The regulatory whirlwind in cybersecurity has reached Slovakia as well. Representatives of the informatisation department outlined how they aim to help public institutions comply with laws and decrees without swallowing their budgets. The focus is on methodological recommendations, training, e‑learning, and a new decree aligned with NBÚ rules.
Support for public administration, not just obligations
Cybersecurity in public administration is framed by two pillars: the Cybersecurity Act (under the remit of the NBÚ) and the Act on Information Technologies in Public Administration (under the remit of the informatisation department). The informatisation department manages and coordinates cybersecurity in the public administration sector and, alongside regulation, also offers practical assistance. The aim is for entities to understand the requirements and know how to implement them in practice, especially where money and specialists are lacking.
A major support is the Recovery and Resilience Plan (component 17), under which reforms and investments focused on training and accessible tools have been created. The priority is people in key roles – for example, cybersecurity managers – to whom the department is providing methodologies and training. E‑learning for the entire public administration is being launched, and online training sessions focused on practical topics such as risk management are continuing.
Methodologies and templates that save money
A common problem is outdated internal directives – sometimes even five years old. Therefore, the department has prepared a Unified Methodological Framework: a package of free templates, procedures, and documentation samples that an organization can tailor and immediately incorporate into its practice. This reduces reliance on expensive deliveries of “paper” security and helps focus on genuine process improvement.
On the central Kyberportál (kyberportal.slovensko.sk), recommendations for municipalities and schools have already been published, with more being added gradually. The department also reminds that responsibility for fulfilling obligations always lies with the organization itself and its statutory representative – help exists, but no one will do the work for them. For this reason, inspections are taking place at both large and small entities under the Act and the sectoral decree; the methodologies and training are intended to ensure they are prepared for them.
New decree, categories of entities, and convergence with the NBÚ
The forthcoming sectoral decree will replace Decree No. 179 and is designed to be largely identical to NBÚ Decree No. 227. However, it adds several measures important for public administration. It is planned to take effect from 1 January 2027, with a transitional period during which the current decree can be applied until 30 June 2027; the valid decree has applied to all governing authorities since 2020.
An amendment to the Act on IT in Public Administration effective from 30 April also brought clarifications of categories: only entities in Category 2 and Category 3 are entered into the register of basic service operators, while “Category 1” (e.g., municipalities up to approximately 6,000 inhabitants and organizations established by them) falls exclusively under the ITVS rules. The department is working intensively with the NBÚ and addressing the impacts of new European rules (e.g., CRA requirements for products and their procurement), although a formal interdepartmental commission has not yet been established. Among the year's greatest successes it counts the completion of all reforms and investments under the Recovery Plan, the launch of e‑learning, and a series of workshops in regional capitals.