The publication of the results of the assessment of the August cyber incident at CSDD has sparked a new wave of discussions around potential damage compensation claims. Jury lawyer Lauris Klāgišs believes that victims no longer need to wait for the conclusion of the Data State Inspectorate (DVI) to file a lawsuit. He expressed this opinion in a post on [Facebook](https://www.facebook.com/photo?fbid=1708434157953886&set=a.458649456265702), commenting on the document from the Ministry of Transport "The assessment of the CSDD cyber incident has been completed, and recommendations for necessary improvements have been prepared." According to the lawyer, the report points out numerous deficiencies in CSDD's cybersecurity system and contains conclusions that, in his opinion, indicate inadequate data protection measures. Among the most important conclusions that Klāgišs highlights are: * the initial cause of the incident was identified as a vulnerability in the web application med.csdd.lv; * the audit revealed technical shortcomings, including incomplete coverage of security checks, insufficient network protection, and lack of multi-factor authentication; * attackers were able to obtain data en masse for an extended period due to the absence of effective request limitation mechanisms and detection of suspicious activity; * as a result of the cyberattack, data of approximately 1.15 million individuals and up to 200,000 legal entities were compromised; * the audit also pointed out the prolonged storage of historical personal data, which, according to the lawyer, contradicts data processing principles. Furthermore, the report from the Ministry of Transport noted deficiencies in the oversight of contractors responsible for monitoring information security. The document states that the service provider should timely identify unusual activity and prevent mass data copying. Klāgišs reported that he had previously submitted an official request for the contract between CSDD and the company Tet regarding the procurement of IT infrastructure. In his opinion, it is necessary to establish the responsibility of all parties that may have been involved in ensuring information security. The lawyer believes that the published report significantly strengthens the legal position of individuals intending to seek compensation. "The negligence of the institution is now not only presumed but also officially documented, which creates a solid foundation for successfully claiming compensation in any civil dispute," he stated. It is important to note that this is the lawyer's assessment, not a judicial conclusion. The final decision on the grounds for compensation in each specific case is made by the court. As previously reported, as a result of the cyberattack on CSDD in August 2026, data of approximately 1.15 million individuals and up to 200,000 legal entities were stolen. The operation of the institution's electronic services was not disrupted, and the access channels used by the attackers were identified and blocked. The investigation of the incident is ongoing in cooperation with CERT.LV and law enforcement agencies. The publication of the report by the Ministry of Transport may become one of the key documents in future legal proceedings; however, the issue of compensation payments will be resolved individually in each case.