From 27–30 April 2026, Western Balkans Cyber Capacity Centre (WB3C) delivered a 4-day foundational training on dark web investigations for law enforcement officers from the Western Balkans, led by our in-house trainer Cyril C.
The dark web continues to host a significant share of illicit activity, from marketplaces trading drugs, weapons and stolen data, to forums enabling cybercrime services, financial fraud and emerging forms of organized digital crime. For investigators, this environment presents both a challenge but also an opportunity to build successful cases using various digital traces and operational mistakes.
This training focused on building those foundational skills, including:
🛡️ Understanding how the dark web ecosystem functions (networks, access points, anonymity layers)
🛡️ Identifying and navigating relevant platforms and marketplaces
🛡️ Applying basic OSINT techniques in a dark web context
🛡️ Preserving and handling digital evidence in line with investigative standards
🛡️Linking online activity to real-world criminal investigations
The aim is to equip investigators with the baseline knowledge and practical tools needed to operate confidently in this space and support more advanced, specialised work.
At WB3C, this is part of a broader effort to translate knowledge into operational capability, ensuring that law enforcement institutions across the region are better prepared to respond to evolving cyber-enabled threats.
This week, we welcomed colleagues from CIVIPOL — Pierre Collet and Amel Belkhadra — to WB3C as part of our new joint EU-funded programme “Improving the resilience of critical entities and the protection of public spaces and cyberspace against security threats in the Western Balkans.”
The visit focused on the practical side of implementation — financial management, coordination, and ensuring that delivery across partners meets EU standards.
We also connected programme management with what it ultimately supports: people and skills. Our guests met participants of the Cybersecurity Diploma delivered with Université de Technologie de Troyes, offering a glimpse into the region’s growing cyber talent pipeline.
Bridging programme governance with hands-on capacity building is key to turning investment into operational capability. We will be working with Civipol over the next three years delivering a rich programme developed by our programme lead Gilles Schwoerer, across cybersecurity, cybercrime and cyberdiplomacy, with new themes added to our portfolio including FIMI and Disinformation.
Western Balkans Cyber Capacity Centre (WB3C) was proud to take part in the International Week 2026 on 21-24 April 2026 organised by the University of Criminal Investigation and Police Studies (UCIPS) in Belgrade, bringing together participants and experts from across Europe and the Western Balkans.
The programme combined practical exercises, operational demonstrations and expert discussions on topics ranging from OSINT and information security to organised crime, artificial intelligence, emergency response and international police cooperation. Representatives and institutions from Serbia, Montenegro, Republic of Srpska, Hungary, Germany and the United Kingdom contributed to a dynamic and highly professional exchange of knowledge and experience.
WB3C participated through its cybercrime trainers Cyril C. and Yannick Casse, who delivered sessions on “OSINT in Police Work”, combining theoretical and practical elements and highlighting the growing importance of open-source intelligence in modern investigations and law enforcement cooperation.
The week also featured contributions from international law enforcement experts, including representatives of the FBI and the U.S. Diplomatic Security Service, as well as a round table on international police cooperation in combating organised crime and terrorism.
We are honoured to have been part of such an important international initiative that strengthens professional networks, operational cooperation and shared understanding of today’s evolving security challenges.
Thank you to UCIPS for the invitation and excellent organisation.
From 14 to 24 April, WB3C delivered a two-week intensive session of the Digital Forensics one-year diploma programme, implemented in partnership with the Université de Technologie de Troyes (UTT).
This final teaching block combined one week of online instruction with one week of in-class training, bringing participants together at WB3C for the concluding phase of their academic journey.
Led by UTT expert Reza El Galai, the session focused on preparing trainees for their final oral defence exam in June, guiding them through the structuring and presentation of their casework, strengthening both analytical and communication skills required for professional practice.
As the programme approaches its conclusion, this milestone marks the transition from structured learning to demonstration of operational competence, reinforcing WB3C’s approach of combining academic rigour with practical application.
WB3C took part in the III International Conference of the Association of Security Managers of Montenegro on 17-18 April in Budva, attended by security professionals from Montenegro and the region.
Every year, the conference creates a platform for discussion on how the security landscape is evolving, particularly in light of rapid technological change.
WB3C had the opportunity to contribute to the panel exploring “The Role of the CISO in the Post Quantum Era: Risks, Investments and Operational Shifts.” The discussion addressed what the emergence of quantum technologies means in practice: for cryptography, data protection, risk management and ultimately for how organisations structure and empower their security leadership.
Across the conference, one message was consistent: cyber resilience is becoming a core governance issue, not just a technical one. In this context, regional cooperation and alignment with European and international partners remain essential.
Our colleagues Gilles Schwoerer and Maja Miranovic took this opportunity to congratulate Dragan Radulović on his election as the next President of the Southeastern Europe Corporate Security Association (SEECSA).
Last week at WB3C, we wrapped up a four-day training on Cyber Threat Intelligence (CTI) focused on the energy sector and government infrastructure, led by Ljuban Petrovic.
Working with SOC, CSIRT and CERT teams from across the region, the training reinforced a simple point: CTI only matters when it informs decisions. When it helps prioritise. When it changes how teams prepare and respond.
The sectoral focus proved its value. Energy infrastructure comes with its own risk landscape, and the discussions reflected that reality—specific, operational, and directly relevant.
We are continuing this work in September, building on what started here.
Because strengthening resilience is not a one-off effort. It is something that develops over time, through practice, exchange, and trust.
Simply put, CTI is about turning information into insight, before a threat happens.
Not just collecting data on threats, but understanding who is behind them, how they operate, and what that means for your own systems.
Without that understanding, cybersecurity remains reactive. With it, organisations can anticipate, prioritise and respond with purpose.
Next week at WB3C, we will be running a four-day regional training on Cyber Threat Intelligence (CTI).
The training is designed for SOC, CSIRT and CERT teams, as well as IT professionals working within critical entities—specifically the energy sector. The choice is deliberate.
We are taking a sectoral approach to cybersecurity capacity building. Because threats are not abstract—they target specific systems, infrastructures and vulnerabilities. And the energy sector, as a backbone of economic and societal stability, requires tailored, operationally relevant skills that reflect its real risk landscape.
Over four days, participants will cover:
💡 understanding CTI in the context of critical infrastructure
💡 analysing threats and assessing their impact
💡 translating intelligence into actionable outputs
All week, we will be working closely with cybersecurity professionals from across the region’s energy sector—moving from concepts to application, and building capabilities that can directly support operational decision-making.
This is where CTI becomes operational. Protecting our energy infrastructure means protecting our economy, our security and our livelihood.
Image: Patrick https://lnkd.in/diYnZEgB
Day 3 was dedicated to direct engagement with industry.
The WB3C delegation attended presentations by leading cybersecurity companies, including Alcyconie, Sekoia.io and GATEWATCHER, gaining insight into practical solutions and operational approaches to current cyber threats.
The day continued with a hands-on workshop by Alcyconie focused on crisis management, built around a real-life scenario. Members of the delegation took part in the exercise, working through response coordination and decision-making in a simulated incident environment. There was a number of informal meetings with numerous industry representatives around the event venue.
Today, the Western Balkans Cyber Capacity Centre (WB3C) team also met with the organisers of the Forum INCYBER (FIC) to advance discussions on bringing a similar event to Podgorica this June. The meeting focused on shaping the concept, format and partnerships of what would become the first cybersecurity industry forum of this kind in the Western Balkans, formally linked to the InCyber network.
A highly productive and valuable study visit to Lille.
Western Balkans delegation had a productive day at the cybersecurity industry fair in Lille. First, they participated in a panel discussion dedicated to the topic of cybersecurity of critical infrastructure. The discussion highlighted regional experiences, key challenges and priorities in protecting critical entities while opening a direct exchange with European counterparts and exchanging views on emerging issues in critical infrastructure protection.
There was a strong interest from the audience which led to a lively discussion, opening numerous related questions.
The panel ensured that perspectives from the region are part of the broader cybersecurity conversation and that the region receives visibility in one of the leading European industry events.
The afternoon was reserved for attending presentations by a selected number of cybersecurity companies, followed by targeted B2B meet-ups. These meetings enabled direct introductions, exchange of practical solutions, and exploration of potential cooperation with industry partners.
Today was an excellent day for creating concrete opportunities for future cooperation and partnership development.
https://lnkd.in/dcAg6kcR
Photo credit: Forum INCYBER (FIC)