Azerbaijan Introduces Cybersecurity Violation Fines

Baku: Fines are being introduced for violations of the requirements of normative legal acts in the field of ensuring cybersecurity, APA reports. This is reflected in the proposed new Article 371-2 of the Code of Administrative Offenses, which was discussed at today's session of the Milli Majlis.

According to Azeri-Press News Agency, the draft outlines various scenarios where fines will be applicable. These include failures by computer incident response centers, security operations centers, and information infrastructure entities, such as internet providers and hosting providers, to comply with cybersecurity measures. Specific violations include not adhering to instructions from the relevant executive authority regarding cyber threat prevention and failing to provide timely information on cyber incidents. Entities are also required to conduct continuous real-time monitoring of cyber events and respond swiftly to inquiries from the designated authority.

For such violations, officials could face fines ranging from 500 to 1,000 manats, while legal entities could be fined between 1,000 and 2,000 manats. Furthermore, operating as a computer incident response center or a security operations center without official registration will result in higher fines, ranging from 1,000 to 1,500 manats for officials and 1,500 to 2,500 manats for legal entities.

The law exempts critical information infrastructure, state bodies, and certain financial and strategic entities from these provisions. These include the Central Bank of the Republic of Azerbaijan, intelligence bodies, and entities involved in financial markets, among others. The draft law was voted on and adopted in its third reading during the session.