Skip to main content
BilgeQor
Back to industries

CTO, IT Director

Construction & Project Platforms

Verified cyberincident context · Croatia / Nacionalni CERT 2025

Croatia Nacionalni CERT 2025 cybersecurity incident and activity context

Market context — not industry-specific evidence

Croatia Nacionalni CERT report context (Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, published 2026-02-05) states that Nacionalni CERT processed 1,513 cyber incidents in 2025, a 35.9% increase compared with 2024. Incident type shares for 2025: phishing attacks 32%, unwanted messages 19%, other financially motivated fraud 18%, and attacker infrastructure 12% — these four categories are a subset of incident types and do not sum to 100%. Nacionalni CERT recorded 126,098 bots by malicious-content type in 2025, a 33.37% decrease compared with 2024. The CERTiffy system was used to check 37,191 URLs in 2025. These figures apply to Nacionalni CERT processed incidents and activities only and must not be presented as all cyber incidents in Croatia, total Croatian business incident prevalence, or industry-specific evidence.

Croatia · Nacionalni CERT 2025 processed-incident and activity context2025 reporting period · Published 2026

Cyber incidents processed by Nacionalni CERT — Croatia 2025

Cyber incidents processed by Nacionalni CERT in 2025
1,513
Unit
cyber incidents processed by Nacionalni CERT in 2025
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context

Includes incidents reported to Nacionalni CERT and incidents detected through Nacionalni CERT's own activities.

Nacionalni CERT 2025 processed cybersecurity incident context only. The 1,513 value refers to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia or total Croatian business incident prevalence. Not industry-specific evidence.

Year-on-year increase in Nacionalni CERT processed incidents — Croatia 2025

35.9% increase in Nacionalni CERT processed cyber incidents in 2025 compared with 2024
35.9%
Unit
percent increase in cyber incidents processed by Nacionalni CERT in 2025 compared with 2024
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context

Nacionalni CERT 2025 processed incident year-on-year change context only. The 35.9% value is a year-on-year change for Nacionalni CERT processed incidents and must not be presented as a measure of all-Croatia cyberattack volume change or total Croatian business incident trend. Not industry-specific evidence.

Nacionalni CERT processed incident type shares — Croatia 2025

Phishing attacks — 32% of Nacionalni CERT processed incidents in 2025
32%
Unit
percent of Nacionalni CERT processed incidents in 2025 categorised as phishing attacks
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context
Unwanted messages — 19% of Nacionalni CERT processed incidents in 2025
19%
Unit
percent of Nacionalni CERT processed incidents in 2025 categorised as unwanted messages
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context
Other financially motivated fraud — 18% of Nacionalni CERT processed incidents in 2025
18%
Unit
percent of Nacionalni CERT processed incidents in 2025 categorised as other financially motivated fraud
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context
Attacker infrastructure — 12% of Nacionalni CERT processed incidents in 2025
12%
Unit
percent of Nacionalni CERT processed incidents in 2025 categorised as attacker infrastructure
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context

Nacionalni CERT 2025 processed incident type share context only. The 32%, 19%, 18%, and 12% values apply only to Nacionalni CERT processed incidents in 2025 and must not be presented as all-Croatia attack prevalence or all-business attack type prevalence. The four categories shown are a subset of incident types and do not sum to 100%. Not industry-specific evidence.

Bots recorded by malicious-content type — Croatia 2025

Bots recorded by malicious-content type by Nacionalni CERT in 2025
126,098
Unit
bots recorded by malicious-content type by Nacionalni CERT in 2025
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context

Recorded bots decreased by 33.37% in 2025 compared with 2024. This refers to Nacionalni CERT bot observations by malicious-content type only and must not be presented as proof of reduced Croatian bot threat.

Nacionalni CERT 2025 recorded bot observation context only. The 126,098 value refers to bots recorded by malicious-content type and must not be presented as confirmed compromised organisations, resolved incidents, protected organisations, or proof of protection. Not total Croatian business incident prevalence and not industry-specific evidence.

URLs checked via CERTiffy — Croatia 2025

URLs checked via the CERTiffy system by Nacionalni CERT in 2025
37,191
Unit
URLs checked via the CERTiffy system by Nacionalni CERT in 2025
Period
Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Scope
Croatia Nacionalni CERT 2025 cybersecurity incident context

CERTiffy is a URL-checking system operated by Nacionalni CERT. The 37,191 value is a count of URL-checking activity only.

Nacionalni CERT 2025 CERTiffy URL-checking activity context only. The 37,191 value refers to URLs checked via the CERTiffy system and must not be presented as confirmed malicious websites, resolved incidents, or protected users. Not total Croatian business incident prevalence and not industry-specific evidence.

Source: Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026

Scope: Nacionalni CERT / CARNET annual report context published 2026-02-05. The 1,513 processed incidents refer only to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia. The 32%, 19%, 18%, and 12% incident-type shares are a subset of Nacionalni CERT processed incident types and do not sum to 100%; they must not be presented as all-Croatia attack prevalence. The 35.9% is a year-on-year change for Nacionalni CERT processed incidents; must not be presented as a measure of all-Croatia cyberattack volume change. The 126,098 bot observations must not be presented as confirmed compromised organisations, resolved incidents, or proof of protection. The 33.37% bot decrease is an absolute value of a year-on-year change for recorded bots only. The 37,191 URL checks are URL-checking activity context and must not be presented as confirmed malicious websites, resolved incidents, or protected users. These figures do not measure total Croatian business incident prevalence, hidden incident prevalence, population-wide victimisation rates, all-sector incident totals, industry-specific evidence, compliance achievement, certification, or security outcomes.

Methodology: Official Nacionalni CERT / CARNET annual report context published 2026-02-05. The admitted indicators describe Nacionalni CERT 2025 processed cybersecurity incidents (total count and year-on-year change), incident-type shares, recorded bots by malicious-content type, and CERTiffy URL-checking activity. The 1,513 processed incidents refer only to incidents reported to Nacionalni CERT or detected through Nacionalni CERT's own activities and must not be presented as all cyber incidents in Croatia. The 32%, 19%, 18%, and 12% incident-type shares apply only to Nacionalni CERT processed incidents in 2025; they must not be presented as all-Croatia attack prevalence or all-business prevalence. The four category shares shown are a subset of incident types and do not sum to 100%. The 35.9% value is a year-on-year change for Nacionalni CERT processed incidents and must not be presented as a measure of all-Croatia cyberattack volume change. The 126,098 recorded bots are observations by malicious-content type and must not be presented as confirmed compromised organisations, resolved incidents, protected organisations, or proof of protection. The 33.37% bot decrease is an absolute value of a year-on-year change for recorded bots and must not be presented as proof of reduced Croatian bot threat. The 37,191 URL checks via CERTiffy are URL-checking activity and must not be presented as confirmed malicious websites, resolved incidents, or protected users. Do not present any admitted indicator as total Croatian business incident prevalence, hidden incident prevalence, population-wide victimisation rate, all-sector incident rate, all-Croatia cyberattack volume, industry-specific evidence, compliance achievement, certification, proof of security, or guaranteed protection.

Accessible data table
Verified Croatia Nacionalni CERT 2025 cybersecurity incident context data from Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026, reporting period Croatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context..
MetricValueSourceScopeReporting period
Cyber incidents processed by Nacionalni CERT in 20251,513 cyber incidents processed by Nacionalni CERT in 2025Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
35.9% increase in Nacionalni CERT processed cyber incidents in 2025 compared with 202435.9% percent increase in cyber incidents processed by Nacionalni CERT in 2025 compared with 2024Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Phishing attacks — 32% of Nacionalni CERT processed incidents in 202532% percent of Nacionalni CERT processed incidents in 2025 categorised as phishing attacksNacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Unwanted messages — 19% of Nacionalni CERT processed incidents in 202519% percent of Nacionalni CERT processed incidents in 2025 categorised as unwanted messagesNacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Other financially motivated fraud — 18% of Nacionalni CERT processed incidents in 202518% percent of Nacionalni CERT processed incidents in 2025 categorised as other financially motivated fraudNacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Attacker infrastructure — 12% of Nacionalni CERT processed incidents in 202512% percent of Nacionalni CERT processed incidents in 2025 categorised as attacker infrastructureNacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Bots recorded by malicious-content type by Nacionalni CERT in 2025126,098 bots recorded by malicious-content type by Nacionalni CERT in 2025Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
URLs checked via the CERTiffy system by Nacionalni CERT in 202537,191 URLs checked via the CERTiffy system by Nacionalni CERT in 2025Nacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.
Croatia Nacionalni CERT report context states that recorded bots decreased by 33.37% in 2025 compared with 2024. The value field stores 33.37 as the absolute value of the percentage decrease. This metric is admitted to records for completeness but must not be charted as a bar; it is referenced in supporting text only. Must not be presented as proof of reduced Croatian bot threat or total Croatian cybersecurity improvement.33.37% percent decrease in bots recorded by malicious-content type in 2025 compared with 2024 — absolute value of decreaseNacionalni CERT / CARNET, Godisnji izvjestaj Nacionalnog CERT-a za 2025. godinu, 2026Croatia Nacionalni CERT 2025 cybersecurity incident contextCroatia Nacionalni CERT 2025 processed cybersecurity incident, incident-category, bot-observation and URL-checking context.

Relevant loss and exposure areas

These existing industry scoping prompts help frame a proposal. They do not assert an incident, loss, or market-specific condition.

Industry themes

  • Data Loss
  • Unauthorized Access
  • Business Email Compromise

Digital surfaces in scope

Project DashboardsBidding PortalsMobile Site Apps

What structured security support changes

The Security File turns risk signals into decisions.

Official market data shows where risk exists. The BilgeQor Security File connects that context to your real websites, apps, accounts, payment flows and team responsibilities, so leaders can decide what to fix first.

Why this matters

The file gives your team one place to understand what was reviewed, what matters, what changed, and what still needs a decision.

BilgeQor Method

What the Security File contains

A Security File is not a generic report. It is a structured decision record for the assets, workflows and risks covered by the agreed scope.

01

Market and sector context

We connect official market signals and industry exposure to the business surfaces in scope.

02

Exposure map

We map websites, apps, accounts, payment journeys, admin roles, vendors and customer-facing workflows.

03

Priority register

We separate urgent risks, important improvements and lower-priority findings so the next action is clear.

04

Executive summary

We provide a concise summary that leadership, operations, vendors or insurers can read without needing raw technical detail.

05

Remediation roadmap

We turn findings into a 14 / 30 / 90-day action path with ownership, evidence notes and follow-through guidance.

What it is not

  • Not a guarantee of perfect security.
  • Not a certification or compliance verdict.
  • Not a per-company loss estimate or fear-based claim.