Writing index
ESSAY — 2024

Cyber Security Capacities and Digital Rights in Montenegro

A 29-page BIRN research report on Montenegro’s cybersecurity capacity, its attack history and what it means for digital rights.

BIRN
Published in
BIRN
Role
Co-author

Co-authored with Andreja Mihailović and Nikola Žarić for the Balkan Investigative Reporting Network with support from the UN Democracy Fund, this report traces Montenegro’s legal and institutional development from the 2010 Law on Information Security through the national cybersecurity strategies of 2013, 2018 and 2022–2026, NATO membership, the Budapest Convention and the new Law on Information Security aligning the country with the EU’s NIS2 Directive and establishing a dedicated Cyber Security Agency.

It documents the attack history that makes this urgent. The 20 August 2022 state cyberattack encrypted 17 systems across 10 institutions, affected 150 computers and left the social welfare information system and the e-Government portal unusable for months, with recovery assistance from the FBI and France’s ANSSI. Earlier, during the 2016 election period, DDoS and spear-phishing campaigns were attributed to the Russia-linked group Fancy Bear.

The report’s original contribution is a survey of 305 respondents from the public and private sectors, academia, NGOs and international organisations, conducted between 12 May and 6 June 2024, measuring how those closest to the field perceive both institutional capacity and digital-rights protection. It closes with recommendations across five areas: institutional capacity, public–private–academic collaboration, legal and regulatory reform, public awareness and incident-reporting transparency, and continuous monitoring and evaluation.

Key findings

  • 01Co-authored with Andreja Mihailović and Nikola Žarić for BIRN, supported by the UN Democracy Fund.
  • 02Original survey data: 305 respondents across public, private, academic and NGO sectors, 12 May – 6 June 2024.
  • 03The 20 August 2022 attack encrypted 17 systems across 10 institutions and affected 150 computers, disabling e-Government and social welfare systems for months.
  • 04The 2023 EU Progress Report noted cybercrime unit staffing rising from 5 to 18, while judicial and enforcement capacity still lags behind legislation.
  • 05DDoS and spear-phishing during the 2016 election period were attributed to the Russia-linked Fancy Bear group.
  • 06Recommendations span five areas: institutional capacity, cross-sector collaboration, legal reform, public awareness and transparency, and ongoing monitoring.
More essays & guides