1. INTRODUCTION Nowhere has technological development been more dynamic and comprehensive than in the area of communication and information technology. The focus has always been on the rapid development and introduction of new services and products, while the security-related aspects usually had little influence on the broad acceptance of new technologies. The life cycles of modern-day information systems, from the process of planning, introduction and usage to their withdrawal from use are very short, which often makes their systematic testing impossible and is most commonly applied as an exception, in expressly prescribed cases. Users usually have minimal knowledge of the technology they are using, and the technology is applied in such a way that makes it very hard to estimate the security characteristics of the majority of commercial products regarding the protection of user data confidentiality and privacy. Due to that, users’ attitude towards the communication and information technology is based almost exclusively on blind confidence. Modern societies are deeply imbued with communication and information technology. People are nowadays connected using various technologies for the transmission of text, image and sound, including the increasing Internet of Things (IoT) trend. While a deviation in the normal functioning of a certain kind of communication and information system could go unnoticed, improper operation of some other systems could have harsh consequences for the functioning of the State; it can cause loss of life, damage to health, great material damage, pollution of the environment and the disturbance of other functionalities essential for the proper functioning of the society as a whole. From the beginning of the development of communication and information technologies until the present day, deviations in their proper functioning have occurred due to different reasons, from human error or malicious action to technological error or organizational omission. The creation of the Internet and connecting a number of communication and information systems of the public, academic and economic sectors, as well as citizens, created the contemporary cyberspace composed not only of this interconnected infrastructure, but also of the ever growing amounts of available information, and users communicating increasingly among themselves using a growing number of different services - some completely new, some traditional, but in a new, virtual form. Deviations in the proper operation of these interconnected systems or their parts are no longer merely technical difficulties; they pose a danger with a global security impact. Modern societies counter them with a range of activities and measures collectively called “cyber security”. The term “cyber” entered the Croatian legal system upon the ratification of the Budapest Convention on Cybercrime1 back in 2002. Following from that, the term “cyber” is most 1 Act on the Ratification of the Convention on Cybercrime (Official Gazette No 09/02) and Act on the Ratification of the Additional Protocol to the Convention on Cybercrime, concerning criminalisation of acts of a racist and xenophobic nature committed through computer systems (Official Gazette No 04/08). 3 of 31

Select target paragraph3