Cyber Resilience Is Built Before a Crisis and Depends on More Than Compliance
Ljubljana, 24 September 2026 – Cyber resilience is built long before a system goes down. It depends on knowing which services the business cannot afford to lose, who makes decisions when information is incomplete, whether recovery plans have actually been tested, and how quickly different teams can act when something goes wrong. Compliance creates an important baseline, but the real test comes when an incident disrupts operations and the organisation has to keep critical services running. This was the focus of the latest Tea with Reason Conference, organised by the British-Slovenian Chamber of Commerce.
An attacker can remain inside an organisation’s systems for months before the visible disruption begins. During his opening keynote, Adel Abusara, Director, Cyber Security Policies at PwC CEE, stressed that awareness of cyber risk has grown considerably at board level, but confidence in organisations’ ability to withstand an incident remains much lower. PwC data presented at the conference showed that only 6 per cent of organisations feel fully confident in their resilience across all surveyed vulnerabilities.
The difference, Abusara argued, lies in what happens when prevention is no longer enough. "Every organization today, regardless of its size or type of business, faces the same attackers, increasing complexity, and rising regulatory expectations. The differentiator is resilience: the ability to withstand disruption, maintain critical services, recover with confidence, and transform risk management into a competitive advantage. In other words: compliance is what you are audited on; resilience is what is left at 3 am."
That distinction between having controls in place and knowing whether they will work under pressure carried into the first panel discussion, moderated by Mark Vidrih, Consultant at Pristop. The discussion quickly moved from what organisations have on paper to how they approach cyber risk in practice.
Many companies still do not know enough about their own processes or the business impact if a critical system stopped working, said Blaž Osrajnik, Head of Business Product Development Team at A1 Slovenia. Rather than relying on checklists and backups, he stressed the importance of running exercises, using independent security assessments to uncover weaknesses, and paying closer attention to supply-chain risks. More broadly, he argued that organisations are better prepared when they treat cybersecurity as a risk management process rather than simply a set of technologies. At A1 Slovenia local expertise is combined with the international experience of the A1 Group to help companies build a safer and more resilient business environment.
Regulation can create structure and accountability, but it does not in itself demonstrate whether an organisation can continue operating after an attack. Rok Praprotnik, Head of Compliance and Integrity at NLB, drew a clear distinction between the two: "Compliance tells us what we need to have in place. Resilience shows whether those measures actually work in practice. The same distinction applies to cybersecurity. Security focuses on whether we can prevent an attack. Resilience, however, is about whether we can withstand an attack, limit its impact, recover quickly, and continue delivering services to our customers without disruption."
The regulatory framework is also placing greater responsibility directly on management. Dr Niko Gamulin, Acting Director of the Government Information Security Office, presented Slovenia’s progress in implementing NIS2, including the self-registration of around 800 entities and the development of a national platform for incident reporting and information sharing. The aim is to strengthen cooperation and preparedness across critical sectors as the new requirements become part of day-to-day governance.
For boards, this means treating cybersecurity as a question of culture, not simply compliance. Stella Litou, CEO of Pro Plus Slovenia and RTL Croatia, stressed that leaders need to understand the risk in business terms, including the potential financial loss, if they are to act on it. Cybersecurity teams therefore need to translate technical information into something decision-makers can use. She also pointed to changing technologies such as AI, where experimentation should be encouraged, but supported by governance that keeps pace with it.
The second half of the conference shifted from preparedness before an incident to the decisions that have to be made once one is already underway. Moderated by Sašo Novak, Strategic Communications and Public Affairs Consultant at S3M line, the discussion focused on the first 24 hours, when organisations may be working with incomplete information while simultaneously trying to contain the attack, restore operations, communicate with stakeholders and meet legal obligations.
Experience from an actual cyberattack showed how quickly those priorities become very concrete. Pavel Škerlj, Group CIO and IT Executive Director at Holding slovenske elektrarne, recalled that one of the first steps during HSE’s 2023 cyberattack was assessing the scale of the problem and disconnecting systems from the outside world to contain the attackers. Clear priorities, coordinated action, and the ability to restore operations quickly matter, but so does establishing whether the threat is still present before systems are returned to normal use.
The first hours also expose whether responsibilities have been agreed before the crisis begins. Goce Kalamadevski, Group Head of Software Security at Endava, said: "The first 24 hours of a cyber incident test leadership and technical capability. Clear accountability, informed decisions, well-coordinated teams, effective automation and risk-based prioritisation are essential to a rapid response." He added that resilience starts much earlier, through secure systems, security operations, tabletop exercises, rehearsed communication plans and tested recovery procedures.
Having a crisis plan is therefore only useful if people know how to use it. Iztok Prezelj, Professor and Head of the Defence Research Centre at the Faculty of Social Sciences, University of Ljubljana, stressed that exercises can reveal where internal capacities may fall short and when external expertise should be brought in. But preparedness also continues after the crisis. Post-crisis reviews should not stop at identifying lessons, he argued, but lead to concrete changes in plans and procedures. Organisations can also learn from incidents experienced by others, rather than waiting for their own crisis to expose the same weaknesses.
The same preparation applies to communication. Jernej Smisl, Managing Director at Pristop, argued that crisis management plans should be tested regularly as risks and circumstances continue to change. Communication during an incident needs to be honest with affected partners, the media and regulators, while leaders need to be ready to communicate externally. Preparing them for difficult questions starts before the crisis, rather than when cameras are already waiting for answers.
Speed, however, has to be balanced with legal obligations that may operate on different timelines. Amela Žrt, Partner at CMS Slovenia, stressed the importance of knowing in advance which regulatory, data protection, contractual and insurance notification requirements apply, who needs to be contacted and within what timeframe. Contractual deadlines may be even shorter than regulatory ones, making clear responsibilities essential during a crisis.
The conference was supported by the Main Partner: A1 Slovenia & Partners: PwC Slovenia and NLB.
The photo gallery is available here.
Photo: Jaka Tai Gubenšek (Mediaspeed)