CRA full compliance required 453 days left What it means for you
THZ Networks Under attack? SOS — incident response, any hour of any day

REPORTS

Slovenia in numbers: what SI-CERT actually handled

The national response centre publishes its own figures every year. They are more useful than any vendor threat map, and they say something uncomfortable about the ones that get reported.

The trend

Incidents handled by SI-CERT: 3,177 in 2021, 4,123 in 2022, 4,280 in 2023, 4,587 in 2024 and 6,196 in 2025. That last step is a 35% rise in a single year, and it is the reported figure — the floor, not the total.

€40.4 million was reported lost to cyber fraud in 2025, a third more than the year before. 1,995 of the cases were phishing, still the single commonest way in. 778 were classed as technically demanding.

The number that should not be read as good news

Twenty-nine ransomware incidents were recorded in the whole of Slovenia in 2025 — every sector, every reporter, the national total. In Serbia the same year, 48 were recorded from designated critical operators alone: organisations that have to file a return.

A smaller country reporting fewer incidents than one neighbour's mandatory-reporting subset is not a sign that less is happening. It is a sign of what reaches a register when reporting is not yet compulsory — which is precisely what NIS2 changes.

Source

All Slovenian figures above are SI-CERT's own, from its annual review at cert.si. We publish them rather than a live threat map because a map drawn from somebody else's sensor telemetry says nothing about this market, and usually replays a recording.

SLOVENIA, MEASURED

It is not levelling off

These are not our numbers. They are SI-CERT's — the national response centre every Slovenian organisation reports to — and 2025 is the year the line stopped being a slope and became a step.

  • 3,177 2021
  • 4,123 2022
  • 4,280 2023
  • 4,587 2024
  • 6,196 2025
Incidents handled by SI-CERT per year. 2025: 6,196, up 35% on 2024, with 44% more reports received. Source: SI-CERT
  • €40.4 MReported to SI-CERT as lost to cyber fraud in 2025, a third more than in 2024
  • 1,995Phishing cases handled in one year — still the single commonest way in
  • 778Technically demanding incidents: the ones that needed somebody who knew what they were doing

THE REGION, COUNTED

Slovenia's ransomware figure is the one nobody had to report

Serbia has required every operator of a critical ICT system to file a return on every incident since 2020. In Slovenia the equivalent duty reached roughly a thousand organisations only on 19 June 2025. Put the two ransomware counts beside each other and the gap is not the attack rate — it is who was obliged to count.

SLOVENIA · 2025 29 ransomware incidents recorded in the entire country — every sector, every reporter, the national total.
SERBIA · 2025 48 ransomware incidents from the designated critical operators alone — organisations that have had to file a return on every incident since 2020.

A few hundred obliged Serbian operators found 1.7× more ransomware than the whole of Slovenia recorded. And across the second half of 2025, nine sectors covered by ZInfV-1 — drinking water, waste water, postal, waste, chemicals, manufacturing, digital providers, space and managed ICT — recorded zero incidents between them. That is not a quiet half-year. It is a half-year nobody was counting. ENISA names under-reporting as one reason the impact of ransomware is documented in so few cases across the EU, and since 19 June 2025 not counting is no longer an option: the incident you never recorded is still the one you answer for.

  • 21.5% of EU enterprises suffered consequences from an ICT security incident in a single year.
  • 81.1% of cybercrime incidents against EU organisations in ENISA's latest threat landscape were ransomware.
  • 328.9 M port scans against Serbia's critical operators in 2025 — three times the 2024 figure.
  • −71% fall in ransomware that got through those operators, 168 to 48, while attack volume tripled. That is what being watched buys.

THE COUNTER-ARGUMENT

“Slovenia has one of the lowest incident rates in the EU.”

It does, on paper. Eurostat puts Slovenian enterprises at 11.6% reporting consequences from an ICT security incident against an EU average of 21.5% — second-lowest of the twenty-seven, behind only Austria.

In the same window SI-CERT handled 6,196 incidents against 4,587 the year before — a 35% rise — and nine ZInfV-1 sectors recorded none at all. A survey measures what a company noticed and chose to say. A response centre measures what somebody actually had to work on. When the two disagree by that margin the difference is not the threat. It is the visibility, and visibility is the part you can buy.

None of this is abstract. Ransomware took down the passenger information system at Split Airport, halting take-offs and landings until every flight was suspended. In November 2023 it reached Holding Slovenske elektrarne, which generates about 60% of Slovenia's electricity. Sources: URSIV / SI-CERT, Nacionalni CERT RS, ENISA Threat Landscape 2025, Eurostat, HSE.