DISCUSSION "Change in Risk Doctrine"
Czech and Slovak cybersecurity experts agreed that risks need to be managed—the dispute is more about how precisely and for whom. Alongside qualitative procedures, semi‑quantitative and quantitative methods already exist, but their deployment runs up against practice, people, and money. The key theme of the entire debate was culture: without it, methodologies won’t achieve much. Risk management methodologies are now available in the Czech Republic and Slovakia across the full spectrum—from qualitative through semi‑quantitative to quantitative. However, the panelists pointed out a yawning gap between paper and practice: even large organizations, after years of obligations, still have incomplete or purely formal risk analyses. Smaller operators, such as municipalities, often lack the capacity or experts to keep “heavy” methods running. The result is that many are dealing with the very basics, while others are already experimenting with advanced risk quantification.Maturity and reality: from municipalities to large companies