By Hadyn Green
August 25, 2026
Knowledge is power. It’s an old saying, but no less apt for the times we find ourselves in. It’s also the motto of Serbia’s National CERT (SRB-CERT). More to the point, the team is focused on sharing knowledge with other people and, hence, distributing that power.
Adaptive training is a core philosophy for SRB-CERT, ensuring it is relevant to specific roles, sectors, and maturity levels rather than delivered as a one-size-fits-all package. (Since this is how the team at FIRST likes to work, we fully endorse this model.)
Moreover, the team is expanding the training it offers. Starting in 2019 with two scenarios focused on Microsoft/NTLM environments, they now run a cyber range with over 800 labs.

Director of the Cybersecurity, Technologies and Finance Sector of the Serbian Regulatory Authority for Electronic Communications and Postal Services (RATEL), Duško Kodžić, says that the new platform and training opportunities they’ve created “enable participants to progressively enhance their cybersecurity skills and improve different defensive skills according to their needs.”
“We can run basic, more complex or extremely complex scenarios. So, it really allows us to tailor and adapt the training, which we deliver according to relevant cybersecurity threats.”
They work mostly with critical information infrastructure (CII) organizations, but, understanding the importance of knowledge, Head of RATEL’s Cybersecurity and SRB-CERT, Goran Paunović, notes that connection between institutions is very important.
“We have brought together numerous institutions across Serbia and organized 50 to 60 technical trainings since 2019. Our new platform gives us access to thousands of video resources, labs, and scenarios allowing us to cover many different sectors.”
Kodžić adds that these technical trainings are designed to reach a broad range of people:
“We use the training to collaborate with other CERTs in the Republic of Serbia and academia, by holding training sessions with students. We also have a public-private partnership with sectorial CERTs in Serbia, such as the financial sector, and we provide trainings to them.”
SRB-CERT has MOUs signed with multiple universities and faculties across Serbia and dedicated training organized in collaboration with the partner institutions in the country. They have even created educational materials, including some designed for school children, like the Cybersecurity Alphabet.
Part of the reason for the expansive training sessions is the Law on information security. The act determines protective measures, including methods, principles, and procedures required to achieve and maintain an adequate level of system security. So the training run by SRB-CERT is designed to help organizations adopt the measures defined in the law, in accordance with ISO 27001.
“Training on the Cyber Range platform develops specific knowledge and skills needed to prevent or minimize security risks and ensure timely and effective response to cyber incidents.” SRB-CERT also runs something rare in the cybersecurity world (but close to my heart): annual training for journalists.
“You need to clearly communicate to prevent panic and avoid jeopardizing your response efforts. We organize these technical trainings, but the feedback we get is ‘Okay, we've done everything, but our management needs to be aware of it and they are worried about the media.’”
“Because of this we organize once a year a training for the media representatives to help them understand cybersecurity from a media perspective. So, they are aware of these baselines in cybersecurity when they inform the public, and their message is more meaningful.”
This level of adaptable and tailored training is exceptional. While it’s not possible for every team to reach the same number of sectors or have a large training platform, the idea remains the same: knowledge is power, and adaptability helps share that power.
—-----
This blog is part of a series with FIRST’s current and former Suguru Yamaguchi Fellows, sharing lessons learned and showcasing how they work.