Home / Business and Politics / Investment in the Education of Cybersecurity Experts is a Matter of National Interest

Investment in the Education of Cybersecurity Experts is a Matter of National Interest

On Friday, the first conference on the new Cybersecurity Regulation, which was put out for public consultation last Tuesday, was held in a packed Algebra Spark Space. Among other topics, the discussion focused on the global need for raising competencies, retraining, and additional education for experts in the field of cybersecurity. The conference brought together experts and industry representatives who exchanged experiences, knowledge, and perspectives on the new legal frameworks regulating cybersecurity.

On Tuesday, October 8, 2024, the Cybersecurity Regulation, enacted under the Cybersecurity Act, was published for public consultation. It prescribes criteria for the categorization of entities and the measures or controls that obligated parties must implement, as well as the criteria for reporting significant incidents. In this process, after entities are informed by the competent authority of their category and the measures applicable to them, it is crucial to understand the scope of implementing specific measures, following a prior assessment (gap analysis) of the current maturity level of the applied measures and those that each entrepreneur needs to implement, along with planning an adequate budget for the implementation of specific measures.

– Given the constant advancement of technology, cyber threats are becoming increasingly sophisticated and harder to detect. Today’s attacks can involve highly sophisticated methods such as ‘zero-day’ exploits, which exploit vulnerabilities in software that are not yet known or patched by the manufacturer. Additionally, advanced phishing is used to target specific individuals through tailored messages that appear extremely convincing. Social engineering techniques have also advanced; attackers conduct thorough preparations to make their methods as effective as possible. The greatest threats still come from individuals who are not sufficiently educated and thus make mistakes – emphasized Robert Petrunić, a lecturer at the newly launched Cybersecurity Study at Algebra University.

Irena Weber, the CEO of HUP, had the honor of opening the conference, and in her introductory speech, she highlighted the perspective of entrepreneurs in digital transformation and the development of cybersecurity.

– Cybersecurity is no longer considered solely within the IT sector, but much broader. HUP participated in drafting the law to assist companies and the entire economy. The provisions help entrepreneurs adapt their business and ensure a secure digital future for all. The new Cybersecurity Act brings numerous obligations but also opportunities. By introducing a higher level of security, our companies have the chance to secure customer trust and become more competitive in the global market. The law provides us all with opportunities for further growth, and this conference and additional education on cybersecurity are a significant and important step in the right direction, and I believe it will ensure a secure future for all of us – said Weber.

With the Cybersecurity Act, on February 15, the functionality of a central state body for cybersecurity was established, which will be performed by SOA, and for this purpose, the existing Cybersecurity Center of SOA will be transformed into the National Cybersecurity Center (NCSC-HR). On this occasion, Aleksandar Klaić from the Cybersecurity Center of SOA reflected on the detection, early warning, and protection against cyber attacks and presented a development plan and awareness-raising for the broader population about cybersecurity.

– Due to the seriousness of the entire process, everything needs to be accompanied in a new organizational way in which the enacted law will assist us. SOA will focus in the coming weeks and months on the core issues occurring in cybersecurity worldwide, namely, insufficient awareness of cybersecurity risks. However, this is not only true for Croatia or the EU but for most countries in the world – Klaić began.

– We must consider the entire regulatory framework. A significant amount of work awaits us, but the deadlines are set liberally, not to avoid work, but to develop a culture of risk management and to raise the maturity level of cybersecurity in all key segments, whether they are state or private entities – he explained, adding that the Ministry of Defense (MORH) and the Ministry of the Interior (MUP) provide support. Indeed, MORH plays an important role in the military or defense sector, while MUP combats cybercrime.

– The process must be completed by April 2025, as we must have an initial list for the European Commission by then. The initial categorization will be conducted no later than March 2025, by which time you will receive a notification about the categorization, and then the obligations for entrepreneurs will commence. After April 2025, the implementation of measures in entities will follow within a year. You had a year to study the Law, and now you have another year to implement the measures. The deadlines are not very tight but are liberal because we expect a partnership relationship from the entire society. Measures and penalties must be prescribed because the law is nothing but a security policy – Klaić conveyed to the gathered entrepreneurs, adding that if the mentioned measures are not implemented, economic growth will be impossible.

Krešimir Šipek from the Institute for Information Security spoke about the implementation of self-assessment of cybersecurity. Self-assessment of cybersecurity in key entities can be conducted as preparation for the implementation of a cybersecurity audit. It should be conducted at least once every two years with the help of internal resources or external service providers. Self-assessment is crucial for establishing systematic risk management at the organizational level, better understanding and protection of one’s IT infrastructure, and raising awareness of cybersecurity among employees, as well as strengthening the resilience of the entire digital society, which is one of the key points of the NIS2 directive.

Marina Dimić Vugec from the National CERT explained the role of the Pixi platform through which incidents, threats, and information are reported and exchanged at the national and European levels, emphasizing that the primary goal of the new Law is to align the resilience levels of EU member states to cyber threats.

The panel on skills featured Ivona Loparić, information security consultant, Diverto; Goran Car, CEO, Combis; Andro Galinović, CEO for information security, Infobip; Bruno Pavić, security and intelligence expert, ProForca; and Robert Petrunić, lecturer at the newly launched Cybersecurity Study at Algebra University.

– The key word is interdisciplinarity, which means strengthening soft skills alongside these technical skills. One cannot live on past glory in cybersecurity; it is essential to continuously raise knowledge and competencies. That is why we launched a new, the first Cybersecurity Study in Croatia at Algebra University, which this year welcomed its first generation of students who will soon enter the job market – said Petrunić.

The panel concluded that it is necessary to first educate the broader society, then industry representatives, and finally the cybersecurity experts themselves, as it is clear today that much greater attention must be paid to this area. Regular training and education on the latest security threats, as well as the implementation of advanced security solutions, such as behavioral analysis and artificial intelligence for detecting anomalies in network traffic, are key to defending against sophisticated attacks.

On the topic of Security Controls and Technologies in Cybersecurity, the panel included Tamara Hađina, head of research projects, Končar; Boris Bajtl, vice president of the Croatian Institute for Cybersecurity; Jurica Čular, information security expert, Infobip; Saša Jusić, senior information security consultant, Infigo; and Sven Škrgatić, head of corporate security, A1.

– In the process of introducing a cybersecurity risk control methodology, people are the most important; they need education, at a general level, to recognize threats and respond appropriately because it is not intuitive, which is why it is good to discuss this topic at today’s event. The Regulation has already achieved great success even before it was adopted, as there is much discussion about cybersecurity, which is certainly one of the goals – said Boris Bajtl, vice president of the Croatian Institute for Cybersecurity.

– Regulations and legislative documents are often poorly written, which was not the case with this Regulation. They often require companies to undertake activities that are not feasible – said Jurica Čular, information security expert, Infobip.

The third panel discussion titled “Who Controls Us: Challenges and Opportunities for Women in Cybersecurity” focused on the role of women in the world of IT and cybersecurity. Moderated by Martina Dragičević from the telecommunications giant A1, experts in enterprise and client security management discussed the position of women in this challenging sector: Vlatka Jajetić, head of the Cyber Incident Response and Security Management Service, CARNET/National CERT; Marija Portner Marinković, representative of the Office of the National Security Council, SOA; Antonija Vojnović, head of the InfoSec team, SPAN; and Blanka Zubelj, security director, RBA.

Cybersecurity represents one of the specific and very important branches within the STEM field, which is generally recognized as an area where it is also necessary to encourage women from an early age to engage in and develop within it. According to the panelists, ten years ago, a very small number of women were represented in this field, but fortunately, progress is visible, and the interest of women in this very interesting and dynamic STEM area is growing.

Entrepreneurs should certainly seize the opportunity and attend workshops conducted by Algebra, SOA, ZSIS, and CARNET, where clarifications regarding the upcoming obligations are provided. Cyber attacks are increasing, and to prevent them, it is not enough to invest only in technology but also in the people who will use that technology. Given the significant shortage of IT professionals in the country, the solution that will yield the best results lies in the additional education of existing IT specialists and their retraining in the field of cybersecurity – it was concluded at this year’s conference.

Tagged: