×

Regulatory Framework for the Protection of Children Online

27.02.2026

Image for Regulatory Framework for the Protection of Children Online

Today, WB3C participated in a multisectoral roundtable on the “Protection of Children in the Digital Environment – A New Draft Law”, hosted by the Ulysseus European University – Innovation Hub for Cybersecurity at the University of Montenegro, led by Andreja Mihailovic, PhD in academic cooperation with the University of Genoa.
The discussion, opened by Prof. Dr. Savo Tomović and MP Slađana Kaludjerović, addressed the proposed Law on the Protection of Minors in the Digital Environment from multiple professional angles.

Our Senior Project Manager Vanja Madzgalj MBE noted that clearly this is an exceptionally complex regulatory space. 
On one hand, states face structural barriers: limited jurisdiction over very large digital platforms operating across borders, difficulties in enforcing obligations against global service providers and the technical opacity of algorithmic systems. On the other hand, children are digital natives with legitimate rights to access, participate in, and benefit from the digital world. Protection cannot mean exclusion.

⚡ At the same time, the data are stark.
We see increasing numbers of minors falling victim to digital crimes, including online sexual exploitation and abuse. We also see minors committing digital offences, often without understanding the legal consequences. Internet addiction is emerging at an early age, with long-term psychological and social impacts. Uncontrolled and unsupervised digital exposure is producing measurable harm.
The forum brought together ICT professionals, children’s rights organizations, parent associations, regulators, policymakers, and educators. 

There was broad agreement that:
Cross-border cooperation with EU regulators is essential, particularly in light of the Digital Services Act and emerging European enforcement mechanisms.
Parents and schools carry a critical share of responsibility.
Children’s rights — including access to information and digital participation — must be preserved alongside protection measures.
Clear criminalization of digital child sexual abuse material (CSAM), grooming, and manipulation of minors online is essential.
We also agreed that waiting for perfect solutions is not an option. We must start somewhere.
National awareness campaigns on digital risks, structured parental education, and early cybersecurity education in schools are foundational. Parents need greater support — and greater accountability. At the same time, targeted institutional regulation and enforceable legal provisions remain necessary, particularly in areas of exploitation, manipulation, and platform responsibility.
Protecting minors online is not a single-law issue. It is a societal, institutional, and technological challenge that requires coordinated national action and effective alignment with European regulatory frameworks. The complexity should not paralyze us — it should push us toward pragmatic, enforceable, and balanced solutions.


CTI for Critical Infrastructure Training Completed

Last week at WB3C, we wrapped up a four-day training on Cyber Threat Intelligence (CTI) focused on the energy sector and government infrastructure, led by Ljuban Petrovic.

Working with SOC, CSIRT and CERT teams from across the region, the training reinforced a simple point: CTI only matters when it informs decisions. When it helps prioritise. When it changes how teams prepare and respond.
The sectoral focus proved its value. Energy infrastructure comes with its own risk landscape, and the discussions reflected that reality—specific, operational, and directly relevant.

We are continuing this work in September, building on what started here.
Because strengthening resilience is not a one-off effort. It is something that develops over time, through practice, exchange, and trust. 

What is Cyber Threat Intelligence (CTI) — and why does it matter?

Simply put, CTI is about turning information into insight, before a threat happens.

Not just collecting data on threats, but understanding who is behind them, how they operate, and what that means for your own systems.
Without that understanding, cybersecurity remains reactive. With it, organisations can anticipate, prioritise and respond with purpose.

Next week at WB3C, we will be running a four-day regional training on Cyber Threat Intelligence (CTI).
The training is designed for SOC, CSIRT and CERT teams, as well as IT professionals working within critical entities—specifically the energy sector. The choice is deliberate.

We are taking a sectoral approach to cybersecurity capacity building. Because threats are not abstract—they target specific systems, infrastructures and vulnerabilities. And the energy sector, as a backbone of economic and societal stability, requires tailored, operationally relevant skills that reflect its real risk landscape.
Over four days, participants will cover:
💡 understanding CTI in the context of critical infrastructure
💡 analysing threats and assessing their impact
💡 translating intelligence into actionable outputs

All week, we will be working closely with cybersecurity professionals from across the region’s energy sector—moving from concepts to application, and building capabilities that can directly support operational decision-making.
This is where CTI becomes operational. Protecting our energy infrastructure means protecting our economy, our security and our livelihood.

Image: Patrick https://lnkd.in/diYnZEgB

Day 3 at the Forum INCYBER (FIC) Europe 2026 in Lille

Day 3 was dedicated to direct engagement with industry.
The WB3C delegation attended presentations by leading cybersecurity companies, including Alcyconie, Sekoia.io and GATEWATCHER, gaining insight into practical solutions and operational approaches to current cyber threats.
The day continued with a hands-on workshop by Alcyconie focused on crisis management, built around a real-life scenario. Members of the delegation took part in the exercise, working through response coordination and decision-making in a simulated incident environment. There was a number of informal meetings with numerous industry representatives around the event venue.

Today, the Western Balkans Cyber Capacity Centre (WB3C) team also met with the organisers of the Forum INCYBER (FIC) to advance discussions on bringing a similar event to Podgorica this June. The meeting focused on shaping the concept, format and partnerships of what would become the first cybersecurity industry forum of this kind in the Western Balkans, formally linked to the InCyber network.

A highly productive and valuable study visit to Lille.


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.