Skip to main content
Have a personal or library account? Click to login
Big Tech and Cyber Resilience in the Balkans: A Comparative Analysis of Cyber Incidents in 2022 Cover

Big Tech and Cyber Resilience in the Balkans: A Comparative Analysis of Cyber Incidents in 2022

By:   
Open Access
|Sep 2026

Full Article

Introduction

In 2022, cyber incidents across the Balkans varied significantly in scale, attribution, and character. Albania and Montenegro experienced large-scale attacks attributed to state-linked actors. Bosnia and Herzegovina and Romania faced both cybercriminal attacks and Distributed Denial-of-Service (DDoS) attacks, whereas North Macedonia experienced nationalist-oriented cyber activity. In Croatia and Kosovo, incidents largely targeted specific sectors and often lacked clear attribution.

From 2021 to 2024, Albania experienced multiple waves of cyberattacks believed to be orchestrated by Iranian state-sponsored actors. The most severe cyberattacks occurred between July and September 2022, targeting government computer systems and resulting in data loss and service disruptions. Hackers accessed, deleted, and leaked sensitive and classified information from both public and government sources, including financial records, data of individuals crossing Albania over 17 years, and the identities of undercover intelligence officers. Prime Minister Edi Rama stated, “Based on the investigation, the scale of the attack was such that the aim behind it was to completely destroy our infrastructure back to the full paper age, and at the same time, wipe out all our data” (Cybersecurity & Infrastructure Security Agency (CISA), 2022; Starks, 2022; Oghanna, 2023).

In September 2022, Bosnia and Herzegovina was hit by an extensive ransomware attack targeting the Parliamentary Assembly's central server. This attack disrupted parliamentary functions and led to the shutdown of the server, email, and website. The assault occurred amid political unrest, as concerns mounted about secession efforts by Republika Srpska, three weeks before general elections in Bosnia and Herzegovina (Greig, 2022; Kurtic, 2022; OSCE Mission to Bosnia and Herzegovina, 2022; Sarajevo Times, 2022).

Furthermore, Bosnia and Herzegovina experienced over 9.2 million cybersecurity threats between mid-November and mid-December 2022. The majority of these threats were DDoS attacks originating from Brazil, the Netherlands, the United States, Russia, Germany, and China. This was primarily due to attackers employing Virtual Private Networks (VPNs) to conceal their actual locations and simulate origins from other regions. A report by Mahmutovic and Hodzic (2023) from the Balkan Investigative Reporting Network of Bosnia and Herzegovina (BIRN BiH) noted that “Many of these attacks are consistent with the methods and capabilities observed from Russia and China,” but explicitly stopped short of formal attribution. Additionally, the report stated that “Western European countries and NATO have also expressed growing concern regarding Russian influence in Bosnia and Herzegovina, particularly in the lead-up to the 2022 elections”. No official attribution has been made. This study treats the case of Bosnia and Herzegovina as unattributed, and avoids causal inferences with regard to perpetrator identity.

Croatia's phone provider, A1 Hrvatska, revealed a data breach affecting about 10% of its customers, approximately 200,000 people, in February 2022 (Paganini, 2022). A month later, the daily website Slobodna Dalmacija was hacked by an unknown assailant who managed to replace “a couple of older articles with articles promoting Russian propaganda in the war with Ukraine” (Grgurinovic, 2022). Like other countries, Croatia has experienced a rise in the number of detected cyberattacks. The Security Intelligence Agency identified 14 attacks in 2021, and in 2022, this number grew to 19 (Lozančić, 2023). Neither the perpetrators nor the Croatian authorities made any claims of responsibility or attribution.

In January 2022, Kosovo's media regulatory authority, the Independent Media Commission (IMC), faced a significant cyberattack which caused data loss and disrupted access to official email and internal systems for nearly two months (Isufi, 2022). In the first week of September 2022, government IT systems were targeted by DDoS attacks, leading to intermittent internet outages across government offices and occasional service disruptions in the Ministers` Offices, the Kosovo Police, the e-Kosova Platform, some media outlets, and Kosova Telekom. Its technical director stated that the attacks were unidentified, originating from various foreign IP addresses, and were executed by 30,000 computers. A local IT expert estimated that the attacker used more than 8,000 infected computers to carry out the attacks (Fetahaj, 2022; KOHA, 2022; Вистиномер.мк, 2022). The Prime Minister's Office announcement indicated that “In cooperation with external experts, applying adequate measures, the cyberattack has been overcome and attempts to continue the attack have been prevented” (Qeveria e Republikës së Kosovës, 2022).

In August 2022, the Government of Montenegro's digital infrastructure was hit by an ‘unprecedented’ ransomware attack which encrypted and locked data and other important files. The attack resulted in the domain gov.me being down for almost a month, along with all government portals, including the websites of the ministries of defence, finance, and the interior, the government's online platforms, the Property Administration, the Revenue and Customs Administration, the courts, the water supply systems, and transportation services. Even the state-owned power utility, EPCG, switched its operations to manual handling to prevent potential damage from a cyberattack described as “the worst attack on its critical IT infrastructure so far” (Kajosevic, 2022b; Šćekić, 2022). Although a hacker group known as Cuba-Ransomware claimed responsibility, Montenegro's Agency for National Security officially attributed the attack to Russia, although it did not provide public evidence. Separately, Trend Micro Research, a commercial cybersecurity vendor, attributed the Cuba-Ransomware variant to Russia-linked actors based on technical indicators, claiming that “Cuba-Ransomware seems to originate from Russia, as evidenced by its routine of terminating itself when a Russian keyboard layout or language is detected on the system” (Trend Micro Research, 2022). The outgoing Prime Minister, Dritan Abazovic, added that “it was politically motivated following the fall of his government last week” (Milic, 2022; Reuters, 2022; Stojanovic, 2022; Ivanovic, 2024b, 2024a).

North Macedonia's Ministry of Education was targeted in February 2022 by a cyberattack allegedly carried out by a group called ‘Powerful Greek Army’, which claimed to have access to the ministry's camera system (Marusic, 2022). In August of the same year a DDoS attack targeted St. Cyril and Methodius University (UKIM), targeting the iKnow electronic support system. The Ministry of Education was hacked again, this time allegedly by the ‘Greek Hacking Team Netwatchers’, which affected the Ministry's website. The Ministry of Agriculture was targeted by the ransomware group BlackByte (Вистиномер.мк, 2022; Elshani, 2025).

Romania's Rompetrol petrol station network was impacted by a ‘complex cyberattack’ involving ransomware from the Hive group in March 2022, demanding a $2 million ransom. The attack forced Rompetrol to shut down its websites and the Fill&Go service at its petrol stations. Indeed, in an email to employees, Rompetrol acknowledged that the attack affected “most of the IT services” (Sharma, 2022). A month later, the Romanian government's websites were targeted by a DDoS attack, including those of key public institutions such as the government, the border police, the Defence Ministry, Romanian Railways, and private organisations. The Romanian National Cybersecurity Directorate (NCSD) asserted that the cybercrime group ‘Killnet’, a pro-Russia hacker group, claimed responsibility for the attack on a Telegram channel, arguing that the attacks were justified by Romania's support for Ukraine in the military conflict with the Russian Federation (Necsutu, 2022; The Romanian National Cybersecurity Directorate (NCSD), 2022; Radware, no date).

In mid-June 2022, two months after general elections, Serbia experienced a significant ransomware attack targeting the Republic Geodetic Authority (RGZ). Because RGZ manages vital data, including real estate and land ownership records, as well as information systems used by external parties such as public notaries, the attack paralysed the Serbian real estate market for several weeks (Sasa, Aleksa, 2022; Freedom House, 2023; Salipur, 2024). The Commissioner for Information of Public Importance and Personal Data Protection completed an extraordinary inspection and stated that there was no violation of personal data (Commissioner for Information of Public Importance and Personal Data Protection, 2022).

The term ‘Big Tech’ is commonly used to describe the most dominant technology corporations – typically including Google, Apple, Microsoft, Amazon and Meta – whose market capitalisations exceed the GDP of many large economies, and whose platforms, infrastructure, and data capacities give them influence across economic, political, and security domains (Birch, Bronson, 2022; Rosencrance, 2021). While various acronyms, such as GAFA, GAFAM, and FAANG, have been used to delineate this group, the boundaries remain contested and context-dependent (Rosencrance, 2021; Birch, Bronson, 2022).

Despite the increasing scholarly focus on Big Tech's geopolitical influence, regulatory role, and involvement in major conflicts such as the war in Ukraine, there remains a significant empirical gap in the literature: systematic, comparative analyses of how and under what conditions major technology firms intervene during specific national cyber crises, especially in small and medium-sized states, are limited. The 2022 cyberattacks on the Balkan states offer a comparative perspective for addressing this gap, providing meaningful variation in both attack severity and the presence or absence of Big Tech engagement.

In this study, the term ‘Big Tech’ refers specifically to large technology firms which (1) provide critical digital infrastructure to governments and (2) maintain dedicated cyber threat intelligence and incident response capabilities. ‘Cyber resilience’ is regarded as a multidimensional capacity encompassing (1) intelligence, investigation and attribution; (2) incident response and containment; (3) recovery and continuity of services; (4) learning and adaptation following attacks; and (5) governance arrangements which facilitate coordination between state and non-state actors. Therefore, cyber resilience is regarded both as a short-term outcome, measured by the ability to restore services and contain damage, and as a longer-term process involving institutional learning, adaptation, and governance reform. The Big Tech involvement is assessed in terms of its contribution to immediate crisis response and its influence on longer-term resilience (Björck et al., 2015; Linkov, Kott, 2019; Safitra et al., 2023; Alhidaifi et al., 2024).

1. LITERATURE REVIEW

Scientific research covers different aspects of Big Tech; some studies investigate its unique contributions to international and local cyber resilience and their effects on geopolitics, while others examine the countermeasures and mitigation strategies in place.

Big Tech companies hold a vital position in geopolitical and security spheres by shaping infrastructure and technological standards which influence international security and state sovereignty. Kitchen (2025) and Khanal et al. (2025) highlighted the increasing influence of Big Tech in both international and domestic policy and security mechanisms. This influence stems from its technological monopoly over the supply and management of essential digital infrastructure, which is crucial to discussions of national digital sovereignty and frequently plays a fundamental role in geopolitical cyber conflict. Their dual-use technologies (civilian and military applications) help shape what some refer to as the “digital-military-industrial complex”. Their operations significantly impact global diplomatic relations and their lobbying efforts against international regulatory bodies. Consequently, governments increasingly regard Big Tech as sovereign actors, appointing “tech ambassadors” to liaise with these companies, highlighting their quasi-state status.

Big Tech focuses on shaping policies on regulation, taxation, and global digital standards to favour their business models. They exert considerable influence over legislative processes and regulatory procedures governing data privacy, antitrust, digital rights, and internet governance through direct lobbying, government consultations, and political contributions. Furthermore, through social media and digital platforms, Big Tech influences public discourse, culture, and information ecosystems worldwide. Its algorithms and content moderation policies shape societal narratives, public opinion, and political mobilisation, producing significant social impacts that extend far beyond economic or political dimensions (Jahangir Khan, 2024).

Passchier (2025) emphasises Big Tech's role as an active political player. Gu (2023) argues that Big Tech has become the new data sovereign that governments must accept in the data era. Tarrant and Cowen (2022) analyse the role of Big Tech in lobbying within the EU concerning the Digital Markets Act. Leclercq-Vandelannoitte and Bertin (2024) coined the term “Big Tech Raj”, arguing that “Big Tech firms produce a new form of biopower in the digital era by virtue of their material configurations (constituted by technology, such as applications, algorithms, AI systems), which create conditions for steering people's conduct”.

Another significant aspect of policy concerns the climate. Big Tech companies are increasingly involved in climate-related initiatives, including commitments to sustainability in data centres, investments in green technology, and support for global climate governance. Their extensive energy consumption and carbon emissions also position them as key players in discussions of environmental impact (Jahangir Khan, 2024; LaForge, 2025).

Big Tech companies significantly influence the digital ecosystems of developing countries, affecting economic dependence and policy development. They lead technological progress by specialising in areas such as AI, cloud services, digital platforms, and telecommunications. Their investments in research and development and dominant platform control encourage innovation, creating new products and services which transform industries and drive global scientific progress (Khanal et al., 2025).

However, Big Tech's concentration of power also exerts pressure on democratic institutions and the rule of law through potentially opaque and unequal practices. Birch and Bronson (2022) analysed the growing public and political backlash known as the ‘techlash’, which has led to a decline in trust in these companies and their practices. Parsheera (2023) examined India's policy responses to Big Tech, which combine traditional regulatory approaches with novel strategies. Vrikki (2024) underscored the need for more “rigorous regulatory frameworks and independent third-party audits to ensure genuine progress towards a sustainable future and proper accountability”. Zingales (2022) argued that mitigating Big Tech power can only be achieved through international structural interventions which restore the conditions for competition, since no national regulator can do so. FitzGerald and Parziale (2017) also emphasised the importance of reforming structures and processes to introduce accountability for Big Tech actors.

Building on this gap, this paper explores two research questions: (RQ1) What types of support did major technology firms offer during and after the 2022 cyber incidents in the Balkans, and how did this support affect the immediate responses and long-term resilience? (RQ2) What factors may explain the differences in Big Tech engagement across cases?

2. METHODOLOGY

This study employs an exploratory, qualitative case-study approach to examine how Big Tech's involvement evolved during the major cyberattacks on Albania, Bosnia and Herzegovina, Croatia, Kosovo, Montenegro, North Macedonia, Romania, and Serbia in 2022. Data collection prioritised diverse and highly reliable sources, grounded in three fundamental principles: relevance, which ensures a direct connection to research questions; reliability, characterised by recognised accuracy and methodological soundness; and diversity, encompassing multiple perspectives and source types. Document retrieval was achieved through searches of Google Scholar, institutional repositories, government portals, and threat intelligence platforms. ‘Highly reliable’ was defined as: produced by or attributable to a named institutional author, government body, peer-reviewed journal, or established investigative outlet with a verifiable editorial process. Key empirical claims, especially those concerning Big Tech's operational involvement, were accepted only if supported by at least two independent sources of different types, such as a threat intelligence report verified by a government statement or a reputable news outlet.

A chronological timeline documented major cyberattacks in the analysed Balkan states in 2022, facilitating the identification of critical junctures and deployment patterns. The final collection comprised 62 primary documents, including: (1) academic publications, (2) official government advisories, (3) threat intelligence corporate reports, and (4) reputable media outlets and think tanks. Sources were included only if they directly documented or analysed the 2022 cyberattacks in the Balkan states in question, contained verifiable factual claims from institutional or expert authors, and were publicly accessible. Conversely, sources were excluded if they were based solely on unverifiable opinion, lacked clear authorship, or originated from outlets with documented records of disinformation.

The documents were analysed using qualitative thematic coding. The coding categories –analysis and investigation, operational support, attribution, infrastructure deployment, and post-incident engagement – were developed inductively from an initial reading of the source material, and remained aligned with the cyber resilience framework specified in the introduction. The coding process was carried out by the author using a single-coder approach; analytical consistency was maintained through iterative review of category definitions against the entire source corpus.

This study examines Big Tech's role in strengthening cyber resilience in the analysed Balkan states during and after the major cyberattacks in 2022. These countries were selected because each experienced a notable, publicly reported cyberattack which affected national infrastructure or government functions within the same year, enabling a controlled comparison over time. They also display differences in the main outcome variable, making the selection meaningful from a theoretical perspective. The focus is on 2022, a pivotal year characterised by high-severity, high-profile cyberattacks targeting government institutions and infrastructure across the region. The research does not investigate commercial partnerships between Big Tech firms and the Balkan countries beyond the incidents discussed.

This study recognises several constraints: (1) reliance on documentary evidence limits access to lived experiences and classified information, (2) limited understanding of Big Tech's cyber intervention policies in the cyber resilience of foreign states, and (3) the predominance of English-language sources may underrepresent domestic perspectives.

3. FINDINGS

The cyberattacks on Albania, Bosnia and Herzegovina, Croatia, Kosovo, Montenegro, North Macedonia, Romania, and Serbia in 2022 were widespread and devastating, targeting critical national infrastructure and government institutions.

In the analysis that follows, Microsoft and Google are considered Big Tech actors in the full sense defined above. Trend Micro and Oracle, which appear in the Montenegrin case, are described as specialised cybersecurity and enterprise infrastructure vendors whose roles are mainly transactional rather than quasi-operational; they are included for completeness but are analytically distinct.

In September 2022, during the widespread cyberattacks, Microsoft actively participated in efforts to counter the threats. Shortly after the damaging cyberattacks against the Albanian government in mid-July, the Microsoft Detection and Response Team (DART), together with the FBI and other specialists, was engaged by the Albanian government to lead an investigation and forensic analysis into the attacks and their various phases. At the time of the attacks, Microsoft publicly stated that it “is committed to helping our customers be secure while achieving more. During this event, we quickly mobilized our Detection and Response Team (DART) to help the Albanian government rapidly recover from this cyberattack by isolating its infrastructure and shutting down critical systems to prevent damage. Microsoft will continue to partner with Albania to manage cybersecurity risks while continuing to enhance protections from malicious attackers”. Additionally, Microsoft's investigation attributed the cyberattacks with high confidence to multiple Iranian government-sponsored actors (Microsoft Threat Intelligence, 2022; Starks, 2022).

Indeed, the White House National Security Council statement confirmed that the U.S. government had been “on the ground” working alongside private-sector partners to mitigate, recover from, and investigate the cyberattack (The White House, 2022). Microsoft assisted Albania not only in recovering from the 2022 cyberattacks but also in countering future cyberattacks by deploying its security solutions “to gain comprehensive visibility across its infrastructure and prepare for future attacks”. (Microsoft, 2023). Google published its own comprehensive report analysing cyberattacks against Albania and attributing them to Iran (Jenkins et al., 2022)

The FBI and the French National Cybersecurity Agency, ANSSI, as well as cyber experts, assisted in investigating the August 2022 Cuba ransomware attack, which the outgoing Montenegrin Prime Minister, Dritan Abazovic, described as “unprecedented” and “dangerous and politically motivated”. However, there were no reports of Big Tech involvement in the analysis, aside from Trend Micro Research's attribution of the Cuba ransomware to Russia (Kajosevic, 2022a; Radio Free Europe/Radio Liberty, 2022; Vujovic, 2023). Since the cyberattack, Montenegro has spent millions of euros across fifteen public tenders to procure servers, IT and communications equipment, and security devices, including Microsoft and Oracle security solutions, rather than open-source software. This spending raised questions from local security experts: “For some reason we tend not to ask such questions in the case of software products, and I strongly believe we should” (Vucinic, 2024).

Public records indicate no involvement by Big Tech companies in enhancing the cyber resilience of Bosnia and Herzegovina, Croatia, Kosovo, North Macedonia, Romania and Serbia during and following the 2022 cyberattacks.

This absence was confirmed through targeted searches of public government communications, Big Tech newsrooms (including Microsoft, Google, and Amazon Web Services), official cybersecurity advisories (such as CISA and ENISA), and investigative reports from BIRN and regional media. No signs of operational activity, advisory roles, or joint statements between Big Tech firms and governments were found.

The lack of documented engagement by Big Tech in Serbia is analytically significant. Serbia's geopolitical stance is ambiguous: although an EU candidate, it maintains close relations with Russia and China and has not acceded to NATO. These alignments may diminish the likelihood of corporate intervention aligned with U.S. interests. The 2022 ransomware incident was attributed to cybercriminals rather than state-sponsored actors, which appears to lessen the incentives for Big Tech to become operationally involved. Furthermore, institutional capacity limitations and the absence of formal public-private cyber crisis frameworks may have further constrained potential avenues for engagement.

Bosnia and Herzegovina presents a structurally distinct negative case. The attack on the Parliamentary Assembly in September 2022 occurred amid acute political tensions concerning secession, rendering coordinated engagement with external partners politically sensitive. The lack of clear attribution to state-sponsored actors, and the absence of a NATO membership framework similarly diminish the structural conditions which would facilitate Big Tech intervention.

In Croatia, cyber incidents in 2022 mainly affected the telecommunications sector, limiting their impact to specific industries rather than core state infrastructure. Although disruptive, these attacks remained relatively contained, and did not attract significant international attention or clear attribution to state actors. Consequently, responses were handled domestically or through sector-specific mechanisms, with no documented operational involvement by major technology firms.

In Kosovo, the cyberattacks targeted government services and public-facing digital infrastructure, causing temporary disruptions. However, the incidents were relatively limited in scale and duration, and lacked strong attribution to state-sponsored actors. This combination of constrained impact and lower geopolitical visibility likely reduced incentives for external corporate engagement, resulting in no documented involvement by Big Tech.

North Macedonia experienced cyber activity marked by nationalist-leaning attacks, driven by politically motivated actors who were either non-state or of unclear attribution. Although these attacks carried political weight, they did not lead to widespread or systemic disruptions of the country's infrastructure. As a result, the responses mainly remained domestic, with no definitive signs of support from major technology firms.

In Romania, the cyber incidents involved both a cybercriminal attack and a DDoS campaign linked to a pro-Russian hacker group. Despite this mixed threat environment, the attacks did not cause sustained nationwide disruption or escalate into a high-profile geopolitical crisis. The responses were managed through national capabilities and existing partnerships, with no documented direct involvement by Big Tech actors.

Collectively, these cases indicate that the lack of Big Tech engagement reflects genuine structural, political, and geopolitical constraints rather than limitations related to data availability.

Table 1:

Cyber attacks on the analysed Balkan states and the implemented countermeasures

StateMeasuresCountermeasures
DateTargetDamageAttributionCompanyIntervention
ToBy
AlbaniaJuly–September 2022The government's computer systemGather, delete and leak private and classified informationIranAlbanian Government, Microsoft, GoogleMicrosoftInvestigation, analysis, technical recovery, attribution, deploying security solutions
GoogleAnalysis, attributions
Bosnia and HerzegovinaSeptember 2022Ransomware targeting the Parliamentary AssemblyCrippled the parliament's operationsNoneNoneNone
November – December 2022DDoSOriginating from Brazil, the Netherlands, the United States, Russia, Germany, and ChinaNoneNone
CroatiaFebruary 2022Phone provider A1 HrvatskaBreach affecting about 10% of its customersNoneNoneNone
March 2022The daily website Slobodna DalmacijaHack and replace old articles with pro-Russian propagandaNoneNoneNone
KosovoJanuary, September 2022DDoS attacks against government IT systemsMinisters' Offices, the Kosovo Police, the e-Kosova Platform, some media outlets, and Kosova TelekomNoneNoneNone
MontenegroAugust 2022Ransomware targeting the government's digital infrastructureShutdown of all Government portals and servicesRussiaMontenegrin Government, Trend MicroMicrosoft, OracleProcurement of security solutions
Trend MicroAttribution
North MacedoniaFebruary 2022Ministry of EducationAccess to the Ministry's camera system and websitePowerful Greek ArmyClaimed responsibilityNoneNone
August 2022St. Cyril and Methodius University (UKIM), Ministry of EducationUKIM's iKnow electronic support systemGreek Hacking Team NetwatchersClaimed responsibilityNoneNone
RomaniaMarch 2022RompetrolShut down of the websites and the Fill&Go serviceHive ransomwareClaimed responsibilityNoneNone
April 2022Government's websites, public institutions and private organisationsDDoSKillnetClaimed responsibilityNoneNone
SerbiaJune 2022Ransomware targeting the Geodetic AuthorityReal estate market paralysed for weeksNoneNoneNone

4. DISCUSSION

This study examined two research questions: (1) What types of support major technology firms offered during and after the 2022 cyber incidents in the Balkans, and how did this support affect cyber resilience? and (2) What factors may explain the observed variation in Big Tech engagement across cases? The findings show a notably uneven pattern of involvement between the states and suggest that such engagement is selective, conditional, and influenced by multiple interacting factors.

Concerning the first research question, the findings reveal three clear patterns of Big Tech involvement. First, Albania exemplifies comprehensive, operational engagement, in which Microsoft and Google contributed across various areas, including threat intelligence, forensic investigation, attribution, incident response, and post-incident resilience-building. This level of involvement had a noticeable effect on both the immediate recovery and the long-term institutional capacity, effectively positioning Big Tech as a quasi-operational extension of national cyber defence.

In the second pattern, the Montenegro case demonstrates a limited and delayed engagement model, where Big Tech did not play a significant operational role during the crisis but became involved indirectly through post-incident procurement of proprietary security solutions. This distinction emphasises an important analytical difference between operational support during a crisis and technology acquisition after the event, with only the former directly contributing to real-time resilience and institutional learning.

In the third pattern, the remaining cases – Bosnia and Herzegovina, Croatia, Kosovo, North Macedonia, Romania and Serbia – demonstrate minimal or no documented Big Tech involvement, despite cyber incidents of varying severity. In these contexts, the responses were largely managed through domestic capabilities or alternative external actors. This absence is analytically significant, indicating that Big Tech engagement is not an automatic response to cyber incidents, even when critical infrastructure is affected.

These differences in engagement align with variations in resilience outcomes. Albania's swift recovery and strengthened defensive stance demonstrate the advantages of integrated external support, whereas Montenegro's slower, procurement-focused approach highlights the drawbacks of delayed engagement. The other cases indicate more limited recovery paths, possibly due to reliance on fragmented or internally constrained response mechanisms.

Addressing the second research question, the findings suggest that the variation in Big Tech involvement is best understood through a multilevel framework involving structural, situational, interactional, and corporate factors.

At the structural level, geopolitical alignment and institutional capacity influence the conditions under which engagement can occur. Albania's alignment with Western institutions appears to have facilitated cooperation with U.S.-based firms, whereas Serbia's more ambiguous stance and Bosnia and Herzegovina's divided governance structure may have limited such engagement. Institutional readiness also plays a role in whether states can effectively absorb and coordinate external assistance.

At the situational level, the nature, attribution, and visibility of cyber incidents are crucial. Large technology firms are more likely to become involved when attacks are clearly attributed to state-sponsored actors and positioned within broader geopolitical conflicts, as seen in Albania. Conversely, ambiguous attribution (Bosnia and Herzegovina), cybercriminal framing (Serbia and Romania), or lower visibility (Croatia, Kosovo, North Macedonia) tend to diminish the incentives for corporate intervention. The type of targeted infrastructure also plays a role: attacks on central government systems are more prone to prompt engagement than those affecting isolated sectors.

At the interactional level, openness, existing public-private partnerships, and trust influence the depth of engagement. Albania's ability to quickly integrate external actors reflects the presence of supportive institutional interfaces. Legal and regulatory frameworks further shape these dynamics by either enabling or restricting foreign corporate involvement.

At the corporate level, Big Tech firms act as strategic and selective actors, guided by considerations such as geopolitical alignment, reputational benefits, and risk exposure. Their engagement is therefore not purely demand-driven, but reflects internal calculations about where intervention is both feasible and advantageous.

Taken together, these findings indicate that Big Tech's involvement in cyber crises is driven not just by technical needs or attack severity, but by a combination of political, institutional, and strategic considerations. This strengthens the view of Big Tech as a quasi-sovereign actor, whose selective engagement transforms the cyber resilience landscape and alters the distribution of authority in cyberspace.

5. FUTURE RESEARCH

Future studies could (1) expand the geographical scope beyond the Balkans to incorporate comparative analyses of Big Tech involvement in cyber incidents affecting other small and medium-sized states, particularly in Eastern Europe, the Caucasus, and the Global South. Such comparisons would help determine whether the patterns observed in the selected Balkan states reflect wider structural dynamics or region-specific conditions. (2) Broaden the chronological scope of Big Tech involvement in Balkan cyber resilience and evaluate whether patterns of Big Tech engagement changed during subsequent cyber incidents in the Balkans. (3) Examine the long-term impacts of Big Tech involvement on national cyber governance. While this study primarily focuses on crisis response and short-term resilience, further research is required to assess how sustained reliance on proprietary technologies affects institutional capacity-building, vendor dependence, and digital sovereignty over time. (4) Investigate Big Tech influence in the Balkans across various domains, including the economy, politics, international relations, society, innovation, and legal spheres. (5) Analyse the decision-making processes behind Big Tech intervention, particularly how these companies decide internally whether, when, and how to intervene during state-level cyber crises. (6) Evaluate the legal and accountability frameworks governing Big Tech intervention in national cyber crises, with special focus on transparency, responsibility, and oversight of democratic processes.

Conclusion

This study examined the role of major technology corporations in shaping cyber resilience in Balkan states during significant cyber incidents in 2022. It found that Big Tech involvement varies considerably across cases and is neither automatic nor evenly distributed. Instead, engagement is selective and depends on a combination of geopolitical alignment, institutional preparedness, incident features, and corporate strategic considerations.

The case of Albania illustrates how extensive operational involvement by Big Tech can greatly improve both immediate crisis response and long-term resilience. Meanwhile, Montenegro reveals the limitations of a procurement-focused approach that lacks real-time external support. The lack of meaningful engagement in Bosnia and Herzegovina, Croatia, Kosovo, North Macedonia, Romania and Serbia further demonstrates that even major cyber incidents do not always prompt corporate intervention.

The findings enhance the literature by developing a multi-level explanatory framework for understanding Big Tech engagement in cyber crises, and by conceptualising these firms as quasi-sovereign actors whose decisions reflect strategic selectivity rather than neutral service provision. This perspective challenges assumptions that private-sector involvement in cybersecurity is universally accessible or evenly distributed.

The study also highlights important policy implications. While Big Tech involvement can significantly enhance national cyber resilience, it may also lead to long-term dependencies and raise concerns about digital sovereignty, accountability, and governance. Countries lacking access to such support may remain disproportionately vulnerable, while those relying heavily on external providers risk losing strategic autonomy in cybersecurity decision-making.

Overall, the findings highlight an increasingly complex and uneven landscape of cyber resilience, in which private corporations play a growing yet selective role. Addressing this imbalance requires not only enhanced national capacity but also clearer frameworks for regulating and institutionalising public-private cooperation in cybersecurity.

Notes

[1] AI Disclosure Statement

When preparing this article, the author used ChatGPT (GPT-5.4) on 27 March 2026 with the following prompt: “Please evaluate the attached paper,” to review the paper. The author subsequently reviewed and edited the output as necessary and accepts full responsibility for the content and integrity of the publication.

DOI: https://doi.org/10.2478/cmc-2026-0018 | Journal eISSN: 2463-9575 | Journal ISSN: 2232-2825
Language: English, Slovenian
Page range: 33 - 51
Published on: Sep 30, 2026
Published by: General Staff of the Slovenian Armed Forces
In partnership with: Paradigm Publishing Services
Publication frequency: 4 issues per year

© 2026 Tal Pavel, published by General Staff of the Slovenian Armed Forces
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 License.