WebArat – GDPR a informačná bezpečnosť | IT ASSISTANCE
Information security and cybersecurity overlap to a significant extent, but they differ in scope, terminology and the sources of their requirements. Information security focuses on protecting information in all forms, while cybersecurity places particular emphasis on protecting networks, information systems and digital services.

Information security

In this area, our focus is not only on complying with GDPR requirements, but also on comprehensively implementing an information security management system in accordance with ISO/IEC 27001:2022. This standard outlines the requirements for effectively managing and protecting information by implementing and maintaining an ISMS (Information Security Management System) .

Cybersecurity

Cybersecurity is closely linked to applicable legislation, specifically Act No. 69/2018 Coll. on Cybersecurity in Slovakia and Act No. 264/2025 Coll., on Cybersecurity in the Czech Republic.

Cybersecurity legislation and the ISO/IEC 27001 standard set requirements for security management and the implementation of appropriate organisational and technical measures. The specific scope of obligations depends on the organisation’s status, the services it provides and the applicable legal or normative requirements.

In accordance with applicable cybersecurity legislation, we offer the following services:

🛡️

Implementation of cybersecurity requirements

⚙️

Security consulting

🔎

Cybersecurity audits

Legislative obligations relating to cybersecurity

Slovak Republic

In Slovakia, cybersecurity is governed by Act No. 69/2018 Coll. on Cybersecurity, as amended. The requirements of the NIS2 Directive were transposed into the Act primarily by Amendment No. 366/2024 Coll., effective from 1 January 2025.

  • The Act is based primarily on the principle of self-identification of regulated entities.
  • An entity that meets the conditions under Sections 17 or 18 of the Act, together with the relevant annexes, identifies itself as an operator of an essential service or an operator of a critical essential service.
  • If an entity identifies itself as regulated, it must notify the Slovak National Security Authority (NBÚ) within the statutory period and is subsequently entered in the relevant register.
  • Regulated entities must implement and maintain appropriate security measures and comply with cybersecurity incident reporting obligations.

Czech Republic

Since 1 November 2025, cybersecurity in the Czech Republic has been governed by Act No. 264/2025 Coll., on Cybersecurity, which implements the requirements of the NIS2 Directive.

  • The Act uses regulated service provider as a key concept.
  • Regulated service providers are classified, according to statutory criteria, under a regime of higher or lower obligations.
  • The scope of security measures, risk management and other obligations depends on the applicable regime.
  • Regulated entities are also subject to cybersecurity incident notification and reporting obligations.

European legislation

  • Directive (EU) 2022/2555 (NIS2) – establishes measures for a high common level of cybersecurity across the EU and repealed the previous Directive (EU) 2016/1148 (NIS).
  • Regulation (EU) 2019/881 (Cybersecurity Act) – strengthens the role of ENISA and establishes an EU framework for cybersecurity certification.
Cybersecurity is not only a legal obligation, but also an essential component of information protection and business continuity. By implementing the requirements of laws and European directives, companies can minimise risks and prepare for current and future threats.