Writing index
INTERVIEW — 2 Oct 2024

Montenegro's proposed new cybersecurity structure raises concerns

BIRN examines a draft information security law that risks blurring responsibility between CIRT and a new Cybersecurity Agency — and opening the door to political appointments.

Balkan Insight
Published in
Balkan Insight
Role
Expert source

The draft law, adopted by the government in May 2024 as a replacement for the 2010 Law on Information Security, was presented as a response to the August 2022 attack that crashed much of Montenegro's public administration. Security practitioners quoted in the reporting warn that its architecture is ambiguous: responsibilities could overlap between the government's CIRT, made responsible for state administration, and a new Cybersecurity Agency responsible for everything outside it.

The remedy proposed in the interview is a clean division of labour: CIRT focused purely on protecting state infrastructure, and the Agency given the broader mandate over the wider cyberspace, including the private sector. Such a split would increase efficiency, strengthen coordination between the two institutions, and avoid both conflicts of jurisdiction and duplicated work. There is also a question of feasibility — Montenegro's cyber security index lags well behind the EU average, with chronic financial, technical and human resource constraints, so whether the public and private sectors can implement the new requirements in practice is genuinely debatable. The 2024 Global Cybersecurity Index places Montenegro in the third of five tiers, 'establishing'.

The second concern is governance. Under the draft, the Agency's head is appointed by a Council whose president and four members are appointed by the government, with nominations from institutions dependent on public funding. Given the crucial role the Agency will play in protecting state infrastructure and the wider cyberspace, its composition has to rest on expertise, experience and impartiality rather than political criteria, through a transparent and rigorous selection process that puts people with proven cybersecurity experience in place. Politically motivated appointments would undermine both the credibility and the efficiency of the institution — and during the public debate the ministry rejected calls to reserve at least one Council seat for the cyber security expert community.

Key findings

  • 01The draft law replaces the 2010 Law on Information Security and answers the August 2022 attack on Montenegro's public administration.
  • 02Responsibilities risk overlapping between CIRT and the new Cybersecurity Agency, threatening a dysfunctional response system.
  • 03Proposed division: CIRT protects state infrastructure only; the Agency covers the wider cyberspace, including the private sector.
  • 04Montenegro's cyber security index lags the EU average — the 2024 Global Cybersecurity Index rates it 'establishing', tier three of five.
  • 05The Agency's Council is government-appointed via institutions dependent on public funding, creating a clear risk of political staffing.
  • 06Selection must be transparent and rigorous, based on proven cybersecurity experience; the ministry rejected reserving a Council seat for the expert community.
More interviews & press