Tech expertise

Information
Security Law

Information security has become a strategic question for every organisation. We turn information risk into an advantage through policies, contracts and procedures that work in practice.

Contact us
New Law on Information Security
Incident Reporting & NIS2
DORA for the Financial Sector
Vendor Risk Management Automation
Trusted by regulated institutions

A Trusted Partner to Banks and Insurers
on Vendor Risk and Information Security

Banks, insurers and payment institutions rely on us for ICT risk management, supplier and cloud contracts, incident reporting and audit readiness.

Lexology Index Awards 2024 Winner
Lexology Index Awards 2025 Winner
Lexology Index Awards 2026 Winner
Why us

Why Zunic Law for Information Security Law?

Four reasons companies bring their security compliance work to us.

Regulation in focus 2025+

We prepare you for the obligations under the new Serbian information security framework, aligned with NIS2 logic: redefined obliged entities, shorter deadlines and expanded supervisory powers.

EU horizon

We explain how European rules (NIS2) spill over into local obligations, what the difference between essential and important entities means, and how it affects supervision, reporting and penalties.

Sector-specific expertise

For finance we connect cyber obligations with the DORA regime, in force since 17 January 2025, including ICT risk management, incident reporting and third-party risk.

End-to-end delivery

From gap analysis and policy to training, incident response playbooks and supplier contracts with cloud, SOC, MSSP and forensics providers.

The frameworks

Which Frameworks Do We Advise On?

Four sets of rules decide your status, your deadlines and what your documentation has to prove.

New Law on Information Security

Priority and important operators, wider sectors, 24-hour incident reporting and higher fines under the Serbian framework.

NIS2

The EU cyber security framework across 18 critical sectors: risk management, incident reporting, supervision and enforcement.

Digital Operational Resilience Act

For finance: ICT risk management, incident reporting, resilience testing and oversight of critical ICT third parties.

GDPR and the Serbian Data Protection Act

Where an incident involves personal data, the 72-hour breach notification runs in parallel with the cyber filing.

Zunic Law services

What We Handle for Information Security

From governance design and risk assessment to incident reporting, supplier contracts and training.

01

Strategy and Security Governance

  • Governance model: responsibilities, lines of defence, committees.
  • Policies for incidents, BCM/DRP, vulnerabilities and key management.
02

Risk Assessment and Hardening

  • Risk assessment per ICT system, with a formal risk act.
  • Data mapping, access control, encryption, SIEM/SOC and log policy.
03

Incident Response and Reporting

  • IR playbooks, RACI matrices and post-incident review.
  • Reporting to the National CERT, and 72-hour data breach filings.
04

Supplier and Cloud Contracts (TPRM)

  • Availability, RTO/RPO, audit rights, penalties, exit and portability.
  • Alignment with group standards such as DORA for EU entities.
05

Resilience Testing and Audit Readiness

  • Pre-audit and audit readiness, guidance through inspections.
  • Coordination of technical testing and forensic readiness.
06

Training and Exercises

  • Role-based training for management, IT, DevOps, product and legal.
  • Table-top incident exercises and staff awareness programmes.
07

Documentation and Records

  • Registers of ICT services, suppliers, incidents and vulnerabilities.
  • Templates for incident and breach filings, and communication plans.
How we work

What Collaboration with Us Looks Like

Four stages, from mapping your status to standing beside you in an incident.

01

Status mapping

We establish whether you are a priority or important operator, and which regimes reach you.

02

Gap analysis

Risk assessment, policies, supplier contracts and records measured against the obligations.

03

Implementation

Policies, playbooks, contracts and training put in place, with owners and deadlines.

04

Incident and audit support

Filings to the CERT and the Commissioner, and representation through inspections.

Technology partnership

Zunic Law & Whisperly AI
Vendor Risk Under Control

Our team works inside Whisperly, an AI-powered compliance platform built for banks. Legal advice and the software that carries it out sit in one place, so every vendor assessment is documented and audit-ready from day one.

Whisperly vendor questionnaire — information security management assessment in the provider portal
1Assessment

Vendor portal, not email

Each vendor completes its questionnaire in a dedicated workspace, and the bank tracks progress live.

2Reporting

Reports from one source

Vendor answers flow straight into the operational risk assessment and the supporting reports.

3Notifications

Regulatory notifications on time

Prepare the notification and track approval status, including the 30-day tacit approval, with reminders on the 30 and 15-day deadlines.

4Evidence

Audit trail and approvals, logged

Every questionnaire, response, revision and approval is time-stamped, ready for supervisory review, with board and audit materials generated in one click.

See how your vendor files would look in Whisperly

We set up your workspace, map your existing documentation and show you where the gaps are.

Learn about Whisperly
FAQ

Most Common Questions

What companies ask us most often about information security.

Are we an obliged entity under the new legislative framework?

It depends on the sector and the role. The draft law introduces priority and important operators of ICT systems of special importance, and the list of sectors is wider than before: water, postal services, information society services, qualified trust services, DNS and the domain registry among them. A formal mapping of status is needed, and that is where every project starts.

What are the key changes in incident reporting?

Shorter deadlines (24 hours for significant incidents), mandatory updates to the filing, and a more precise set of information. The draft also introduces reporting of serious threats, not only events. We recommend a single process that covers the GDPR and Serbian data protection obligations (72 hours) at the same time.

Do we have to report incidents to the National CERT?

Yes. The National CERT is the operational point for reporting and coordination, with public forms and guidance. Its role includes early warning, advice and keeping records of incidents.

How does NIS2 affect us if we operate only in Serbia?

The new Serbian framework is designed to follow NIS2 logic, so you will see similar mechanisms: wider scope, risk management, incident reporting, supervision and penalties. That simplifies cooperation with EU partners and raises compatibility with cross-border delivery.

We have an EU presence in finance. Do we need DORA?

Yes. DORA has applied since 17 January 2025 and requires harmonised ICT risk processes, reporting, testing and strong contracts with ICT third parties, particularly cloud. If you are part of an EU group, the DORA standard becomes the mandatory baseline for contracts and policies.

What if the incident involves personal data?

Alongside the cyber filing, the GDPR and Serbian data protection regime applies with a 72-hour notification to the competent authority, and notice to individuals where the risk is high. That is why the incident response team and the DPO have to work together, and we set up a single decision and documentation flow.

Next step

Let's talk about your security obligations

Tell us what you run and who you serve, and we will map the status, the deadlines and the documents you need.

Contact us
Newsletter

Learn legal updates, and what to do about them

Legal developments in Serbia and the EU, each with the step it asks of your business.

Sign up

Two emails a month. Unsubscribe any time.