Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal
Strengthening cybersecurity in regional governmental units
Department of Military Science Theory (K-105), University of defence, Czech Republic.
Department of Military Science Theory (K-105), University of defence, Czech Republic.
ABSTRACT
The implementation of Directive (EU) 2022/2555 (NIS 2) and the adoption of Act No. 264/2025 Coll. on cybersecurity introduce new obligations for public administration and significantly increase demands on cybersecurity governance. This article analyses the impact of the new cybersecurity legislation on regional governmental units in the Czech Republic.
The study identifies key risk areas related to the performance of obligations of regulated service providers, including increased administrative burden, insufficient funding, lack of methodological guidance, and unclear terminology. A semi-quantitative risk analysis is applied to assess the severity and acceptability of these risks. The results show that increased administrative burden represents an unacceptable risk, while insufficient funding and lack of methodological support are conditionally acceptable but may significantly hinder effective implementation. The findings highlight the need for strengthened institutional support, adequate funding, and clearer regulatory guidance to ensure compliance with cybersecurity requirements.
Keywords: risk analysis, security measures, cybersecurity, regional governmental units.

