×

WB3C joins UK's regional CybHER initiative empowering women and girls for cyber careers

07.11.2025

Image for WB3C joins UK's regional CybHER initiative empowering women and girls for cyber careers

We are proud to be part of the regional CybHER initiative by the British Council, designed to empower girls and women across the Western Balkans to pursue and thrive in cyber careers. For the WB3C, CybHER is not only a regional effort we support, but also a concrete opportunity to invest in our own people and create space for their professional development.

As part of this, WB3C took part in two CybHER components:
1️⃣ A leadership program for early-career women in cybersecurity.
2️⃣ A workshop on gender-sensitive HR policies for cybersecurity organizations.

1. Leadership skills for early-career women in cyber

Our colleague Vanja Radović is representing the WB3C in the CybHER leadership track for young women in cybersecurity. This program is designed to help participants gain both the mindset and the skills needed to grow and lead in a still male-dominated industry. Over the course of the program, participants will:

💡 Build authentic leadership skills by exploring their personal values, leadership styles and emotional intelligence.
💡 Discover diverse cybersecurity career paths and map concrete options for their own development.
💡 Learn practical strategies to navigate stereotypes, bias and workplace barriers with confidence.
💡 Strengthen networking and collaboration skills to build a reliable support system in the sector.
💡 Develop a personal action plan to apply what they learn in their daily work.

We are especially glad that Vanja will learn from experienced regional leaders such as Larisa Halilovic, an international leadership expert, and Andreja Mihailović, PhD, President of Women4Cyber Montenegro, whose guidance connects technical careers with the human skills needed for leadership.

2. Gender-sensitive HR policies in cybersecurity organisations

In parallel, WB3C also joined the CybHER workshop on gender-sensitive HR policies in cybersecurity organizations, focusing on how organizational systems can either open doors for women - or quietly keep them closed. This component, was followed by our colleague Vanja Madzgalj, responsible for strategic communications and with substantive experience in gender mainstreaming, in order to:

💡 Exchange experiences and good practices between companies on inclusive and fair HR approaches.
💡 Look at domestic and international trends in gender-sensitive and inclusive HR in tech and cybersecurity.
💡 Examine how bias, discrimination, the glass ceiling and everyday prejudices show up in recruitment, promotion and leadership opportunities.
💡 Explore practical ways to improve the full HR cycle: from inclusive job descriptions and selection processes, to advancement, leadership roles and supportive workplace culture.
💡 Discuss mechanisms for safety and confidential reporting, and how policies can better protect and empower staff who experience harassment or discrimination.

The workshop concluded with self-assessment of existing HR practices, individual commitments for change and first steps towards mentoring and peer support, so that policy discussions can translate into everyday practice.

At the Western Balkans Cyber Capacity Centre (WB3C), we believe that real change happens when we work on both people and systems. By empowering our own female colleagues through programs like CybHER, and by strengthening HR and organizational practices that support them, we are investing in a cybersecurity community where women can enter, stay, grow and lead.

 


OSINT and the dark web: supporting anti-drug investigations

This week at WB3C, we concluded a four-day OSINT – Dark Web training for anti-drug police units, coming from law enforcement units from across the Western Balkans. The course was designed for police officers working in drug units and joining a WB3C training for the first time. 
The focus was practical: how publicly available information can support internet-based investigations, from identifying potential threats and collecting digital evidence to producing actionable intelligence for operational decision-making. 
Over four days, participants worked through the fundamentals of OSINT, evidence preservation, online protection and anonymisation, social-network investigations, investigative checks, the dark web, and structured data-collection planning. Particular attention was given to preserving the integrity of digital evidence and navigating online environments safely and securely. 
The training was delivered by Nicholas Michee from OFAST, France, together with Cyril CORRIAS, WB3C’s cybercrime trainer. Combining specialist anti-drug investigation experience with cybercrime expertise, they guided participants through the technical and investigative aspects of using open-source information and online environments in support of operational work.
Thank you to Nicholas Michee and our partners at OFAST, France, for their cooperation and expertise, and to Cyril Corrias for his contribution to the training. Thank you also to the participating officers for four days of focused practical work and professional exchange.

 


 

“We just got hacked!”

 Yesterday, we wrapped up “We just got hacked”, a basic three-day technical training on incident response for entry level system administrators and cybersecurity specialists from regional public institutions to work through what happens after a security alert becomes a real incident: how to triage it, identify what matters first, analyse logs, trace the likely attack vector and examine suspicious files for indicators of compromise. 

Participants worked with the MITRE ATT&CK framework, connecting investigative findings with attacker tactics and techniques, and looking at how those findings can be translated into practical hardening and preventive measures. The objective was not simply to understand how an incident happened, but to use that analysis to reduce the organisation’s exposure to similar attacks in the future. 
The training was delivered by Jakub Bajera and Krzysztof Chudzik from NASK – Naukowa i Akademicka Sieć Komputerowa / Research and Academic Computer Network, Poland. We also thank our funding partners at URSIV, Urad Vlade Republike Slovenije za informacijsko varnost for their continued support to WB3C and to the development of cybersecurity capacities across the Western Balkans.
Certificates are awarded by Jean-Pierre Bonnet, JP BNT, our new WB3C colleague working across cybercrime and cybersecurity.

WB3C meets critical infrastrucutre operators in Prishtina

During a recent mission to Prishtina, WB3C joined CIVIPOL colleagues working on a Gap and Needs Assessment related to the protection of critical infrastructure and public spaces.
While the CIVIPOL assessment focused particularly on the institutional and legislative framework, including the role of the Ministry of Interior and alignment with the EU Critical Entities Resilience (CER) Directive, WB3C used the opportunity to engage directly with critical infrastructure operators and better understand their operational needs.
Together with Shkumbin Saneja from the Ministry of Digitalisation and Public Administration, WB3C met representatives from several key sectors: Arijeta Pajaziti Qerimi and Uran Thaci from energy, Adelina Dumani-Hulaj from Prishtina International Airport, Gazmend Gashi from transport/aviation, Arianit Maraj from telecommunications and Arbnor Imeri from the banking sector.
The discussion provided a useful cross-sector view of existing gaps, operational needs and capacity-building priorities. Despite the differences between sectors, a number of common areas of interest emerged.
This forms part of a wider regional process. WB3C will continue meeting key critical infrastructure stakeholders across the Western Balkans to better understand both sector-specific and shared needs, and to use these findings to shape a training and capacity-building plan tailored to the realities operators are facing.
This work is being carried forward in synergy with our partners under the EU-funded CEPS project, linking institutional assessments with the operational perspective of those responsible for running and protecting critical services.
 


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.