Anybody with a phone is part of cybersecurity

Written by Ajna Mešić and Alen Kubat, Young European Ambassadors from Bosnia and Herzegovina
We walked into the e-Governance Academy in Tallinn not entirely sure what to expect. We had done our reading, we knew it was an EU-funded institution, we knew it ran projects in the Western Balkans, and we knew it had something to do with cybersecurity. What we did not expect was to leave feeling like we had been handed a completely different way of thinking about a word we thought we already understood.
That shift started almost immediately, and it started with a reframe. Cybersecurity, we were told, is not a technical problem with a technical solution. It is, above all, about people. The image of a person in a hoodie hunched over a screen in a dark room (the one that comes to most people’s minds when they hear the word), is not just clichéd, it is actively misleading. Because if cybersecurity is only for specialists, then ordinary citizens feel no responsibility for it, and that is exactly how systems become vulnerable.”Anybody who has a phone,” we heard in that room, “is part of cybersecurity.” That line is simple, but also radical in its own way.
Milan Sekulovski, Senior Cybersecurity Expert at the eGA and Project Manager of CyberBalkans, walked us through what the project has actually done across six Western Balkans countries (Albania, Bosnia and Herzegovina, Kosovo, Montenegro, North Macedonia, and Serbia) since 2023. CyberBalkans works across four interconnected pillars: strengthening the organisational capacity of public institutions, aligning national legal frameworks with EU cybersecurity acquis, building crisis management mechanisms, and developing the technical capabilities of national CERTs. This means helping governments adopt real cybersecurity laws, running live-fire exercises that simulate actual attack-and-recovery scenarios, and building the institutional muscle memory to respond when something goes wrong.
On that last point (crisis exercises) the WB Cyber Connect 2025 exercise was a concrete example of what CyberBalkans delivers in practice. Run over four intensive days on a dedicated cyber range, it brought together security professionals from across the region to practise detecting, responding to, and recovering from complex cyber incidents in realistic simulated conditions. The idea behind it is one that Milan put clearly: you cannot always control what will happen, but you can control how you respond. Preparedness is not about preventing every attack. It is about building the resilience to absorb one and keep functioning.
For Bosnia and Herzegovina, the CyberBalkans context is particularly significant, and particularly honest. BiH scores around 33% on the eGA’s own National Cybersecurity Index, lagging well behind the region’s digital development metrics. Critical information infrastructure indicators remain largely unfulfilled. The country’s cyber incident response and crisis management capabilities, given its complex administrative structure, are not yet available at the national level in any consolidated form. What this means in practice is that BiH is digitalising fast while the security layer that should accompany that digitalisation is still being built. CyberBalkans is part of how that gap gets closed: by working with institutions directly, helping them understand what EU standards actually require, and making sure that when laws are passed, they come with the capacity to implement them.
CyberBalkans is now moving into its second phase, 2026 to 2029. The ambition has shifted from laying foundations to chasing long-term impact, and that means taking seriously the cybersecurity workforce challenge. The region trains good people. What it often cannot do is keep them in the public sector. Talent development pipelines, competitive enough conditions to retain expertise, and an understanding in government that cyber investment is strategic rather than bureaucratic: these are the things that will determine whether the progress of phase one holds.
Kristiin Jets, Communications Manager for CyberBalkans at the eGA, brought the other half of the picture into focus. Even the most sophisticated national strategy does not protect a citizen who has never heard of phishing. This is why through the KnowCyber project, grants were distributed to civil society organisations across all six countries, each working with the communities they already know and are trusted by.
The design choice behind all of this matters as much as the activities themselves. Rather than delivering awareness campaigns from the top down, KnowCyber bet on the principle that communities trust the organisations already inside them, and that those organisations (given the right tools and modest funding) are better positioned to change behaviour than any government poster campaign. Every organisation that took part made real value, and a new grant scheme is now being developed to continue the work.
There is a line that connects everything we heard that afternoon, and it runs through trust. Bosnia is digitalising right now, quickly. The risk is that digital systems get built before the trust and resilience that make them worth having. That the problem gets moved online rather than solved. The EU funded CyberBalkans and KnowCyber precisely because cyber resilience is not a box to check on an accession checklist. It is what being ready actually means.
We came to Tallinn to learn about two projects. We left thinking about what kind of digital future is being built at home, and whether the people building it understand that the person most responsible for cybersecurity in BiH might be a teenager in a park with a smartphone and no one who ever told them what to do with it. They are. And now, at least, there are people working to change that.
The visit to the e-Governance Academy in Tallinn took place as part of the YEAs’ take on EU 2.0 project activities within the Young European Ambassadors network. Ajna Mešić and Alen Kubat are Young European Ambassadors from Bosnia and Herzegovina.



