×

EU Legislation and Public Sector Standards for Cyber

09.09.2025

Image for EU Legislation and Public Sector Standards for Cyber

This week in Bar, Montenegro, DCAF - Geneva Centre for Security Sector Governance and Regional School of Public Administration (ReSPA) and Western Balkans Cyber Capacity Centre (WB3C) jointly delivered a three-day regional training on cybersecurity legislation and public-sector standards.
The event gathered representatives from across the Western Balkans’ public administrations — an opportunity to connect networks, exchange practices, and strengthen a common regional approach to cybersecurity capacity. The programme was funded by the UK's Foreign, Commonwealth and Development Office, with Melanie Moffat from the British Embassy Podgorica attending the training. 

Day 1 opened with remarks from Franziska Klopfer (DCAF) and Gilles Schwoerer (Head of WB3C). In his opening address, Gilles underlined that WB3C is not just a centre in Podgorica, but a regional platform designed as a resource for the entire Western Balkans — built for the region, to be used by the region. The day continued with sessions on EU legislation and certification frameworks, including insights into Italy’s cybersecurity architecture and the functions of the Italian National Cybersecurity Agency (Agenzia per la Cybersicurezza Nazionale).
🔹 Day 2 brought a broader audience, as more participants from the ReSPA network joined. Bojana Bajić (ReSPA) joined Franziska and Gilles in addressing the group, stressing the importance of cooperation across institutions in the process of advancing cybersecurity capabilities and aligning normative frameworks with EU standards. Participants then heard from the National Cybersecurity Authority of Greece, explored digital competencies for public administration, and worked on designing cybersecurity training curricula for civil servants, IT staff, and managers.
🔹 On Day 3, the sessions will turn to national practices, with contributions from Serbia’s National Academy for Public Administration and the Civil Service Agency of Bosnia and Herzegovina, offering concrete models for embedding cybersecurity into public administration training systems.
Together with DCAF and ReSPA, and with the support of FCDO, this training strengthened the foundations for a more resilient public sector across the Western Balkans, aligned with the region’s needs and EU accession priorities.


Certified Data Protection Officer training,

This week, 26-28 May 2026, we organized the Certified Data Protection Officer training, a three-day regional programme for public servants involved in the implementation, supervision and monitoring of data protection measures across governmental and public sector institutions.

Data protection is a key part of digital trust. As public services become more digital and interconnected, institutions need the capacity to protect personal data, strengthen compliance, and ensure that citizens’ rights are respected in practice.

For the Western Balkans, this training is especially relevant. Strong data protection frameworks support better public administration, safer digital services, responsible data use and closer alignment with European standards. They also help institutions move beyond formal compliance and towards a more practical, people-centred approach to privacy and accountability.

Over the next three days, participants will work through the key pillars of data protection practice:

Organisational governance — understanding roles, responsibilities and internal accountability
Customer-centric compliance — applying data protection principles in services and institutional processes
People-focused rights and responsibilities — strengthening the protection of individuals and supporting responsible decision-making

The course combines theory with practical exercises, peer exchange, group work and interactive simulations. Participants will work in small groups using a mock organisation aligned with their institutional context, allowing them to apply lessons to realistic public-sector scenarios.

The training is also designed as a certification programme, with short daily quizzes and final certification based on the average score across all three days.

By investing in Data Protection Officer capacities, WB3C is supporting the development of a stronger regional professional network — one that can help institutions protect personal data, build public trust and embed data protection into everyday governance. Big thank you to our trainers Blerta Xhako, Stella Manga Chesnay and Stefano Leucci.

Curtesy Visit by the Norwegian Ministry of Foreign Affairs

WB3C pleased to welcome a delegation of the Kingdom of Norway for a courtesy visit and exchange on possible areas of future cooperation.
The visit was an opportunity to present WB3C’s work as a regional platform for cybersecurity, cybercrime and cyber diplomacy, and to discuss how practical capacity-building can support resilience, institutional cooperation and the European path of the Western Balkans.
We were honoured to receive Mr Eirik Nestås Mathisen, Special Envoy for the Western Balkans at the Norwegian Ministry of Foreign Affairs, together with Ms Anita Krokan, Special Adviser at the Norwegian Ministry of Foreign Affairs, Colonel Dag-Magne Lunde, Defence Attaché of the Kingdom of Norway, Mrs. Ingrid Vik from the Norwegian NGO UTSYN and Mr Rajko Radevic, Adviser at the Norwegian Ministry of Defence, who were welcome by our programme lead Gilles Schwoerer.
Norway has long been a valued partner to the region, with a strong understanding of security, governance and resilience challenges in the Western Balkans. We look forward to continuing the dialogue and exploring concrete ways to work together in the period ahead.

Cyber Vigilance for Children - Session 2

Cyber vigilance starts with very simple questions.
❓ What do we share online?
❓Who can see it?
❓When is screen time too much?
❓What should we do if something online feels strange, scary or unkind?

Yesterday, WB3C held a second session on Cyber Vigilance for Children for the French School in Podgorica, this time with the youngest age group, children aged 7 to 10.
The session, prepared and delivered by Cyril CORRIAS and Yannick CASSE, WB3C cybercrime trainers, introduced children to the basics of safer and healthier digital habits in a way they could understand, discuss and remember.
Together, they explored screen time, passwords, privacy, online behaviour, social media, bullying, and the importance of speaking to a trusted adult when something does not feel right.
The morning ended with a group-game questionnaire and the awarding of an individual Internet License — a small certificate, but with a meaningful message: being online also means learning how to be careful, kind and responsible.
At this age, cyber education is not about fear. It is about giving children confidence, language and instincts that can protect them as their digital world grows.


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.