The chaos caused by the collapse of the Hrvatski Telekom system has raised numerous questions. From the excessive dependence of institutions on a single operator, for example, on Tuesday the Zagreb Stock Exchange was not operational, medical prescriptions could not be sent, POS devices were not working, and so on, to the question of whether there was a security breach in their system.
„Telecommunications networks in Croatia are stable and secure compared to those in Europe and the rest of the world. However, nothing is perfect, and failures and interruptions can happen to anyone, with the most important thing being to restore normal functioning as soon as possible. The interruption of connections and the failure of HT’s network, in mobile and fixed telephony as well as internet access, is the best indicator of how important electronic communications are in our lives and business. Operators are, like all of us, aware of the fact that we live in a time when various attacks, from hacking and other types, on networks and electronic systems are heard from all over the world,“ explains the regulator HAKOM, for whom, as well as for the operators, it is most important to inform users in a timely manner about everything and to resolve failures as quickly as possible, and when they do, they must also ‘deal’ with apologies to users and their compensation if the failures lasted for a longer period. In Croatia, alongside HT, there are other operators whose operations were not affected.
In accordance with the Electronic Communications Act and the Regulation on the manner and deadlines for implementing measures to protect the security and integrity of networks and services, operators are obliged to implement appropriate technical and organizational measures to protect the security of their services, and together with public communications network operators, take necessary measures to protect the security of electronic communication networks and services, which are detailed in the operators’ security policies and submitted to HAKOM once a year.
„The mentioned measures must also include procedures for risk management, security requirements for personnel, system and facility security, process management, security incident management, business continuity management, and security monitoring and testing. The regulation prescribes these minimum measures and reference standards for their implementation. Therefore, following the issue of security incidents, HAKOM has prescribed within this regulation a detailed procedure for the occurrence of a security incident and activities after the incident has been resolved,“ concludes the regulator.
