CSA / NIS2
Entity categorisation under the Croatian Cybersecurity Act, and what follows from it
You do not choose your category and you do not apply for it. It arrives by letter, and from that day a deadline runs. Here is who decides, on what basis, and what actually changes depending on which group you land in.
20 January 20267 min read
CSA / NIS2
13 measures, 99 sub-measures, 132 controls: the anatomy of Annex II
The Croatian Cybersecurity Regulation does not speak of ten NIS2 measures but of thirteen of its own. Beneath them sit 99 sub-measures, and behind those a catalogue of 132 controls with scoring thresholds. This is the map of the whole structure, measure by measure.
10 February 20269 min read
Self-assessment
How the self-assessment is actually scored: the Pi and T thresholds
You can satisfy every individual control and still fail the sub-measure. The evaluation framework has two thresholds, and the second one is the surprise. Here is how the formula works and what it means for planning.
1 September 20266 min read
Incidents
24 hours, 72 hours, 30 days: deadlines that run in parallel
The deadlines for reporting a significant incident do not add up and do not wait for one another. And if the incident also involves a personal data breach, a fourth deadline runs alongside them, under a different instrument and to a different authority.
14 April 20266 min read
ISO standards
You hold ISO 27001. How much is it worth under the Cybersecurity Act?
The certificate does not release you from the obligation, but it shortens the path considerably. The question is only which measures it covers, which it touches, and which it does not reach at all - and how to prove that without writing a second set of documentation in parallel.
3 March 20267 min read
Risk management
A risk register that passes review: five recurring mistakes
The risk register is the document everyone has and almost nobody uses. Five patterns repeat from organisation to organisation, and all five are visible on a first reading.
24 March 20266 min read
ISO standards
ISO 27002:2022: 93 controls and the five attributes most people skip
The 2022 revision cut 114 controls to 93 and reorganised them into four themes instead of fourteen clauses. The bigger change is the attributes - and they are why an old Statement of Applicability cannot simply be renumbered.
5 May 20266 min read
Business continuity
A BIA that produces a usable RTO, not a number everyone ignores
Business impact analysis usually ends as a table in which every process has a four-hour RTO. If everything is critical, nothing is - and the recovery plan built on it will not survive the first real outage.
26 May 20267 min read
DORA
The DORA register of information: it fails on data, not on the rules
The register of contractual arrangements with ICT service providers looks like an administrative exercise until you try to populate it. That is when you discover three departments hold three different supplier lists, and none of them is complete.
16 June 20267 min read