<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Insights - Adventure Spirit Consulting</title>
  <link>https://adventurespirit.hr/en/blog/</link>
  <atom:link href="https://adventurespirit.hr/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
  <description>Expert articles on the Croatian Cybersecurity Act, the 13 measures of the Regulation, self-assessment scoring, incident reporting, ISO standards and risk management.</description>
  <language>en</language>
  <item>
    <title>How the self-assessment is actually scored: the Pi and T thresholds</title>
    <link>https://adventurespirit.hr/en/blog/how-self-assessment-is-scored/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/how-self-assessment-is-scored/</guid>
    <category>Self-assessment</category>
    <pubDate>Tue, 01 Sep 2026 09:00:00 +0200</pubDate>
    <description>An explanation of the scoring system in the ZSIS evaluation framework: the minimum threshold per control, the additional average threshold per sub-measure, and why formal compliance is not enough.</description>
  </item>
  <item>
    <title>Active Directory: five findings we see in almost every assessment</title>
    <link>https://adventurespirit.hr/en/blog/active-directory-attack-paths/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/active-directory-attack-paths/</guid>
    <category>Offensive security</category>
    <pubDate>Tue, 18 Aug 2026 09:00:00 +0200</pubDate>
    <description>The most common findings in Active Directory security assessments: legacy protocols, excessive delegation, passwords in attributes, stale privileged group membership, and access to domain backups.</description>
  </item>
  <item>
    <title>Security culture: why training does not change behaviour, and what does</title>
    <link>https://adventurespirit.hr/en/blog/security-culture-and-the-human-factor/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/security-culture-and-the-human-factor/</guid>
    <category>Human factor</category>
    <pubDate>Tue, 11 Aug 2026 09:00:00 +0200</pubDate>
    <description>How to approach security awareness so it changes behaviour rather than just producing records: what to measure, building a reporting culture, and the link to measure 5 of Annex II.</description>
  </item>
  <item>
    <title>AI in defence: where it genuinely helps and where it just moves the problem</title>
    <link>https://adventurespirit.hr/en/blog/ai-in-defence-where-it-helps/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/ai-in-defence-where-it-helps/</guid>
    <category>Artificial intelligence</category>
    <pubDate>Tue, 04 Aug 2026 09:00:00 +0200</pubDate>
    <description>A realistic assessment of applying AI in cyber defence: where it delivers measurable benefit, where it creates false confidence, and which controls to put in place before adopting it.</description>
  </item>
  <item>
    <title>NIST CSF 2.0 and the Govern function: a framework that finally named the board</title>
    <link>https://adventurespirit.hr/en/blog/nist-csf-2-govern-function/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/nist-csf-2-govern-function/</guid>
    <category>Frameworks</category>
    <pubDate>Tue, 28 Jul 2026 09:00:00 +0200</pubDate>
    <description>What the Govern function brings to NIST Cybersecurity Framework 2.0, how the six functions map to the 13 measures of the Croatian Cybersecurity Regulation, and why the framework is worth using as a common language with the board.</description>
  </item>
  <item>
    <title>The cybersecurity audit: who may perform it and how it runs</title>
    <link>https://adventurespirit.hr/en/blog/cybersecurity-audit-how-it-works/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/cybersecurity-audit-how-it-works/</guid>
    <category>Self-assessment</category>
    <pubDate>Tue, 21 Jul 2026 09:00:00 +0200</pubDate>
    <description>How the independent cybersecurity audit of essential entities runs: who may perform it, the steps of the process, how the auditor scores documentation and implementation, and which evidence is most often rejected.</description>
  </item>
  <item>
    <title>The AI system inventory and the asset register: why they are one list</title>
    <link>https://adventurespirit.hr/en/blog/ai-inventory-and-asset-register/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/ai-inventory-and-asset-register/</guid>
    <category>Artificial intelligence</category>
    <pubDate>Tue, 14 Jul 2026 09:00:00 +0200</pubDate>
    <description>How to extend an existing information asset register so it covers the AI Act&#x27;s inventory requirements, instead of maintaining a separate register of AI systems.</description>
  </item>
  <item>
    <title>What cyber insurers actually ask before they quote</title>
    <link>https://adventurespirit.hr/en/blog/what-cyber-insurers-actually-ask/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/what-cyber-insurers-actually-ask/</guid>
    <category>Cyber insurance</category>
    <pubDate>Tue, 07 Jul 2026 09:00:00 +0200</pubDate>
    <description>Which questions recur in cyber insurance questionnaires, why premium and cover are tied to specific controls, and how to use your existing compliance evidence in the negotiation.</description>
  </item>
  <item>
    <title>Prohibited practices and AI literacy: two provisions already in force</title>
    <link>https://adventurespirit.hr/en/blog/prohibited-practices-and-ai-literacy/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/prohibited-practices-and-ai-literacy/</guid>
    <category>Artificial intelligence</category>
    <pubDate>Tue, 30 Jun 2026 09:00:00 +0200</pubDate>
    <description>Which practices the AI Act prohibits outright, what the AI literacy obligation in Article 4 means, and how to satisfy it without building a separate training programme.</description>
  </item>
  <item>
    <title>Penalties under the Croatian Cybersecurity Act: who pays, how much, and why it is personal</title>
    <link>https://adventurespirit.hr/en/blog/penalties-under-the-cybersecurity-act/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/penalties-under-the-cybersecurity-act/</guid>
    <category>CSA / NIS2</category>
    <pubDate>Tue, 23 Jun 2026 09:00:00 +0200</pubDate>
    <description>The penalty provisions of the Croatian Cybersecurity Act: ranges for essential and important entities, personal liability of management body members, the circumstances affecting the amount, and the rule against double punishment with the data protection authority.</description>
  </item>
  <item>
    <title>The DORA register of information: it fails on data, not on the rules</title>
    <link>https://adventurespirit.hr/en/blog/dora-register-of-information/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/dora-register-of-information/</guid>
    <category>DORA</category>
    <pubDate>Tue, 16 Jun 2026 09:00:00 +0200</pubDate>
    <description>What DORA requires in the register of information on contractual arrangements with ICT service providers, why populating it stalls on data quality, and how to connect it to your existing asset and risk registers.</description>
  </item>
  <item>
    <title>The AI Act: four risk levels and the question that comes first</title>
    <link>https://adventurespirit.hr/en/blog/ai-act-risk-levels/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/ai-act-risk-levels/</guid>
    <category>Artificial intelligence</category>
    <pubDate>Tue, 02 Jun 2026 09:00:00 +0200</pubDate>
    <description>How the EU AI Act divides systems into four risk levels, what makes a system high-risk, and why classification has to start from an inventory of the AI systems in your organisation.</description>
  </item>
  <item>
    <title>A BIA that produces a usable RTO, not a number everyone ignores</title>
    <link>https://adventurespirit.hr/en/blog/bia-that-produces-a-usable-rto/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/bia-that-produces-a-usable-rto/</guid>
    <category>Business continuity</category>
    <pubDate>Tue, 26 May 2026 09:00:00 +0200</pubDate>
    <description>How to run a business impact analysis under ISO 22301 so that RTO and RPO are usable: who supplies the data, how to avoid everything being critical, and how the BIA connects to measure 12 of the Croatian Cybersecurity Regulation.</description>
  </item>
  <item>
    <title>ISO 27002:2022: 93 controls and the five attributes most people skip</title>
    <link>https://adventurespirit.hr/en/blog/iso-27002-2022-control-attributes/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/iso-27002-2022-control-attributes/</guid>
    <category>ISO standards</category>
    <pubDate>Tue, 05 May 2026 09:00:00 +0200</pubDate>
    <description>What changed in ISO/IEC 27002:2022 - four themes instead of fourteen clauses, 93 controls and five attributes. How to migrate an existing Statement of Applicability without losing the evidence base.</description>
  </item>
  <item>
    <title>24 hours, 72 hours, 30 days: deadlines that run in parallel</title>
    <link>https://adventurespirit.hr/en/blog/incident-reporting-deadlines/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/incident-reporting-deadlines/</guid>
    <category>Incidents</category>
    <pubDate>Tue, 14 Apr 2026 09:00:00 +0200</pubDate>
    <description>Deadlines for reporting a significant cyber incident under the Croatian Cybersecurity Act: early warning within 24 hours, notification within 72 hours, final report within 30 days, and the parallel notification under Article 33 GDPR.</description>
  </item>
  <item>
    <title>A risk register that passes review: five recurring mistakes</title>
    <link>https://adventurespirit.hr/en/blog/risk-register-that-passes-review/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/risk-register-that-passes-review/</guid>
    <category>Risk management</category>
    <pubDate>Tue, 24 Mar 2026 09:00:00 +0200</pubDate>
    <description>The most common mistakes in risk registers that surface during compliance reviews: no link to the asset inventory, risks without owners, scores without reasoning, treatment plans without deadlines, and a register that never changes.</description>
  </item>
  <item>
    <title>You hold ISO 27001. How much is it worth under the Cybersecurity Act?</title>
    <link>https://adventurespirit.hr/en/blog/iso-27001-and-the-cybersecurity-act/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/iso-27001-and-the-cybersecurity-act/</guid>
    <category>ISO standards</category>
    <pubDate>Tue, 03 Mar 2026 09:00:00 +0200</pubDate>
    <description>How much of the 13 measures of the Croatian Cybersecurity Regulation is covered by ISO/IEC 27001:2022, where the real gaps are, and how to map existing controls instead of writing new documentation.</description>
  </item>
  <item>
    <title>The correlation overview: the document that halves your work</title>
    <link>https://adventurespirit.hr/en/blog/correlation-of-measures-to-standards/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/correlation-of-measures-to-standards/</guid>
    <category>CSA / NIS2</category>
    <pubDate>Tue, 24 Feb 2026 09:00:00 +0200</pubDate>
    <description>What the correlation overview required by Article 49 of the Croatian Cybersecurity Regulation is, which standards it maps to, and how to use it so existing ISO or NIST documentation is not written twice.</description>
  </item>
  <item>
    <title>13 measures, 99 sub-measures, 132 controls: the anatomy of Annex II</title>
    <link>https://adventurespirit.hr/en/blog/thirteen-measures-annex-ii/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/thirteen-measures-annex-ii/</guid>
    <category>CSA / NIS2</category>
    <pubDate>Tue, 10 Feb 2026 09:00:00 +0200</pubDate>
    <description>A complete overview of the 13 cyber risk management measures from Annex II of the Croatian Cybersecurity Regulation: sub-measures per measure, what each asks for in practice, and how they connect to the control catalogue.</description>
  </item>
  <item>
    <title>Entity categorisation under the Croatian Cybersecurity Act, and what follows from it</title>
    <link>https://adventurespirit.hr/en/blog/entity-categorisation-croatian-cybersecurity-act/</link>
    <guid isPermaLink="true">https://adventurespirit.hr/en/blog/entity-categorisation-croatian-cybersecurity-act/</guid>
    <category>CSA / NIS2</category>
    <pubDate>Tue, 20 Jan 2026 09:00:00 +0200</pubDate>
    <description>How it is determined whether you are an essential or an important entity under the Croatian Cybersecurity Act, which deadlines run from the categorisation notice, and how the duties of the two groups differ.</description>
  </item>
</channel>
</rss>
