Abstract
and system configuration errors. Significant gaps in Kazakhstan’s cyber defence system are identified: lack of effective interagency coordination mechanisms, insufficient regulation of public-private partnerships, and inefficiency of the existing legal framework for regulating the liability of critical infrastructure operators. The author substantiated the need to create a single cyber defence coordination centre that will combine the efforts of the state monitoring system KZ-CERT and the industry system FinCERT and proposes economic mechanisms to stimulate investment in cyber security through a system of tax incentives and grant programmes. The peculiarities of the cybercrime investigation process were analysed, including the procedures for video recording of equipment seizure and the specifics of procedural registration of evidence. According to the General Prosecutor’s Office of the Republic of Kazakhstan, in 2023, 476 criminal cases of cybercrime were brought to court, of which 312 resulted in guilty verdicts. The research findings formed a comprehensive understanding of the relationship between the legal, technical, and socio-economic aspects of cybersecurity and proved the need for systematic interaction between all stakeholders in countering cyber threats
Keywords: information systems; digital evidence; malware; critical infrastructure; public-private partnerships
Suggested citation
[1] A way to combat corruption in law enforcement agencies in Kazakhstan has been found. (2024). Retrieved from https://www.zakon.kz/sobytiia/6450017-nayden-sposob-borby-s-korruptsiey-v-pravookhranitelnykh-organakh-kazakhstana.html.
[2] Anti-Fraud Center results: Suspicious transactions worth over 1.4 billion tenge blocked. (2025). Retrieved from https://nationalbank.kz/kz/news/informacionnye-soobshcheniya/17388.
[3] Azanbay, K. (2024). Innovative technologies as a factor of information security of the Republic of Kazakhstan. Information Systems Engineering, 29(2), 523-532. doi: 10.18280/isi.290213.
[4] Bishmanov, K., Muratzhan, Z., Dilbarkhanova, Z., & Lyutsik, V. (2024). Analysis of modern types of cyberterrorism and methods of countering them. IDP Internet Journal Law and Politics, 41. doi: 10.7238/idp.v0i41.428542.
[5] Bolatbek, M., Baispay, G., Mussiraliyeva, S., & Usmanova, A. (2024). A framework for detection and mitigation of cyber criminal activities using university networks in Kazakhstan. Radioelectronic and Computer Systems, 2, 186-202. doi: 10.32620/ reks.2024.2.15.
[6] Calif, S. (2023). 2023 Cybersecurity Almanac: 100 facts, figures, predictions, and statistics. Retrieved from https://cybersecurityventures.com/cybersecurity-almanac-2023/.
[7] Capacity building on Combating Cybercrime in Central Asia. (n.d.). Retrieved from https://www.osce.org/project/capacity-building-on-combating-cybercrime-in-central-asia.
[8] CEPOL Knowledge Centres. (n.d.). Retrieved from https://cepol.europa.eu/training-education/cepol-knowledge-centres.
[9] Cetindamar, D., Abedin, B., & Shirahada, K. (2021). The role of employees in digital transformation: A preliminary study on how employees’ digital literacy impacts use of digital technologies. IEEE Transactions on Engineering Management, 71, 7837- 7848. doi: 10.1109/tem.2021.3087724.
[10] Computer Fraud and Abuse Act of 1986. (1986, October). Retrieved from https://www.congress.gov/99/statute/STATUTE-100/STATUTE-100-Pg1213.pdf.
[11] Concluding event of the OSCE regional project on combating cybercrime in Central Asia. (2024). Retrieved from https://www.osce.org/secretariat/570738.
[12] Convention on Cybercrime. (2001, November). Retrieved from https://rm.coe.int/1680081561.
[13] CPJ urges Kazakh authorities to investigate cyberattacks on media. (2024). Retrieved from https://cpj.org/2024/02/cpj-urges-kazakh-authorities-to-investigate-cyberattacks-on-media/.
[14] Criminal Procedure Code of the Republic of Kazakhstan. (2014, July). Retrieved from https://adilet.zan.kz/eng/docs/ K1400000231.
[15] Critical Infrastructure Partnership Advisory Council (CIPAC). (n.d.). Retrieved from https://www.cisa.gov/resources-tools/groups/critical-infrastructure-partnership-advisory-council-cipac.
[16] Cybersecurity predictions for 2024. (2023). Retrieved from https://corewin.ua/news-ru/cybersecurity-forecasts-2024/.
[17] Cybersecurity threats to Kazakhstan. (2024). Retrieved from https://e-cis.info/news/566/115478/.
[18] Damage from internet fraud cases in Kazakhstan has grown to 7 billion tenge. (n.d.). Retrieved from https://finprom.kz/ru/article/usherb-ot-sluchaev-internet-moshennichestva-v-kazahstane-vyros-do-7-milliardov-tenge.
[19] Datami Newsroom. (2024). What is threat analysis in cybersecurity? Retrieved from https://datami.ee/blog/shho-take-analiz-zagroz-v-kiberbezpetsi/.
[20] Dimitriadis, A., Ivezic, N., Kulvatunyou, B., & Mavridis, I. (2020). D4I – digital forensics framework for reviewing and investigating cyber attacks. Array, 5, article number 100015. doi: 10.1016/j.array.2019.100015.
[21] Directive of the European Parliament and of the Council No. 2013/40/EU “On Attacks Against Information Systems and Replacing Council Framework Decision 2005/222/JHA”. (2013, August). Retrieved from https://eur-lex.europa.eu/eli/ dir/2013/40/oj.
[22] Djenna, A., Harous, S., & Saidouni, D.E. (2021). Internet of things meet Internet of threats: New concern cyber security issues of critical cyber infrastructure. Applied Sciences, 11(10), article number 4580. doi: 10.3390/app11104580.
[23] ERMProtect Staff. (n.d.). 5 notable digital and crypto forensics investigations of 2022. Retrieved from https://ermprotect.com/ blog/5-notable-digital-and-crypto-forensics-investigations-of-2022/.
[24] Galushko, M. (2022). Industrial sectors were subject to the largest number of cyber attacks in Kazakhstan. Retrieved from https://inbusiness.kz/ru/news/naibolshemu-kolichestvu-kiberatak-v-kazahstane-podverglis-promyshlennye-sektora.
[25] Hiller, J., Kisska‐Schulze, K., & Shackelford, S. (2024). Cybersecurity carrots and sticks. American Business Law Journal, 61(1), 5-29. doi: 10.1111/ablj.12238.
[26] How digital forensics solved famous cybercrime cases? Real-life cases solved using digital evidence. (2025). Retrieved from https://www.webasha.com/blog/how-digital-forensics-solved-famous-cybercrime-cases-real-life-cases-solved-using-digital- evidence.
[27] Incident overview for Q1 2024. (2024). Retrieved from https://cert.gov.kz/news/11/2641.
[28] International Monetary Fund, & Monetary and Capital Markets Department. (2024). Cyber risk: A growing concern for macrofinancial stability. In Global financial stability report: The last mile: Financial vulnerabilities and risks (pp. 53-76).Washington: International Monetary Fund.
[29] INTERPOL. (2022). Financial and cybercrimes top global police concerns, says new INTERPOL report. Retrieved from https://www.interpol.int/News-and-Events/News/2022/Financial-and-cybercrimes-top-global-police-concerns-says-new-INTERPOL-report.
[30] Ishekenova, B. (2023). Kazakhstani companies lose millions due to hacker attacks. Retrieved from https://lsm.kz/kazahstanskie-kompanii-teryayut-milliony-iz-za-hakerskih-atak.
[31] Jekebayeva, M., Iztaeva, V., Anassova, K., & Manapbayev, N. (2023). Cybersecurity: Importance for Kazakhstan and international experiences. Bulletin of Ablai Khan KazUIRandWL Series “International Relations and Regional Studies”, 54(4). doi: 10.48371/ ismo.2023.54.4.005.
[32] Jilkishiyev, R., & Begaliyev, Y. (2024). Problems of investigation of crimes in the field of information technology. Pakistan Journal of Criminology, 16(3), 97-114. doi: 10.62271/pjc.16.3.97.114.
[33] Kadena, E., & Gupi, M. (2021). Human factors in cybersecurity. Security Science Journal, 2(2), 51-64. doi: 10.62271/ pjc.16.3.97.114.
[34] Karafili, E., Wang, L., & Lupu, E.C. (2020). An Argumentation-Based Reasoner to assist digital investigation and attribution of cyber-attacks. Forensic Science International Digital Investigation, 32, article number 300925. doi: 10.1016/j.fsidi.2020.300925.
[35] Kassymzhanova, A.A., Usseinova, G.R., Baimakhanova, D.M., Ibrayeva, A.S., & Ibrayev, N.S. (2022). Legal framework for external security of the Republic of Kazakhstan. International Journal of Electronic Security and Digital Forensics, 14(2), 209-222. doi: 10.1504/IJESDF.2022.121180.
[36] Kazakhtelecom announced DDoS attacks from abroad on Kazakhstan’s information resources. (2022). Retrieved from https://zonakz.net/2022/09/26/kazaxtelekom-zayavil-o-ddos-atakax-iz-za-rubezha-na-informresursy-kazaxstana/.
[37] Kobets, M. (2023). Extraction of information from a cellular phone (mobile communication device) during investigative (search) actions. Scientific Journal of the National Academy of Internal Affairs, 28(2), 52-60. doi: 10.56215/naia-herald/2.2023.52.
[38] Kuek, A., & Hakkennes, S. (2020). Healthcare staff digital literacy levels and their attitudes towards information systems. Health Informatics Journal, 26(1), 592-612. doi: 10.1177/1460458219839613.
[39] KZ-CERT. (n.d). Incidents statistics. Retrieved from https://cert.gov.kz/press_club/infographics.
[40] KZ-CERT. National computer emergency response team. (n.d.). Retrieved from https://cert.gov.kz/.
[41] KZ-FinCERT. team information. (n.d.). Retrieved from https://www.first.org/members/teams/kz-fincert.
[42] Law of the Republic of Kazakhstan No. 418-V “On Informatization”. (2015, November). Retrieved from https://adilet.zan.kz/ eng/docs/Z1500000418.
[43] Lehto, M. (2022). Cyber-attacks against critical infrastructure. In M. Lehto & P. Neittaanmäki (Eds.), Cyber security: Critical infrastructure protection (pp. 3-42). Cham: Springer. doi: 10.1007/978-3-030-91293-2_1.
[44] Leyden, J. (2023). Bug Bounty Radar // The latest bug bounty programs for March 2023. Retrieved from https://portswigger.net/daily-swig/bug-bounty-radar-the-latest-bug-bounty-programs-for-march-2023.
[45] Li, Y., & Liu, Q. (2021). A comprehensive review study of cyber-attacks and cyber security; Emerging trends and recent developments. Energy Reports, 7, 8176-8186. doi: 10.1016/j.egyr.2021.08.126.
[46] Llazo, E., Ryspaeva, A., Kubiczek, J., Mehdiyev, V., & Ketners, K. (2024). Trends and prospects of financial system development in the context of digitalization. Theoretical and Practical Research in the Economic Fields, 15(4), 783-797. doi: 10.14505/tpref. v15.4(32).01.
[47] Lysenko, S., Bobro, N., Korsunova, K., Vasylchyshyn, O., & Tatarchenko, Y. (2024). The role of artificial intelligence in cybersecurity: Automation of protection and detection of threats. Economic Affairs, 69, 43-51. doi: 10.46852/0424- 2513.1.2024.6.
[48] Mazur, T., & Flogaitis, S. (2023). Electronic parliament as a factor of sustainable development: History and prospects. Law Journal of the National Academy of Internal Affairs, 13(2), 19-29. doi: 10.56215/naia-chasopis/2.2023.19.
[49] Metelskyi, I., & Kravchuk, M. (2023). Features of cybercrime and its prevalence in Ukraine. Law, Policy and Security, 1(1), 18-25.
[50] Mitsarakis, K. (2023). Contemporary cyber threats to critical infrastructures: Management and counter-measures. Thessaloniki: International Hellenic University.
[51] Naprys, E. (2024). Germany plans to decriminalize whitehat hacking. Retrieved from https://cybernews.com/security/germany- plans-to-decriminalize-whitehat-hacking/.
[52] Naseer, I. (2024). The role of artificial intelligence in detecting and preventing cyber and phishing attacks. European Journal of Engineering Science and Technology, 11(9), 82-86.
[53] New types of fraud have emerged in Kazakhstan. (2024). Retrieved from https://dknews.kz/ru/finansy/348558-v-kazahstane- poyavilis-novye-vidy-moshennichestva.
[54] Nurbatyrova, R., Japarov, B., Apakhayev, N., Abdulaziz, B., & Khushkeldiyeva, S. (2024). Digital transformation of archives in the context of the introduction of an electronic document management system in Kazakhstan. Preservation, Digital Technology and Culture, 53(3), 147-155. doi: 10.1515/pdtc-2024-0017.
[55] Ofori, A.Y., & Akoto, D. (2020). Digital forensics investigation jurisprudence: Issues of admissibility of digital evidence. HSOA Journal of Forensic, Legal & Investigative Sciences, 6, article number 045. doi: 10.24966/FLIS-733X/100045.
[56] Only 5% of cybercrime cases reach court in Kazakhstan. (2023). Retrieved from https://surl.gd/mqento.
[57] Order of the Minister of Digital Development, Innovation and Aerospace Industry of the Republic of Kazakhstan No. 175/НК “On Determining the Amount of Payment for Services of State Registration of Civil Status Acts”. (2023, June). Retrieved from https://adilet.zan.kz/rus/docs/V2300032755.
[58] OSCE trains Central Asian law enforcement experts to combat cybercrime through open source digital forensics. (2022). Retrieved from https://www.osce.org/secretariat/518697.
[59] Our World in Data. (2023). Democracy index. Retrieved from https://ourworldindata.org/grapher/democracy-index- eiu#research-and-writing.
[60] Over 223 million cyberattack attempts by foreign hackers on Kazakhstan in 2023. (2024). Retrieved from https://www.kt.kz/ rus/society/bolee_223_mln_popytok_kiberatak_soversheno_ot_zarubezhnyh_1377959819.html.
[61] Penal Code of the Republic of Kazakhstan. (2014, July). Retrieved from https://adilet.zan.kz/eng/docs/K1400000226.
[62] Phishing and social engineering: Virtual communication awareness training DS-IA103.06. (n.d.). Retrieved from https://www.cdse.edu/Training/eLearning/DS-IA103/.
[63] Pollini, A., Callari, T.C., Tedeschi, A., Ruscio, D., Save, L., Chiarugi, F., & Guerri, D. (2022). Leveraging human factors in cybersecurity: An integrated methodological approach. Cognition Technology & Work, 24, 371-390. doi: 10.1007/s10111-021- 00683-y.
[64] Regulation of the European Parliament and of the Council No. 2016/679 “On the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation)”. (2016, April). Retrieved from https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng.
[65] Report on the implementation of the Strategic Plan of the Ministry of Digital Development, Innovations and Aerospace Industry of the Republic of Kazakhstan for 2020-2024. (2021). Retrieved from https://www.gov.kz/memleket/entities/mdai/documents/details/130694?lang=kk.
[66] Resolution of the Government of the Republic of Kazakhstan No. 407 “On Approval of the Concept of Cybersecurity” (“Cyber Shield of Kazakhstan”). (2017, June). Retrieved from https://adilet.zan.kz/rus/docs/P1700000407.
[67]
Saraswat, A., & Tiwari, G. (2025). United Nations and beyond: Legal strategies for defending critical energy infrastructure against cyber attacks. In M. Chawki & A. Abraham (Eds.), Cybercrime unveiled: Technologies for analysing legal complexity. Studies in computational intelligence (pp. 291-307). Cham: Springer. doi: 10.1007/978-3-031-80557-8_13.
[68] Satbayeva, A.M., Alimbetova, A.R., & Beissenbayeva, M.T. (2024). Cybercrime challenges: Experience of international cooperation. Bulletin of Institute of Legislation and Legal Information of the Republic of Kazakhstan, 3(78), 211-221. doi: 10.52026/2788-5291_2024_78_3_211.
[69] Shaisultanov, S., Akimzhanov, T., Abdrakhmanov, B., Bazarlinova, A., & Bazarlinova, A. (2024). Combating internet fraud through operative-search measures. Law, State & Telecommunications Review, 16(2), 257-275. doi: 10.26512/lstr.v16i2.50740.
[70] Shandler, R., & Gomez, M.A. (2023). The hidden threat of cyber-attacks – undermining public confidence in government. Journal of Information Technology & Politics, 20(4), 359-374. doi: 10.1080/19331681.2022.2112796.
[71] Sobirov, S. (2023). Comparative legal analysis of the regulation of electronic evidence in criminal proceedings: The experience of the USA, EU, and CIS countries. Society and Innovations, 4(5), 96-117.
[72] Tabrez, Y.E. (2020). National cybersecurity innovation. West Virginia Law Review, 123(2), 483-546.
[73] Tokayev signs law banning collection of copies of identity documents. (2023). Retrieved from https://atpress.kz/ru/news/v- kazakhstane/tokaev-podpisal-zakon-zapreshchayushchij-sbor-kopij-dokumentov-udostoveryayushchikh-lichnost.
[74] Turlybek, S. (2023). International cyber conference held at Almaty Academy of the Ministry of Internal Affairs. Retrieved from https://polisia.kz/ru/mezhdunarodnaya-kiberkonferentsiya-provdena-v-almatinskoj-akademii-mvd/.
[75] Turlybek, S. (2024). The Ministry of Internal Affairs has created a department to combat cybercrime. Retrieved from https://polisia.kz/ru/v-mvd-sozdan-departament-po-protivodejstviyukiberprestupnosti/.
[76] UNODC and partners conducted a regional seminar “Specific Features of the Investigation of Criminal Cases on Cybercrime: International Cooperation, Experience, Trends, Tactics and Problems” in Kazakhstan. (n.d.). Retrieved from https://www.unodc.org/roca/en/NEWS/Archive/unodc-and-partners-conducted-a-regional-seminar-specific-features-of-the-investigation-of-criminal-cases-on-cybercrime_-international-cooperation--experience--trends--tactics-and-problems-in-kazakhstan.html.
[77] Vuković, M., & Štefanac, T. (2023). Digital cultural heritage, cybersecurity, and the human factor. Preservation, Digital Technology & Culture, 52(4), 129-141. doi: 10.1515/pdtc-2023-0040.
[78] Walshe, T., & Simpson, A. (2020). An empirical study of bug bounty programs. In X. Luo, W. Shang, X. Sun & T. Zhang (Eds.), Proceedings of the 2020 IEEE 2nd international workshop on intelligent bug fixing (IBF) (pp. 35-44). London: Institute of Electrical and Electronics Engineers. doi: 10.1109/IBF50092.2020.9034828.
[79] Where is the rise of cyber attacks observed in Kazakhstan? (2023). Retrieved from https://bluescreen.kz/gdie-nabliudaietsia- rost-kibieratak-v-kazakhstanie/.
[80] Yamin, M.M., Ullah, M., Ullah, H., & Katt, B. (2021). Weaponized AI for cyber attacks. Journal of Information Security and Applications, 57, article number 102722. doi: 10.1016/j.jisa.2020.102722.
[81] Zabikh, S. (2020). International experience of legal support of information security and the possibilities for its application in the Republic of Kazakhstan. Political Science Review, 3, 71-85. doi: 10.14746/pp.2020.25.3.6.
[82] Zeadally, S., Adi, E., Baig, Z., & Khan, I.A. (2020). Harnessing artificial intelligence capabilities to improve cybersecurity. IEEE Access, 8, 23817-23837. doi: 10.1109/access.2020.2968045.
[83] Zhakenov, K., Kultemirova, L. & Ibraeva, A. (2024). Comparative analysis of the activities of authorities to ensure the prevention of offenses in the Republic of Kazakhstan and other world countries. Security Journal, 37, 1430-1446. doi: 10.1057/s41284- 024-00425-5.
[84] Zhumagali, A. (2024). 158 executives punished for corruption since the beginning of the year in Kazakhstan. Retrieved from https://ulysmedia.kz/news/22683-158-rukovoditelei-nakazali-za-korruptsiiu-s-nachala-goda-v-kazakhstane/.