·
All episodes
Biljana Cerin
Episode · #59

TEHNOBIZ Biljana Cerin

Guest Biljana CerinHosted by Dražen TomićMay 3, 2026
About this episode
What you'll hear in this conversation

The conversation around cybersecurity often centers on technical defenses and compliance mandates. Yet, for all the talk of data breaches and regulatory fines, many businesses still treat information security as a reactive burden rather than a strategic asset. Biljana Cerin, a leading expert from Ostendo Consulting and a board member of IS Squared, argues that the most sophisticated technical controls mean little if the human element is overlooked. She unpacks why companies abroad proactively embed security into new projects, while those closer to home often wait for a crisis or a looming penalty. This discussion reveals not just the technological gaps, but the deeper organizational and communication breakdowns that leave businesses vulnerable, prompting listeners to reconsider how they value and protect their most critical asset: information.

Insights from the conversation
What to take from this episode
01
Biljana states that security "always comes down to the person themselves." If individuals don't grasp the value of information, personally or for their organization, they won't protect it. Security is not just a technical problem; it's a human one that begins with understanding information's worth.
02
Most cybersecurity projects in Croatia are initiated "because of regulatory and legal demands." While this can establish systems, it means security is often driven by the threat of penalties, not a proactive desire to manage risk. Don't mistake mandated compliance for genuine risk management.
03
Clients engaging Biljana abroad typically seek protection "when launching their products and services to the market." This contrasts with a reactive approach, showing that market responsibility, not just avoiding fines, should drive early security integration. Proactive security is a market enabler, not a cost center.
04
Security experts, Biljana admits, "get tangled in technological terminology," making it incomprehensible to senior management. This communication barrier prevents buy-in and makes security seem like an IT problem, not a business one. Your most advanced technical insight is useless if the decision-maker can't understand it.
05
Biljana questions how senior management can lead companies "if they don't understand at least the basics of technology." Effective cybersecurity requires a two-way street: experts must simplify, but leaders must also invest in basic technological understanding. Leadership in the digital age demands more than just financial acumen.
06
The role of a CISO (Chief Information Security Officer) is crucial but often "not organizationally placed in the right position," sometimes reporting to the IT director. This creates a conflict of interest; the CISO needs a direct, independent line to the board to effectively oversee and challenge IT decisions. Security oversight requires organizational independence.
07
Cybersecurity is "relatively unknown to our students" until later university years, and Biljana suggests it "should be brought down to earlier years." Building a robust talent pool for cybersecurity starts long before a student picks a major. The future of security depends on early exposure and clear career paths.