HR EN

CYRES 2026 · Security 4.0

Cybersecurity
& digital resilience

A scientific and professional conference on cybersecurity and digital resilience. Four sessions: scientific, professional, management and student.

View program
Date
21–22 Sep 2026
Venue
FSRE · Mostar
Registration
Open

Security 4.0 - cybersecurity
and digital resilience

CYRES 2026 brings together the technical, governance and legal sides of cybersecurity - from secure architectures and protection models to incident response - set against growing digital dependency and an increasingly demanding EU regulatory landscape.

The conference runs in four complementary sessions: a scientific session with peer-reviewed papers and panels, a closed professional session for the security sector and law enforcement focused on practical digital forensics and incident response, a management session (in preparation) for executives and CISOs, and a student session for student papers and projects.

Our goal is to strengthen the research and professional community in Bosnia and Herzegovina and the broader Western Balkans. The host is FSRE, University of Mostar.

Topics

  1. Cyber Defense

    Red / Blue / Purple team, threat hunting, incident response, detection engineering - SOC practice from the field.

  2. Critical Infrastructure

    OT / ICS, SCADA, energy and telecom. When the target is not a server, but a turbine or substation.

  3. AI & Security

    Adversarial ML, prompt injection, model supply chain, AI red-teaming.

  4. Privacy & Compliance

    NIS2, DORA, GDPR, data governance - when regulation becomes an engineering problem.

  5. Regional & hybrid threats

    Hybrid warfare, state-sponsored operations and Western Balkans cyber capacity.

Program

Four sessions across two days. Select a session for topics, schedule and participation details.

Agenda

Two days of program. Open a day for the detailed schedule, topics and speakers. The program is indicative and subject to minor changes.

Committees

The conference is led by the FSRE organizing committee, while the scientific & professional committee brings together professors from across the region. Click a committee card to view its members.

Call for Papers

Original research papers, review articles and preliminary communications - all submissions undergo double-blind peer review in the IJISE Special Issue.

Deadline
31 August 2026
Format
original paper · review article · preliminary communication
Review
double-blind
Access
open access · no APC
Languages
HR · EN
Submit to IJISE Special Issue

Papers are submitted to one of the three thematic scientific sessions (A, B, C) - the list of topics is in the Program section. IJISE is an international open-access journal of the University of Mostar - no APC, rolling publication. Before submitting, please read Instructions for Authors.

Date

21–22. 09. 2026.

Two working days, Monday and Tuesday. The detailed schedule and speakers will be announced in the first program release.

Venue

FSRE

Faculty of Mechanical Engineering, Computing and Electrical Engineering,
University of Mostar.
Matice hrvatske bb, 88000 Mostar, BiH.

Open in maps

Sponsors

Partners

FSRE · IJSE · FSB

Media partners

Registration is
open

Sign up for CYRES Conference 2026. You will receive a confirmation email with a QR ticket for conference entry.

Open navigation

Organizing committee

FSRE, University of Mostar - leads technical and logistical organization of the conference.

  1. Ivan Markić

    PhD, Assistant Professor

    FSRE · University of Mostar

  2. Željko Marušić

    PhD, Assistant Professor

    FSRE · University of Mostar

  3. Danijel Zelenika

    PhD, Assistant Professor

    FSRE · University of Mostar

  4. Igor Bošnjak

    PhD, Assistant Professor

    FSRE · University of Mostar

  5. Igor Jurčić

    PhD, Assistant Professor

    FSRE · University of Mostar

  6. Jelena Matković

    PhD, Assistant Professor

    FSRE · University of Mostar

  7. Petar Marić

    MEng EE, Senior Assistant

    FSRE · University of Mostar

  8. Nina Popović

    LLM

    FSRE · University of Mostar

  9. Marija Grubešić

    LLM

    FSRE · University of Mostar

Scientific & professional committee

Professors from Mostar, Zagreb, Split, Rijeka, Sarajevo and Tuzla - responsible for scientific quality, peer review and program design.

  1. Davorka Šaravanja

    PhD, Full Professor

    FSRE · University of Mostar

  2. Adisa Vučina

    PhD, Full Professor

    FSRE · University of Mostar

  3. Nebojša Rašović

    PhD, Associate Professor

    FSRE · University of Mostar

  4. Ivan Ramljak

    PhD, Associate Professor

    FSRE · University of Mostar

  5. Goran Kraljević

    PhD, Associate Professor

    J.P. Hrvatske telekomunikacije

  6. Jadranko Matuško

    PhD, Full Professor

    FER · University of Zagreb

  7. Josip Knezović

    PhD, Full Professor

    FER · University of Zagreb

  8. Jonatan Lerga

    PhD, Full Professor

    Faculty of Engineering · University of Rijeka

  9. Maja Štula

    PhD, Full Professor

    FESB · University of Split

  10. Toni Perković

    PhD, Full Professor

    FESB · University of Split

  11. Marin Bugarić

    PhD, Full Professor

    FESB · University of Split

  12. Ivo Stančić

    PhD, Associate Professor

    FESB · University of Split

  13. Mario Čagalj

    PhD, Full Professor

    FESB · University of Split

  14. Saša Mrdović

    PhD, Full Professor

    ETF · University of Sarajevo

  15. Samim Konjicija

    PhD, Associate Professor

    ETF · University of Sarajevo

  16. Aljo Mujčić

    PhD, Full Professor

    Faculty of Electrical Engineering · University of Tuzla

  17. Jasmin Azemović

    PhD, Full Professor

    FIT · „Džemal Bijedić“ University of Mostar

Session 1 · IJISE Special Issue

Scientific session

Peer-reviewed papers, plenary lectures and panel discussions for the academic community, organised into three thematic sessions. Papers are submitted to one of the sessions below.

Session A

Cybersecurity of information systems

  • Modelling and classification of cyber threats and attack vectors
  • Methods and architectures for detection and protection of information systems
  • Software security and formal methods for code verification
  • Security of network protocols and communication infrastructure
  • Cryptographic protocols, identity management and access control models
  • Security of operating systems and virtual environments
  • Digital forensics and investigation of cyber incidents
  • Methodologies for security exposure assessment and resilience testing
  • Security of embedded systems, IoT architectures and the industrial internet
  • Security of telecommunication infrastructure and next-generation protocols
  • Business continuity and recovery of information systems after cyber incidents
  • Cyber operations in the context of hybrid warfare, geopolitical tensions and state-sponsored attacks
Session B

Cybersecurity management and regulatory frameworks

  • Analysis and comparative research of cybersecurity regulatory frameworks
  • Information security management models and compliance methodologies
  • Research on methodologies for assessing and quantifying cyber risk
  • Legal and institutional liability frameworks in cyberspace
  • Personal data protection and privacy research in the digital environment
  • Supply chain and third-party security management
  • Security capacity building, educational frameworks and human resource development in cybersecurity
  • Comparative analyses of regulatory implementation across jurisdictions
  • Research on cyber policy and strategic governance at national and supranational level
Session C

Artificial intelligence and security analytics

  • Application of machine learning in threat detection, network traffic analysis and anomaly identification
  • Models for automated incident response and event correlation
  • Application of large language models in threat, malware and security report analysis
  • Interpretability, reliability and limitations of analytical models in a security context
  • Ethical and legal aspects of automated decisions in security systems
  • Evaluation methods and comparison of machine-learning approaches to security problems

Session 2 · by invitation · fee 200 KM

Professional session

Practical workshops for the security sector, law enforcement and relevant institutions.

Day 1 · Forensics and analytics

  1. 10:00 - 12:00

    Workshop 1

    Digital forensics in operational investigations

    Approaches, methodology and an overview of the digital evidence processing workflow.

    • Digital forensics fundamentals
    • Methodology
    • Best practices
    • Trends and updates across selected digital forensics areas
    • Problems and challenges
    • Training
  2. 12:00 - 13:00

    Break

    Lunch

  3. 13:00 - 15:30

    Workshop 2

    Digital traces and analytical procedures

    Identification, interpretation and correlation of digital artifacts in criminal proceedings.

    • Tools for artifact identification and analysis
    • Partner solution demo block
    • Tool capabilities and limitations
    • Correlating artifacts across multiple tools or cases
    • OSINT techniques
    • Reporting
    • Expert discussion and experience exchange

Day 2 · Incident handling

  1. 10:00 - 12:00

    Workshop 3

    Cyber incident handling

    Operational decision-making, field response and coordination of technical and investigative capabilities.

    • Incident response
    • On-site response
    • Triage
    • Discussion of operational needs, challenges and future training/project opportunities

Session 3 · fee 200 KM

Management session

Strategic and managerial perspective on cybersecurity - executives, CISOs and decision-makers in the public and private sector.

View the schedule in the Agenda

Session 4 · student forum

Student session

A space for student papers, projects and research in cybersecurity and digital resilience.

View the schedule in the Agenda

Day 1 · 21 September 2026

Management session — plenary lectures

The program is indicative and subject to minor changes.

  1. 08:30 – 09:30

    Participant registration

    Arrival and registration of participants, collection of badges and conference materials.

  2. 09:30 – 10:00

    Conference Opening

    Opening remarks by the organizers, partner institutions and representatives of the competent authorities, followed by a presentation of the objectives of the Management Session and an emphasis on the importance of cybersecurity for the public sector, the economy, critical services and large organizational systems.

    • Prof. Davorka Šaravanja, PhD, Dean, Faculty of Mechanical Engineering, Computing and Electrical Engineering, University of Mostar
    • Prof. Marko Odak, PhD, Vice-Rector for Science, University of Mostar
    • Prof. Nebojša Rašović, PhD, Vice-Dean for Science, Faculty of Mechanical Engineering, Computing and Electrical Engineering, University of Mostar
    • Krešimir Hausknecht, INsig2
  3. 10:00 – 10:20

    Digital Resilience as a Common Challenge of Science, Professional Practice, Management and Education

    The paper distinguishes between digital security and resilience and proposes a framework for integrating technical, organizational and educational aspects in IT and OT environments. The framework emphasizes the maintenance of critical functions and service recovery during disruptions.

    • Asst. Prof. Ivan Markić, PhD, Vice-Dean for Digitalization and Innovation, Faculty of Mechanical Engineering, Computing and Electrical Engineering, University of Mostar
  4. 10:20 – 10:40

    Management of Security Policies and Controls in Organizational Systems

    The lecture addresses the transition from formal security policies to their effective implementation within an organization, including the definition of controls, responsibilities, deadlines, implementation monitoring, reporting and auditability of security processes.

    • Prof. Jasmin Azemović, PhD, Faculty of Information Technologies, Džemal Bijedić University of Mostar
  5. 10:40 – 11:00

    Coffee Break

  6. 11:00 – 11:20

    RISC-V ISA and the Architecture of Trust — Security in an Open, Modular Instruction Set Architecture

    RISC-V's open and modular ISA enables auditable, composable security, from privilege modes and PMP to CoVE-based confidential computing. It also highlights emerging research challenges and links RISC-V security to European digital sovereignty.

    • Prof. Josip Knezović, PhD, Faculty of Electrical Engineering and Computing, University of Zagreb
  7. 11:20 – 11:40

    Application of Artificial Intelligence in Cyber Threat and Security Event Analysis

    The lecture examines the use of artificial intelligence in cybersecurity, with a focus on security event analysis, pattern recognition, support for incident handling, automation of selected security processes and the limitations of AI tools in security environments.

    • Prof. Edis Mekić, PhD, State University of Novi Pazar
  8. 11:40 – 12:00

    Forensic Readiness of Information Systems and Preservation of Digital Evidence

    The lecture examines how organizations can prepare information systems in advance for effective post-incident handling, including event logging, preservation of digital traces, evidence integrity, basic forensic procedures and cooperation with competent authorities.

    • Prof. Saša Mrdović, PhD, Faculty of Electrical Engineering, University of Sarajevo
  9. 12:00 – 13:00

    Lunch

  10. 13:00 – 13:20

    DIGI SAFE UNION Project: An Institutional Framework for Strengthening Digital Resilience

    The presentation introduces the objectives, activities and expected outcomes of the DIGI SAFE UNION project, with an emphasis on strengthening institutional capacities, education, improving the level of digital security and connecting academia, the public sector and professional practice.

    • Prof. Mirjana Miličević, PhD, Project Office, University of Mostar
  11. 13:20 – 13:40

    Institutional Coordination and Cyber Incident Reporting

    A brief presentation on the role of competent institutions in reporting, recording and coordinating responses to cyber incidents, with an emphasis on cooperation with CERT, law enforcement authorities, institutions and organizations affected by incidents.

    • Davor Bagarić, Ministry of Security of Bosnia and Herzegovina / CERT
  12. 13:40 – 14:00

    Collection and Analysis of Digital Evidence in Investigations of Terrorism and Security-Sensitive Criminal Offences

    The lecture addresses the specific requirements for collecting, preserving and analyzing digital evidence in investigations of terrorism and other security-sensitive criminal offences. Particular emphasis is placed on identifying relevant digital traces, ensuring evidence integrity, documenting procedures, forensic analysis of communications and computer data, and maintaining the chain of custody through cooperation among law enforcement, prosecutors and digital forensics experts.

    • Marko Banožić, PhD, Ministry of Interior of West Herzegovina Canton
  13. 14:00 – 14:20

    Domain-Specific Accelerators for Post-Quantum Cryptography

    Falcon stands out among NIST-standardized digital signatures for its compact public keys and signatures, making it attractive for bandwidth- and storage-constrained systems. However, its reliance on floating-point arithmetic and Gaussian sampling makes secure and side-channel-resistant implementation particularly challenging.

    • Asst. Prof. Ratko Pilipović, PhD, Faculty of Computer and Information Science, University of Ljubljana
  14. 14:20 – 14:40

    Coffee Break

  15. 14:40 – 15:00

    Crisis Communication During a Cyber Incident

    The presentation addresses communication during an incident with employees, users, partners, the media and competent authorities, including coordination among management, IT, the legal department and public relations.

    • Marin Čuljak, Public Relations Office, University of Mostar
  16. 15:00 – 15:20

    Security of ERP Systems, Business Applications and Access Rights

    The lecture addresses the security of business systems, access rights, privileged users, audit trails, accountability of business process owners and control of external vendors.

    • Miljenko Stipić, Galileo
  17. 15:20 – 15:40

    Security Challenges of (Autonomous) IoT Systems

    Autonomous IoT systems introduce new security risks across physical, wireless, and decision-making layers. This talk highlights key threats and secure-by-design principles for resilient IoT architectures.

    • Prof. Marin Vuković, PhD, Faculty of Electrical Engineering and Computing, University of Zagreb
  18. 15:40 – 16:00

    Cross-Border Data Governance for Accessible Public Services: Lessons from a Comparative Assessment on the Italy – Croatia Adriatic Corridor

    • Prof. Martin Žagar, PhD, RIT Croatia

Day 2 · 22 September 2026

Scientific session and student forum

The program is indicative and subject to minor changes.

  1. 09:00 – 10:45

    Part I

    Presentations of accepted scientific papers.

  2. 10:45 – 11:00

    Coffee Break

  3. 11:00 – 13:00

    Part II + Student Research Forum

    Continuation of scientific paper presentations and showcasing of student research and projects.

  4. 13:00

    Lunch

By submitting, you agree that your data may be processed solely for conference participation.