
For years, cybersecurity advice was built around a few simple rules: don't open suspicious emails, check the sender's address, use a strong password, and never click an unfamiliar link.
Those rules still apply. But they are no longer enough.
What happens when the email is written with perfect grammar? When the person calling you sounds exactly like your CEO? Or when an attacker already knows enough about your company to make an unusual request feel completely legitimate?
Preskar's answer is straightforward: the goal is not to prevent every attack. It is to make sure an attack does not bring the business to a standstill.
“We cannot completely prevent attacks, but we can certainly make them less effective.”
The biggest shift is not simply that AI can write a convincing phishing email. It has made preparing and carrying out fraud faster, cheaper and easier to scale.
As Preskar points out, language is no longer much of a barrier for attackers.
“A fraudster can be on the other side of the world, may never have heard of Croatia or the Croatian language, and still be able to write a correct email or message in Croatian,” he explains. “Or they don't write it themselves at all. They simply give the task to an AI agent.”
That changes the scale of the problem. An attacker no longer needs to invest the same amount of time in researching, writing and adapting every individual attempt.
AI can also help attackers profile potential victims using information from purchased databases and publicly available sources.
Email addresses, phone numbers, card details and other information about individuals and companies can already be obtained through various channels. AI makes it easier to turn that information into a profile of a potential target.
“AI profiling of potential targets from available databases and publicly available information on the internet allows attackers to select targets that are more suitable for specific types of attacks,” Preskar says.
The result is a security environment where recognising a suspicious message is becoming increasingly difficult.
And that leads to an important change in how organisations need to think about their employees.
For years, the human being has been described as the weakest link in cybersecurity.
Preskar sees the problem differently.
If a phishing message contains obvious spelling mistakes, comes from a strange address and asks you to click an unfamiliar link, it is reasonable to expect an employee to notice something is wrong.
But what if none of those signals are there?
AI can produce convincing language. Voice cloning can reproduce a familiar voice. Public information can make a fraudulent request fit the context of a real business relationship.
At that point, telling employees to “be more careful” is not much of a security strategy.
Organisations still need continuous employee education, Preskar stresses, but that education should happen in realistic conditions.
“Run occasional simulated internal phishing campaigns. Change them and try to introduce something that resembles emails from the tools you actually use in your company,” he recommends.
The purpose is not to catch employees making mistakes. It is to give them a safe environment in which to practise recognising threats and to show them how seemingly harmless information can turn against the organisation.
But training cannot carry the entire burden.
Behind the employee, there need to be controls that limit what happens when someone does make the wrong decision.
One of the clearest examples is CEO or CFO fraud.
Imagine that your director is travelling. You receive a call from a different number. The director says their phone has been lost or stolen. You hear background noise that sounds like an airport. Their voice sounds right. They know enough about the situation to make the story believable.
Then comes the urgent request to transfer money.
“This is one of several CEO/CFO attack scenarios,” Preskar explains. “The attacker identifies that the director is travelling and then creates a situation where everything seems logical.”
The most unsettling part is the voice.
“Certain AI services need only around ten seconds of someone's speech to reproduce the characteristics of their voice. After that, they can say whatever the attacker types.”
These scams are not hypothetical examples happening somewhere far away. Preskar notes that similar fraud attempts are happening in Croatia as well.
So what should an employee do?
Something surprisingly simple: verify the request through another channel.
For sensitive financial transactions, companies can go one step further by introducing an internal verbal password or an additional authentication mechanism for unexpected and urgent requests.
The point is not to make every business interaction unnecessarily complicated. It is to have a second way of establishing trust when the first one can be faked.
There is another assumption Preskar considers particularly dangerous: that a smaller company is unlikely to be worth an attacker's time.
“A small company can actually be a very attractive target,” he says.
The reason is simple. Smaller organisations are less likely to have IT or security teams, and security may not yet be a standard business process.
AI makes this even more relevant because attackers can now prepare and execute large numbers of attacks with less effort.
The same technology that makes a scam more convincing also makes target selection easier.
Attackers can combine purchased data with information available online, then use AI to identify people and companies that are more likely to respond to a particular type of attack.
That means company size is no longer a reliable indicator of whether an organisation will attract attention.
The regulatory environment reflects this growing risk. NIS2, DORA (Digital Operational Resilience Act) and the CRA (Cyber Resilience Act) all introduce requirements intended to raise the level of security across organisations and digital products.
But meeting a regulatory requirement is not the same thing as eliminating risk.
Preskar is clear on this distinction.
“Compliance with a particular regulation does not mean absolute invulnerability,” he says. “But it does significantly increase an organisation's resistance to a large majority of attacks.”
The value of NIS2 lies in the processes it encourages organisations to establish: regularly assessing their security, understanding their risks and knowing how to respond when an incident occurs.
It should not become a checklist that is completed once and then forgotten.
And yes, a company can formally comply with NIS2 and still be vulnerable.
“NIS2 was never a universal tool for eliminating vulnerabilities or completely preventing cyberattacks,” Preskar explains. “It is a way of making organisations significantly more resistant to the cyber threats that are now part of everyday business.”
That distinction matters because security is not a certificate you receive and then put on a shelf.
It is an ongoing process of identifying what could go wrong and making sure you are ready when it does.
One of the areas where Preskar sees organisations repeatedly falling short is identity management.
The problem often becomes visible only after an incident.
Companies discover that credentials were stolen months earlier, sometimes long before the attacker actually used them.
“A properly implemented Identity and Access Management (IAM) system significantly reduces the attack surface,” Preskar says.
The key is not simply knowing who has access today. It is making sure that access changes automatically as people move through the organisation.
That means onboarding when someone joins, crossboarding when their role changes, and offboarding when they leave.
If those processes are handled manually or inconsistently, old access rights can remain active long after they should have been removed.
“One classic mistake is when the credentials of a former employee whose identity is still active are exploited,” Preskar says.
Adding strong password policies and Multi-Factor Authentication (MFA) further reduces the risk associated with stolen identities.
There is also an organisational dimension to IAM. IT may own the implementation, but it cannot operate effectively in isolation.
HR, for example, plays an important role because changes in employment status and job responsibilities directly affect access rights.
In other words, knowing who has the keys to your digital doors is not only an IT question.
Identity management is not the only area where the less visible parts of infrastructure can create very visible problems.
TLS certificates are a good example.
Most users never think about them. They simply expect websites and online services to work.
Behind the scenes, TLS certificates help verify server identity and establish encrypted communication. Their validity periods are also getting shorter.
A certificate that could previously remain valid for almost 400 days is moving toward 200 days, then 100 days, and ultimately 47 days by 2029.
For organisations still replacing certificates manually, that creates a very practical operational challenge.
“If you replace certificates manually, you will have to increase the amount of work required from the people doing it by eight to nine times,” Preskar estimates.
The reason for the change is not simply administrative.
According to Preskar, expired certificates have been responsible for more than 60% of internet service unavailability cases in previous years. The move toward shorter validity periods aims to encourage organisations to automate certificate replacement and reduce outages caused by certificates expiring unnoticed.
There is another security benefit too. Shorter validity periods mean cryptographic key pairs are replaced more frequently, reducing the amount of time the same keys remain in use.
For management, however, the immediate question is practical.
Do you want your IT team spending an increasing amount of time manually replacing certificates, or do you want that process automated?
Preskar's answer is clear.
“Of course you should invest in automation and eliminate a potential problem.”
So, what does being secure actually mean in 2026?
For Preskar, expecting to prevent every incident is unrealistic.
“I think it is absurd to expect that in 2026 we will prevent every incident.”
The more useful question is what happens after something gets through.
Can you detect it quickly? Can you contain the damage? Can you recover? Can you continue operating without major disruption?
That requires more than security tools. It requires tested procedures and clear ownership.
Preskar has three questions he believes every company should be able to answer.
Not when was the last backup created.
When was the last successful restoration, how long did it take, and who verified it?
“A backup is not the same as a tested recovery plan,” Preskar says. “If you have never tried to restore a system from a backup, you don't know how long recovery would take, whether the backup works properly, or whether you are actually prepared for an attack.”
This is not only a question about whether detection technology exists.
It is also about decision-making.
Who decides that a system needs to be isolated? Who has the authority to shut something down? What happens in those first critical minutes?
Having a detection tool is useful. Knowing what to do when it raises an alert is essential.
Every organisation has risks.
The important thing is whether you know what they are, whether someone owns them, and why they remain unresolved.
That answer can reveal much more about your actual security posture than a list of tools or certifications ever could.
There are plenty of cybersecurity issues competing for an organisation's attention. But when asked what companies in Croatia still tend to underestimate, Preskar returns to identity management.
“It is one issue I often see in practice and in reports about cyber incidents in Croatia: organisations still neglect the implementation of Identity and Access Management systems.”
That may sound like a technical problem, but it rarely stays one.
Identity determines who can access systems, data and resources. It changes when someone joins the company, changes roles or leaves. Managing that properly therefore requires cooperation between IT, HR and other parts of the organisation.
And that is ultimately the bigger point behind Preskar's view of cybersecurity.
The question is no longer whether an attacker can find a way in. With AI making fraud more convincing, more targeted and easier to scale, organisations have to assume that sooner or later, someone will try.
The real question is what happens next.
Can you recognise what is happening? Can you limit the damage? Can you recover? And do you already know who is responsible for making those decisions?
You may not be able to stop every attack.
But you can make sure the attack does not get the final word.
This article is adapted from the original published on Telegram.