BAKU, Azerbaijan, September 2. Fines for violating cybersecurity requirements have been approved in Azerbaijan.
This is reflected in amendments to the Code of Administrative Offenses approved by the President of the Republic of Azerbaijan, Ilham Aliyev. The text of the document was published on the official website of the President of Azerbaijan.
The fines will be imposed for violations of the requirements of regulatory legal acts in the field of ensuring cybersecurity in the country.
According to the amendment, officials will be fined for 500 manat ($294) to 1,000 manat ($590), while legal entities will be fined for 1,000 manat ($588.2) to 2,000 manat ($1,180) for failure to take measures to ensure the cybersecurity of information infrastructure connection with computer incident response centers, security operations centers, as well as information infrastructure entities, including owners of Internet information resources, internet providers and host providers, are subject to penalties for failure, namely:
- failure to comply with the instructions of the body (organization) designated by the relevant executive authority regarding ensuring the cybersecurity of information infrastructure (prevention of cyber threats, cyber attacks, and cyber incidents and elimination of their consequences), as well as conducting digital research and providing information on its results;
- failure to promptly submit information on cyber threats, cyber attacks, and cyber incidents directed at information infrastructure, as well as information obtained as a result of continuous monitoring of cyber incidents and cyber attacks in real time and implementation of initial technical response measures to them to the body (organization) designated by the relevant executive authority;
- failure to respond to requests sent by the relevant executive authority (organization) for the purpose of studying the cybersecurity status of the information infrastructure and conducting proactive cybersecurity research within 24 hours, and to requests sent for conducting digital research within 5 working days;
- failure to implement continuous monitoring of cyber incidents and cyber attacks in real time and initial technical response measures to them;
- violation of general and specific requirements for cybersecurity of information infrastructure performing public functions by information infrastructure entities, including internet providers, host providers, and owners of internet information resources;
- failure to create conditions for digital research and proactive cybersecurity research, as well as failure to protect the integrity of information obtained during digital research, allowing its alteration, deletion, or falsification.
For operating as a computer incident response center and security operations center without being included in the register of computer incident response centers and security operations centers, officials will be fined from 1,000 manat ($588.2) to 1,500 manat ($880), and legal entities will be fined 1,000 manat ($588.2) to 1,500 manat ($880).
The above provisions won't apply to critical information infrastructure, state bodies (institutions), including the Central Bank, intelligence and counterintelligence entities, entities whose activities are controlled in the financial markets (banks, insurers, reinsurers, persons licensed in the securities market, joint-stock investment funds and investment fund managers, payment service providers, etc.), as well as to the information infrastructure of protected persons, protected and strategic facilities, as well as to the computer incident response centers and security operations centers established by the body (institution) determined by the relevant executive authority and the Central Bank.
The amendments will enter into force on July 1, 2027.
