Montenegro and cyber security: still unprotected
An investigation by the Centre for Investigative Journalism of Montenegro into a missing Cyber Security Agency and a budget that does not match the risk.
Under the Law on Information Security adopted in December 2024, Montenegro's Cyber Security Agency should have been established by the end of March 2025. It was not. The Ministry of Public Administration sent the government proposals for a director and management board twice — in February, within the legal deadline, and again in June — and received no answer. Meanwhile the proposed 2026 budget is short an estimated 2.5 million EUR for information infrastructure and cyber security, money tied to obligations under the EU Reform Agenda 2024–2027.
The consequence is a gap in the chain of defence. After the 2024 law, CIRT — which had covered cyber security for all Montenegrin institutions since 2012 — lost jurisdiction over independent and private entities, which now fall to an agency that does not exist. As this investigation quotes: establishing the agency urgently is a priority both for the security of the state and its citizens and for Montenegro's credibility in EU accession; the budget planned for the agency sits unused, and in the event of a serious attack every state body is left to itself with no central support. That is untenable and directly endangers critical systems.
The reporting places this against a familiar backdrop: the August 2022 ransomware attack that took ministries, tax and customs administration and courts offline, persistent shortages of financial, technical and human resources, and a national cyber security index that still trails the EU average. The pattern the investigation documents is legislation moving ahead of institutions — laws adopted on time, bodies and budgets arriving late or not at all.
Key findings
- 01The Cyber Security Agency, legally due by the end of March 2025, still did not exist in late November 2025.
- 02The Ministry of Public Administration twice proposed a director and board — in February and June — with no response from the government.
- 03The proposed 2026 budget is short around 2.5 million EUR for cyber security and information infrastructure, tied to EU Reform Agenda obligations.
- 04Since the 2024 law, CIRT no longer covers independent and private entities — jurisdiction sits with an agency that has not been formed.
- 05Without central support, each state body faces a serious attack alone, while the agency's planned budget goes unspent.
- 06Delay is both a security problem and a credibility problem in the EU accession process.
