
The “Bite Latvija” and SKDS survey “The use of ICT solutions in companies and exposure to cyber risks” was carried out in 2026 from May to July, surveying the heads of 750 active companies across Latvia through an internet survey and telephone interviews.
