·
All episodes
Ivan Kovačević
Episode · #623

PAMETNA HRVATSKA Ivan Kovačević, powered by Janaf

Guest Ivan KovačevićHosted by Boris ŽivkovićMay 3, 2026
About this episode
What you'll hear in this conversation

The landscape of cybersecurity has fundamentally shifted. It's no longer a matter of *if* an organization will face a cyberattack, but *when*. This new reality means technical defenses alone are often insufficient; the human element — how people respond under pressure — becomes the critical variable. Ivan Kovačević, founder and director of CyberArrange, addresses this challenge by building a platform that allows organizations to train for these inevitable incidents. He helps companies move beyond theoretical policies to practical readiness, simulating real-world attacks in a controlled environment. Readers will consider how much their own organization's resilience depends not just on technology, but on the preparedness of its people.

Insights from the conversation
What to take from this episode
01
Ivan Kovačević points out that the core question in cybersecurity has moved from 'will we be attacked?' to 'when will we be attacked?' This shift means that technical defenses, while necessary, are no longer sufficient; the human element — how people react under pressure — becomes the critical factor in saving the company.
02
Many firms, despite having policies and procedures in place, are 'lost' when a real cyberattack occurs because they’ve never truly tested their response. Policies are only as good as the practice that proves them; without simulation, organizations have no way to validate if their plans actually work.
03
Traditional, sophisticated cyber exercises have historically been expensive, inaccessible, generic, and quickly outdated. Ivan Kovačević recognised that the market demanded a solution that could be prepared quickly, tailored precisely to an organization's specific needs, and automate the weeks of manual expert labor typically required.
04
The CyberArrange platform is designed to significantly reduce the time and manual effort required to prepare sophisticated cyber simulations. By abstracting and automating complex setup tasks, the platform makes high-quality, customized cyber readiness far more efficient and accessible than traditional methods.
05
When the host compares CyberArrange's work to NATO's large-scale military simulations, the parallel is precise: the methodologies once exclusive to state-level cyber defense are now being democratized. This means even private sector organizations can train against sophisticated threat actors using similar, rigorous simulation techniques.
06
While large companies are a natural fit for CyberArrange due to regulatory obligations and high-value assets, the platform also targets smaller firms previously priced out of quality training. The goal is to make sophisticated cyber readiness accessible to those who otherwise might face the choice, as Kovačević puts it, to 'rather be robbed' than invest in preparation.
07
What interests a bank in a cyber simulation will likely not interest a water utility, because their threat profiles and attacker motives differ significantly. While CyberArrange builds on common core mechanisms, effective training requires deep customization to the specific risks and operational context of each client.
08
The CyberArrange system is designed for 'minimalist onboarding,' leveraging existing cloud technologies and solutions clients already use for virtualization and backup. The point is to deliver the value of the simulation and the readiness it fosters, without adding the burden of learning an entirely new, complex technical platform.