Serious companies have long taken cybersecurity seriously: statistics show that a serious cyber attack occurs every fourteen seconds worldwide. The last large-scale attack in Croatia was recorded at the beginning of the year when the financial regulator, the Croatian Financial Services Supervisory Agency (Hanfa), was hacked from abroad. Although, according to the claims of the institution’s top officials, no data was compromised, the attack caused many inconveniences and disruptions in daily operations, some of which were resolved weeks later.
The public and private sectors in Croatia should, at least according to the legislator’s idea, become much more resilient to such attacks by implementing the European directive NIS2. This guideline has been incorporated into the new Croatian Cybersecurity Act, which came into force in mid-February. Thus, the implementation of NIS2 is not complete – a series of subordinate regulations still need to be adopted, and their adoption is not only the obligation of the Parliament but also of the European Commission.
However, who needs to align with the NIS2 directive, why, and how, is still not entirely clear in many domestic companies. A survey conducted by the Croatian Chamber of Economy (HGK) on a sample of two hundred respondents shows significant challenges and uncertainties in companies related to compliance, says the head of HGK’s Industry Department Tajana Kesić Šapić.
Furthermore, the concept of ESG (environmental, social, governance), which signifies adherence to environmental and social principles and good corporate governance, has become indispensable in recent years. This topic is particularly relevant as the first mandatory ESG sustainability reports that companies will have to publish alongside financial reports will arrive next year. Mandatory non-financial reporting comes with the Corporate Sustainability Reporting Directive (CSRD), which affects more than fifty thousand companies listed on stock exchanges in the EU and an additional ten thousand outside the Union. Croatia will have to incorporate this regulation into the Accounting Act, the Audit Act, and the Capital Market Act by July 2024.

;