The Government Has Approved the Draft Cyber Resilience Act. What Could It Mean for Critical Infrastructure?
The Government of the Slovak Republic has approved a draft act on the cybersecurity of products with digital elements, also referred to as the cyber resilience act. This is a further step in the legislative process; the bill will subsequently be debated in the National Council of the Slovak Republic.
The very focus of the forthcoming legislation opens up an important topic from the perspective of critical infrastructure. Energy, transport, water management, healthcare, digital networks and public administration are today heavily dependent on products containing digital elements. The security of these products therefore cannot be seen separately from the security and resilience of the services they support.
From the perspective of the Critical Infrastructure Association of the Slovak Republic, the broader idea is what matters most: the resilience of critical infrastructure begins with the technologies it is built from.
The forthcoming legislation will not, however, apply to all digital products without distinction. Exemptions cover, for example, certain open-source products, as well as areas already subject to specific European regulation – such as civil aviation or the automotive industry. A special regime also applies to products developed exclusively for national security or defence purposes.
Security Begins Before Procurement
In cybersecurity, attention often focuses on protecting one's own networks, systems, data and user accounts. That is essential, but it is not enough. An organisation may have sound internal security measures in place and still remain vulnerable if it uses a product with serious security shortcomings or inadequate support.
The risk therefore arises as early as the decision on which technology the organisation will buy and under what conditions it will operate it.
For products intended for critical processes, alongside price, functionality and technical parameters, their long-term security sustainability should also be assessed. What matters is how vulnerabilities are handled, the availability of updates, the length of technical support, the options for secure configuration and the extent of the supplier's remote access.
Security should thus not be a property addressed after the fact, but one of the criteria applied when the product is selected.
Technological Dependence Is an Operational Risk
Modern critical infrastructure operates within an extensive network of technological and supplier relationships. Besides manufacturers, it involves integrators, service companies, providers of communication and cloud services and other subcontractors.
For a critical entity it is therefore important to know which technologies are indispensable for providing the essential service, which components have no immediate substitute, and where there is a pronounced dependence on an external partner. Mapping of this kind makes it possible to identify the points at which technological or supplier dependence may turn into an operational risk in a crisis.
Recording them is not enough in itself.
Real preparedness is tested only by concrete scenarios – for example the unavailability of a manufacturer, the failure of a service company, the compromise of an update mechanism, or the unavailability of an external digital service. It is precisely such situations that can reveal the difference between formally established processes and an organisation's actual ability to cope with disruption.
The Long Service Life of Equipment Brings a Particular Challenge
In energy, transport, industry and water management, technologies are often in use for decades. The digital components within them, however, age considerably faster than the physical infrastructure itself.
A situation can therefore arise in which equipment is still technically functional, but its operating system, communication protocol or security feature is no longer supported by the manufacturer.
When making investment decisions it is therefore necessary to consider not only the purchase price and technical service life, but also future security maintenance and modernisation. Technological debt can gradually turn into a vulnerability whose removal will be costly or operationally complicated.
Cyber Resilience as Part of Strategic Decision-Making
Cyber resilience cannot be the exclusive task of the IT or security department. In critical infrastructure it concerns the organisation's management, operations, investment, procurement and continuity management. In major technological decisions it is therefore necessary to assess not only the likelihood of an incident, but also its possible consequences and the organisation's ability to restore safe operation.
Resilience presupposes readiness for a situation in which preventive measures fail to avert disruption. This may mean the option of temporary operation in a limited mode, the replacement of a critical component, or the use of an alternative procedure.
From Preventing an Incident to the Ability to Carry On
Cyber resilience does not mean a state in which an incident never occurs. It represents the ability to identify an incident in good time, limit its consequences and maintain the provision of the service, or restore it within an acceptable time.
For critical infrastructure it is therefore essential to link cybersecurity with operational continuity. The significance of an incident is measured not only by the extent of the information systems affected, but above all by its possible impact on the provision of essential services and on other interdependent sectors.
Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic, comments in this connection:
“The resilience of critical infrastructure begins with the technologies it is built from. A critical entity needs to know not only what a given product can do, but also where it comes from, what dependencies arise from using it, and whether it will be secure and supported throughout the entire period during which the provision of an essential service depends on it.”
An Opportunity to Prepare in Advance
From the perspective of critical infrastructure, the government's approval of the bill can be seen as an impulse for a broader discussion on the security of the technologies that enter critical processes. Regardless of how the legislative process unfolds, it is already appropriate today to consider whether organisations know their key technological dependencies, the support conditions of the products they use, and the risks associated with their suppliers.
The Critical Infrastructure Association of the Slovak Republic is systematically developing professional capacities in assessing technological risks, monitoring supply chains and sharing information between individual sectors – activities that can contribute to the early identification of risks and to strengthening the resilience of critical infrastructure.
The forthcoming legislation thus opens up an opportunity to shift the view of cybersecurity from protecting individual products towards a broader goal: increasing the resilience of the services and systems on which the functioning of society depends.





Gas as a Test of Slovakia's Resilience: Energy Security Does Not End with the Price of the Commodity




