ER10 · August 25, 2026 · 1Cifer
From August 25, every employer must appoint a cybersecurity expert
From August 25 a requirement applies in Kazakhstan obliging every employer to designate a cybersecurity expert. The norm is not just for IT companies: any business with employees, data and digital systems — which is practically everyone — must have an appointed person.
For large organizations with information security departments it is a formality. The real change is for small and mid-sized business, where questions like "who grants and revokes access", "who answers for a leak" and "whom to call after a breach" often have no answer at all. Now there must be one, documented.
The sensible way to comply is not to buy a nominal signature but to use the occasion: appoint the person and hand them a short starter plan. Inventory access to banking, 1C and CRM; two-factor protection wherever money and data live; an offboarding procedure that revokes every right; an incident action plan. That is the basic hygiene that stops most real attacks on small companies — and turns a formal requirement into useful work.


