Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Cybersecurity Law
  4. Incident Response
  5. Cyber Attack Response

Loading...

Incident Response

Cyber Attack Response

Whom must a cyber incident be reported to?

First- and second-category subjects immediately notify the Operational-Technical Agency's computer incident response team, third-category subjects the Digital Governance Agency's team, and defense-sphere subjects the Cybersecurity Bureau's team. Notification of identification is immediate.

What fine threatens an organization for failing to respond?

For a first-category subject, failure to notify, non-compliance with binding instructions or failure to report measures entails a warning or a GEL 5 000 fine; repetition within one year means GEL 10 000. The same measures apply to third-category subjects.

Can the state demand access to the organization's systems by instruction?

Toward first-category subjects — yes, where necessary for responding to an ongoing or past incident, with access ensured immediately upon demand and with the computer security specialist's participation. An instruction toward second- and third-category subjects cannot contain an access obligation; access there requires consent.

Do these requirements cover payment systems?

No. The incident-identification requirements do not extend to payment, securities settlement and reserve management systems, nor to critical systems used for monetary and currency operations.

4 min·...

The legal trail of a cyberattack

A cyberattack brings not only operational disruption but also legal duties: Georgian legislation obliges subjects of critical information systems to identify computer incidents, notify the relevant response teams, and carry out the instructions issued to them. Article 10 of the Georgian Law on Critical Information Systems and Cybersecurity regulates exactly these three pillars: studying, describing and responding to the incident; notification; and compliance with binding instructions. The administrative-liability norm of the same law attaches fines to breach of these duties. Below we examine what is required of each category of subject, whom the incident must be reported to, and what sanctions await a defaulter.

Incident identification and the network sensor

Under point 1 of Article 10, the subject of a critical information system carries out the identification of a computer incident, which includes its study, description and response. For this purpose the subject uses a network sensor, whose configuration rules are set for first- and second-category subjects by order of the head of the Operational-Technical Agency, for third-category subjects by order of the chair of the Digital Governance Agency, and for subjects in the defense sphere by order of the Minister of Defense of Georgia. The configuration rules must exclude access to the substantive content of the subject's communications. For a first-category subject's network, identification of an ongoing incident is carried out by the Operational-Technical Agency's computer incident response team and/or the subject's computer security specialist — the state and the subject act in parallel at this stage.

Notification — to whom, when and how

Identification of a computer incident is immediately notified: for first- and second-category subjects — to the Operational-Technical Agency's computer incident response team; for third-category subjects — to the Digital Governance Agency's team; and for subjects in the defense sphere — to the Cybersecurity Bureau's team. To store and protect incident information, the subject takes emergency measures where necessary. The response team studies, describes and responds to the incident, and after study submits binding instructions for execution. An instruction cannot include an obligation of access to a second- or third-category subject's network sensor, information asset, system or infrastructure — the subject's property is not left exposed through this route. The subject must respond to the instructions within a reasonable period and submit information on the measures taken to the relevant team.

The response teams' powers and their limits

The Operational-Technical Agency's team has broad powers toward first-category subjects: access to the network sensor — except where the traffic-identifying data contains information about bank transfers; a demand for access to the subject's information asset, system or infrastructure necessary for responding to an ongoing or past incident — such access must be ensured immediately, upon the demand, and is exercised with the participation of the subject's computer security specialist. Toward second-category subjects, access requires their consent, with the information security manager deciding within a reasonable period. To prevent repetition of an incident, the team may request an electronic communications company to carry out measures to identify and neutralize a similar incident — the demand must take account of the company's technical capabilities. It is separately stipulated that these requirements do not extend to payment, securities settlement and reserve management systems, nor to critical systems used for monetary and currency operations.

The teams' functions and priority threats

Article 8 of the law establishes that incident management in cyberspace is carried out by the computer incident response teams of the Operational-Technical Agency, the Digital Governance Agency and the Cybersecurity Bureau. Priority threats include: a cyberattack threatening human life and health, state interests or the country's defense capability; a cyberattack against the information systems of a critical information system subject; a cyberattack threatening the financial resources or property rights of the state, an organization or a private person; and any other action that, by its character, purpose, source, volume or quantity, contains a sufficient danger to the normal functioning of a critical system. The teams' duties include issuing recommendations and guidance, timely detection of incidents, response and its coordination, recording and categorization, analysis, assistance in remedying consequences and minimizing damage, and participation in preventive measures — an affected organization is not left alone.

Fines for non-performance of the duties

The administrative liability established by the law prices precisely what non-response to a cyberattack costs. A first-category subject's failure to notify identification of an incident, failure to comply with binding instructions issued by the Operational-Technical Agency, or failure to submit information on the measures taken entails a warning or a fine of GEL 5 000; repetition of the same violation within one year after an administrative penalty was imposed entails a fine of GEL 10 000. For third-category subjects the rule is the same: failure to notify or non-compliance with the Digital Governance Agency's instructions — a warning or a fine of GEL 5 000, and upon repetition within one year — a fine of GEL 10 000. Fast, documented response is therefore not only a security matter but a financial risk question. The Legal.ge team assists with the legal side of incident response — from formalizing notifications to answering instructions.

Updated: ...

Verified against current law: 09/07/2026

Legal basis:

  • საქართველოს სისხლის სამართლის კოდექსი
  • საქართველოს სისხლის სამართლის საპროცესო კოდექსი

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer