Home / Newsroom / Baseline assessments

News

Baseline cybersecurity assessments begin

WP2 audits of maturity, technical vulnerabilities, staff practices and regulatory compliance start across the pilot hospitals in Slovenia and Croatia.

Planned activity — this entry follows the project work plan and will be updated with results once the activity takes place.

From September 2026, Work Package 2 — led by Combis — begins the structured baseline assessment of all 11 pilot hospitals. It is the project's evidence-gathering phase: before anything is deployed, every hospital's starting point is measured.

What is assessed

  • Cybersecurity maturity — governance, internal capacity and existing security tooling.
  • Technical vulnerabilities — network architecture and segmentation, log availability, legacy systems and the exposure of connected medical devices.
  • Staff practices — how IT, clinical and administrative staff work with systems day to day.
  • Regulatory compliance — control mapping against NIS2, GDPR and applicable Slovenian and Croatian national legislation.

Based on the assessment, hospitals are categorised into integration-complexity profiles that determine the sequencing and depth of later deployments — so that lessons from earlier integrations reduce risk in subsequent ones, and no deployment disrupts patient care.

Why it matters

The consolidated requirements and maturity model produced by these assessments is the foundation for Work Package 3 — technology selection and hospital-specific pilot blueprints — and the baseline against which the project's impact will ultimately be measured.

Follow the project.

Milestones, public deliverables, training opportunities and events — a short update, only when there is something worth reading.

Get project updates
More from the newsroom Back to the newsroom