Cyber incidents and strategies for their prevention
| Site: | Loomen za stručna usavršavanja |
| Course: | Security and Privacy in the Digital Environment |
| Book: | Cyber incidents and strategies for their prevention |
| Printed by: | Gost (anonimni korisnik) |
| Date: | Wednesday, 29 July 2026, 3:14 AM |
Table of contents
- 1. Introduction
- 2. Strategies to prevent future cyberattacks
- 3. Implementing strong security policies
- 4. Education of employees and users, teaching and administrative staff and students about security threats
- 5. Regular testing and safety assessment
- 6. Use of advanced data protection technologies
- 7. Planning and creating procedures for responding to cyber incidents
- 8. Cyber incident statistics
1. Introduction
In today’s digitally connected environment, cyber incidents are becoming increasingly frequent, more sophisticated, and more damaging for both organisations and individuals. Preventing incidents requires a systematic, proactive approach that includes technical, organisational, and educational measures.
The aim of this topic is to explore external literature sources in order to gain a deeper understanding of strategies for preventing future cyber incidents. The focus will be on implementing strong security policies, providing continuous education for all participants in the educational process, regularly testing and assessing security measures, applying advanced data‑protection technologies, and planning and developing procedures for effective incident response.
With the help of the analysed sources, the goal is to build awareness of the importance of cyber resilience and to acquire practical knowledge that will help you recognise threats, improve security practices, and ensure a safe and reliable digital environment.

Figure 3: Strategies for preventing future cyber incidents
Review external literature on strategies to prevent future cyber incidents on the following topics:
- implementing strong security policies,
- educating employees and users,
- educating faculty, administrators, and students about security threats,
- regular security testing and assessment, using advanced data protection technologies,
- planning and developing procedures for responding to cyber incidents.
2. Strategies to prevent future cyberattacks
Strategies for preventing future cyberattacks represent an integrated set of measures and procedures that combine technological tools, the human factor, and organisational processes to reduce risks and strengthen resilience to threats.
- Technology – includes the use of advanced security solutions such as firewalls, intrusion detection and prevention systems (IDS/IPS), antivirus tools, data encryption, multi‑factor authentication (MFA), and systems for monitoring and analysing network traffic. These tools help with early detection and blocking of potential attacks.
- People – involves continuous education of employees, students, and users about threats, security practices, and recognising attack attempts such as phishing or social engineering. The human factor is often the weakest link, so awareness and knowledge play a crucial role in prevention.
- Organisation – refers to establishing clear security policies, procedures, and protocols for responding to cyber incidents, conducting regular risk assessments, testing security systems, and planning business continuity and disaster recovery (BCP/DRP). Well‑structured organisational measures ensure a coordinated and timely response.
By combining these three aspects — technology, people, and organisation, it is possible to build a comprehensive security framework that not only provides a ready response to threats but also proactively prevents them. These measures include:
- regular updating of systems and applications,
- the use of strong passwords and two‑factor authentication (2FA),
- educating all users and raising awareness of cyber threats,
- regularly creating backups on physically separate devices,
- applying the principle of least privilege,
- using firewalls, antivirus protection, and monitoring systems,
- encrypting data (at rest, in processing, and in transit),
- establishing an effective incident response plan,
- regularly reviewing all of the above measures.
Sources that provide guidance and recommendations for strategies to prevent future cyber incidents:
- National CERT
- National Cyber Security Centre (NCCS)
- Personal Data Protection Agency (AZOP)
- European Union Agency for Cybersecurity (ENISA)
3. Implementing strong security policies
Security policies have become a standard in all organisations and represent a fundamental component of every organisation’s security system.
The implementation of strong security policies ensures clearly defined rules and procedures for protecting data, systems, and users within the organisation. Such policies include rules on access management, password use, software updates, backups, incident response, and employee training. Their application reduces the risk of cyber threats such as unauthorised access, malware, and data theft. In addition, security policies ensure compliance with applicable laws and regulations, such as the General Data Protection Regulation (GDPR), thereby safeguarding the institution’s legal security. A key advantage of strong policies is the development of security awareness within the workplace, encouraging responsible employee behaviour and proactive recognition of security risks. In this sense, security policies are not merely a technical framework but the foundation of an organisation’s overall security culture.
4. Education of employees and users, teaching and administrative staff and students about security threats
Changes that occur on an almost daily basis require all users of information systems to engage in continuous education and stay informed about new developments. Without constant learning and improvement in the area of cyber threats, we become easy targets for cybercriminals.
Educating employees, users, teaching and administrative staff, and students about security threats is extremely important, as the human factor often represents the weakest link in the cybersecurity chain. Without a basic understanding of cyber threats and security protocols, even the most advanced systems can be compromised due to user negligence or lack of awareness. Regular training increases awareness of risks, reduces the likelihood of unintentional mistakes, and strengthens the overall system’s resilience to cyberattacks such as phishing, malware, and data theft.
Education should cover topics such as recognising suspicious messages, password security, the importance of system updates, rules for using online services, and responsible behaviour on social networks and in the use of cloud services. It is especially important to tailor training content to different roles within the institution: teaching staff must be aware of threats that may arise during online classes, administrative staff must know how to securely handle sensitive personal data, and students should be taught how to protect their own data and digital identity. Systematic and continuous investment in security education builds a culture of responsibility and proactive behaviour, significantly contributing to the overall information security of the organisation.
5. Regular testing and safety assessment
Regular testing and assessment of cybersecurity are important because they enable the timely detection of vulnerabilities and weaknesses in the system before they can be exploited by malicious actors. The practice of regular security testing helps maintain a high level of protection, ensures compliance with regulations, and reduces the risk of cyber incidents that could have serious consequences for an organisation.
Tests such as penetration testing, security audits, attack simulations, and configuration analyses provide an objective evaluation of the actual security posture. These activities reveal technical, procedural, and organisational weaknesses, allowing corrective measures to be taken in a timely manner. In addition to technical aspects, assessments also include reviewing user awareness of security practices and adherence to internal policies. Awareness checks for all employees regarding cyber risks should be conducted at least twice a year through phishing exercises.
The regularity of these assessments and exercises is crucial due to the constantly evolving nature of threats and the development of new attack methods and techniques. Furthermore, by conducting them, organisations and institutions demonstrate responsibility for protecting the data of their users and partners, thereby increasing public trust. In educational institutions, where sensitive data is processed daily, and a large number of connected devices is used, such practices become essential for preserving the integrity, availability, and confidentiality of information systems.
6. Use of advanced data protection technologies
The use of advanced data‑protection technologies such as encryption, intrusion detection systems (IDS), artificial intelligence (AI), and machine learning (ML) has become essential for effective defense against sophisticated cyber threats.
- Encryption ensures that data remains unreadable to unauthorised individuals, even if it falls into their hands. Examples include emerging solutions such as post‑quantum cryptography and quantum key–based protection (e.g., Quantinuum).
- Intrusion Detection Systems (IDS) monitor network traffic or device activity (NIDS and HIDS), searching for known attack patterns or anomalies. Modern IDS platforms use both signature‑based and anomaly‑based detection, often supported by machine learning to identify unexpected threats.
- Artificial intelligence and machine learning enable automated analysis of large volumes of security data, rapid threat detection, and proactive defense. These solutions rely on models that identify anomalies in network traffic, malicious software, and user behaviour, and automatically generate alerts.
- AI also optimises encryption by automating key management and identifying weaknesses in encryption algorithms, for example, in the context of post‑quantum encryption and improving the efficiency of cryptographic systems.
7. Planning and creating procedures for responding to cyber incidents
Planning and developing procedures for responding to cyber incidents are extremely important, as they enable an organisation to face an attack quickly, effectively, and in an organised manner while minimising the resulting damage. The question is not whether a cyberattack will occur, but when it will occur. Well‑designed plans allow for rapid threat identification, containment of consequences, notification of relevant stakeholders, and restoration of normal operations, thereby protecting the organisation’s reputation, data, and business continuity. Predefined procedures ensure that everyone involved in the incident‑response process knows their role and how to reduce the impact of a cyber incident.
In addition to planning and developing incident‑response procedures, organisations should conduct cyber incident response exercises to test the effectiveness of these procedures in practice. Exercises should be carried out using different scenarios, such as a ransomware attack, data loss involving stolen personal information, or the shutdown of part of the information system due to a DDoS attack.
By conducting such exercises across the entire organisation, an effective response team can be formed, and all employees can increase their awareness of cyber threats.
8. Cyber incident statistics
Studying cybersecurity incident statistics is important because it provides real, measurable data about the types of attacks that occur, how often they happen, how they are carried out, and with what consequences. Such data enables a better understanding of threats, the identification of trends, and the making of effective security decisions.
The following link is available in Croatian only. Participants may use free AI-powered translation tools to access the provided materials.
You can find the latest statistical data on cybersecurity incidents at the provided link.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight