Knowledge base
What the rules ask for and what proves it
Articles on the Croatian Cybersecurity Act, ISO standards, data protection and risk management. No generalities: every claim carries the article of the law or standard behind it, where one exists.
CSA / NIS2
13 measures, 99 sub-measures, 132 controls: the anatomy of Annex II
The Croatian Cybersecurity Regulation does not speak of ten NIS2 measures but of thirteen of its own. Beneath them sit 99 sub-measures, and behind those a catalogue of 132 controls with scoring thresholds. This is the map of the whole structure, measure by measure.
Self-assessment
How the self-assessment is actually scored: the Pi and T thresholds
You can satisfy every individual control and still fail the sub-measure. The evaluation framework has two thresholds, and the second one is the surprise. Here is how the formula works and what it means for planning.
Offensive security
Active Directory: five findings we see in almost every assessment
Domain infrastructure rarely falls to an unpatched vulnerability. It falls to configuration that once made sense, was left behind, and that nobody looks at any more. These five findings show up in most environments.
Human factor
Security culture: why training does not change behaviour, and what does
An annual presentation about phishing produces a record, not a change. Measure 5 requires awareness raising, but what actually gets measured is behaviour - and behaviour moves on different levers.
Artificial intelligence
AI in defence: where it genuinely helps and where it just moves the problem
The promise is that a model will catch the attack a human missed. The reality is that models do well on tasks with many examples and a clear outcome, and badly where neither exists - which is exactly where the expensive failures live.
Frameworks
NIST CSF 2.0 and the Govern function: a framework that finally named the board
Version 2.0 added a sixth function above all the others. It is not cosmetic - Govern answers a finding that kept recurring for years: technical controls do not fix an organisation with no owner for its risk.
Self-assessment
The cybersecurity audit: who may perform it and how it runs
Essential entities do not self-assess - they undergo an independent audit. It is carried out by a provider holding the prescribed authorisation, and for state administration bodies by the competent authority. Here is how it runs and what usually is not accepted.
Artificial intelligence
The AI system inventory and the asset register: why they are one list
Organisations that introduce an AI system inventory as a separate document discover a year later that they have two registers drifting apart. The overlap is larger than the difference, and the difference fits into four columns.
Cyber insurance
What cyber insurers actually ask before they quote
A cyber insurance questionnaire is not a formality but a risk assessment somebody else is doing about you. The questions get more specific every year, and an inaccurate answer can become grounds for declining a claim.
Artificial intelligence
Prohibited practices and AI literacy: two provisions already in force
While the debate runs on high-risk systems, two provisions of the AI Act apply first. One bans certain practices outright, the other requires that the people using these systems know what they are doing.
CSA / NIS2
Penalties under the Croatian Cybersecurity Act: who pays, how much, and why it is personal
Up to EUR 10 million or 2 per cent of global turnover for essential entities. But the figure that changes the conversation with a board is the other one: members of the management body are liable personally, out of their own pocket.
DORA
The DORA register of information: it fails on data, not on the rules
The register of contractual arrangements with ICT service providers looks like an administrative exercise until you try to populate it. That is when you discover three departments hold three different supplier lists, and none of them is complete.
Artificial intelligence
The AI Act: four risk levels and the question that comes first
Regulation (EU) 2024/1689 does not govern the technology but its application. The same model can be an unregulated convenience and a high-risk system, depending on what you use it for - which means classification starts with an inventory, not a legal analysis.
Business continuity
A BIA that produces a usable RTO, not a number everyone ignores
Business impact analysis usually ends as a table in which every process has a four-hour RTO. If everything is critical, nothing is - and the recovery plan built on it will not survive the first real outage.
ISO standards
ISO 27002:2022: 93 controls and the five attributes most people skip
The 2022 revision cut 114 controls to 93 and reorganised them into four themes instead of fourteen clauses. The bigger change is the attributes - and they are why an old Statement of Applicability cannot simply be renumbered.
Incidents
24 hours, 72 hours, 30 days: deadlines that run in parallel
The deadlines for reporting a significant incident do not add up and do not wait for one another. And if the incident also involves a personal data breach, a fourth deadline runs alongside them, under a different instrument and to a different authority.
Risk management
A risk register that passes review: five recurring mistakes
The risk register is the document everyone has and almost nobody uses. Five patterns repeat from organisation to organisation, and all five are visible on a first reading.
ISO standards
You hold ISO 27001. How much is it worth under the Cybersecurity Act?
The certificate does not release you from the obligation, but it shortens the path considerably. The question is only which measures it covers, which it touches, and which it does not reach at all - and how to prove that without writing a second set of documentation in parallel.
CSA / NIS2
The correlation overview: the document that halves your work
Article 49 of the Regulation requires a correlation overview mapping every sub-measure onto ISO 27001, ISO 27002, ISO 22301, NIST CSF 2.0, NIST SP 800-53 and CIS v8. Organisations that ignore it write documentation they already have.
CSA / NIS2
Entity categorisation under the Croatian Cybersecurity Act, and what follows from it
You do not choose your category and you do not apply for it. It arrives by letter, and from that day a deadline runs. Here is who decides, on what basis, and what actually changes depending on which group you land in.