×

Confronting Ransomware: Analysis and Strategy for the Western Balkans 2–3 December 2025 | Science and Technology Park of Montenegro

02.12.2025

Image for Confronting Ransomware: Analysis and Strategy for the Western Balkans 2–3 December 2025 | Science and Technology Park of Montenegro

Ransomware continues to pose one of the most serious and persistent cyber threats to institutions and businesses across the Western Balkans. In response to this growing challenge, the Western Balkans Cyber Capacity Centre (WB3C) is hosting a two-day conference that brings together national authorities, law enforcement agencies, EU institutions, the private sector and international experts to examine the evolving threat landscape and identify practical paths forward.

The discussions will follow the structure of the latest published agenda (available below), covering operational, legal, technical and strategic dimensions of ransomware response.

A diverse regional and European expert community

The conference brings together a wide range of contributors, reflecting the cross-sectoral nature of ransomware resilience:

  • National cybersecurity authorities, CSIRTs and police high-tech crime units from Montenegro, Albania, Bosnia and Herzegovina, Serbia, and North Macedonia
  • European and international law enforcement institutions, including Europol and France’s Anti-Cybercrime Office (OFAC)
  • Judicial representatives and prosecutors from France, Serbia, Montenegro and EUROJUST
  • Private-sector leaders in cybersecurity, including technical experts, CISOs, SOC practitioners and incident-response specialists from across the region and the EU
  • Academic and research communities specialising in cybercrime, digital forensics and AI-enabled cyber threats

Key themes across the two-day programme

The agenda examines several critical aspects of the ransomware ecosystem:

  • Mapping current ransomware tactics and regional threat activity
  • Understanding criminal group structures, operational models and international cooperation needs
  • Lessons learned from high-profile investigations and successful dismantling of ransomware groups
  • Comparative legal frameworks and the challenges of jurisdiction, prosecution and evidence handling
  • Real-world case studies from organisations that have managed and recovered from ransomware attacks
  • Technical and legal issues surrounding cryptocurrency tracing and seizure
  • The emerging role of AI in enhancing both attacker capabilities and defensive measures
  • Operational insights from securing major international events, including Paris 2024
  • The complexities of negotiating under pressure during active ransomware incidents

Through panels, keynotes, and practitioner-to-practitioner exchanges, the event aims to deepen understanding of how ransomware is evolving, where regional vulnerabilities lie, and what coordinated action is needed to strengthen resilience.

WB3C is committed to strengthening cybersecurity capacity across the Western Balkans by connecting national stakeholders with European expertise and by translating insights into practical improvements for public authorities, critical service operators and the wider digital ecosystem.

Access the latest agenda below.


Visit by CBRN Centres of Excellence Project 101

WB3C was pleased to meet with representatives of the EU CBRN Centres of Excellence Project 101 to discuss potential cooperation in strengthening critical infrastructure protection and security.
The exchange with Alexandre Custaud, EU CBRN CoE Project 101 Team Leader and Scott S. focused on possible synergies between cybersecurity, CBRN risk mitigation and broader critical infrastructure resilience. As threats to essential services become increasingly interconnected, cross-sector cooperation is essential to support more coordinated, practical, and future-oriented capacity building.
WB3C team Gilles Schwoerer and Maja Miranovic stressed that sectoral approach in building resilience for critical infrastructure is central in our 3-year EU funded programme and expressed readiness to explore areas where our respective expertise and regional engagement can contribute to stronger resilience and security.

Police officers complete demanding 15-month journey from investigator to digital forensics graduate

When fourteen police investigators recently graduated from WB3C's Digital Forensics programme delivered in partnership with the University of Technology of Troyes (UTT), the public saw the final result: internationally recognised diplomas, successful thesis defences and a new generation of specialised cybercrime investigators.

Less visible was the work that took place behind the scenes to get there.

For fifteen months, participants balanced full-time operational duties with a university-level programme requiring approximately 1,400 hours of study. While continuing to investigate cybercrime cases and fulfil their professional responsibilities, they attended classes, completed practical assignments, conducted research and prepared professional theses.

As the programme entered its final stage, WB3C and UTT intensified their support to help participants navigate one of the most demanding parts of the academic journey: the preparation and defence of their final papers.

Participants received detailed guidance on thesis writing, academic standards and defence procedures applied by UTT. Following the submission of their papers, mentors conducted individual reviews and provided detailed feedback, recommendations and improvement points. Students then worked through revisions and refinements before receiving final confirmation that their work met the required academic standards.

Throughout this process, mentors remained available for consultations, questions and individual support, ensuring that participants could successfully bridge the gap between operational expertise and academic requirements.

The final result was more than a successful examination. It demonstrated the determination of investigators who committed to a demanding programme while remaining on active duty, and the value of sustained mentorship and international cooperation in building specialised cybercrime capabilities.

The graduation of all fourteen participants stands as a testament not only to their professional competence, but also to the perseverance required to complete a rigorous university programme alongside the realities of modern law enforcement work.

Advancing Cyber Resilience of Critical Entities through ISO 27001 Training

This week, at Western Balkans Cyber Capacity Centre (WB3C) we are running a three-day training on ISO/IEC 27001:2022, delivered in cooperation with our partner Čikom and led by its CISO and SOC Manager Mladen Bukilic.

As countries across the region advance their alignment with European cybersecurity requirements, organisations responsible for public services and critical functions face growing expectations to manage risks in a systematic and measurable way.
The training introduces participants to the principles of Information Security Management Systems (ISMS), covering topics such as risk assessment, security governance, incident management, internal audits and continual improvement. Through practical exercises and case studies, participants develop the tools needed to translate security requirements into organisational practice.
More than a compliance exercise, ISO 27001 provides a framework for protecting information assets, strengthening organisational resilience and building trust in an increasingly interconnected environment.
The activity is delivered within the regional project "Improving the Resilience of Critical Entities and the Protection of Public Spaces and Cyberspace against Security Threats in the Western Balkans", funded by the European Union.


Copyright © WB3C

Disclaimer: Translations of the original content written in English into other languages are AI generated by Weglot.