New fines to be introduced in Azerbaijan for violations in cybersecurity
New penalties will be introduced for violations of regulatory legal acts in the field of ensuring cybersecurity.
This is provided for by amendments proposed to the Code of Administrative Offenses, which were submitted for discussion at a joint meeting of the Milli Majlis committees on legal policy and state building, as well as on labor and social policy, reports 1news.az citing Qafqazinfo.az.
According to the bill, liability will be provided for:
- Failure to comply with the instructions of the relevant body (institution) determined by the authorized executive authority related to ensuring the cybersecurity of information infrastructure (preventing cyber threats, cyberattacks, and cyber incidents, as well as eliminating their consequences), as well as conducting digital investigation and providing information on its results;
- Failure to provide the relevant body (institution) determined by the authorized executive authority with urgent information about cyber threats, cyberattacks, and cyber incidents directed at information infrastructure, as well as data obtained as a result of activities specified in Article 371-2.1.4 of this Code;
- Failure to respond within 24 hours to requests from the relevant body (institution) determined by the authorized executive authority aimed at studying the state of cybersecurity of information infrastructure and conducting proactive research in the field of cybersecurity, as well as failure to respond within 5 working days to requests related to conducting a digital investigation;
- Failure to conduct continuous monitoring of cyber incidents and cyberattacks in real time, as well as failure to take primary technical response measures against them;
- Violation by subjects of information infrastructure, including internet providers, hosting providers, and owners of internet information resources, of general and special cybersecurity requirements for information infrastructure performing functions of public importance;
- Failure to take measures to ensure conditions for conducting digital investigation and proactive research in the field of cybersecurity, as well as violation of the integrity of data obtained during digital investigation, their alteration, deletion, or falsification - entails a fine on officials in the amount of 500 to 1000 manats, and on legal entities - from 1000 to 2000 manats.
- Carrying out activities as a computer incident response center or a security operations center without being included in the "Register of Computer Incident Response Centers and Security Operations Centers" - entails a fine on officials in the amount of 1000 to 1500 manats, and on legal entities - from 1500 to 2500 manats.











