
Do you know what software is installed on your company’s computers right now? Not according to the accounting records, but in reality – including devices used by remote employees and equipment belonging to contractors with access to internal systems.
Over the past year, the stakes have risen sharply. Since November 2025, using unlicensed software can carry the risk of criminal liability and pirated distributions have become one of the channels through which malicious code enters corporate networks.
Legal risk: new requirements for business
Uzbekistan has enacted amendments to copyright legislation that toughen liability for illegal use of software – Law No. ZRU-1080. Since November 2025, Article 149-1 of the Criminal Code has also been in force, providing for liability for illegal use of copyrighted works. The maximum penalty is up to three years’ imprisonment.
The scale of the problem is reflected in international estimates. According to the most recent assessment by the BSA in its Global Software Survey (2018), 37% of software installed on computers worldwide was unlicensed, with a commercial value of $46.3 bn. The same report estimated that companies spend nearly $359 bn a year dealing with the fallout from infections linked to unlicensed software.
“What you should really compare isn’t the price of a license, but the cost of a single incident. Recovery after a breach, legal costs, and conversations with partners whose data has leaked – combined, these outweigh years’ worth of savings on software,” said Dmitry Shulikov, Head of Information Security at Beeline Uzbekistan.
There’s also a broader context to these changes. By early 2026, Uzbekistan had completed bilateral WTO accession talks with 33 of 34 countries and expects to finish the process this year. Membership means joining the TRIPS Agreement, which requires member states to establish criminal liability for at least willful copyright infringement on a commercial scale – not only to adopt such rules, but also to ensure procedures that allow for their effective enforcement.
In addition, information security experts view unlicensed software distributions as a potential entry point for malware into corporate networks.
Technical risk: software as an entry point

According to the Verizon Data Breach Investigations Report 2025, credential compromise remained the most common method of initial access for attackers into corporate systems for the second year running, accounting for 22% of investigated incidents. Infostealers – malware that often disguises itself as free versions of popular commercial software – remain one of the main channels for spreading these threats.
The same report found corporate credentials on 30% of corporate-managed devices and on 46% of devices outside corporate management – personal employee laptops and contractor equipment.
“In practice, most incidents don’t start with sophisticated technical attacks – they start with compromised credentials. And the source of the leak can be inside the company just as easily as on an employee’s home computer,” Shulikov notes.
Cyber incidents can also originate not from an attack on the company itself but through its partners, contractors, or suppliers who have access to corporate data and services. According to Verizon, the share of such third-party incidents rose from 15% to 30% over the past year, making the security of a business’s entire digital ecosystem just as important as protecting its own infrastructure.
Another distinctive feature of modern attacks lies in the tools used. Infostealer malware can steal not only saved passwords but also session cookies. This allows attackers to gain access to already-authenticated accounts, bypassing password checks and, in some cases, multi-factor authentication. That’s why two-factor authentication alone is no longer enough: companies also need to monitor active user sessions, track device status and detect signs of compromise in time.
How to assess your company’s situation: five steps

A practical minimum to work through before the question is raised externally.
- Take inventory. Compile a list of software actually installed on every workstation and server.
- Check contractors and remote workstations. Employees’ personal laptops and contractors’ equipment with access to corporate systems carry the same risk as office computers.
- Check for credential leaks. Find out whether corporate email addresses show up in known breaches, and force password and active-session resets wherever there’s doubt.
- Turn on what you’re already paying for. Multi-factor authentication, role-based access, logging and mail filtering are included in standard corporate subscriptions but are often not enabled by default.
- Put the policy in writing. A written policy on which software is allowed and who approves it is a basic document for any audit.
How to reduce the risks
Companies that go through software legalization typically tackle several tasks at once: taking inventory of installed software, migrating to licensed solutions, and setting up baseline information security measures.
As a Microsoft partner, Beeline Business helps conduct software audits and organize the transition to Microsoft 365 corporate licenses and Azure cloud services without disrupting business operations.
“Today, licensed software can no longer be viewed purely as a matter of regulatory compliance. For businesses, it’s simultaneously a question of IT infrastructure resilience, data protection, and corporate risk management. And the sooner a company gets a full picture of what software is actually running in its infrastructure, the cheaper it is to fix potential problems,” said Shulikov.
More information on corporate licenses and cloud services is available on the Beeline Business website.
About Beeline Uzbekistan
Beeline Uzbekistan (Unitel LLC) has been operating as a digital operator under the trademark since September 12, 2006. Beeline Uzbekistan is one of the largest taxpayers in the country and has paid an estimated $2,1 bn in taxes during its operations in Uzbekistan. Beeline Uzbekistan, with more than 2,000 employees, is a Certified Top Employer 2024, 2025and 2026.
Beeline Uzbekistan is part of the VEON Group. VEON has invested more than $1.6 bn into Uzbekistan’s telecommunications sector since 2006, when the Group first entered the market.
VEON is a digital operator that provides connectivity and digital services over 150 mln connectivity and 229 mln digital users. Operating across five countries that are home to more than 6% of the world’s population, VEON is transforming lives through technology-driven services that empower individuals and drive economic growth. VEON is listed on NASDAQ. For more information, visit: https://www.veon.com.
Website: beeline.uz
Facebook: @beeline.uz
Instagram: @beeline_uzbekistan
Telegram: @beelineuzbekistan
X: @beeline_uz
LinkedIn: @beeline-uzbekistan