TWINLADDER
TwinLadder logoTwinLadder
Back to Insights

Governance & Oversight

Who Read the Seam?

Latvia's road traffic directorate lost the data of 1.2 million people through a portal nobody was watching — not because anyone decided to stop watching it, but because it sat outside the contract. An absence produces no owner, no report and no register line. After five years, the only party that still understood the contract was the party being paid under it.

August 31, 2026Alex Blumentals, Founder & CEO9 min read

Listen to this article

0:000:00

Who Read the Seam?

A specification is a governance document, not an engineering one. Latvia's largest data loss is a case about what happens to the parts of a contract nobody was asked to cover — and about which side of a long relationship still knows what it says.


Latvia's road traffic directorate, CSDD, lost the personal data of 1.2 million people this month — most of the adult population of the country — along with details on around 200,000 companies, pulled from eighteen years of payment records. The way in was a portal called med.csdd.lv, which about two hundred doctors use to file drivers' medical certificates. Username and password, no second factor, never penetration-tested, sitting in a network that let the intruder move a good deal further than it should have.

That part is a security story, and plenty of people are writing it. I want to write about the four days afterwards.

Two accounts of the same contract

On 18 and 19 August the chairman of CSDD's management board said publicly that the monitoring had been the supplier's job. CSDD has a five-year contract with Tet, signed in February 2022, worth about nine million euros, covering the register's IT infrastructure — provision, management, firewall, continuous monitoring, incident monitoring. His words were that nobody knew about the attack even though it was their responsibility, and that CSDD pays that company a great deal of money every month for exactly that monitoring.

On 21 August Tet answered with the contract in hand. It manages the network, the connections and the infrastructure, and it monitors data flow. It is not the security provider for services and applications CSDD built and runs itself. The contract also never gave Tet access to the med.csdd.lv log files. A few days later the economy minister, after meeting Tet's management, said the company had met its contractual obligations.

Take that at face value for a moment, because the investigations are still open and nobody should be assigning blame this early. If the supplier did what it was contracted to do and the outcome was the largest data loss in the country's history, then whatever failed sits in what was asked for.

Scope silence

Here is the part I keep coming back to. Nobody decided to leave that portal unwatched. I would be very surprised if there is a meeting anywhere in the record where someone said: we will not hand our monitoring supplier the logs of an internet-facing system holding health information about drivers, and therefore nobody at all will be watching it.

It was simply outside the scope. And scope silence behaves completely differently from a clause you disagree with.

A clause gets argued over. It gets an owner, gets escalated, ends up in somebody's quarterly pack. Something absent from a contract produces no owner, no report, no alarm and no line on any register. It generates nothing whatsoever, which is exactly why it can sit there undisturbed for five years.

Why the gap survived

Then there is why it lasted, which I think has very little to do with anyone being careless.

A supplier reads its contract constantly. It is the document by which staff are tasked, scope is defended, margin is set and disputes are won, and there are people on that side whose whole job is to know what it says. The buyer reads the same contract once, at signature, and then the people who read it move on to other work — or out of the building.

Five years later the supplier's map of the relationship is still accurate, because it has been in continuous use. The buyer's has quietly decayed, because it hasn't been used at all.

Which gets you to a sentence worth sitting with. After five years, the only party that still understood the contract was the party being paid under it.

The same will be true of any long outsourcing relationship where the buyer's side of the reading gets done once. It is what happens to any capability an institution stops practising, and reading your own commercial terms is a capability like any other.

The mechanism, with no AI in it

Oksana Sivokobilska and I have spent two years on a book about a version of this — what happens to an institution's capacity to form and hold judgment when the work that used to build it gets handed to a machine. The contract case is the same mechanism with no AI anywhere near it, which is part of why it is worth writing about. Hand over the doing, keep the accountability, and the capacity to know whether the handover was well made goes quietly, over years, while every number you report looks fine.

One of the six failure modes we ended up naming is authorship erosion — the share of an institution's output that nobody inside could now rebuild from scratch with the tools off. We had analysis in mind when we wrote it. This case says it applies to an institution's own governing documents just as well. A contract nobody in the building can reconstruct from first principles is an unowned instrument, whatever the signature page says.

The law was already there

And then the uncomfortable bit.

Latvia has already transposed NIS2. Since 1 September 2024, under the national cyber security law, the management body of an essential entity has to approve the cyber risk-management measures, oversee their implementation, and can be held liable for failures. Directors are required to be trained. Cabinet regulation 397 followed in July 2025, with a designated cyber security manager due that October.

All of it was in force, and it still produced a board that could not answer the question what did we buy, and what is left uncovered?

Approving something and being able to interrogate it are two different capacities, and the law can only require the first. Signing off a measure you cannot question is the compliance artefact left behind by a judgment the institution no longer holds.

The question for your own board

If I sat on a board this month I would ask one question, and I would ask it about the largest outsourced service rather than about cyber.

What did we hand over, and what did nobody take?

Which layers sit in the supplier's scope, which sit in ours, and who has read the seam between them in the last twelve months? A good answer is a map with a named owner against every line and a date on it. A weaker answer is the contract value and the uptime figure — the supplier's health, offered up to a question about your own coverage.

The CSDD contract, incidentally, was in its final year. Re-procurement was coming, and a re-tender is the one moment when somebody has to read the thing end to end. The seam surfaced in a breach a few months before it would have surfaced in a tender document.

The service inspection reports in early September and the data inspectorate has its own case open, so much of this will get sharper. In the meantime I've been asking people this week whether they have ever seen a current layer map of a large outsourcing deal, with owners written against each line. Haven't found one yet.

If you have one, I'd like to see it.


Every statement of scope above comes from the parties' own public statements and from the economy minister. Proceedings are open — the Transport Ministry's service inspection reports in early September, and the Data State Inspectorate and Prosecutor General's Office both have live cases — and this piece draws no conclusion about responsibility. No individuals are named.