×

Regional Conference on Ransomware Concludes with Cross-Sector Dialogue

04.12.2025

Image for Regional Conference on Ransomware Concludes with Cross-Sector Dialogue

The Western Balkans Cyber Capacity Centre (WB3C) hosted the regional conference Confronting Ransomware: Analysis and Strategy for the Western Balkans” on 2-3 December 2025. The event served as a platform for structured dialogue among key stakeholders from the region and international partners. The discussions were guided by Vanja Madzgalj, our Senior Project Manager, who served as the conference host, ensuring a cohesive and productive exchange of ideas throughout the two-day programme.

The conference was opened by Mr. Marash Dukaj, Minister of Public Administration of Montenegro who stressed the importance of continued development and collaboration, despite significant progress Montenegro has made over the past few years. The critical role of international cooperation was acknowledged by H.E. Anne-Marie Maskay, Ambassador of France to Montenegro, and H.E. Bernarda Gradišnik, Ambassador of Slovenia to Montenegro, highlighting the partnership that established the WB3C.

Over two days, sessions were designed to address the ransomware challenge from distinct professional viewpoints.

Day 1: Understanding the Threat and Response Mechanisms

  • Panel 1: The Operational Threat Landscape. This session provided a technical and strategic overview of ransomware from national and private sector perspectives.
    • Moderator: Igor Kovač, Government Information Security Office of Slovenia (URSIV).
    • Panelists: Dušan Polović (Ministry of Public Administration, Montenegro), Saimir Kapllani (National Cyber Security Authority, Albania), Predrag Puharić (Cyber Security Excellence Centre, BiH), and Mladen Bukilić (Čikom, Montenegro).
    • Key Discussion: The panel detailed the current scale and methods of attacks, emphasizing the need for shared threat intelligence. They looked at how ransomware has been evolving in the recent years and how governments and private sector are preparing for to prevent and respond growing threats. Disparity in defensive resources, especially sophisticated AI capabilities, affects overall organizational esilience.
  • Panel 2: Law Enforcement Perspective on Cybercriminal Organizations. This panel focused on the investigative viewpoint, examining the structure and operations of ransomware groups.
    • Moderator: Francisco Losada, Cybercrime Specialist, EUROPOL.
    • Panelists: Julien Hamm (Anti-cybercrime Office (OFAC), France), Nenad Bogunović (High-Tech Crime Unit, Ministry of Interior, Serbia), and Sreten Ćorić (High-tech Crime Unit, Police Directorate of Montenegro).
    • Key Discussion: Experts outlined the sophisticated, business-like models of cybercriminal groups. Challenges highlighted included the cross-jurisdictional nature of investigations and the constant evolution of adversarial tactics, which require continuous adaptation and closer international police collaboration.
  • Keynote Presentation: A Law Enforcement Blueprint. Captain Pascal Martin of the French Gendarmerie delivered a keynote address, decrypting a successful operation against a ransomware network. His presentation provided a concrete blueprint for combining digital forensics, international judicial cooperation, and public-private intelligence sharing to achieve tangible results.
  • Case Study: The Private Sector Response. Vladimir Mlynar, CISO for VINCI Energies CEE, presented a detailed case study from the private sector. He walked through the operational timeline of a real-world ransomware incident, offering insights into crisis management, communication challenges, and recovery strategies under pressure.
  • Panel 3: The Legal and Jurisdictional Framework. This discussion explored the judicial and prosecutorial challenges in combating ransomware.
    • Moderator: Ana Bukilić, International Development Law Organisation (IDLO).
    • Panelists: Aurélien Brouillet (Deputy Prosecutor, Judicial Court of Paris), Marina Barbir (Judge, Higher Court of Belgrade), and Ivaylo Iliev (Assistant to the National Member for Bulgaria, EUROJUST).
    • Key Discussion: The conversation centered on the complexities of applying national laws to transnational cybercrime. Key challenges involve harmonizing legal standards for evidence collection, ensuring effective prosecutions, and streamlining formal international cooperation channels to keep pace with the speed of cyber incidents. The need for training in digital forensics for prosecutors and judges was emphasized as key in advancing judicial response in cases involving digital evidence and other sophisticated technologies.  
  • Special Session: Technical and Legal Aspects of Cryptocurrency Seizure. This exchange focused on the financial dimension of ransomware response.
    • Participants: Laurent Tisseyre (TRM Labs) and Dr. Arben Murtezić (Legal Counsel and Law Professor).
    • Key Discussion: The dialogue between a technical analyst and a legal expert underscored the difficulty of tracing and immobilizing illicit cryptocurrency payments. Challenges include the need for specialized blockchain forensic tools and navigating varied national regulations for asset seizure and recovery.

Day 2: Evolving Tactics and Crisis Management

  • Panel 1: The Impact of Artificial Intelligence. This session assessed AI's dual role in both advancing threats and empowering defenses.
    • Moderator: David Toulotte, Cyber reservist, Head of Global IT @ ArcelorMittal Europe.
    • Panelists: Mitja Trampuž (Creaplus/ai4si, Slovenia), Ivan Bošković (IT Advanced Services, Montenegro), and Prof. Dimitar Bogatinov (Military Academy, Skopje).
    • Key Discussion: Panelists explored how AI lowers barriers for executing more persuasive and adaptive attacks. A significant challenge is the rapid adoption of AI systems without corresponding security safeguards, creating new vulnerabilities even as AI offers new tools for cyber defense. Constant advancement of attacks forces defenders to also develop faster. The conclusion of the panel was that AI is here to stay, as one of the greatest inventions of man.
  • Panel 2: Incident Response and Negotiation Dynamics. This panel addressed the critical decision-making processes during an active ransomware attack.
  • Presentation: Resilience at Scale. Jérémy Couture, former Head of Cybersecurity for the Paris 2024 Olympic Games, provided a unique testimony on defending a hyper-complex, global target. His presentation on managing extreme-scale threats and stakeholder coordination offered critical lessons for national and corporate resilience planning.
    • Moderator: Gilles Schwoerer, Head of WB3C.
    • Panelists: Jean-Dominique Nollet (CISO, TotalEnergies) and Captain Pascal Martin (French Gendarmerie).
    • Key Discussion: The session covered the operational, legal, and ethical complexities of ransom negotiations. The main challenges discussed were balancing incident containment, legal obligations, and business continuity under severe pressure, all while coordinating with law enforcement investigations.

The conference facilitated a substantive exchange of perspectives from law enforcement, the judiciary, the private sector, and policy makers. The discussions reinforced that an effective response to ransomware requires continuous, practical collaboration across these sectors and borders, with a focus on addressing shared challenges in capacity, legislation, and joint operations.  The highly engaged audience, whose numerous questions created a dynamic, two-way conversation deepened the value of each session.  We thank all the speakers and participants for their great contribution to this conference and our Project Manager Maja Miranovic for putting together this great event. 

Check out event photos here: 

https://www.jaredic.com/p467614661 (day 1)

https://www.jaredic.com/p549115929 (day 2)


Cybersecurity Training for Medium and Large Networks

Resilient critical infrastructure depends on secure networks, prepared teams and the ability to keep essential services running when cyber incidents occur.
This was the focus of WB3C’s regional training on Network Security for medium and large networks, hosted on 18–19 May in partnership with Slovenia Government Agency for Cybersecurity - URSIV (Urad Vlade Republike Slovenije za informacijsko varnost) and led by Slovenian expert Primoz Bratanic.
The training brought together institutions whose work is closely connected to the stability of public services, government systems and essential infrastructure across the Western Balkans. Participants came from the Secretariat for Legislation - Government of R.Macedonia and the Ministry of Digital Transformation (Министерство за дигитална трансформација) of North Macedonia, Serbia’s Jaroslav Černi Water Institute, the Autoriteti Kombëtar për Sigurinë Kibernetike / National Cyber Security Authority of Albania, GOV-CIRT within Montenegro’s Crnogorski elektrodistributivni sistem, the Agencija za sajber bezbjednost Crne Gore / Cybersecurity Agency of Montenegro, and Ministry of Digitalization and Public Administration - Kosovo.
Over the two days, participants worked through practical approaches to making complex networks safer, reducing unnecessary exposure, recognising early warning signs and responding before a cyber incident disrupts services, operations or public trust.
A ransomware scenario was also part of the training, with a focus on the decisions institutions need to make under pressure: how to contain the incident, preserve evidence, coordinate internally and plan recovery.
For Western Balkans Cyber Capacity Centre (WB3C), this type of regional training is directly linked to the wider goal of strengthening cyber resilience of critical infrastructure - the systems, services and institutions that citizens rely on every day.
Thank you to Igor Kovač of Urad Vlade Republike Slovenije za informacijsko varnost, Primoz Bratanic and all participating institutions for two productive days and great engagement as a group.

Cyber Vigilance for Schoolchildren

Children grow up online long before they fully understand what the online world can expose them to. This is why early cyber vigilance is important, whether as part of the school curriculum or informal education for children and teens. 
This week, Western Balkans Cyber Capacity Centre (WB3C) delivered a three-hour course titled "Our Digital Space: Screen Time Balance & Online Safety", for children of the French School in Montenegro. The session was prepared and delivered by our in-house trainers for cybercrime Cyril CORRIAS and Yannick CASSE, with a simple but important goal: to help children build safer, healthier and more responsible digital habits.
The session covered screen time balance, with age-appropriate recommendations from early childhood to teenage years, as well as the basics of online safety: strong passwords, privacy, social media, and how to recognise situations that should not be ignored.
The session also opened the discussion on child protection online — from risky content and behaviour to reporting mechanisms, parental controls and the role of schools in preventing online bullying and harassment.
To make the learning practical and engaging, the children took part in a group-game questionnaire and received their individual Internet License at the end of the morning.
Cybersecurity education does not begin with technology, it begins with awareness, good habits and the confidence to ask for help when something feels wrong online.

OSINT Training for Trafficking in Human Being and Migrant Smuggling

Four days in the training room, focused on a topic where online traces can make a very real difference: OSINT for Trafficking in Human Beings (THB) and Migrant Smuggling.
WB3C has just concluded this regional training for law enforcement units, organised together with Marie Pierre MOSIN, EU4FAST and CIVIPOL and delivered by our in-house trainer Cyril CORRIAS.
For investigators working on THB and migrant smuggling, the digital aspect is essential. Recruitment, communication, movement, facilitation networks and financial signals often leave online traces. Knowing how to find, assess, preserve and use that information responsibly can strengthen investigations and support better cross-border cooperation.
This is why OSINT remains part of WB3C’s core programme. It connects cyber skills with real operational needs in the Western Balkans and helps law enforcement units build practical capacity against serious and organised crime.
A strong three days, with committed participants and a clear regional purpose.


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.