×

ReSPA and the Western Balkans Cyber Capacity Development Center are enhancing the digital security of public administrations in the Western Balkans through a three- day cyber hygiene training program

04.06.2024

Image for ReSPA and the Western Balkans Cyber Capacity Development Center are enhancing
the digital security of public administrations in the Western Balkans through a three-
day cyber hygiene training program

In a major step towards strengthening cyber resilience and promoting a robust cybersecurity culture in the Western Balkans, the Regional School of Public Administration (ReSPA) andthe Western Balkans Cyber Capacity Centre (WB3C) launched a three-day comprehensive Training for Trainers in Cyber Hygiene today at the University of Montenegro's Rectorate building.

 

The training aims to educate 17 senior public officials to become skilled trainers in cyber hygiene. Equipped with new knowledge and skills, these officials will be able to train their peers to better recognise and manage cybersecurity risks at the operational level.

 

Cybersecurity is not just a technical issue but a fundamental aspect of national security and public administration efficiency. Our collaborative efforts with our partners from the WB3C are significant steps towards a resilient cyber ecosystem in the Western Balkans. Understanding and adopting the skills in cyber hygiene across public administrations willstrengthen this first line of protection, and augmenting the number of civil servants practising it will enable their organisations to react promptly or recover swiftly if attacks occur. This training will result in having new trainers in public administration on cyber security, new resources for transferring the knowledge and ultimately achieving bigger digital security and resilience,  underlined Olivera Damjanović, ReSPA Programme Manager. 

 

Cedric Grousset, Head of the Western Balkans Cyber Capacity Centre, emphasised the

importance of strong collaboration between the Centre and public institutions and partners,

including the Ministry of Public Administration of Montenegro and ReSPA. He highlighted

the significance of a regional approach in training modules for civil servants.

 

Today, for the first time, we have gathered civil servants from the Western Balkans who work in cyber security to learn, exchange ideas, and advance in cyber hygiene and cyber security. More importantly, we will train them to become trainers, enabling them to further disseminate this knowledge to their peers across the region.

 

Dušan Polović, Director of the Directorate for Infrastructure, Information Security, Digitization, and e-Services in the Ministry of Public Administration, also addressed the participants, emphasizing the importance of continuously developing resilient cyber security structures in the Western Balkans. He noted that this three-day training is a crucial step in strengthening regional capacities in cyber security.

 

The training combines engaging lectures, in-depth skill acquisition, theoretical insights, and practical exercises on cyber hygiene. This approach will produce highly skilled trainers and advocates who understand the importance of preventative measures and effective cyber risk management.

 

Completing this training is a significant milestone in the region's journey towards improved cyber security. Since last year, ReSPA and WB3C have been collaborating on initiatives to support the public administration of the Western Balkans in data protection and cyber security.

 

The Regional School of Public Administration (ReSPA) represents a distinctive, regionally- driven platform committed to advancing the reform of public administration (PAR) by fostering policy dialogue at the highest levels, sharing expertise, facilitating learning opportunities, fostering networking initiatives, promoting public sector mobility and capacity building, conducting topical research, and meticulously analysing policies.

Established as a collaborative initiative between the European Commission and the governments of the Western Balkans, ReSPA operates under the stewardship of five Member States: Albania, Bosnia and Herzegovina, North Macedonia, Montenegro, and Serbia, with Kosovo* benefitting from its programs.

With a primary focus on empowering civil servants, ReSPA endeavours to catalyse the development of modern, transparent, and efficient public institutions capable of effectively serving their citizens and facilitating the European integration process within the Western Balkans.

The Western Balkans Cyber Capacity Center (WB3C) is a regional cyber capacity-building initiative based in Montenegro. It is a training center focusing on fight against cyber crime, cyber security and cyber diplomacy. It aims at improving the cyber capacities and cyber resilience of the Western Balkans admistrations. Besides education and training for specialised groups of professionals and training for trainers WB3C promotes exchange of good practices, regional and international cooperation between administrative, technical and educational institutions.

France and Slovenia in partnership with Montenegro initiated this project in order to facilitate region’s approximation the EU membership.


OSINT and the dark web: supporting anti-drug investigations

This week at WB3C, we concluded a four-day OSINT – Dark Web training for anti-drug police units, coming from law enforcement units from across the Western Balkans. The course was designed for police officers working in drug units and joining a WB3C training for the first time. 
The focus was practical: how publicly available information can support internet-based investigations, from identifying potential threats and collecting digital evidence to producing actionable intelligence for operational decision-making. 
Over four days, participants worked through the fundamentals of OSINT, evidence preservation, online protection and anonymisation, social-network investigations, investigative checks, the dark web, and structured data-collection planning. Particular attention was given to preserving the integrity of digital evidence and navigating online environments safely and securely. 
The training was delivered by Nicholas Michee from OFAST, France, together with Cyril CORRIAS, WB3C’s cybercrime trainer. Combining specialist anti-drug investigation experience with cybercrime expertise, they guided participants through the technical and investigative aspects of using open-source information and online environments in support of operational work.
Thank you to Nicholas Michee and our partners at OFAST, France, for their cooperation and expertise, and to Cyril Corrias for his contribution to the training. Thank you also to the participating officers for four days of focused practical work and professional exchange.

 


 

“We just got hacked!”

 Yesterday, we wrapped up “We just got hacked”, a basic three-day technical training on incident response for entry level system administrators and cybersecurity specialists from regional public institutions to work through what happens after a security alert becomes a real incident: how to triage it, identify what matters first, analyse logs, trace the likely attack vector and examine suspicious files for indicators of compromise. 

Participants worked with the MITRE ATT&CK framework, connecting investigative findings with attacker tactics and techniques, and looking at how those findings can be translated into practical hardening and preventive measures. The objective was not simply to understand how an incident happened, but to use that analysis to reduce the organisation’s exposure to similar attacks in the future. 
The training was delivered by Jakub Bajera and Krzysztof Chudzik from NASK – Naukowa i Akademicka Sieć Komputerowa / Research and Academic Computer Network, Poland. We also thank our funding partners at URSIV, Urad Vlade Republike Slovenije za informacijsko varnost for their continued support to WB3C and to the development of cybersecurity capacities across the Western Balkans.
Certificates are awarded by Jean-Pierre Bonnet, JP BNT, our new WB3C colleague working across cybercrime and cybersecurity.

WB3C meets critical infrastrucutre operators in Prishtina

During a recent mission to Prishtina, WB3C joined CIVIPOL colleagues working on a Gap and Needs Assessment related to the protection of critical infrastructure and public spaces.
While the CIVIPOL assessment focused particularly on the institutional and legislative framework, including the role of the Ministry of Interior and alignment with the EU Critical Entities Resilience (CER) Directive, WB3C used the opportunity to engage directly with critical infrastructure operators and better understand their operational needs.
Together with Shkumbin Saneja from the Ministry of Digitalisation and Public Administration, WB3C met representatives from several key sectors: Arijeta Pajaziti Qerimi and Uran Thaci from energy, Adelina Dumani-Hulaj from Prishtina International Airport, Gazmend Gashi from transport/aviation, Arianit Maraj from telecommunications and Arbnor Imeri from the banking sector.
The discussion provided a useful cross-sector view of existing gaps, operational needs and capacity-building priorities. Despite the differences between sectors, a number of common areas of interest emerged.
This forms part of a wider regional process. WB3C will continue meeting key critical infrastructure stakeholders across the Western Balkans to better understand both sector-specific and shared needs, and to use these findings to shape a training and capacity-building plan tailored to the realities operators are facing.
This work is being carried forward in synergy with our partners under the EU-funded CEPS project, linking institutional assessments with the operational perspective of those responsible for running and protecting critical services.
 


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.