Nineteen startups in eleven countries
The mapping of early-stage cybersecurity startups across Southeast Europe, and why only two confirmed active product startups sit in Serbia.
I went looking for the early-stage cybersecurity startup scene in Southeast Europe and the Balkans, expecting to find something thin. What I found was thinner than that: across eleven countries, roughly nineteen early-stage companies that are genuinely building a cybersecurity product. In Serbia, two confirmed active product startups.
The number needs a definition, because the definition is where most regional counts go wrong. I was not counting integrators, resellers, managed service providers, consultancies, or outsourcing shops with a security practice. Those exist in real numbers and they employ a lot of very good people. I was counting companies whose own product is the thing they sell.
That distinction matters because the two paths need completely different support. A services company needs clients and a pipeline. A product company needs design partners, patient capital, and a first reference customer willing to be named. Programs in the region are mostly built for the first and then surprised when the second does not appear.
Why so few? Three reasons keep showing up in conversations. The first is that security expertise here sits inside banks, telcos, and large integrators, where compensation is good and the risk of leaving is high, so the people most capable of founding a product company are the least likely to. The second is that the local market is too small to validate against and the enterprise buyers who could validate you demand references you cannot have yet. The third is that almost nobody has seen a regional peer do it, which loops back to the first two.
The uncomfortable implication for anyone designing programs: an accelerator cohort call aimed at cybersecurity startups in this region will not fill from the existing pool, because the pool is nineteen companies wide and most are not at your stage. You either widen the definition, which quietly turns your security program into a general tech program, or you go upstream and create founders instead of recruiting them.
Upstream is slower and it is the only honest option. It looks like student camps that put real offensive and defensive work in front of people early, meetups where practitioners show what they actually shipped, sector-specific rooms where CISOs say out loud what they would buy, and alliances that let a two-person company stand next to a bank without being dismissed.
Upstream work has a measurement problem, which is why so few organizations choose it. You cannot report founders created this quarter. What you can report is how many people did serious hands-on security work for the first time, how many practitioners presented real production experience to a room instead of a vendor deck, and how many enterprise buyers said out loud what they would actually purchase. Those are leading indicators of a pipeline, and they are the only ones available at this stage.
The other thing worth saying plainly: the region's strongest security people are not missing, they are employed. Any serious attempt at building a product pipeline here has to make it thinkable for a senior person inside a bank or a telco to spend two evenings a week on something of their own, without it looking like disloyalty. That is a cultural problem more than a financial one, and it is solved by visible examples rather than by grants.
What would change my number? A first regional product company with a named enterprise reference outside its home market. That single event does more for the count than any cohort, because it converts an abstract possibility into a thing a colleague did.
I keep publishing the number because it reframes the conversation. The regional problem is not that our startups cannot compete. It is that there are almost no startups to compete, and that is a pipeline problem with a decade-long horizon. Better to name it than to keep announcing programs for companies that do not exist yet.
If you are building a security product anywhere in the region, or you know someone who is, tell me. I would genuinely like the number to be wrong.
Reply
If any of this is wrong, or right in a way you can add to, I would rather hear it. Write to antanaskoviczarko@gmail.com or find me on LinkedIn.