Become a partner

DISCUSSION "Application Practice of the New Decree on Security Measures"

Jindřich Kalíšek - Attorney and registered mediator, Cyber Security Commission · Štefan Pilár - , Attorney · Marcel Zanechal - Corporate Security Manager, SLOVAK TELEKOM · Jaroslav Ďurovka - Director, National Cyber Security Center ·

Slovakia has a new decree on security measures: 227/2025 replaces the previous 362/2018. Lawyers, the regulator, and people from cybersecurity operations discussed what this means in practice. They agreed that the key points are proportionality, clarity, and the ability to translate the rules into the real-world functioning of organizations.

Why the "new king": fewer details, more responsibility

The previous decree had hundreds of detailed requirements, but practice did not show higher compliance or a better understanding of the field. The new 227/2025 is more concise and relies more on principles of open-endedness and proportionality, thereby shifting a larger share of responsibility onto organizations. This requires knowledge of the environment, sound guidance, and the ability to make decisions based on risks, not just a checklist.

Law is not meant to substitute for technical standards, but without regulation many entities, especially in the public sector, will not take the necessary steps. The argument “I don’t have a paper for that” still works in practice and slows down investment in security. The role of the regulation, therefore, is not to be a “cookbook” for technicians, but to create a framework that is workable and enforceable.

Read more

Sign in to ITAPA Health & Care 2026

Jaroslav Ďurovka

National Cyber Security Center
In 2000, he successfully completed his studies at the Faculty of Law, Comenius University in Bratislava. After a short period of employment at Matador – Obnova, a.s. in Bratislava, in June 2001 he took up the position of senior lawyer at Globtel, a. s., Bratislava (later Orange Slovensko, a.s. since 2002). Since 2003, he has been professionally …

Štefan Pilár

SIGNUM.LEGAL
Lawyer specializing in cybersecurity, personal data protection, IT law, electronic signatures, and AI. His professional focus also includes training courses and seminars on the implementation and practical application of legislative requirements in these areas of expertise. He participates in implementation projects introducing measures for the …

Jindřich Kalíšek

regfor
Lawyer specializing in information and new technology law, especially personal data protection, cybersecurity, IT services, software and compliance. He has more than 15 years of experience in providing legal advice in the Czech Republic, the EU and the USA and has collaborated with major Czech and international companies in the fields of IT, cyb…

Marcel Zanechal

SLOVAK TELEKOM
He is the corporate security manager at Slovak Telekom. He has over 25 years of experience in information security, which he has gained not only within an international corporation but also through consulting, providing IT products and services, and working in government administration. He also shares his knowledge through external lecturing act…

Recommendation speakers

Johanna-Kadri Kuusk

e-Estonia Briefing Centre

Vanda Tuxhorn

Head of the Department of Pediatrics and Neonatology, Landau in der Pfalz, Germany

Christian Kumar

Capital Kinetics

Lukáš Benzl

Czech Association of Artificial Intelligence
Páčil sa ti článok? Zdieľaj ho a povedz o ňom aj ostatným