The State Audit Office’s report on the implementation of cloud computing services in public administration clearly highlights a problem we have been discussing for years – Latvia lacks a unified, coordinated, and purposeful approach to developing cloud computing in the public sector. Cloud technologies are no longer a question of the future – they are today’s reality, shaping the efficiency of national digital governance, cybersecurity, and international competitiveness.
Cloud computing is not just a technology – it is the foundational infrastructure that enables the state to operate more efficiently, securely, and intelligently. It helps optimise costs, strengthen cybersecurity, and create a flexible IT environment where services for institutions and citizens are equally secure and fast. The value of cloud computing cannot be reduced solely to cost savings; it is far more important to consider benefits such as time efficiency, automation and system integration capabilities, improved security, and overall process effectiveness. Technology must be evaluated comprehensively, taking into account functionality, interoperability, and security parameters – not just cost.
The Latvian Information and Communications Technology Association (LIKTA) fully supports the State Audit Office’s recommendation to establish a centralised approach to cloud computing with unified standards, clear security principles, and practical guidelines for all public institutions. This is a recommendation the industry has repeatedly expressed in various forums and meetings.
There must be clear efficiency criteria and quality standards for evaluating all cloud computing solutions – both state and private. This would make it possible to assess how to use existing resources and expertise most effectively, avoid creating parallel structures, and ensure efficient use of public funds. Latvian companies are capable of providing high-quality, secure, and cost-competitive cloud solutions – they simply need the opportunity to operate under equal competition conditions. Equally important is clearly defining how institutions responsible for storing and processing state data in the cloud are selected and evaluated, while ensuring healthy competition between public and private providers. Such an approach would foster innovation, quality, and security within the state’s digital infrastructure.
The State Audit Office report notes that 86% of public institutions already use some cloud services, and 54% plan to expand their use further. Institutions most often use state-provided cloud services and those offered by international vendors (Office365, Azure), but least often – services from local providers. Cloud services are being used, yet fewer than half of institutions conduct risk assessments or cost-benefit analyses related to their use.
It is also crucial to ensure geographical redundancy by placing infrastructure in other friendly European countries, thereby increasing resilience against cyberattacks. To avoid crisis situations caused by major cyber incidents or interruptions to data centres in Estonia, the country established a state data embassy in Luxembourg in 2017. It is located in a TIER IV certified data centre, where servers are operated remotely from Estonia. This data centre, like those in Estonia, is operated by a private company that provides services to the Estonian state according to clearly defined quality criteria. A second phase is now being considered, which would place additional infrastructure in another country to further increase geographic distribution.
The question is – has Latvia implemented a similar solution to strengthen the security of state data? It would be useful to evaluate the effectiveness and role of existing structures and define clear standards and criteria for what the state expects from service providers. The state’s task is to create a transparent and competitive environment in which both public and private solutions can compete on equal terms. If the state’s internal solution can ensure higher quality and a better price, it should receive priority in procurement processes, and vice versa. This approach would promote efficiency, innovation, and public trust in digital government solutions.
Given the rapid development of cloud technologies, many European countries have realised that building such competencies in-house is neither efficient nor cost-effective; it is easier and more efficient to procure necessary services from the private sector. European countries are shifting to a model where criteria are defined for private companies so that they can provide services to the public sector. For example, the European Commission procures the necessary computing resources for itself and its institutions from qualified private suppliers using the CLOUD III DPS programme, designed for procuring infrastructure (IaaS) and platform (PaaS) services.
Security is often a topic of debate – where is it safer? At the same time, both private and public sectors use the same service providers or manufacturers of security equipment and software. It is equally important for public sector specialists to acquire appropriate knowledge of cloud technologies. Technology is no longer just an IT issue – it is part of the state governance culture, where everyone must understand how digital solutions help improve work quality, reduce bureaucratic burden, and provide society with faster and more secure services.
It is positive that on 14 October, Cabinet Regulation No. 606 “Regulations on the State Data Processing Cloud” was adopted, allowing public sector institutions to choose either state or private cloud solutions by assessing the most effective and secure option in each specific case. Meanwhile, work is still ongoing on the Cabinet regulation on requirements for information system placement and data centre security, which the industry eagerly awaits to establish clear conditions and criteria for all service providers. Without these regulations, the State Data Processing Cloud regulations cannot operate effectively.
We hope that the responsible institutions will use the State Audit Office’s recommendations as an opportunity to act – not only to identify problems but to begin a systematic transition to modern, secure, and sustainable IT governance. Cloud computing is not a risk; it is an opportunity that will allow Latvia to become a more efficient, secure, and technologically advanced state.
Author: Signe Bāliņa, President of Latvian Information and communications technology association (LIKTA)
Source: likta.lv (translated with an artificial intelligence tool)




