Slovakia is moving forward in cyber resilience, as confirmed by the European cybersecurity index. However, attacks are becoming more sophisticated and affecting larger parts of the infrastructure, so the demands on people and technical measures are also increasing. Experts emphasize that what matters are implementation, cooperation, and smart use of available resources.
Where we’ve advanced and what’s changed
Cybersecurity has undergone a step change in recent years – thanks in part to artificial intelligence, attacks have accelerated and become more complex. Many players have realized they have gaps, and that applies to both the state and the private sector. Today, a training session about “not clicking” on suspicious links is no longer enough; systematic measures and coordinated responses are needed.
According to the index prepared by the ENISA agency, Slovakia has been rising steadily. Early transposition of the NIS2 directive and good cooperation among key institutions helped; implementing regulations are being finalized with an emphasis on technical measures, not just paperwork. Nevertheless, experts avoid self-congratulation – trumpeting about “bulletproof” security for too long is an unnecessary provocation for attackers.
People, money, and paperwork: where things get bogged down
The biggest weakness is capacity: users lack digital skills and there are not enough qualified specialists. A well-established rule of thumb in organizations is a dedicated cybersecurity budget of roughly five percent of total spending – below this threshold, risks are hard to manage. In the public sector, the degree of assumed responsibility among leaders varies, and municipalities often lack both money and people.
Paradoxically, there are plenty of European funds, but directly managed programs are underused and public procurement discourages with its length and uncertainty. It is important to distinguish “inspection” (the state’s administrative procedure) from “audit” (independent assessment) and to focus on implementing measures, not just on documentation. Slovak regulation therefore places emphasis on technical steps that can also be objectively verified.
Priority steps for a more resilient Slovakia
In the short term, the key is protecting critical infrastructure and building shared security services (e.g., joint monitoring centers) for smaller operators and municipalities. They will never be able to afford a high level of protection individually, but in a shared model they can achieve a higher level of detection and response. In parallel, it is necessary to invest in people – education, qualifications, and practical skills.
Another priority is supply chain security, today one of the most common entry points for attackers. Organizations should meaningfully require security standards from suppliers and manage vulnerabilities regardless of “vendor lock-in.” Finally, it is time to prepare for post-quantum encryption and deploy tools according to risks and architecture – one-size-fits-all approaches (for example, “SIEM everywhere”) don’t make sense.